The following does not correctly filter for devicecode/transfer auth flows correctly. correctly
if($CAPolicy.Conditions.AdditionalProperties.Values.Values -and $CAPolicy.GrantControls.BuiltInControls -eq 'block'){
$CAPBlockAuthFlow += $CAPolicy
}
This should eval to true in the correct situations.
if($CAPolicy.Conditions.AuthenticationFlows.TransferMethods -and $CAPolicy.GrantControls.BuiltInControls -eq 'block'){
$CAPBlockAuthFlow += $CAPolicy
}
Thanks for the module.