We have a Teams rooms resource account for our Teams Android Device, and we configured a conditional access policy to exclude the resource account from MFA prompts if it comes from a known location (basically "to only ask for MFA if it comes from an unknown location") and excluded that resource account from all the conditional access policies involving MFA. We even excluded the resource account from SSPR. But the policy does not seem to work as expected. The policy is configured correctly as per Microsoft Learn's documentation and have been tested using the What If tool as well, but the desired end results are not achieved. When we look into the sign in logs to see if any other policy could possibly be affecting it, we see the following in Authentication Details:
Authentication Policies Applied Session Lifetime Policies Applied
App requires multifactor authentication Register passwordless authentication methods
And I'm unable to find where these policies or settings are configured in our tenant and if these are globally applied policies, where am I supposed to look for them? I created a support ticket with Microsoft as well, which has been ongoing for a month now, and have not found an acceptable answer or solution to my problem. On further digging into the sign-in logs, I find the names of two applications which are:
Application Name Application ID
Microsoft App Access Panel 0000000c-0000-0000-c000-000000000000
Microsoft Authentication Broker 29d9ed98-a469-4536-ade2-f981bc1d605e
which is a bit weird because we are trying to use the resource account on our Teams device via device login. Does anybody have a clue on how to fix this behavior?
Our sole purpose to setup this policy in the first place was to reduce the labor of signing into the Teams device again and again with the Teams room resource account, as and when the session expires. Currently we have configured a sign in frequency of 180 days to save ourselves from frequently signing into the device every 30 days, but is there any workaround? and how do large organizations handle this issue? Do they also have to keep signing into the Teams device again and again? I'm pretty sure that there must be a way out. Please reach out to me with any possible solutions.