A reported phishing-as-a-service kit is said to abuse Microsoft’s device-code flow, showing how cloud identity abuse can outlast a simple password theft.