Share via

Intune - Login stuck in Authenticator loop

Eren Üçüncü 0 Reputation points
2026-02-16T20:06:42.78+00:00

Hi,

I'm trying to have my Teams & Outlook on my phone. I learned that it's possible with Intune. I downloaded it and tried to login. I selected work or school, then entered my e-mail. It asked me my password and I gave it too. Then it gave me an authenticator code and wanted me to go to authenticator app and enter it. I also did this. After that it said go and download authenticator...

I already have it and I already used it in the process i don't know what to do.

Also I tried creating work profile for android. When I go to settings->google->work profile it says you need to get code from your IT manager. I ask this to my manager, he told me he does not know where to get it.

Is not having a work profile on my android device a blocker for logging in to Intune? If so how can my manager get that code?

Extra info:

1- Authenticator has device registration.

2- Phone model : Poco X6 Pro

3- Android version : 15 AO3A.240905.015.A2

Thanks in advance

Microsoft Security | Intune | Microsoft Intune Android
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. FIRAT BOYAN 380 Reputation points Microsoft External Staff
    2026-02-16T23:28:14.33+00:00

    You are facing two separate but related flows here. Authentication and Android Enterprise enrollment. The loop you describe is almost always caused by Conditional Access requiring compliant or managed device state while the device is not yet enrolled in Intune.

    First clarify the architecture.

    Intune Android enrollment for corporate access requires Android Enterprise. On personal devices this is Work Profile based enrollment. The work profile is not created manually from Google settings. It is created automatically by the Intune Company Portal during enrollment.

    If Android settings ask for a code from IT, that refers to legacy Google enterprise enrollment using a QR or token. That is not the standard user driven Intune enrollment flow.

    Now the loop.

    When you sign in to Teams or Outlook, Azure AD evaluates Conditional Access. If there is a policy requiring compliant device or approved client app with app protection plus device registration, the sign in will redirect to Authenticator and Company Portal. If the device is not properly enrolled and marked compliant, the token is rejected and you are sent back to sign in again. That creates the loop.

    What to check from tenant side.

    Confirm Android Enterprise is configured in Intune under Devices Android Enrollment.

    Confirm the tenant is connected to Managed Google Play.

    Confirm a compliance policy exists and is assigned to your user group.

    Confirm a Conditional Access policy requires compliant device or app protection and check its grant controls.

    Verify your device appears in Entra ID and Intune after enrollment attempt.

    What you should do on the device.

    Remove existing work account from Android settings.

    Uninstall Authenticator and Company Portal.

    Reinstall Company Portal first.

    Sign in from Company Portal and complete enrollment. This should automatically create the Work Profile.

    After device shows as enrolled and compliant in Intune, open Teams or Outlook.

    Authenticator device registration alone is not sufficient. That only registers the device in Entra ID for authentication. It does not make the device Intune managed or compliant.

    If your manager does not know where to get the code, it is because the correct flow is not a manual Google work profile code. The admin must configure Android Enterprise and assign enrollment and compliance policies properly.

    In short, yes. Not having a proper Intune Work Profile can block access if Conditional Access requires compliant device. The fix is tenant side configuration plus enrollment through Company Portal, not Google settings.

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.