The device code flow user experience will now include an app confirmation prompt

The device code flow user experience will now include an app confirmation prompt

As a security improvement, the device code flow has been updated to include an additional prompt, which validates that the user is signing into the app they expect.

When this will happen:

We will roll this starting in early June and expect to complete by the end of June.

How this affects your organization:

This prompt is being added to help prevent phishing attacks, where an attacker tricks the user into signing into a malicious application.

The prompt being added looks like this:


View image in new tab

 

This will be added to the device code login flow (used in apps like Intune on mobile devices, or the PowerShell CLI) starting June 2021.

All users will see this prompt while signing in using the device code flow. As a security measure, it cannot be removed or bypassed.

What you need to do to prepare:

You may consider updating your training and documentation as appropriate.

 

No Comments

Sorry, the comment form is closed at this time.