A cloud-based identity and access management service for securing user authentication and resource access
Block device code flow in old Microsoft Entra tenants
I read that new Microsoft Entra tenants (created 1 July 2026 or later) no longer need Entra P1 to block device code flow. It is now part of the security defaults.
Starting July 1, 2026, all new Microsoft Entra tenants block device code flow as part of security defaults. Applications or devices that depend on device code flow won't be able to complete sign-in while security defaults are enabled.
Is there a way to get the same protection for older tenants? I have to older tenants with security defaults enabled since many years. Both of them still allow device code flow-based authentication. Disabling and re-enabling security defaults didn’t help.