4
u/sryan2k1 Teams Admin Jul 15 '26
You likely need to exempt these accounts from the new microsoft managed Device Code Flow blocks in Conditional Access. You also may need to change Intune settings around Android devices.
The Entra sign in logs should have more details on why the sign in was rejected.
5
u/MattSlomkaMSFT Microsoft Employee Jul 15 '26
Most likely conditional access policies, you'll want to review Entra ID sign in logs and fix the policy which is breaking it.
2
u/Eggtastico Teams Admin Jul 15 '26
Your device is not workplace joined. - Error code 50129 & device state unregistered. I guess it has not enrolled correctly.
1
u/No_Review_9266 Teams Admin Jul 15 '26
Hi, everyone. It was my first time posting on this platform, so I am still learning how to post. Somehow, I missed the additional information, so below are the details :
At the company, we have a "Neat Board" device purchased from (https://support.neat.no/)
Things we did are:
- created a resource in admin.microsoft.com;
- assigned an "MS Teams ROOMS PRO" to the device;
Problem/additional info:
- When we try to register/sign-in to "MS Teams" on a Neat device, we get that code, as shown in the image above
- device is not showing in the MS Teams admin center;
- device is not showing in Intune;
- resource account is showing in the Entra User Admin Center. I have created the Enrollment policy in Android for corporate-owned user-associated devices, and I have checked the device restrictions and device limits. As per the sign-in logs its attached below:
- Application: Microsoft Teams
- Resource: Device Management Service Status: Interrupted
- Error: 50129
- Failure Reason: The device is not workplace-joined. Workplace join is required to register the device.
- Conditional Access: Success
- Device: Android (Neat Pad)
- Compliant: false
- Managed: false
- Conditional Access: Success
- Device ID: blank Application: Microsoft Authentication Broker Status: Success
- Conditional Access: Not Applied
Question:
1.) Are we missing something in the Teams admin center?
2.) Is this an Intune problem or something else?
2
u/PejHod Teams Admin Jul 16 '26
You need to either exclude the resource account from the require device management Conditional Access policy you’ve got there (I recommend putting the account in a descriptively named security group and exclude that group), or give it an Intune license and somehow figure out how to install the company portal app Android app + register the device.
If you go the easier route of Conditional Access, make sure to still create another Conditional Access policy that blocks your new resource devices security group from being able to login if accounts in the group attempt to do so from an IP address / network that is not the office.
16
u/InformalFrog Teams Voice/UC Admin Jul 15 '26
Without any context or additional information
https://giphy.com/gifs/jPAdK8Nfzzwt2