Two messages, one difference

The link really is microsoft.com. Does that make the code request real?

No. A real domain does not settle it. In a device-code sign-in, the page really is Microsoft, but the question is who started the sign-in. A code someone else hands you to enter is theirs, not yours.

Two messages. One difference.

A sign-in you started QUIET
illustrative example
EXHIBIT · PASTED MESSAGE
Received via: On screen EN
You started signing in to Microsoft 365 on a new laptop. Enter the code shown on your screen at microsoft.com to finish. If this was not you, you can close this.

Illustrative example of the pattern, not a real message someone received.

A code someone hands you WORTH A CHECK
illustrative example
EXHIBIT · CHECK BEFORE YOU ENTER YOUR PASSWORD.
Received via: Chat EN
Hi, I am sharing a meeting document with you. Please go to microsoft.com/devicelogin, enter this code 9823-4471 to verify, then send me the code back to confirm. Do it in the next few minutes or the invite expires.

Illustrative example of the pattern, not a real message someone received.

The one difference

Both point at the real microsoft.com. In the first, you started the sign-in and the code is on your own screen. In the second, someone else started it and hands you the code to enter. The domain is the same, only who started it changed.

The link really is microsoft.com. Isn't a real domain enough?

No. A real domain only tells you the page is genuine, not that the request is. Device-code sign-in happens on the real site by design, which is exactly why the domain cannot settle it.

Is code-on-a-real-page phishing actually a thing?

Yes. Anthropic's September 2026 threat report describes a campaign whose primary technique was device-code phishing that abused legitimate sign-in flows for cloud email services, on the real provider's pages.

What should I actually check?

Who started this sign-in. If you did not begin it yourself, a code someone sends you is theirs, and entering it can hand them into your account. Only enter a code you requested, shown on your own screen.

What to do

  • Only enter a sign-in code you started yourself and that appears on your own screen.
  • Never enter or send back a code that someone else gave you, even if the page is the real Microsoft site.
  • If someone pushes a code plus a deadline, stop. Open Microsoft yourself and check your recent sign-in activity.

Common questions

The page is really microsoft.com, so it must be fine to enter the code, right?

Not on that basis alone. The real page is used in device-code sign-in by design. What matters is whether you started the sign-in, not whether the domain is real.

Someone sent me a Microsoft link and a code to enter to join a meeting. Should I?

No. A code another person hands you is theirs. Entering it can authorize their session, not yours. Join meetings from your own calendar or app instead.

How can a real sign-in page be used against me?

A device-code flow lets one device approve another. If you enter a code someone else generated, you can approve their access. That is why you only enter a code you requested.

Not sure about a message?

Check a message you are not sure about

Detection runs 100% locally on your device. We store nothing.

Related reading

Source: Anthropic, "Detecting and countering misuse of AI: September 2026"