❌ Admins, please block Device Code Flows (DCF) in your tenant today!!
In the post below I share how device code phishing works, the CA policy to create and finally show how it get's blocked with the policy.
🧵👇
The ability to block Device Code Flow just became available in Microsoft Entra ID Conditional Access.
Here's a quick walkthrough of how attackers use device code flow to get access to your tenant and what you can do to protect yourself.