Transition to Password-less Teams Shared Space device Resource Accounts

Password-less Teams Shared Space device Resource Accounts enable a Teams device to sign in using a secure device bound resource account credential instead of relying on stored username and password credentials. This new authentication methodology is intended to reduce dependencies on password-based authentication, improve sign-in resilience, and ensure a secure by default device deployment mechanism. This new methodology builds on the existing Teams Resource Account creation and device deployment process while adding a step post deployment to switch the device authentication method from password based to a secure device bound credential.

This article describes the initial required pre-requisites and the steps required for migrating a Teams Room and its associated resource account to password less.

Benefits

  • Eliminates manual credential management for Teams devices.
  • Improved security posture by using a secure device-bound token to communicate between the endpoint and Microsoft 365.
  • Device admins have full visibility to the mapping between the device and the resource account credentials.
  • Improved sign in resilience by allowing re-authentication attempts without manually re-signing in.
  • End users notice no changes to the device functionality.
  • Existing resource account creation processes remain and all existing accounts can be transitioned.
  • Allow admins to remove or scramble passwords on the accounts so they're unknown.
  • Authentication to Microsoft 365 services (Teams, Intune, Pro Management Portal, etc) does not change.

Note

At this time, the password is not removed from the resource account once migrated to password-less. We recommend IT administrators remove using the cleanup steps or manually rotate the password post the transition to ensure the password is unknown and secure.

What happens in the background

When a Teams device and the associated resource account is transitioned to password-less several actions are taken in the background:

  1. Set as Resource is configured on the resource account
  2. For Teams Rooms on Windows devices, the Teams Rooms app is migrated from using the local 'Skype' Windows user account to instead sign into Windows using the resource account. All Teams Rooms app settings are moved over as part of this transition
  3. The device connects to Entra ID and requests its secure token for password-less authentication
  4. The device signs in using its new secure token and connectivity is validated. If the device is unable to login successfully the transition will be rolled back automatically.
  5. The Pro Management Portal is updated with migration status

Prerequisites

  • Teams Resource Account created and signed into your Teams device.
  • The resource account can be Entra ID only or synchronized from Active Directory.
  • Third party federated identity providers are supported.
  • The Teams resource account must be licensed to convert it to password-less:
    • Teams Rooms on Windows and Teams Rooms on Android require a Teams Rooms license
    • Teams panels and Teams phones require a Teams Shared Space license

      Note

      Teams panels if using the same resource account as a room device just require the Teams Rooms license you do not need to add the additional Shared Space license in that scenario

  • Teams device and Resource Account are both visible in the Teams Rooms Pro Management Portal.
  • Supported Teams Devices:
    • Teams Rooms on Windows
    • Teams Rooms on Android
    • Teams panel
    • Teams phone
  • Administrative access required to transition devices to password-less: Teams Administrator
  • Administrative access required to use the Cleanup Password wizard: User Administrator or Global Administrator

Teams Rooms on Windows Requirements

  • Windows 11 24H2 running build 26100.8655 or later.
  • Entra ID joined to the same Entra ID where the resource account was created (hybrid join is not supported).
  • Teams Rooms on Windows app 5.6.135.0

Note

Teams Rooms on Windows devices configured for a proxy are not yet supported but will be in the coming weeks.

Teams Rooms on Android Requirements

Teams panel Requirements

  • Android OS 10 or later
  • Teams panels app 1449/1.0.97.2026164101
  • Authenticator app 6.2605.3066
  • Teams Admin Agent app 1.0.0202606082157
  • Teams panels can be stand alone or signed into the same account as a Teams Room device. Teams panels using the same account as a Teams Room device will migrate to password-less at the same time.

Teams phone Requirements

Tip

We recommend testing with a small batch of devices prior to migrating your entire environment.

Step 1: Transition devices and accounts to password-less

Note

The administrator performing this transition must have the Teams Administrator role assigned to their account. Other administrative roles are planned to be added in the future, including Global Administrator.

  1. Sign in to the Teams Rooms Pro Management Portal using an account with the Teams Administrator admin role.
  2. Select Planning > Resource Accounts in the left navigation.
  3. Select the Migration tab.
  4. Select eligible resource account(s) to migrate.
  5. Select Schedule migration to open the migration wizard.
  6. Choose to either migrate now or during the next maintenance window.
  7. Review the select and select Confirm.
  8. The device(s) and account(s) will migrate at their scheduled time.

Step 2: Verify migration progress

After the migration completes you may want to verify the following:

  • The room reports a healthy status in the Pro Management Portal.
  • The device signs in successfully.
  • Teams device starts without repeated sign-in prompts.
  • Teams device functionality works as expected.

Step 3: Cleanup or rotate the resource account password

Note

The administrator performing this transition must have permissions to reset the resource account password. This is typically User Administrator or Global Administrator, but other RBAC roles or those scoped through an administrative unit can offer permissions as well.

Once the Teams device has transitioned to using the password-less authentication methodology, the password on the account remains but can be scrambled or rotated to something complex, secure, and not known. The following instructions are for cloud only resource accounts, hybrid synchronized accounts can scramble them without impacting the password-less authentication token on the Teams device.

Built-In Cleanup Wizard to remove the password

  1. Sign in to the Teams Rooms Pro Management Portal.
  2. Select Planning > Resource Accounts in the left navigation.
  3. Select the Migration tab.
  4. Select eligible resource account(s) to clean up.
  5. Select Cleanup password.
  6. Confirm the cleanup.

Manually scramble the password

  1. Using an account with administrative permissions to change a user's password. See prerequisites.
  2. Login to Microsoft 365 admin center.
  3. Select users and find the resource account password to be scrambled.
  4. Follow these instructions on password resets.
  5. The Teams device should remain signed in.

Troubleshooting, Known Issues, and FAQs

Troubleshooting Tips

  • Verify that the room meets the required platform software and app version requirements.
  • Confirm that the resource account is correctly assigned.
  • Check sign-in logs within Entra ID for failures.
  • Review the migration status in the Pro Management portal – open detail panel for the failed account to see failure reason.
  • Retry the migration after remediating any the failure reason or report blocking issues.
  • Revert to password authentication:
    • Teams Rooms on Windows: A reset of the Teams Rooms on Windows devices is required to revert from password-less authentication. A reset can be performed using the recovery image from your Teams Rooms manufacturer or with the recovery tool.
    • Teams Rooms on Android, Teams panels, and Teams phones: A full account sign out on the device will remove the password-less authentication token and allow a new sign in with a username and password. A sign out can be performed locally within the Teams settings on the device or by using the remote sign-out functionality in the Pro Management Portal.

Known issues

Device Replacement or Credential Changes

If you need to replace a device or change the credentials, you must setup the new device using the account with a password first, and then perform the migration steps again to convert to password-less authenmtication.

Pro Management operations fail on a Teams Rooms on Windows device that uses a system-wide proxy

On affected Pro Management agent versions, the agent might check the signed-in user's proxy settings before the system-wide Windows proxy settings. If the resource-account user profile has no proxy or has stale proxy settings, Pro Management operations such as app updates, log collection, and driver updates can fail even when the Teams Rooms app can connect through the system-wide proxy. As a temporary workaround, configure matching proxy settings for the signed-in resource-account user. Don't use bitsadmin /Util /SetIEProxy LOCALSYSTEM for this issue because the affected agent path doesn't read that configuration and Windows feature updates can remove it, instead follow the proxy configuration guidance in Proxy for Teams Rooms on Windows.

Teams Rooms on Windows remains on the sign-in page when network connectivity is delayed

If network or switch configuration delays network connectivity to a Teams Rooms on Windows device during startup (for example STP delays or portfast being disabled on certain model switches), Resource Account migration might not complete automatic sign-in. The device can remain on the sign-in page after migration. To recover, manually sign in on the device or retry the Resource Account migration after network connectivity is available. To prevent the issue, configure the network so that the device has connectivity during startup.

Crestron Teams Rooms on Windows devices are not compatible

Crestron's unique software configuration is not currently compatible with password-less resource accounts. If a Crestron device has been migrated and you're experiencing issues, the device will need to be factory reset using the Crestron recovery media and continue to use password-based authentication for the time being. Crestron is working on resolution for this.

Frequently Asked Questions

Is migration automatic, or does an administrator need to start it?

Migration is administrator-initiated. Microsoft doesn't automatically migrate eligible devices or resource accounts. An administrator must schedule the migration from Planning > Resource Accounts > Migration in the Teams Rooms Pro Management portal.

Is migration to password-less authentication required?

Migration is currently optional. We recommend migrating eligible devices to improve security and reduce password-management overhead. Test the migration with a small group of devices before migrating your broader environment.

Is Set as Resource required before transitioning?

No. The migration process sets the account as a resource. You don't need to use Set as Resource before migrating an eligible account.

Can I deploy a new device as password-less without needing a username and password?

No. Devices must be deployed using existing deployment methods using username and password and then transitioned to password-less after the fact. Deployment directly to password-less will come in the future.

Which devices can be transitioned?

Teams Rooms on Windows, Teams Rooms on Android, Teams panels, and Teams phones can be migrated when they meet the prerequisites in this article. Common area phones that use an eligible resource account and supported license are included as Teams phones.

What changes after the transition?

Only the authentication method changes. The device uses a secure, device-bound resource account credential instead of a stored username and password. Meeting, calling, device-management, and other supported device functionality remain unchanged. Administrators don't need to provision or manage a certificate manually. If the resource account password is modified the device will remain signed in unlike prior to the transition where the device would be signed out.

On a Teams Rooms on Windows device, after the transition, does it change administrative actions on the device?

No accessing admin mode and changing settings on the device doesn't change. The only difference is that to return to the Teams Rooms experience, you need to reboot the PC as the local Skype user account is no longer available to sign-in with.

Do resource account passwords still need to be managed after transition?

After converting, the device no longer uses the resource account password to sign in. We recommend resetting the resource account password to something complex and unique so that it can no longer be used using Microsoft 365 Admin Center. Resetting the password requires the User Administrator, Exchange Administrator, or Global Administrator role.

Will a converted device sign-in automatically after a restart?

Yes. The device continues to use its device-bound credential and should sign in automatically after a restart.

What happens if a migrated device is reimaged or replaced?

The password-less credential is bound to the device and can't be transferred. The credential is also lost when a device is reset or re-imaged. When setting up the re-imaged or replacement device, reset the resource account password following the guidance in Step 3, setup the device using that username and password, and then migrate the device to password-less authentication again starting from Step 1.

Is this new authentication method similar to something else already available from Microsoft?

Password-less resource accounts function similarly to Windows Hello for Business authentication for end users. Both store a secure credential that is device bound and used to authenticate against Entra ID. Changing passwords does not impact existing deployed devices adding both security and resiliency.

I manually signed out or reset my device, why does the device need a password again?

This is expected, the password-less authentication token is lost during a manual device sign out or device reset. This is done to allow a way to switch accounts utilized on a device. In a future release we will offer ways to deploy devices from the login screen without needing a password. When setting up the reset device, reset the resource account password following the guidance in Step 3, setup the device using that username and password, and then migrate the device to password-less authentication again starting from Step 1.

Is the token stored securely? Is the token bound to the device? When does the token expire?

Yes, the password-less token is stored in the TPM on Windows and Keystore on Android. In either platforms scenario, the token is device bound and cannot be moved to another device. The token itself does not have a specific expiration.

How do I revoke a token from a device remotely?

Because the password-less token is device bound to the identity in Entra ID, you can delete the device itself from Entra ID and that will invalidate the password-less token. The device will then be signed out automatically at next authentication refresh. Deleting the device in Entra ID deletes that specific make/model/serial device for Android or breaks Entra ID join for Windows device, the account itself and any other devices associated will not be impacted. Manage devicse in Microsoft Entra ID has the steps for deleting devices.