---
title: How Microsoft Entra Conditional Access Stops AI Phishing Attacks
description: Learn how Microsoft Entra Conditional Access blocks AI-driven device code phishing and protects identities from modern token theft attacks.
---

[![looking-point_LogoWhite _ Presidio-1](https://www.lookingpoint.com/hubfs/looking-point_LogoWhite%20_%20Presidio-1.svg) ![LOOKINGPOINT](https://www.lookingpoint.com/hs-fs/hubfs/Theme%20Oct%202019/images/logo@mobile.png?width=444&height=86&name=logo@mobile.png) ](https://www-lookingpoint-com.sandbox.hs-sites.com/-temporary-slug-c10ae2f5-f23e-43f2-8214-f73884fb09ae)

- [Solutions](https://www.lookingpoint.com) 
    - [Collaboration](https://www.lookingpoint.com/it-solutions-collaboration)
    - [Security ](https://www.lookingpoint.com/it-solutions-security)
    - [Networking ](https://www.lookingpoint.com/it-solutions-networking)
    - [Data Center ](https://www.lookingpoint.com/data-center)
    - [Cloud](https://www.lookingpoint.com/cloud)
    - [Managed Services](https://www.lookingpoint.com/it-support-services)
    - [Lifecycle Management](https://www.lookingpoint.com/lifecycle-management-acela)
- [Services](https://www.lookingpoint.com/en/solutions-services) 
    - [Assess and Design ](https://www.lookingpoint.com/assess-and-design-it-solutions)
    - [Deployment](https://www.lookingpoint.com/deployment-it-services-solutions)
    - [Support](https://www.lookingpoint.com/it-support-services)
    - [Wireless Surveys Assessments](https://www.lookingpoint.com/en-us/wireless-surveys-assessments)
    - [Project Management ](https://www.lookingpoint.com/project-management)
    - [Integration Center](https://www.lookingpoint.com/integration-services)
    - [Lifecycle Support](https://www.lookingpoint.com/it-lifecycle-support)
    - [Locations Serviced](https://www.lookingpoint.com/it-consulting-san-francisco-bay-area)
    - [Customer Success](https://www.lookingpoint.com/services-customer-success)
- [Partners](https://www.lookingpoint.com/partner)
- [Blog](https://www.lookingpoint.com/blog)

- [Solutions](https://www.lookingpoint.com) 
    - [Collaboration](https://www.lookingpoint.com/it-solutions-collaboration)
    - [Security ](https://www.lookingpoint.com/it-solutions-security)
    - [Networking ](https://www.lookingpoint.com/it-solutions-networking)
    - [Data Center ](https://www.lookingpoint.com/data-center)
    - [Cloud](https://www.lookingpoint.com/cloud)
    - [Managed Services](https://www.lookingpoint.com/it-support-services)
- [Services](https://www.lookingpoint.com/en/solutions-services) 
    - [Assess and Design](https://www.lookingpoint.com/assess-and-design-it-solutions)
    - [Deployment](https://www.lookingpoint.com/deployment-it-services-solutions)
    - [Support](https://www.lookingpoint.com/it-support-services)
    - [Wireless Survey Assessment](https://www.lookingpoint.com/en-us/wireless-surveys-assessments)
    - [Project Management ](https://www.lookingpoint.com/project-management)
    - [Lifecycle Management](https://www.lookingpoint.com/lifecycle-management-acela)
    - [Integration Center](https://www.lookingpoint.com/integration-services)
    - [Locations Serviced](https://www.lookingpoint.com/it-consulting-san-francisco-bay-area)
    - [Customer Success](https://www.lookingpoint.com/services-customer-success)
- [Partners](https://www.lookingpoint.com/partner)
- [Blog](https://www.lookingpoint.com/blog)
- [+1 925-566-3480](tel:+1%20925-566-3480)
- [DO NOT SHARE OR SELL MY PERSONAL INFORMATION](https://na1.hs-data-privacy.com/request/TrvvEe3VpnlESmYolHn3xw)

- [![phone@2x](https://www.lookingpoint.com/hubfs/Theme%20Oct%202019/fonts/phone@2x.png) +1 925-566-3480 ](tel:+19255663480)
- [![user@2x](https://www.lookingpoint.com/hubfs/Theme%20Oct%202019/fonts/user@2x.png) Acela Portal ](https://my.lookingpoint.com/)
- [Free Consultation](https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks#get-free-popup)

 Let’s Connect

[Home](https://www.lookingpoint.com/) [Blog](https://www.lookingpoint.com/blog) How Microsoft Entra Conditional Access Stops AI Phishing Attacks

# Blog

 Jul  8

How Microsoft Entra Conditional Access Stops AI Phishing Attacks

 Posted by [Ryan Alibrando](https://www.lookingpoint.com/blog/author/ryan-alibrando)

[**0](https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks#comments-listing)

** Share

- [**](https://www.facebook.com/sharer/sharer.php?u=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&title=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&picture=&description=Learn%20how%20Microsoft%20Entra%20Conditional%20Access%20blocks%20AI-driven%20device%20code%20phishing%20and%20protects%20identities%20from%20modern%20token%20theft%20attacks.)
- [**](https://twitter.com/intent/tweet?source=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&text=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks)
- [**](https://plus.google.com/share?url=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks)
- [**](http://www.linkedin.com/shareArticle?mini=true&url=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&title=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&summary=Learn%20how%20Microsoft%20Entra%20Conditional%20Access%20blocks%20AI-driven%20device%20code%20phishing%20and%20protects%20identities%20from%20modern%20token%20theft%20attacks.)
- [**](mailto:?subject=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&body=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks%20https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks)

[IT consulting](https://www.lookingpoint.com/blog/topic/it-consulting) [IT Solutions](https://www.lookingpoint.com/blog/topic/it-solutions) [Conditional Access](https://www.lookingpoint.com/blog/topic/conditional-access) [Microsoft Entra ID](https://www.lookingpoint.com/blog/topic/microsoft-entra-id) [Conditional Access Policies](https://www.lookingpoint.com/blog/topic/conditional-access-policies) [Device Code Flow](https://www.lookingpoint.com/blog/topic/device-code-flow) [Device Code Phishing](https://www.lookingpoint.com/blog/topic/device-code-phishing) [Microsoft Entra](https://www.lookingpoint.com/blog/topic/microsoft-entra) [AI Phishing](https://www.lookingpoint.com/blog/topic/ai-phishing) [AI-Driven Phishing](https://www.lookingpoint.com/blog/topic/ai-driven-phishing) [OAuth Token Theft](https://www.lookingpoint.com/blog/topic/oauth-token-theft) [Session Token Theft](https://www.lookingpoint.com/blog/topic/session-token-theft)

# Cover Your Assets: How Microsoft Entra Conditional Access Stops AI-Driven Device Code Phishing

You can spend lots of time meticulously hardening your network perimeter, adjusting firewalls, and making sure your infrastructure is pristine. But the second a user falls for a clever phishing trick, an attacker halfway across the world instantly gets a valid token to walk straight into your corporate cloud. In cybersecurity, we always talk about the importance of **CYA—Covering Your Assets**. But all the asset coverage in the world doesn’t matter if you leave the digital back door wide open for attackers to walk right through.

Historically, we told our teams to watch out for fake login pages that steal passwords. But the threat landscape has changed dramatically. A recent [FBI Public Service Announcement (PSA260521)](https://www.ic3.gov/PSA/2026/PSA260521) warned organizations about an emerging Phishing-as-a-Service platform called **Kali365**.

Distributed on Telegram channels, **Kali365** allows even low-skill attackers to use AI-generated lures that perfectly mimic corporate jargon to bypass Multi-Factor Authentication (MFA) entirely. They don't want your password; they want your **OAuth session tokens**, and they are abusing a legitimate protocol called **Device Code Flow** to get them.

In the modern enterprise landscape, identity is your new perimeter. If you are your company’s cloud assets bouncer, you need a way to say: *"Congratulations, you solved the password riddle. But you're on an unknown computer, outside our corporate network, in a country we've never operated in. You're not getting past the velvet rope."*

That is where **Microsoft Entra Conditional Access Policies** come into play. It is Microsoft’s "if/then" engine for identity security. Let's look at how to architect these filters properly to stop bad actors in their tracks—without interrupting your users.

---

 

**Visualizing Conditional Access: Like Water Filtration**

Think of your corporate identity ecosystem as a stream of raw, incoming water. It contains essential resources your business needs to survive, but it also carries some dirty little debris, sediment, and microscopic pathogens.

If you try to stop everything with one single massive block, you’ll end up filtering out too much or not enough. Instead, layered purpose-built Conditional Access Policies function just like a multi-stage water filtration system.

![How Microsoft Entra Conditional Access Stops AI Phishing Attacks](https://www.lookingpoint.com/hs-fs/hubfs/undefined-Jun-29-2026-10-12-57-0285-PM.png?width=600&height=326&name=undefined-Jun-29-2026-10-12-57-0285-PM.png)

### **Filter 1: The Coarse Mesh (Global Authentication & Basics)**

This first layer catches the largest, most obvious debris. It represents your broad, sweeping organizational baselines.

 

### **Filter 2: The Medium Sediment Filter (Context & Location)**

As the water flows deeper, the pores get smaller. This stage inspects the contextual signals surrounding the login request to catch suspicious elements that slipped through the mesh.

 

### **Filter 3: The Micro-Filter (Device Health & Flow Controls)**

This is the finest layer of defense, designed to trap microscopic pathogens—like session hijacking attempts or unauthorized device code flows—that look like clean water but carry hidden malicious payloads.

---

 

**Let’s Talk About Device Code Flow, and Where is it Used?**

**Device Code Flow** is like logging into Netflix on a smart TV. Because typing with a remote is difficult, the TV gives you a short code to enter into your phone's browser instead. There are plenty of IOT devices without a keyboard or browser, so this method gives us another way to authenticate.

The device displays a unique code (like B2C4D6F8) and directs the user to open a browser on a secondary device (like a smartphone) at https://microsoft.com/devicelogin. The user logs in on their phone, enters the code, and the session token is handed back to the original device.

**Kali365** abuses this. The attacker triggers a device code flow, sends the code to your user via an AI-generated email lure, and tricks them into entering it onto the legitimate Microsoft page. Once the victim approves it, the attacker steals the session token and bypasses MFA completely.

We might not want to just disable it completely though. Device Code Flow can be a vital operational tool. It is commonly found in environments where traditional web-based sign-in forms can’t be used:

---

 

**Staging a "Report-Only" Policy to Block Device Code Flow**

Turning off an entire authentication protocol across an organization can feel like defusing a bomb. If you flip the switch too fast, you risk breaking vital business operations. To prevent these headaches, use Microsoft Entra ID's **Report-only mode**. This evaluates real-time sign-ins against your new rules and logs exactly what *would* have happened—without interrupting a single user.

**Step-by-Step Configuration:**

![How Microsoft Entra Conditional Access Stops AI Phishing Attacks](https://www.lookingpoint.com/hs-fs/hubfs/undefined-Jun-29-2026-10-12-56-6765-PM.png?width=470&height=490&name=undefined-Jun-29-2026-10-12-56-6765-PM.png)

---

 

**Checking on the Report-Only Policy**

After creating your policy, you can go back to policies, select your device code blocking policy and click on “Policy impact” to see how many sign-ins would fail if the policy were on. That should help you decide if you need to add any exceptions or go talk to some people about what they’re doing.

![How Microsoft Entra Conditional Access Stops AI Phishing Attacks](https://www.lookingpoint.com/hs-fs/hubfs/undefined-Jun-29-2026-10-12-56-4233-PM.png?width=485&height=461&name=undefined-Jun-29-2026-10-12-56-4233-PM.png)

** **

**Automatically Auditing Device Code Usage via PowerShell**

Although you could check the portal daily to see who’s using device code flow, you can automate this discovery phase. Because authentication protocol tracking data resides in the advanced sign-in telemetry, you need to call the Microsoft Graph Beta endpoint.

The following PowerShell script leverages the Microsoft.Graph.Beta module to automatically look for any logins that utilized the devicecode protocol within your tenant:

powershell

*# Install the required Beta module if you don't have it*

*# Install-Module Microsoft.Graph.Beta -Scope CurrentUser*

* *

*# Connect to Microsoft Graph with the necessary audit log read permissions*

*Connect-MgGraph -Scopes "AuditLog.Read.All"*

* *

*# Query the Beta Sign-in logs specifically for the Device Code protocol*

*Write-Host "Searching for Device Code Flow authentication events..." -ForegroundColor Cyan*

*$DeviceCodeSignIns = Get-MgBetaAuditLogSignin -Filter "AuthenticationProtocol eq 'devicecode'" -All*

* *

*# Parse and display the results cleanly*

*if ($DeviceCodeSignIns) {*

* $DeviceCodeSignIns | Select-Object CreatedDateTime, UserPrincipalName, AppDisplayName, IPAddress, ClientAppUsed | *

* Out-Gridview -Title "Detected Device Code Flow Sign-ins"*

*} else {*

* Write-Host "No Device Code Flow authentication events detected in the log history." -ForegroundColor Green*

*}*

By mapping out the users, applications, and IP addresses generated by this script, you can gather a complete list of legitimate devices that require a tailored policy exclusion group before flipping your policy toggle from **Report-only** to **On**.

---

 

**Wrapping Up**

Identity security is a continuous process, not a one-time project. Before you start turning things off, you need to understand who or what it will affect. Extra time in planning and testing will be worth it to keep your data safe while keeping your daily operations moving smoothly.

LookingPoint offers multiple IT services if you’re interested. Want more information, give us a call! Please reach out to us at [sales@lookingpoint.com](mailto:sales@lookingpoint.com) and we’ll be happy to help!

[![Contact Us](https://no-cache.hubspot.com/cta/default/2215854/7814218f-8d49-4d01-9a8c-095c00c0b08d.png)](https://cta-redirect.hubspot.com/cta/redirect/2215854/7814218f-8d49-4d01-9a8c-095c00c0b08d)

 Written By:

Ryan Alibrando, Managed Services Team Lead

 SHARE:

- [**](https://www.facebook.com/sharer/sharer.php?u=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&title=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&picture=&description=Learn%20how%20Microsoft%20Entra%20Conditional%20Access%20blocks%20AI-driven%20device%20code%20phishing%20and%20protects%20identities%20from%20modern%20token%20theft%20attacks.)
- [**](https://twitter.com/intent/tweet?source=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&text=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks)
- [**](https://plus.google.com/share?url=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks)
- [**](http://www.linkedin.com/shareArticle?mini=true&url=https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks&title=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&summary=Learn%20how%20Microsoft%20Entra%20Conditional%20Access%20blocks%20AI-driven%20device%20code%20phishing%20and%20protects%20identities%20from%20modern%20token%20theft%20attacks.)
- [**](mailto:?subject=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks&body=How%20Microsoft%20Entra%20Conditional%20Access%20Stops%20AI%20Phishing%20Attacks%20https://www.lookingpoint.com/blog/how-microsoft-entra-conditional-access-stops-ai-phishing-attacks)

### Topics

- [cisco](https://www.lookingpoint.com/blog/topic/cisco)
- [security](https://www.lookingpoint.com/blog/topic/security)
- [cybersecurity](https://www.lookingpoint.com/blog/topic/cybersecurity)
- [Cisco ISE](https://www.lookingpoint.com/blog/topic/cisco-ise)
- [collaboration](https://www.lookingpoint.com/blog/topic/collaboration)
- [ISE](https://www.lookingpoint.com/blog/topic/ise)
- [webex](https://www.lookingpoint.com/blog/topic/webex)
- [IT Solutions](https://www.lookingpoint.com/blog/topic/it-solutions)
- [cisco webex](https://www.lookingpoint.com/blog/topic/cisco-webex)
- [SD-WAN](https://www.lookingpoint.com/blog/topic/sd-wan)

### Latest Tweets **

### subscribe to our blog

## Get New Unique Posts

![looking-point_LogoWhite _ Presidio-1](https://www.lookingpoint.com/hubfs/looking-point_LogoWhite%20_%20Presidio-1.svg)

 391 Taylor Blvd. Suite 120 Pleasant Hill, California 94523

[Call Us +1 925-566-3480](tel:+19255663480)

[sales@lookingpoint.com](mailto:sales@lookingpoint.com)

- [**](https://www.facebook.com/lookingpoint?fref=ts)
- [**](https://twitter.com/lookingpoint)
- [**](https://www.linkedin.com/company/lookingpoint)
- [**](https://www.instagram.com/lookingpoint/)

 SOLUTIONS

- [Collaboration](https://www.lookingpoint.com/it-solutions-collaboration)
- [ Security](https://www.lookingpoint.com/it-solutions-security)
- [Networking ](https://www.lookingpoint.com/it-solutions-networking)
- [Cloud](https://www.lookingpoint.com/cloud)
- [Data Center ](https://www.lookingpoint.com/data-center)
- [Project Management ](https://www.lookingpoint.com/project-management)
- [Lifecycle Management](https://www.lookingpoint.com/lifecycle-management-acela)
- [Wireless Surveys Assessments](https://www.lookingpoint.com/en-us/wireless-surveys-assessments)

 MANAGED SERVICES

- [Assess and Design](https://www.lookingpoint.com/assess-and-design-it-solutions)
- [Deployment](https://www.lookingpoint.com/deployment-it-services-solutions)
- [Support](https://www.lookingpoint.com/it-support-services)
- [Integration Center](https://www.lookingpoint.com/integration-services)
- [Lifecycle Support](https://www.lookingpoint.com/it-lifecycle-support)
- [Locations Serviced](https://www.lookingpoint.com/it-consulting-san-francisco-bay-area)
- [Customer Success](https://www.lookingpoint.com/services-customer-success)

 COMPANY

- [Contact Us](https://www.lookingpoint.com/contact-us)
- [Career](https://www.lookingpoint.com/career)
- [About Us](https://www.lookingpoint.com/about-us)
- [ FAQ](https://www.lookingpoint.com/faq)
- [ Partners](https://www.lookingpoint.com/partner)
- [Blog](https://www.lookingpoint.com/blog)
- [Privacy Policy](https://www.lookingpoint.com/privacy-policy)
- [DO NOT SELL OR SHARE MY PERSONAL INFORMATION](https://na1.hs-data-privacy.com/request/TrvvEe3VpnlESmYolHn3xw)

 GET IN TOUCH

 Join our mailing list to stay up to date and get notices about our new releases!

 Looking Point Inc. 2026

 Cookie Settings