Use when an Azure CLI command fails with a Conditional Access / MFA error, when deploying to App Service / Web Apps in a tenant with Entra Conditional Access policies, or when troubleshooting why `az login --use-device-code` works for some operations but not for ARM writes. Explains the difference between ARM control-plane writes (subject to MFA) and Kudu / SCM data-plane operations (not), and the auth methods that satisfy each.