Discover how new Microsoft-managed policies enhance identity security.
Updated Mar 11, 2025
Version 4.0If Microsoft is following secure-by-default principles, why is device code flow enabled for all users instead of being restricted to only those who need it? Shouldn’t it be limited to specific devices that require it? This seems like closing the stable door after it was unnecessarily left open.