CreativeTechsBaseline
tenant security posture
CTB-04 · Tier 1 · Silent · M365 · P1

Block device code flow and authentication transfer

Huntress Managed CA template · High · FoundationalMaester MT.10521 authority
0
Tenants failing
0
Tenants meeting
0
Measured
REQUIRED
Disposition
The settingWhat we hold this to
CreativeTechs minimum
A CA policy in state ENABLED targeting All users, Conditions → Authentication flows → Device code flow AND Authentication transfer, grant = Block. Break-glass excluded.
Benchmark position
No published benchmark value in CIS, CISA or EIDSCA. Huntress ships this as a managed CA template and rates it High · Foundational.
Where we differ, and why
We are ahead of the standards here, deliberately. Device-code phishing is current; the frameworks have not caught up.
Where the switch is
Entra admin centre → Protection → Conditional Access → Policies → New policy → Conditions → Authentication flows.
How to verify
Graph: /identity/conditionalAccess/policies  →  conditions.authenticationFlows.transferMethods contains 'deviceCodeFlow','authenticationTransfer' and grantControls.builtInControls contains 'block'
Across the fleet
Client
State
Evidence
Blackwing
UNKNOWN
No Secure Score evidence — awaiting Maester.
BravicaOne
UNKNOWN
No Secure Score evidence — awaiting Maester.
CMG Law
UNKNOWN
No Secure Score evidence — awaiting Maester.
CreativeTechs
UNKNOWN
No Secure Score evidence — awaiting Maester.
DCG One
UNKNOWN
No Secure Score evidence — awaiting Maester.
Diversified Management Services
UNKNOWN
No Secure Score evidence — awaiting Maester.
Double Z
UNKNOWN
No Secure Score evidence — awaiting Maester.
Electric Pen
UNKNOWN
No Secure Score evidence — awaiting Maester.
Graphiti Associates
UNKNOWN
No Secure Score evidence — awaiting Maester.
Guidance Engineering
UNKNOWN
No Secure Score evidence — awaiting Maester.
India Tree
UNKNOWN
No Secure Score evidence — awaiting Maester.
MIR Corp
UNKNOWN
No Secure Score evidence — awaiting Maester.
Phinney Bischoff
UNKNOWN
No Secure Score evidence — awaiting Maester.
Quiver Dental
UNKNOWN
No Secure Score evidence — awaiting Maester.
RHO Architects
UNKNOWN
No Secure Score evidence — awaiting Maester.
Retail Voodoo
UNKNOWN
No Secure Score evidence — awaiting Maester.
Riverstone
UNKNOWN
No Secure Score evidence — awaiting Maester.
SSF
UNKNOWN
No Secure Score evidence — awaiting Maester.
Slingshot Architecture
UNKNOWN
No Secure Score evidence — awaiting Maester.
Stoke
UNKNOWN
No Secure Score evidence — awaiting Maester.
Turnstyle
UNKNOWN
No Secure Score evidence — awaiting Maester.
Urban Animal
UNKNOWN
No Secure Score evidence — awaiting Maester.
WLIHA
UNKNOWN
No Secure Score evidence — awaiting Maester.
Zak Designs
UNKNOWN
No Secure Score evidence — awaiting Maester.
Why it matters
Device-code phishing needs no fake site — the victim sees a genuine Microsoft prompt and types a code the attacker supplied. Near-zero legitimate use at this size.
How we check
Maester MT.1052.
Fix — M365
Conditional Access → all users → Authentication flows → Device code flow and Authentication transfer → Block.
Fix — Google
No direct equivalent.
User notices
None, unless you provision shared displays, Apple TVs or CLI tooling that relies on it.
Expected pushback
None from users. Note for ourselves: the Maester PoC authenticated by device code, so the posture runner needs an exclusion or app-only auth before this lands.
Reason on file
Standards lag the threat; Huntress rates it High and Foundational.