The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Use az login --use-device-code when a Linux terminal has no usable browser. Open https://aka.ms/devicelogin on an approved browser, enter the code printed by Azure CLI, and complete MFA or Conditional Access normally. For browser automation, launch Chrome with Playwright in headless mode, but do not expect headless mode to bypass Entra policy. MFA, device compliance, federation and broker requirements still apply.
Choose the authentication path first
The right method depends on whether a person is present, whether the Linux machine is a managed desktop, and whether the workload must run unattended.
| Situation | Recommended path | Why |
|---|---|---|
| Interactive terminal on a server with no graphical browser | az login --use-device-code |
The user completes sign-in and MFA in a separate approved browser. |
| Managed Linux desktop with Microsoft’s broker available | Azure CLI browser login with brokered SSO | The Identity Broker can provide Linux SSO and store refresh tokens in the user’s keyring. |
| Repeatable browser task that needs cookies | Playwright with a dedicated persistent profile | Cookies and storage state survive browser restarts, but the profile becomes a credential-bearing secret. |
| Unattended production job | Service principal or managed identity | Microsoft recommends workload identities instead of a human user session for automation. |
Azure CLI 2.61.0 and later use browser-based login by default on Linux and macOS. User identities are subject to Microsoft’s MFA requirement introduced in September 2025; service principals and managed identities are not affected by that user-MFA requirement.
Use Azure CLI on a terminal-only Linux host
1. Install and verify Azure CLI
Install Azure CLI using Microsoft’s package instructions for your distribution, then verify the installation:
#1 Best Overall
az version
Check that the reported version is at least 2.61.0. If the command is missing, install the package before continuing. If your organization uses a private tenant or cloud, confirm that your normal Azure CLI cloud configuration is selected before signing in.
2. Start device-code sign-in
Run this command on the Linux host:
az login --use-device-code
Azure CLI prints a short user code and a verification URL. On a separate browser that your organization approves, visit https://aka.ms/devicelogin, enter the code, select the correct account and tenant, and complete every MFA or Conditional Access prompt. Return to the terminal; Azure CLI exchanges the completed device flow for tokens.
3. Confirm tenant and subscription context
Do not assume that the first subscription shown is the one your job should use. Inspect the account:
az account show --output table
az account list --output table
Select the intended subscription explicitly:
az account set --subscription "SUBSCRIPTION_ID_OR_NAME"
az account show --output json
The final command should show the expected tenant, subscription and signed-in user. A successful device-code flow authenticates the CLI; it does not grant permissions that the account does not already have.
Recommended Free Tools
4. Use the session and sign out deliberately
Run Azure commands normally after the context is correct. On a shared or temporary host, remove the local CLI session when finished:
az logout
Also remove any temporary shell history, output files or diagnostic logs that contain identifiers or sensitive data. On a persistent server, protect the Azure CLI configuration directory with normal Unix ownership and permissions.
What headless Chrome changes—and what it cannot change
Headless Chrome suppresses the visible window; it does not turn an interactive Entra sign-in into a non-interactive one. Entra still evaluates MFA, Conditional Access, device compliance, broker availability, federation and tenant-specific sign-in rules. Microsoft does not guarantee that every Conditional Access policy will permit a headless Chrome session, and there is no universal way to automate MFA safely.
Launch Chrome with Playwright CLI
Install Playwright CLI according to the supported Playwright distribution for your environment, then select Chrome explicitly:
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →Repair Windows errors before they cause bigger problemsFix Now →playwright-cli open --browser=chrome https://entra.microsoft.com
The CLI runs headless by default. For first-run setup or diagnosis, add headed mode:
playwright-cli open --browser=chrome --headed https://entra.microsoft.com
A headed run is useful when a sign-in page waits for a human click, a security key, a phone approval or a visual challenge. It is not a bypass for those controls.
Use a persistent profile only with approval
Playwright keeps its browser profile in memory by default. Cookies and storage state survive between calls in one session but disappear when the browser closes. A persistent profile can retain a successful sign-in for repeatable work, but it contains credential-bearing cookies and local storage.
mkdir -p "$HOME/.config/entra-playwright"
chmod 700 "$HOME/.config/entra-playwright"
playwright-cli open --browser=chrome --persistent
--user-data-dir="$HOME/.config/entra-playwright"
https://entra.microsoft.com
Use a dedicated Unix account or directory, restrict permissions, keep the user’s keyring available when required, and follow your organization’s retention policy. Never copy token databases or cookies from another machine. Destroy the profile when the task or authorization ends.
Free tools Windows power users keep installed
One-click scans. No signup required.
Linux broker, PRTs and device-based policy
Microsoft’s Identity Broker powers SSO for Linux on supported desktop distributions. Microsoft states that Linux supports both unregistered Primary Refresh Tokens (PRTs) for Microsoft Edge and registered PRTs when the broker is present. The broker returns an access token to the calling application and stores refresh tokens locally; those refresh tokens are encrypted with a key kept in the Unix user’s sign-in keyring.
This distinction matters on a minimal server. A server without the broker, a usable keyring or the required device registration cannot be assumed to satisfy a policy that checks device state. A PRT is valid for 90 days and is continuously renewed while the user actively uses the device, although tenant session-frequency controls can force reauthentication sooner. A PRT is not itself a general-purpose access token for every Azure resource.
Production automation: replace user sign-in
Device code is appropriate when a person is intentionally starting an interactive session. It is a poor fit for cron, CI or a daemon because it depends on a human and produces a user session. Use a service principal or managed identity where your deployment supports it.
Service principal
Store the application ID, tenant ID and secret in your organization’s secret manager or protected CI variables, not in source control or a command history. A standard Azure CLI form is:
az login --service-principal
--username "$AZURE_CLIENT_ID"
--password "$AZURE_CLIENT_SECRET"
--tenant "$AZURE_TENANT_ID"
Grant the application only the roles it needs, rotate the secret according to policy, and select the subscription explicitly after login.
Managed identity
When the process runs on an Azure resource with an assigned managed identity, use the platform identity instead of storing a secret:
Rank #4
az login --identity
az account show --output table
This option depends on the host actually having an enabled identity and the required role assignments. It is not available on an arbitrary Linux server outside an Azure resource that provides managed identity.
A practical decision checklist
- No local browser: use device code and an approved browser elsewhere.
- MFA or Conditional Access asks for interaction: complete it as a person; do not attempt to defeat it with headless flags.
- Managed desktop with broker and keyring: test brokered SSO under the same Unix account that will run Azure CLI.
- Cookies must persist: use a dedicated, permission-restricted Playwright profile only after your organization permits that storage.
- Nightly or unattended execution: use a service principal or managed identity.
- Policy outcome is unclear: ask the Entra administrator which tenant, device and session controls apply before changing browser settings.
Troubleshooting common failures
“Browser could not be opened”
On a terminal-only host this is expected with plain az login. Repeat the command with az login --use-device-code and finish sign-in at the device-login URL.
The device code is rejected or expires
Use the newest code printed by the current CLI process and enter it promptly. Ensure the separate browser is signed into the intended account and that the tenant’s policy allows device-code authentication. Start a new command rather than reusing an old code.
MFA succeeds but Azure CLI still fails
Conditional Access can evaluate more than the user’s second factor, including device compliance, location, client type or session frequency. A successful browser prompt does not guarantee that a headless or unregistered Linux host meets those conditions. Ask the tenant administrator for the specific sign-in log result and required remediation.
Playwright opens the page but the session is lost
The default in-memory profile is discarded when the browser closes. Use one dedicated persistent profile if policy permits it, and keep all calls in the same session. Verify that the profile directory is writable and that the Unix keyring or broker dependency is available.
Automation hangs at MFA or a security challenge
Do not script around the challenge. Switch to --headed for an approved interactive setup, complete the challenge manually, or redesign the workload around a service principal or managed identity. Some tenants intentionally require a compliant device or broker that a minimal server cannot provide.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Repair Windows errors before they cause bigger problems3Fix the driver behind crashes, sound loss and screen glitchesBest Value
The wrong subscription appears
Azure CLI can retain several subscriptions in one tenant. Run az account list --output table, then use az account set --subscription with the exact intended ID or name before running resource commands.
Or skip the browser setup
If your actual goal is to capture a webpage rather than operate an Entra session interactively, ScreenshotNeo provides a one-request screenshot API. It is not an Entra authenticator, so use it only with pages and credentials your organization authorizes. Before capture it accepts consent banners and removes more than 60 known consent platforms, newsletter popups and chat widgets; bot checks, blank pages, timeouts, failed loads and cache hits are not billed, and response headers identify the page verdict and billing status. Its MCP server exposes take_screenshot, get_page_info and capture_pdf to Claude, Cursor and other MCP clients.
cURL:
curl -G "https://api.screenshotneo.com/v1/shot" -d access_key=YOUR_API_KEY --data-urlencode url=https://stripe.com -o shot.webp
Python:
import requests
r = requests.get("https://api.screenshotneo.com/v1/shot", params={"access_key": "YOUR_API_KEY", "url": "https://stripe.com"}, timeout=90)
r.raise_for_status()
open("shot.webp", "wb").write(r.content)
Node.js:
const q = new URLSearchParams({ access_key: 'YOUR_API_KEY', url: 'https://stripe.com' });
const res = await fetch(`https://api.screenshotneo.com/v1/shot?${q}`);
if (!res.ok) throw new Error(`HTTP ${res.status}`);
const data = Buffer.from(await res.arrayBuffer());
require('fs').writeFileSync('shot.webp', data);
See the ScreenshotNeo documentation for authentication and capture options. The Free plan includes 1,000 screenshots per month with no card; paid plans start at $5 for 3,000 shots. Create a free ScreenshotNeo account.
FAQ
Frequently Asked Questions
Can a Primary Refresh Token be used as an Azure resource access token?
No. A PRT is broker and device-sign-in state used to obtain tokens; applications still request an access token for the specific resource and scope they need.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteHow long can a Linux PRT remain valid?
Microsoft documents a 90-day validity period with continuous renewal while the user actively uses the device. Tenant session-frequency controls can require a new sign-in sooner.
The Bottom Line
For a headless Linux terminal, start with az login --use-device-code. Use Playwright headless Chrome only for permitted browser tasks, protect any persistent profile like a secret, and move unattended jobs to a service principal or managed identity.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

