IT Network Support That Stops the Phishing Attack Your MFA Can't Catch

IT Network Support That Stops the Phishing Attack Your MFA Can't CatchThe fastest growing phishing technique of 2026 does not try to steal a password or bombard an employee's phone with approval requests until someone taps yes. It tricks a person into approving a real Microsoft sign in on a real Microsoft page, using a method called device code phishing, and industry tracking now shows it has overtaken classic credential harvesting as the leading technique behind Microsoft 365 account takeovers. For Central Texas business owners, that means the multi-factor authentication you already trust may not close the gap by itself, and the right IT network support partner needs to be watching for this exact blind spot in 2026.

What Is at Stake

A single approved device code can hand an attacker a live, MFA verified session without ever touching a password.

Device code phishing works because it does not look like an attack. An employee gets an email that looks like a shared document, a calendar invite, or a Teams meeting request. It asks them to enter a short code at a genuine Microsoft address to confirm access. The employee is not typing a password into a fake page. They are authorizing a real Microsoft login, and the attacker on the other end receives full access to that account, including email, files, and anything connected through single sign on.

Weekly tracking from phishing kit researchers found OAuth device code abuse rose sharply during the last full week of July 2026, with kits like EvilTokens and Kali365 built specifically around this technique. Kali365 alone is sold as a subscription service and was flagged in a federal advisory earlier this year. These kits let low skill attackers run the same attack that once required a custom built phishing infrastructure. Once inside, the financial exposure is real. National data shows business email compromise cost companies more than three billion dollars in a single recent year, most of it moving through wire transfers and payroll redirects that started with exactly this kind of quiet account takeover.

Why Central Texas Businesses Face This Challenge

Austin's dense tech and professional services sector makes local companies efficient targets, and a breach anywhere in the vendor chain can reach a business that never clicked anything.

Attackers are not guessing at random businesses. They are running these campaigns at scale against Microsoft 365 tenants everywhere, and a growing tech and professional services base in Austin, combined with the number of construction, real estate, and healthcare firms across New Braunfels and Round Rock that depend on email for daily operations, makes Central Texas a productive hunting ground. Smaller companies are often the easiest targets because they run lean IT teams without the budget for dedicated security monitoring. One Central Texas company recently paid twenty five thousand dollars just to get its data back after an attack, and most small businesses in Texas still carry no cyber insurance at all to soften that kind of loss.

The problem is compounded by a false sense of security. Many owners believe that once MFA is turned on, the account is protected. Device code phishing proves that assumption wrong, because it does not try to defeat MFA. It asks the user to complete it voluntarily, on a legitimate Microsoft screen, for what looks like an ordinary work request.

How CTTS Helps You Shut Down Device Code Phishing

Closing this gap takes configuration changes most businesses have never heard of, paired with monitoring that catches the sign ins that do not belong.

CTTS approaches this the same way we approach every identity risk, by combining policy, technology, and a human layer that can catch what the technology misses.

First, we restrict device code sign ins through Conditional Access, so this authentication path is blocked entirely for accounts that have no legitimate reason to use it, which is the majority of a typical office staff. Second, we move privileged accounts, meaning finance, executives, and anyone with payment authority, onto phishing resistant MFA using hardware keys or platform passkeys, so even if a device code request slips through, the account behind it is bound to a physical device an attacker cannot reach. Third, we monitor sign in and Graph API activity for the specific fingerprints of this attack, including device code logins from unfamiliar devices, new inbox forwarding rules, and unexpected OAuth application approvals, so a compromise gets caught in minutes rather than weeks. Fourth, we update security awareness training so employees recognize a device code request for what it is, an unusual and rarely legitimate ask, rather than a routine step in opening a shared file.

IT Network Support Best Practices for Closing the Device Code Phishing Gap

What Is Device Code Phishing?

Device code phishing is an attack where a victim is tricked into entering a short code on a genuine Microsoft or Google login page, which hands the attacker a fully authenticated session without any password ever being stolen or typed into a fake site. Unlike classic phishing, there is no fake login page to spot and no password to protect, which is exactly what makes it so effective against businesses that think MFA alone has them covered.

How Do You Know If Conditional Access Is Blocking This?

The only reliable way to know is to check your tenant's Conditional Access policies directly, since device code sign in is enabled by default in Microsoft 365 and stays that way until someone turns it off. Most businesses have never reviewed this setting because it rarely comes up in a general IT support conversation. A quick audit of your Entra ID Conditional Access policies will show whether device code flow is currently open to every user in your organization.

Restrict Device Code Sign Ins With Conditional Access

Set a Conditional Access policy that blocks the device code authentication flow for all users except the specific service accounts or command line tools that genuinely require it. This single change removes the entire attack path for the vast majority of employees without disrupting how they work day to day.

Move Privileged Accounts to Phishing Resistant MFA

Push notifications and text message codes can be approved by mistake or under pressure. Hardware security keys and platform passkeys cannot, because they are cryptographically tied to the real Microsoft session and simply will not work on an attacker's device, even if an employee is fooled.

Watch Sign In Logs for Anomalies

Look for device code sign ins from devices or locations your team does not normally use, sudden new mail forwarding rules, and OAuth application consent grants nobody remembers approving. These are the fingerprints this attack leaves behind, and catching them early is often the difference between a blocked login attempt and a six figure wire fraud loss.

Take the Next Step

If you are not certain whether device code sign in is open on your Microsoft 365 tenant right now, that uncertainty is the risk. CTTS can run a focused review of your Conditional Access policies, sign in logs, and MFA coverage, and show you exactly where this gap exists in your environment.

Reach out to schedule a conversation about IT network support built around the threats businesses are actually facing in 2026, not the ones from two years ago.

Frequently Asked Questions

Is device code phishing different from MFA fatigue or push bombing attacks?

Yes. MFA fatigue relies on flooding a phone with approval requests until someone taps yes out of frustration, while device code phishing asks the user to voluntarily enter a code on a genuine login page as part of what looks like a normal work task, so it does not trigger the repeated push notifications that make MFA fatigue noticeable.

Can Conditional Access really stop this on its own?

Conditional Access is the single most effective control because it can block the device code sign in path entirely for users who have no legitimate reason to use it, closing off the attack before it ever reaches an employee's inbox, though it works best paired with phishing resistant MFA on privileged accounts and active monitoring of sign in logs.

What does managed IT network support cost for a business with 25 to 250 employees in Central Texas?

Pricing depends on user count, current infrastructure, and the level of security monitoring required, but most Central Texas businesses in this range invest in managed IT network support as a predictable monthly cost rather than facing the unpredictable expense of a breach, and CTTS can provide a specific quote after a short assessment of your environment.


Contact CTTS today for IT support and managed services in Austin, TX. Let us handle your IT so you can focus on growing your business. Visit CTTSonline.com or call us at (512) 388-5559 to get started!