Share via

Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Adriaan Kruger 0 Reputation points
2026-04-08T16:31:07.9966667+00:00

Access has been blocked by Conditional Access policies. The access policy does not allow token issuance.

Installed Apps4.Pro for Migration and the Microsoft-managed CA policy "Block device code flow" is blocking my connection to our tenant.

When I search for Microsoft Azure CLI i see a lot of attempts to use this.

What is the best practice to not have this blocked

Microsoft Security | Microsoft Entra | Microsoft Entra ID

1 answer

Sort by: Most helpful
  1. Yutaka_K_JP 1,655 Reputation points
    2026-04-09T03:13:03.3033333+00:00

    I think the block comes from the MS‑managed CA rule cuttin the device‑code flow at the token‑gate, so just add a tiny exclde for that mig usr/app in Entra → CA. If it still fails, peek the sign‑in logs once… it shows exactly where CA drops it.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.