Device Code Authentication
Device code is the recommended delegated flow for remote shells.
teams auth login --device-code
The CLI prints a user code and verification URL. After login, tokens are stored in the OS keyring for the selected profile.
Use --tenant-id for customer-specific onboarding and --client-id for BYO apps. A successful
login saves both flags to the profile, so later logins for it reuse them; see
Multi-Tenant Profiles.