Skip to main content
Entra ID Device Code Phishing: Token Theft operation cover
COMING SOONIntermediate

Entra ID Device Code Phishing: Token Theft

A Microsoft 365 user at a financial services firm receives a convincing phishing email asking her to enter a device code at the legitimate Microsoft devicelogin page. The code completes the attacker's OAuth request, handing over a valid token. Working through Entra sign-in logs, Graph audit events, and the email trail, trace how the token was stolen and what the attacker read from the victim's mailbox.

45m
7 tasks
50 points
Free

Launches in 4 days

Aug 11, 2026

Tuesday, August 11, 2026 at 9:00 AM

Create your free account

Be ready the moment it drops, free.

Training Tools

CloudSIEMEmail

What you'll investigate

7 objectives unlock when this operation goes live.

1Identify the compromised account
2Name the authentication anomaly
3Locate the attacker's first IP
4Name the rogue application
5Identify the phishing sender domain
6Trace what data the attacker accessed
7Classify the credential theft technique

Be first when it launches

Create your free account now. The moment this operation goes live on Aug 11, 2026, you can jump straight in — and you'll have the rest of the catalog to train on meanwhile.

Get Started Free