"Allow access" & device-code tricks
A link opens a genuine Google or Microsoft screen asking you to "Allow" an app, or to type a short "device code." Approving it can hand an attacker a real login token — even though you have 2FA.
What to do: cancel. Never grant app access or type a device code that arrived via a link. Review and remove unknown apps in your account's security settings.
Threat examples
To open this shared document, go to microsoft.com/devicelogin and enter code: (provided) — this lets our viewer display the file.