Jump to content

Recommended Posts

Posted
Quote

This policy blocks device code flow, where a user initiates authentication on one device, completes on another, and their token is sent back to the original device. This type of authentication is common where users can't enter their credentials, like smart TVs, Microsoft Teams Room devices, IoT devices, or printers.

Device code flow is rarely used by customers, but is frequently used by attackers. Enabling this Microsoft-managed policy for your organization helps remove this attack vector.

 

Apparently this is being turned on. Can anyone see any problems?

Posted

Reading through it, I didn't spot anything that would impact the day to day running of my school.

 

You can check if the policy would have impacted any logins by opening up Conditional Access Policies, click the policy, then Policy Impact. It wouldn't have impacted any logins for the past 30 days for me.

  • Thanks 1
Posted
1 hour ago, LeMarchand said:

Can anyone see any problems?

 

The only place it causes us issues is when logging in to an account inside a remote desktop session and with only USB keys set up as 2FA options. We only have a few staff still using our remote desktop, and I think they've all added phones or similar as additional 2FA devices for when working offsite, so a very limited problem.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...