How to Block Device Code Flow With Conditional Access
Device code phishing kits like EvilTokens trick users into completing MFA on an attacker's behalf. Blocking device code flow with Conditional Access removes the technique for most users. Here is how.
Step 1: Find legitimate device code usage
Before blocking, check who uses it. In the Entra admin center, filter Sign-in logs by Authentication protocol = Device code over the past 30–90 days. Common legitimate uses:
- Microsoft Teams Rooms and shared meeting devices.
- Some CLI tools used by administrators and developers (Azure CLI, older tools).
- Certain IoT or kiosk devices.
Step 2: Create a blocking policy
In Conditional Access → New policy:
- Users: All users; exclude break-glass accounts and a security group for approved device code users.
- Target resources: All resources.
- Conditions → Authentication flows: select Device code flow (and consider Authentication transfer).
- Grant: Block access.
Start in Report-only mode, review results for a week, then enable.
Step 3: Constrain exceptions
For approved device code users (for example, Teams Rooms accounts):
- Restrict to specific named locations (office IPs).
- Use dedicated resource accounts rather than personal accounts.
- Review the exception group quarterly.
Step 4: Move CLI users to better flows
Modern Azure CLI and PowerShell versions support interactive browser sign-in and Web Account Manager (WAM) on Windows. Encourage those instead of device code.
Step 5: Review Microsoft-managed policies
Microsoft has rolled out managed Conditional Access policies that block device code flow in some tenants. Check whether one exists and align it with your policy.
Verify
Sign-in logs should show device code sign-ins only from approved exception accounts and locations.