Device code authentication is a legitimate Microsoft flow for devices with limited interfaces, like a smart TV or a printer, that cannot support a standard interactive login: the device displays a short code, and the user enters it in a browser on a separate device to finish signing in. Device code phishing abuses that flow. The user reaches microsoft.com through a lure, but the sign-in itself is a real Microsoft flow, with a real password prompt and real MFA. The code is real too, requested from Microsoft by the attacker for a session the attacker started, so entering it signs the attacker in rather than a device of the user's own. Microsoft's April 2026 research documented campaigns running this at scale.

DefensX now cuts the flow off at the browser. Under Management → Settings → SaaS Restrictions, Device Code Authentication Restriction blocks web-initiated Microsoft device code authentication, which is Microsoft's own recommendation wherever the flow is not required.

Organizations that still need web-based device code sign-in for specific sites can list those domains, with wildcards such as *.example.com supported. Everything else is blocked, so a code arriving from a phishing page has nowhere to be used.
For configuration details, see the SaaS Restrictions knowledge base article.
This feature is available in extension version v4.2.221 / v4.3.221 or later.