Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchEvilTokens abused Microsoft’s legitimate device-code sign-in flow to take over organizational accounts without asking victims to give the phisher their passwords. A victim could visit Microsoft’s genuine sign-in page, enter a code, and still authorize a session started by an attacker. Microsoft reported that the EvilTokens service was disrupted on September 22, 2026, but the underlying technique remains a risk wherever device-code sign-in is available and insufficiently controlled.
What is device-code phishing?
Device-code authentication is a legitimate OAuth sign-in method for devices with limited interfaces, such as smart TVs, printers, Teams devices, and conferencing equipment. The device displays a short code; its user enters that code on a different device, usually in a browser, and completes sign-in there.
In device-code phishing, the attacker starts the sign-in request and then persuades a victim to complete it. The victim’s approval binds the account to the attacker’s pending request—not necessarily to a device or activity the victim intended to authorize. Because the person may use Microsoft’s real device-login site and never disclose a password to the phisher, advice focused only on spotting fake login pages or protecting passwords does not address this attack.
The flow also changes what multi-factor authentication (MFA) protects. A victim may complete the normal authentication steps, including MFA, while the attacker receives the resulting authenticated session. Microsoft describes the decoupled flow as a way attackers can circumvent traditional MFA protections; MFA is not a guarantee against a victim approving an attacker-initiated sign-in.
Recommended Free Tools
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
How did the EvilTokens attack work?
Microsoft’s April 6, 2026 campaign analysis describes a phishing page that could obtain a live device code near the time a victim arrived, rather than relying on a code embedded in an email well in advance. Microsoft says a device code is valid for 15 minutes. Generating it near the victim’s visit avoids the risk that it will expire before the victim acts. The attacker’s service checked the sign-in request’s status while the victim completed Microsoft’s ordinary flow.
This timing is important for defense: a genuine Microsoft sign-in page does not establish that the sign-in was initiated by the person using it. The meaningful question is whether the device-code request and resulting session match an expected user, app, device, and business purpose.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What Microsoft reported about the service
Microsoft Threat Intelligence reported on September 22, 2026, that EvilTokens was a phishing-as-a-service platform associated with threat actor Storm-2992. It used AI-assisted phishing infrastructure as well as device-code authentication abuse. Microsoft said campaigns affected more than 12,000 inboxes in over 10,000 organizations worldwide. The sectors it named included wholesale distribution, construction, financial services, real estate, higher education, and healthcare; its highest observed victim concentrations were in the United States, Canada, the United Kingdom, Australia, India, and France.
Microsoft’s Digital Crimes Unit and partners facilitated a coordinated disruption of infrastructure used to operate EvilTokens. That is Microsoft’s reported status for the service as of September 22, 2026; it does not mean device-code phishing as a technique has ended.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What can an attacker do after taking over an account?
Microsoft reported that EvilTokens users could access victims’ email and refresh captured tokens. The service could scan inboxes for keywords and use AI assistants to summarize or translate messages, identify financial conversations and organizational roles, and find trusted relationships or potential impersonation targets.
Reported post-compromise activity included mailbox exfiltration, malicious inbox rules intended to conceal communications, Microsoft Graph reconnaissance, and, in some cases, registering devices to establish persistence. Microsoft’s April campaign analysis describes examples in which some persistence actions occurred within minutes while other activity was delayed for hours. Those are observed examples, not a guaranteed sequence or timing.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What should Entra administrators investigate?
Look for device-code sign-ins that are unexpected for the user, application, resource, device context, or location, especially when followed by suspicious token activity or mailbox changes. Microsoft’s September 2026 EvilTokens article maps relevant behaviors to Defender for Identity and Defender XDR detections and hunting guidance. Treat an alert as a lead to investigate, not proof by itself that EvilTokens was involved.
- Device-code authentication followed by anomalous token exchange or refresh activity.
- Unfamiliar device registrations, particularly when they follow an unexpected sign-in.
- Unexpected Microsoft Graph activity, mailbox access, or mailbox exfiltration.
- Suspicious inbox rules, forwarding, or other changes that could hide or redirect messages.
- Unexpected device-code use by privileged users, emergency access accounts, unfamiliar apps, or from unusual locations.
Microsoft Entra sign-in logs distinguish Authentication protocol = Device code flow from Original transfer method = Device code flow. The first can identify a sign-in using the flow; the second can help identify later sign-ins or token refreshes linked to an earlier device-code session. Review both when investigating related activity.
Best Value
- Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
- Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
- Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
- Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
- For the driver download and user guide, please visit TrustKey Solutions Home support page.
How can you block device-code flow without breaking legitimate work?
Microsoft’s official guidance states: “Microsoft recommends blocking device code flow wherever possible.” A tenant-wide block may disrupt legitimate dependencies, so first establish which users, apps, resources, locations, and devices actually rely on it. Microsoft identifies Azure CLI, developer tools, admin tools, and legacy command-line workflows as possible non-Teams dependencies.
| Option | When it fits | What to validate |
|---|---|---|
| Block device-code flow | Use where inventory shows no necessary dependency, or after dependencies have migrated. | Check sign-in logs and Conditional Access report-only results for expected effects before enforcement. |
| Migrate the dependency | Prefer this when a tool or workflow can use browser-based or brokered sign-in, a managed identity, or workload identity federation instead. | Confirm the replacement works for the app and its users, then document the change and reassess the need for an exception. |
| Keep a narrowly scoped exception | Use only when a documented business dependency still requires device-code flow. | For Teams device scenarios, Microsoft’s guidance recommends a narrowly scoped exception for the Teams device resource account; it also calls out excluding Device Registration Service where the policy requires it. Validate the policy and sign-in results, and avoid broad user exclusions. |
Microsoft’s Teams-specific Conditional Access guidance recommends testing with report-only policy results and reviewing sign-in logs. Keep an exception tied to a known business owner and the required app or resource, location, and device context. Revisit it as dependencies change; do not treat an exception as a permanent substitute for migration or monitoring.
What should you do if you suspect a takeover?
Follow your organization’s incident-response process and investigate the affected identity, sessions, mailbox, and devices. Revoke affected sessions and tokens as part of containment; Microsoft’s public EvilTokens explainer warns that access could persist after a password reset if associated sessions and tokens were not also revoked.
- Review mailbox rules, forwarding, and affected mailbox content for concealment, redirection, or exposure.
- Check device registrations and related OAuth, token, and Microsoft Graph activity.
- Investigate related accounts and activity, including any signs of impersonation or access to financial conversations.
- Use Microsoft’s current Defender guidance to investigate and remediate the observed activity.
Can Token Protection stop device-code phishing?
Token Protection is one part of Microsoft’s broader guidance for reducing attack surface, detecting and mitigating token theft, and protecting against token replay. Microsoft says the feature can cryptographically bind supported refresh tokens to a device, but coverage is limited to supported applications and platforms and applies only to the user signed in on the device. Check current support for the specific app, platform, and identity scenario before relying on it. It complements restricting unnecessary device-code flow and monitoring; it does not replace either control.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesQuick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

