Accessing and using Microsoft Teams on smartphones and tablets across platforms
For Teams on Android devices, Conditional Access can still appear to work for a period after a policy is configured because sign-in behavior depends on token renewal and policy evaluation.
Common causes to check:
- The device is noncompliant, but the existing token has not yet been replaced If a device is marked noncompliant, Microsoft Entra stops renewing or can revoke tokens for that device object. Until token renewal or reauthentication occurs, access can appear to continue.
- Sign-in frequency settings If Conditional Access policies use Sign-in frequency, reauthentication happens periodically. This can cause delayed enforcement and can also create new device objects during reauthentication. If device object limits are exceeded, sign-in can then fail.
- Unsupported Conditional Access or Intune compliance settings for Teams Android devices Unsupported policy settings can cause unexpected behavior such as sign-in loops, random sign-outs, or freezes instead of clean blocking.
- Terms of Use and MFA policies together Using both can cause known issues on Teams phones.
To verify what is actually blocking or allowing access:
- Go to the sign-in logs in the Azure portal.
- Open User sign-ins (non-interactive).
- Add filters:
- Status = Failure
- Application = Teams
- For the affected account, check these application entries:
- Microsoft Teams
- Microsoft Teams Service
- Microsoft Teams – Device Admin Agent
- Open each failed sign-in and review on Basic info:
- Sign-in error code
- Failure reason
- Additional Details
- If the error looks compliance-related, open the Conditional Access tab and identify policies showing Failure.
- Review the failing policy details.
If a specific Conditional Access policy is the cause, device filters can be used to exclude affected Teams Android devices from that policy. Common filter properties include manufacturer and model. For devices transitioning to Intune AOSP device management, device.displayName is useful because it includes manufacturer information early in sign-in, before full Intune enrollment finishes.
Also verify device compliance in the Intune Device compliance dashboard and check each policy for unsupported settings for Teams devices.
If the scenario is specifically mobile app access continuing after a new block policy, one documented Q&A case notes that Outlook and Teams mobile can use long-lived tokens, so blocking may not be immediate until token renewal, sign-in frequency enforcement, or session revocation occurs.