denniskniep/DeviceCodePhishing ? reverse-engineered prompt
Reverse engineered prompt
Build me a safe educational demo that helps security teams understand the Device Code phishing risk in Azure Entra, especially the note that normal tenants were fixed but federated tenants may still be affected. I want it to feel like the original flow from a user point of view, with a local page that explains what would happen when someone clicks a lure link, then shows the redirect and sign in steps as a simulation only.
Please make it very clear this is for awareness and testing in a lab. It must never capture credentials, request real tokens, automate a real sign in, or send people to a live Microsoft login page. A simple local server with a clean warning page, a fake mock sign in screen, and a short explanation of why FIDO and MFA can still be impacted in this kind of flow would be great. Include easy run instructions, preferably with Go and Docker, and look up current docs online if you need to.
Have a live product UI? Try website reverse