Recently we held an internal EntraIDiots CTF where the challenge “HelloThere” required the CTF contestant to device-code phish a user. Then use the acquired refreshtokens to register a device, ...