
COMING SOONIntermediate
Entra ID Device Code Phishing: Token Theft
A Microsoft 365 user at a financial services firm receives a convincing phishing email asking her to enter a device code at the legitimate Microsoft devicelogin page. The code completes the attacker's OAuth request, handing over a valid token. Working through Entra sign-in logs, Graph audit events, and the email trail, trace how the token was stolen and what the attacker read from the victim's mailbox.
45m
7 tasks
50 points
FreeLaunches in 4 days
Aug 11, 2026
Create your free accountTuesday, August 11, 2026 at 9:00 AM
Be ready the moment it drops, free.
Training Tools
CloudSIEMEmail
What you'll investigate
7 objectives unlock when this operation goes live.
1Identify the compromised account
2Name the authentication anomaly
3Locate the attacker's first IP
4Name the rogue application
5Identify the phishing sender domain
6Trace what data the attacker accessed
7Classify the credential theft technique
Be first when it launches
Create your free account now. The moment this operation goes live on Aug 11, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.
Get Started Free