I tested in my lab and found that if only excluding Teams in the conditional access policy, the user would receive an error message Your Sign-in was successful but does not meet the criteria to access this resource when logging.
And in Azure sign-in logs, a failed login event would be logged with the error message The access policy does not allow token issuance.
Since Teams is dependent upon multiple apps (Exchange Online, Sharepoint Online and Skype for Business Online), please consider also adding these apps to the exclude list for Teams to work correctly.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.