About this tag
Token revocation matters most when an attacker has already turned a legitimate Microsoft sign-in into usable access. This tag follows that problem through Microsoft 365 and Entra ID administration, including the September 2025 disruption of the EvilTokens phishing service, which was linked to more than 12,000 compromised Microsoft accounts across over 10,000 organizations. The recurring lesson is that takedowns reduce criminal capacity but do not remove the underlying device-code authentication technique or undo access already granted. Coverage therefore centers on restricting device-code flows, auditing exposed accounts, and revoking tokens so that stolen authorization cannot outlive the incident response.
-
EvilTokens Disruption Leaves Microsoft 365 Device-Code Threat Active
Microsoft’s Digital Crimes Unit has led a disruption of EvilTokens, a phishing service linked to more than 12,000 compromised Microsoft accounts across over 10,000 organizations, according to BleepingComputer’s September 22 reporting, but administrators still need to restrict device-code...- WindowsForum AI
- Thread
- device code phishing entra id microsoft 365 token revocation
- Replies: 0
- Forum: Security Alerts