Securing Your Law Firm logoSecuring Your Law Firm
Back to resources
Microsoft 365 Security2026-09-29By Securing Your Law Firm

A Real Microsoft Login Page Can Still Lead to a Law Firm Email Compromise

A real Microsoft login page can still authorize an attacker. Learn how device code phishing threatens law firm email and what staff and IT should check.

An employee gets a message about a client document and is asked to enter a code on Microsoft's sign-in page. The page is real. But if an attacker started the sign-in, entering that code may give the attacker access to the employee's account.

This is Microsoft 365 device code phishing. The risk is easy to miss because the web address can be legitimate.

Microsoft's September 22, 2026 EvilTokens report describes campaigns that compromised more than 12,000 inboxes across over 10,000 organizations worldwide. The figures cover multiple industries, not law firms alone.

How the trick works

Device code sign-in is a legitimate option for equipment that is awkward to type on, such as a printer or smart TV. The device shows a short code, and someone enters it in a browser to approve sign-in. Microsoft's device authorization documentation explains the process.

In a phishing attempt, the attacker starts the request and persuades an employee to enter the attacker's code. The employee may see Microsoft's genuine page, but approving the request can authorize the attacker's session without revealing the employee's password.

That is why checking the web address is not enough. MFA still matters, but it cannot make an unexpected approval safe.

What owners and office managers should ask

An email about a shared client file or an account problem can feel routine during a busy day. If an employee approves an attacker's sign-in, the attacker may be able to read correspondence, learn matter details, or use a real email thread to make a payment request more convincing. This is an example of how the technique could affect a firm, not an incident from Microsoft's report.

Ask your IT provider:

  • Do any of our devices or applications need device code sign-in?
  • If not, can the sign-in method be blocked?
  • If yes, which users and applications need it, and who reviews those exceptions?
  • Is the policy actively blocking sign-ins, or is it still in report-only mode?

Microsoft's Conditional Access guidance recommends testing a policy in report-only mode before enforcing it. Report-only mode does not block sign-ins. Ask your provider to confirm licensing, document any exceptions, and show the policy scope and test results. For a broader review, see our Microsoft 365 security checklist for small law firms and MFA verification guide.

Staff should know how to verify and report suspicious requests, not just how to spot a fake web address. Include unexpected code requests in your cybersecurity awareness training, and make sure employees know whom to contact.

If someone has already entered a code

Call your IT provider or administrator using a known number. Share the message and when the code was entered. Don't wait for an unusual email or other visible sign of misuse.

Your provider should investigate the sign-in, contain access, revoke sessions, and check authentication methods, application permissions, and mailbox rules. A password reset alone may not address an approved session. Follow Microsoft's compromised-account response guidance and your firm's incident-response process. Our first-72-hours guide can help owners plan who does what.

Verify the Microsoft 365 controls protecting your firm

Ask for evidence of what is enabled, who it covers, and whether it is enforced. Our Email & Microsoft 365 Security service can review agreed sign-in and mailbox controls in coordination with your existing IT provider. These tenant settings require authorized access; the Free Zero-Access Exposure Review™ checks public information and cannot verify them.

Start by asking your IT provider whether device code sign-in is needed—and how any restriction is verified.

This article is for informational purposes only and does not constitute legal, compliance, or insurance advice.