The link really is microsoft.com. Does that make the code request real?
No. A real domain does not settle it. In a device-code sign-in, the page really is Microsoft, but the question is who started the sign-in. A code someone else hands you to enter is theirs, not yours.
Two messages. One difference.
Illustrative example of the pattern, not a real message someone received.
Illustrative example of the pattern, not a real message someone received.
The one difference
Both point at the real microsoft.com. In the first, you started the sign-in and the code is on your own screen. In the second, someone else started it and hands you the code to enter. The domain is the same, only who started it changed.
The link really is microsoft.com. Isn't a real domain enough?
No. A real domain only tells you the page is genuine, not that the request is. Device-code sign-in happens on the real site by design, which is exactly why the domain cannot settle it.
Is code-on-a-real-page phishing actually a thing?
Yes. Anthropic's September 2026 threat report describes a campaign whose primary technique was device-code phishing that abused legitimate sign-in flows for cloud email services, on the real provider's pages.
What should I actually check?
Who started this sign-in. If you did not begin it yourself, a code someone sends you is theirs, and entering it can hand them into your account. Only enter a code you requested, shown on your own screen.
What to do
- Only enter a sign-in code you started yourself and that appears on your own screen.
- Never enter or send back a code that someone else gave you, even if the page is the real Microsoft site.
- If someone pushes a code plus a deadline, stop. Open Microsoft yourself and check your recent sign-in activity.
Common questions
The page is really microsoft.com, so it must be fine to enter the code, right?
Not on that basis alone. The real page is used in device-code sign-in by design. What matters is whether you started the sign-in, not whether the domain is real.
Someone sent me a Microsoft link and a code to enter to join a meeting. Should I?
No. A code another person hands you is theirs. Entering it can authorize their session, not yours. Join meetings from your own calendar or app instead.
How can a real sign-in page be used against me?
A device-code flow lets one device approve another. If you enter a code someone else generated, you can approve their access. That is why you only enter a code you requested.
Not sure about a message?
Check a message you are not sure about
Detection runs 100% locally on your device. We store nothing.
Related reading
Source: Anthropic, "Detecting and countering misuse of AI: September 2026"