Media Summary: Dirk-Jan Mollema (Outsider Security) Microsoft Entra ID (formerly Azure AD) offers many options to harden your tenant against ... Become an Entra Security Black Belt in 60 Minutes: Security Alert: Hackers don't hack anymore—they log in. In this video, Mohamed Morsy (Co-Founder of FrontierZero) breaks down one of the ...

Device Code Phishing Primary Refresh - Detailed Analysis & Overview

Dirk-Jan Mollema (Outsider Security) Microsoft Entra ID (formerly Azure AD) offers many options to harden your tenant against ... Become an Entra Security Black Belt in 60 Minutes: Security Alert: Hackers don't hack anymore—they log in. In this video, Mohamed Morsy (Co-Founder of FrontierZero) breaks down one of the ... Azure AD authentication offers multiple methods based on tenant and user configuration. While these methods can be enforced to ... Azure and every cloud providers are powerful computing solutions, but misconfigurations, if not handled properly, can be ... This is a snippet from PwnedLab's new lab - "Leverage

Hello everyone welcome back in this video we will be talking about a technique called Join hosts Brandon and John as they discuss: How In this video, we take a deep technical look at

Photo Gallery

Device Code Phishing, Primary Refresh Tokens, and STORM-2372
Phishing The  Resistant: Phishing For Primary Refresh Tokens In Microsoft Entra - Dirk-Jan Mollema
How to Stop Device Code Flow Attacks in Entra [Phishing Defense]
Device Code Login Phishing Presentation Attack, Detect, Mitigate
How we Hacked a Microsoft 365 Account in 10 Minutes — Device Code Attack Explained
Device Code Phishing Is Dead, Long Live New Azure AD Attacks! - Elias Issa
180 SECONDS TO EXPLAIN A CLOUD ATTACK: DEVICE CODE PHISHING
Hacking Azure: Device Code Phishing! - [Educational Purposes Only]
18. Initial Access using Device code phishing
YOU NEED TO BLOCK THIS (Device Code Auth in M365)
Tradecraft Tuesday | We Need to Talk About Device Code Phishing
Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook
View Detailed Profile
Device Code Phishing, Primary Refresh Tokens, and STORM-2372

Device Code Phishing, Primary Refresh Tokens, and STORM-2372

Recorded live at RSAC 2026, Principal

Phishing The  Resistant: Phishing For Primary Refresh Tokens In Microsoft Entra - Dirk-Jan Mollema

Phishing The Resistant: Phishing For Primary Refresh Tokens In Microsoft Entra - Dirk-Jan Mollema

Dirk-Jan Mollema (Outsider Security) Microsoft Entra ID (formerly Azure AD) offers many options to harden your tenant against ...

How to Stop Device Code Flow Attacks in Entra [Phishing Defense]

How to Stop Device Code Flow Attacks in Entra [Phishing Defense]

Become an Entra Security Black Belt in 60 Minutes: https://eu1.hubs.ly/H0wc0380 Security Alert:

Device Code Login Phishing Presentation Attack, Detect, Mitigate

Device Code Login Phishing Presentation Attack, Detect, Mitigate

A couple weeks ago, I explored

How we Hacked a Microsoft 365 Account in 10 Minutes — Device Code Attack Explained

How we Hacked a Microsoft 365 Account in 10 Minutes — Device Code Attack Explained

Hackers don't hack anymore—they log in. In this video, Mohamed Morsy (Co-Founder of FrontierZero) breaks down one of the ...

Device Code Phishing Is Dead, Long Live New Azure AD Attacks! - Elias Issa

Device Code Phishing Is Dead, Long Live New Azure AD Attacks! - Elias Issa

Azure AD authentication offers multiple methods based on tenant and user configuration. While these methods can be enforced to ...

180 SECONDS TO EXPLAIN A CLOUD ATTACK: DEVICE CODE PHISHING

180 SECONDS TO EXPLAIN A CLOUD ATTACK: DEVICE CODE PHISHING

Azure and every cloud providers are powerful computing solutions, but misconfigurations, if not handled properly, can be ...

Hacking Azure: Device Code Phishing! - [Educational Purposes Only]

Hacking Azure: Device Code Phishing! - [Educational Purposes Only]

This is a snippet from PwnedLab's new lab - "Leverage

18. Initial Access using Device code phishing

18. Initial Access using Device code phishing

Hello everyone welcome back in this video we will be talking about a technique called

YOU NEED TO BLOCK THIS (Device Code Auth in M365)

YOU NEED TO BLOCK THIS (Device Code Auth in M365)

Attackers increasingly try to phish "

Tradecraft Tuesday | We Need to Talk About Device Code Phishing

Tradecraft Tuesday | We Need to Talk About Device Code Phishing

OAuth

Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook

Device Code, OAuth, PhaaS: How Session Token Theft is Breaking the Phishing Playbook

Join hosts Brandon and John as they discuss: • How

How Device Code Phishing Works (Kali365 & FBI Warning)

How Device Code Phishing Works (Kali365 & FBI Warning)

In this video, we take a deep technical look at