Microsoft Entra ID
Monitoring

Policy Teams Devices Device Code Flow

In brief

The guide now directs administrators to use Exclude > Select resources > Select specific resources before adding Device Registration Service.

What Entra admins need to know

Follow the updated selection path to prevent device registration through device code flow from being blocked.

This editorial summary was generated by AI from the documentation changes. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

    - Select **Users and groups** and choose your organization's emergency access or break-glass accounts and your approved device code flow exception groups. Audit this exclusion list regularly.
  1. Under Target resources > Resources (formerly cloud apps):
    1. Under Include, select All resources (formerly 'All cloud apps') unless your organization validated a narrower resource scope for the scenario.
    2. Under Exclude, select Select excluded cloud appsresources then select Select specific resources and add Device Registration Service. This exclusion is required so device registration through device code flow isn't blocked by your policy. For more information, see Enforcement of Authentication Flows policies on Device Registration Service resource.
  2. Under Conditions > Authentication Flows, set Configure to Yes.
    1. Select Device code flow.
    2. Select Done.
Daily Entra.News

Get daily email updates

Get a concise summary of the latest Microsoft Entra updates delivered straight to your inbox.

Loading the secure signup form…