Policy Teams Devices Device Code Flow
Doc updateAction requiredThe instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
Daily.Entra.NewsDaily AI-generated highlights from Microsoft Learn and Message Center. Browse the archive from 15 April 2025 → About this project →
External ID’s passkey-management guidance now directs applications away from the preview credential management API and toward Microsoft Graph FIDO2 provisioning APIs, while identifying low-privilege passkey APIs as roadmap work. A related credential-management API reference was removed, and the device code flow exclusion procedure now uses a more specific resource-selection path.
The Sign In With Passkey page no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and says low-privilege passkey credential-management APIs are on the roadmap. No immediate administrator action is stated.
The Microsoft Entra External ID credential management API reference was deleted; it had covered listing, registering, and deleting passkeys for signed-in customers. Use the redirected Microsoft Graph documentation and update internal links or bookmarks that point to the old page.
The policy procedure now directs administrators through Exclude > Select resources > Select specific resources before adding Device Registration Service. Follow this path when configuring the exclusion, which the guide says is required to prevent device registration through device code flow from being blocked.
This period briefing was generated by AI from the tracked Microsoft Learn and Message Center changes.
The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.
The Microsoft Entra External ID credential management API reference was deleted. It previously documented how applications let signed-in customers list, register, and delete passkeys.
The documentation no longer directs applications to the preview credential management API. It now recommends Microsoft Graph FIDO2 provisioning APIs and states that low-privilege passkey credential management APIs are on the roadmap.