Policy Teams Devices Device Code Flow
In brief
The instructions now direct administrators to choose Resources > Specific resources, instead of Cloud apps, when adding Device Registration Service to the exclusion list.
What Entra admins need to know
Use the updated path when configuring the policy; the exclusion is required to prevent device registration through device code flow from being blocked.
This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
- Select **Users and groups** and choose your organization's emergency access or break-glass accounts and your approved device code flow exception groups. Audit this exclusion list regularly.
- Under Target resources > Resources (formerly cloud apps):
- Under Include, select All resources (formerly 'All cloud apps') unless your organization validated a narrower resource scope for the scenario.
- Under Exclude, select Select
excluded cloud appsresources then select Select specific resources and add Device Registration Service. This exclusion is required so device registration through device code flow isn't blocked by your policy. For more information, see Enforcement of Authentication Flows policies on Device Registration Service resource.
- Under Conditions > Authentication Flows, set Configure to Yes.
- Select Device code flow.
- Select Done.
@@ -83,7 +83,7 @@ Create one policy that blocks device code flow by default. - Select **Users and groups** and choose your organization's emergency access or break-glass accounts and your approved device code flow exception groups. Audit this exclusion list regularly. 1. Under **Target resources** > **Resources (formerly cloud apps)**: 1. Under **Include**, select **All resources (formerly 'All cloud apps')** unless your organization validated a narrower resource scope for the scenario.- 1. Under **Exclude**, select **Select excluded cloud apps** and add **Device Registration Service**. This exclusion is required so device registration through device code flow isn't blocked by your policy. For more information, see [Enforcement of Authentication Flows policies on Device Registration Service resource](concept-authentication-flows.md#enforcement-of-authentication-flows-policies-on-device-registration-service-resource).+ 1. Under **Exclude**, select **Select resources** then select **Select specific resources** and add **Device Registration Service**. This exclusion is required so device registration through device code flow isn't blocked by your policy. For more information, see [Enforcement of Authentication Flows policies on Device Registration Service resource](concept-authentication-flows.md#enforcement-of-authentication-flows-policies-on-device-registration-service-resource). 1. Under **Conditions** > **Authentication Flows**, set **Configure** to **Yes**. 1. Select **Device code flow**. 1. Select **Done**. 