Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Note
This feature is currently in private preview. Track general availability on the roadmap: 558853
Password-less Teams Shared Space device Resource Accounts enable a Teams device to sign in using a secure device bound resource account credential instead of relying on stored username and password credentials. This new authentication methodology is intended to reduce dependencies on password-based authentication, improve sign-in resilience, and ensure a secure by default device deployment mechanism. This new methodology builds on the existing Teams Resource Account creation and device deployment process while adding a step post deployment to switch the device authentication method from password based to a secure device bound credential.
This article describes the initial required pre-requisites and the steps required for migrating a Teams Room and its associated resource account to password less.
Migration Prerequisites
- Teams Resource Account created and signed into your Teams device.
- The resource account can be Entra ID only or synchronized from Active Directory.
- Third party federated identity providers are supported.
- The Resource Account must be licensed with a Teams Rooms or Teams Shared Space license.
- Teams device and Resource Account are both visible in the Teams Rooms Pro Management Portal.
- Supported Teams Devices:
- Teams Rooms on Windows
- Teams Rooms on Android
- Teams panel
- Teams phone
- Administrative access to complete the migration:
- Teams Room Pro Management Portal permissions: Teams Rooms Pro Manager, Teams Administrator, Teams Device Administrator or direct Inventory Management read/write
- Reset the Resource Account Password: User Administrator, Exchange Administrator, or Global Administrator
Teams Rooms on Windows Requirements
- Windows 11 24H2 running build 26100.8655 or later.
- Entra ID joined to the same Entra ID where the resource account was created.
- Teams Rooms on Windows app 5.6.135.0
Teams Rooms on Android Requirements
- Android OS 10 or later.
- Teams Rooms on Android app 1449/1.0.96.2026129709
- Authenticator app 6.2605.3066
- Teams Admin Agent app 1.0.0202506082157
Teams panel Requirements
- Android OS 10 or later
- Teams panels app 1449/1.0.96.2026164101
- Authenticator app 6.2605.3066
- Teams Admin Agent app 1.0.0202506082157
- Teams panels can be stand alone or signed into the same account as a Teams Room device. Teams panels using the same account as a Teams Room device will migrate to password-less at the same time.
Teams phone Requirements
- Android OS 10 or later.
- Teams phone app 1449/1.0.96.2026104705
- Authenticator app 6.2605.3066
- Teams Admin Agent app 1.0.0202506082157
Known limitations
- If you need to replace a device or change the credentials, you must setup the new device using an account with a password first, before migrating over.
Tip
We recommend testing with a small batch of devices prior to migrating your entire environment.
How to migrate devices and accounts to password-less
- Sign in to the Teams Rooms Pro Management Portal.
- Select Planning > Resource Accounts in the left navigation.
- Select the Migration tab.
- Select eligible resource account(s) to migrate.
- Select Schedule migration to open the migration wizard.
- Choose to either migrate now or during the next maintenance window.
- Review the select and select Confirm.
- The device(s) and account(s) will migrate at their scheduled time.
Verify migration progress
After the migration completes you may want to verify the following:
- The room reports a healthy status in the Pro Management Portal.
- The device signs in successfully.
- Teams device starts without repeated sign-in prompts.
- Teams device functionality works as expected.
Troubleshooting tips
- If migration does not complete successfully:
- Verify that the room meets the required platform software and app version requirements.
- Confirm that the resource account is correctly assigned.
- Check sign-in logs within Entra ID for failures.
- Review the migration status in the Pro Management portal – open detail panel for the failed account to see failure reason.
- Retry the migration after remediating any the failure reason or report blocking issues.
- If the new authentication path is not yet available on a device, Teams devices can continue using the existing sign-in flow until the room is ready to migrate.