I have configured Conditional Access for Teams

Kiran 0 Reputation points
2026-09-23T09:05:16.5533333+00:00

I have configured Conditional Access for Teams not to work on Mobile devices, but it is still working

Microsoft Teams | Microsoft Teams for business | Teams on mobile devices
0 comments No comments

2 answers

Sort by: Most helpful
  1. Liora 2,080 Reputation points Independent Advisor
    2026-09-23T09:34:37.4533333+00:00

    Dear @Kiran,

    I hope you’re having a good day. 

    If Teams is still working on mobile devices after you configured a Conditional Access policy to block it, the quickest way to identify the cause is to check whether the policy is actually being evaluated for the affected sign-ins.

    I recommend reviewing a recent mobile Teams sign-in in Microsoft Entra Admin Center > Sign-in logs. Open the sign-in event and check the Conditional Access section. This will show whether the policy was successfully applied, not applied, or excluded.

    Screenshot 2026-09-23 at 16.34.00

    A few common causes are:

    • The policy is targeting Microsoft Teams, but the actual access is occurring through another Microsoft 365 service that is not included in the policy.
    • The Device platforms condition is not configured as expected, so the mobile device is not matching the policy.
    • The Client apps condition does not match the authentication flow being used by Teams Mobile.
    • The affected user, group, device, or location is excluded from the policy.
    • The policy is configured in Report-only mode rather than On.
    • The user signed in before the policy was created and is still using a valid session or refresh token.

    To help identify the exact reason, could you share a screenshot of the Conditional Access policy configuration (with any sensitive information removed), particularly:

    • Assignments (Users, Groups, and Target Resources)
    • Conditions (Device platforms and Client apps)
    • Access controls (Grant)

    The Conditional Access results in the sign-in logs and the policy configuration are usually enough to determine why Teams is still accessible on mobile devices.

    Warm regards,  


    If the answer is helpful, please select "Yes, accept answer". If you have any questions or new updates, please feel free to comment below. 

    Was this answer helpful?


  2. AI answer

    2026-09-23T09:05:38.98+00:00

    For Teams on Android devices, Conditional Access can still appear to work for a period after a policy is configured because sign-in behavior depends on token renewal and policy evaluation.

    Common causes to check:

    1. The device is noncompliant, but the existing token has not yet been replaced If a device is marked noncompliant, Microsoft Entra stops renewing or can revoke tokens for that device object. Until token renewal or reauthentication occurs, access can appear to continue.
    2. Sign-in frequency settings If Conditional Access policies use Sign-in frequency, reauthentication happens periodically. This can cause delayed enforcement and can also create new device objects during reauthentication. If device object limits are exceeded, sign-in can then fail.
    3. Unsupported Conditional Access or Intune compliance settings for Teams Android devices Unsupported policy settings can cause unexpected behavior such as sign-in loops, random sign-outs, or freezes instead of clean blocking.
    4. Terms of Use and MFA policies together Using both can cause known issues on Teams phones.

    To verify what is actually blocking or allowing access:

    1. Go to the sign-in logs in the Azure portal.
    2. Open User sign-ins (non-interactive).
    3. Add filters:
      • Status = Failure
      • Application = Teams
    4. For the affected account, check these application entries:
      • Microsoft Teams
      • Microsoft Teams Service
      • Microsoft Teams – Device Admin Agent
    5. Open each failed sign-in and review on Basic info:
      • Sign-in error code
      • Failure reason
      • Additional Details
    6. If the error looks compliance-related, open the Conditional Access tab and identify policies showing Failure.
    7. Review the failing policy details.

    If a specific Conditional Access policy is the cause, device filters can be used to exclude affected Teams Android devices from that policy. Common filter properties include manufacturer and model. For devices transitioning to Intune AOSP device management, device.displayName is useful because it includes manufacturer information early in sign-in, before full Intune enrollment finishes.

    Also verify device compliance in the Intune Device compliance dashboard and check each policy for unsupported settings for Teams devices.

    If the scenario is specifically mobile app access continuing after a new block policy, one documented Q&A case notes that Outlook and Teams mobile can use long-lived tokens, so blocking may not be immediate until token renewal, sign-in frequency enforcement, or session revocation occurs.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.