attacking-oauth-with-device-code-phishing - Assess OAuth device-code phishing in Entra ID
Conduct authorized testing of OAuth device-code and illicit-consent phishing against Microsoft Entra ID and assess token theft, MFA bypass, and cloud access risks.
Tags
Updated: 2026-09-29device-code-phishingoauthentra-idtoken-theftmfa-bypassillicit-consentred-teamidentity-access-management
Capabilities
Typical Inputs
What this skill does
- Initiate device-code requests
- Deliver authorized phishing pretexts
- Poll token endpoints
- Capture OAuth tokens
- Refresh Microsoft 365 tokens
- Test illicit consent grants
- Enumerate accessible resources
- Document findings and remediation
Inputs
- Written authorization and rules of engagement
- Target Entra ID tenant
- Sanctioned delivery channel
- Attacker host
- TokenTactics installation
- ROADtools installation
- OAuth client and scope configuration
Outputs
- Device-code request responses
- OAuth access and refresh tokens
- Microsoft 365 resource access
- Resource enumeration results
- Assessment findings and remediation recommendations
Requirements
- Authorized security-testing scope
- Linux or Windows host
- Python 3.8 or later
- PowerShell 7 or later
- TokenTactics
- ROADtools
