Hi @Justin
Thank you for posting your question in the Microsoft Q&A forum.
Based on your description, it's likely you're facing a critical issue where 76 Poly X50 Android-based room devices are unable to authenticate into Microsoft Teams due to enforced Intune enrollment and Multi-Factor Authentication (MFA) requirements, particularly after a recent Microsoft update. This is affecting your NHS single tenant environment.
Here are some suggestions may be helpful to you:
- Remove Intune License from Device Accounts
If the device accounts (used to sign into Teams) have Intune Plan 1 licenses assigned, remove them:
- Go to Microsoft 365 Admin Center > Users > Active Users.
- Select the affected device account.
- Under Licenses and Apps, uncheck Microsoft Intune Plan 1.
- Save changes.
This has resolved the issue for other Poly X50 users
- Use Device Administrator Mode Instead of Android Enterprise
Poly X50 devices may fail to enroll if Android Enterprise is enforced. Instead:
- In Intune Admin Center, go to Devices > Android > Android enrollment.
- Enable Device Administrator mode for these devices.
- Optionally, create a separate Enrollment Profile for Poly devices.
- Exclude Devices from Conditional Access MFA Policies
Create a Conditional Access policy exception:
- Go to Azure AD > Security > Conditional Access.
- Identify the policy enforcing MFA.
- Under Assignments > Users or workload identities, exclude the device accounts or a group containing them.
- Alternatively, exclude the Poly X50 device platform under Conditions > Device platforms.
4.Use Microsoft Teams Admin Center for Device Management
If Intune is not required for your use case:
- Manage Poly X50 devices directly via the https://admin.teams.microsoft.com/devices.
- Ensure firmware is up to date and Teams Rooms app is configured correctly.
5.Declare Devices as Corporate-Owned in Intune
To avoid enrollment failures:
- Pre-declare Poly X50 devices as corporate-owned in Intune.
- Go to Intune Admin Center > Devices > Android > Corporate device identifiers.
- Add the device serial numbers or IMEIs.
This allows Intune to treat them as trusted without requiring full enrollment
After tried all the option above but you still can't sign in to your account on any other platform please contact your IT team at your organization and ask them to follow this article: LINK to reset your multi-factor authentication (MFA), allowing you to re-register Microsoft Authenticator.
Hope these options that mentioned above can help you. If you encounter any issues or have further update, please don't hesitate to reply to my answer once you have any replies/updates.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.