The settingWhat we hold this to
CreativeTechs minimum
A CA policy in state ENABLED targeting All users, Conditions → Authentication flows → Device code flow AND Authentication transfer, grant = Block. Break-glass excluded.
Benchmark position
No published benchmark value in CIS, CISA or EIDSCA. Huntress ships this as a managed CA template and rates it High · Foundational.
Where we differ, and why
We are ahead of the standards here, deliberately. Device-code phishing is current; the frameworks have not caught up.
Where the switch is
Entra admin centre → Protection → Conditional Access → Policies → New policy → Conditions → Authentication flows.
How to verify
Graph: /identity/conditionalAccess/policies → conditions.authenticationFlows.transferMethods contains 'deviceCodeFlow','authenticationTransfer' and grantControls.builtInControls contains 'block'
- Why it matters
- Device-code phishing needs no fake site — the victim sees a genuine Microsoft prompt and types a code the attacker supplied. Near-zero legitimate use at this size.
- How we check
- Maester MT.1052.
- Fix — M365
- Conditional Access → all users → Authentication flows → Device code flow and Authentication transfer → Block.
- Fix — Google
- No direct equivalent.
- User notices
- None, unless you provision shared displays, Apple TVs or CLI tooling that relies on it.
- Expected pushback
- None from users. Note for ourselves: the Maester PoC authenticated by device code, so the posture runner needs an exclusion or app-only auth before this lands.
- Reason on file
- Standards lag the threat; Huntress rates it High and Foundational.
