M365 Changelog: The device code flow user experience will now include an app confirmation prompt

MC260554 – As a security improvement, the device code flow has been updated to include an additional prompt, which validates that the user is signing into the app they expect.

When this will happen:

Microsoft will roll this starting in early June and expect to complete by the end of June.

How this affects your organization:

This prompt is being added to help prevent phishing attacks, where an attacker tricks the user into signing into a malicious application.

The prompt being added looks like this:

pic1

This will be added to the device code login flow (used in apps like Intune on mobile devices, or the PowerShell CLI) starting June 2021. 

All users will see this prompt while signing in using the device code flow. As a security measure, it cannot be removed or bypassed.

What you need to do to prepare:

You may consider updating your training and documentation as appropriate.