A cloud-based identity and access management service for securing user authentication and resource access
I think the block comes from the MS‑managed CA rule cuttin the device‑code flow at the token‑gate, so just add a tiny exclde for that mig usr/app in Entra → CA. If it still fails, peek the sign‑in logs once… it shows exactly where CA drops it.