UCPrimer
  • UCprimer
  • About

Teams Rooms Android updates for AOSP and DCF

6/13/2025

0 Comments

 
Picture
​Microsoft Teams Android devices are transitioning to Intune Android Open Source Project (AOSP) device management. This migration aims to enhance reliability, improve deployment experiences for admins, and pave the way for future innovations in managing Teams devices. Additionally, there are important updates regarding device code flow (DCF) authentication policies to further secure your tenants. Read this blog post to get up to speed on all the latest updates and changes within the last two months. 
1. Migrating Microsoft Teams Android Devices to AOSP Device Management

Microsoft Teams Android devices are transitioning to Intune Android Open Source Project (AOSP) device management. This migration aims to enhance reliability, improve deployment experiences for admins, and pave the way for future innovations in managing Teams devices.The migration will occur in phases:

  • Validation Phase: 0-15 days
  • General Phase: 16-45 days
  • Final Phase: 45-60 days

For example, if the auto-update starts on May 15th, devices in the Validation phase will update first, followed by the General phase starting May 30th, and finally the Final phase starting June 28th.Do note that this update is mandatory and cannot be postponed indefinitely.

Prerequisites for Migration
To ensure a smooth migration, complete the following prerequisites:
  • Create Enrollment Profiles: Set up new enrollment profiles and configuration/compliance policies in Intune.
  • Install Firmware Updates: Once the AOSP-compatible firmware is available, install updates for each supported Teams device.

Step-by-Step Migration Process
Step 1: Create Enrollment Profiles
Create new enrollment profiles and configuration/compliance policies in Intune. This step must be completed before the firmware updates is completed. Please note that only few policies are supported at this time. Failure to create enrollment profiles will result in devices failing to enroll properly in Intune. Ensure the AOSP Device Management enrollment profile is created with an extended enrollment token and the Teams Devices option enabled. For step-by-step guidance, refer to the earlier blog post on AOSP device management Preparing for AOSP Enrollment on Teams Android Devices - UCPrimer

Step 2: Install Firmware Updates
When the AOSP-compatible firmware is released, install the updates for each Teams device.
The firmware update will automatically unenroll the device from Device Administrator and re-enroll it with AOSP Device Management.

HP Poly has released the latest firmware 4.5.x supporting AOSP Device Management and recommends all owners of Poly Teams Room Android devices to update to this latest version.
Picture
Best Practices for Conditional Access Policies
To avoid issues during migration, follow these recommendations:
  • Device Compliance Requirement: Ensure enrollment profiles are created in Intune.
  • Multi-factor Authentication (MFA): Not supported for shared devices.
  • App Protection Policies: Not supported.
  • Terms of Use (ToU): Not supported for shared devices.
  • Sign-in Frequency: Avoid using "1 hour" or "Every time" for Teams devices undergoing migration.

Important Update for Teams Phones with MFA
Teams Phones updated to AOSP ready firmware, such as PVOS 9.1.x, do not supported device code authentication when MFA is enabled. Users must login on the device itself in order to be able to trigger the MFA process. Please see this link for more information Some Poly phones may sign out after migration to Microsoft AOSP | HP® Support

For further guidance on AOSP migration, please refer to this Microsoft post ​Moving Teams Android Devices to AOSP Device Management | Microsoft Community Hub
Picture
Picture
Picture
For HP Poly specific video and phones, the following table shows the update timings:
Picture

​2. Policy Changes for Microsoft Teams Devices Using Device Code Flow Authentication

Microsoft has introduced new policies to enhance the security of Microsoft Teams devices using Device Code Flow (DCF) authentication. This section will guide you through the recent policy changes, their implications, and how to manage these policies effectively. Device Code Flow (DCF) authentication is a method used by devices to authenticate without requiring user interaction on the device itself. This is particularly useful for shared devices like Microsoft Teams Rooms, IP phones, and other Android-based Teams devices.

Policy Changes Overview
First announced in February 2025, Microsoft is rolling out new policies to secure tenants against potential threats to accounts using DCF authentication. The rollout began in February and will continue until May. These policies will initially be in report-only mode, allowing administrators to review their impact before enforcement.

Key Points of the New Policies:
  • Report-Only Mode: Policies are initially created in report-only mode, giving administrators at least 45 days to evaluate and configure them before they are automatically enforced.
  • Exclusion Lists: Administrators can create exclusion lists for accounts that sign in on Android-based shared Teams devices. This ensures that these devices can re-authenticate with DCF after sign-out.
  • Impact on Shared Devices: Without exclusions, devices cannot re-authenticate with DCF, leading to a loss of remote sign-in and management capabilities.

Steps to Manage the New Policies
  • Evaluate the Policies: Use the report-only mode to understand the impact of the new policies on your organization.
  • Create Exclusion Lists: Identify and exclude accounts that need to sign in on shared devices. This can be done in the Microsoft Entra admin center.
  • Configure Policies: Customize the Microsoft-managed policies according to your organization's specific needs.
Picture
The exclusion lists for this policy should be created by tenants that have deployed Android-based Teams devices in shared spaces like:
  • Microsoft Teams Rooms on Android front-of-room displays and consoles
  • IP Phones (licensed as Teams Shared Devices)
  • Panels
  • Displays
Picture
Conclusion
Migrating to AOSP Device Management will bring a more reliable and improved experience for managing Microsoft Teams Android devices. Follow the steps and best practices outlined to ensure a smooth transition. DCF enhances security for device authentication using code flow
0 Comments

Your comment will be posted after it is approved.


Leave a Reply.

    UCPrimer

    Picture
    Picture
    Picture
    View my profile on LinkedIn

    Important Links

    Microsoft Teams Docs
    Microsoft Learn

    ​Microsoft MVP Blogs

    Michael Tressler’s Blog
    Michael’s MTR Quick Tip Videos
    Jimmy Vaughan’s Blog
    Jeff Schertz
    Adam Jacobs
    James Cussen
    ​Damien Margaritis

    Archives

    June 2025
    April 2025
    March 2025
    February 2025
    January 2025
    December 2024
    November 2024
    October 2024
    August 2024
    July 2024
    May 2024
    April 2024
    March 2024
    February 2024
    December 2023
    November 2023
    October 2023
    September 2023
    July 2023
    March 2023
    February 2023
    January 2023
    November 2022
    October 2022
    September 2022
    August 2022
    July 2022
    March 2022
    February 2022
    January 2022
    December 2021
    November 2021
    October 2021
    September 2021
    August 2021
    June 2021
    April 2021
    March 2021
    December 2020
    October 2020
    September 2020
    August 2020
    April 2020
    March 2020
    February 2020
    January 2020
    December 2019
    November 2019
    October 2019
    September 2019
    August 2019
    July 2019
    March 2019
    November 2018
    October 2018
    September 2018
    August 2018
    June 2018
    March 2018
    February 2018
    January 2018
    December 2017
    November 2017
    August 2017
    July 2017
    April 2017
    March 2017
    February 2017
    January 2017
    November 2016
    October 2016
    September 2016
    August 2016
    July 2016
    June 2016
    May 2016
    April 2016
    March 2016
    January 2016
    November 2015
    October 2015
    September 2015
    August 2015
    July 2015
    June 2015
    May 2015
    April 2015
    March 2015
    February 2015
    January 2015
    December 2014
    November 2014
    October 2014
    September 2014
    August 2014
    July 2014
    June 2014
    May 2014
    April 2014
    March 2014
    February 2014
    January 2014
    December 2013
    November 2013
    October 2013
    September 2013
    August 2013
    July 2013
    June 2013
    May 2013
    April 2013
    March 2013
    February 2013
    January 2013
    December 2012
    November 2012
    September 2012
    August 2012

    Categories

    All
    Edge
    Exchange 2013
    Hybrid
    Lpe
    Lync 2010
    Lync 2013
    Mobility
    Oauth
    Office365
    Polycom
    Ucs

    RSS Feed

    This website uses marketing and tracking technologies. Opting out of this will opt you out of all cookies, except for those needed to run the website. Note that some products may not work as well without tracking cookies.

    Opt Out of Cookies