Managing Android devices using Microsoft Intune
Hi Damian, the ownership flag is probably not changing; the sign-in is more likely losing the broker/device compliance claim after the password change. Pick one affected user and compare the Entra sign-in log before and after the failure: device ID, managed, compliant, authentication broker, Conditional Access result, and any duplicate device objects. On the phone, confirm Android Device Policy/Company Portal and Microsoft Authenticator are current, the work profile account can refresh its token, and Google Play services are healthy. Also review the Intune compliance record and enrollment token type, because Fully Managed devices should not be sent through a personal registration flow. Collect Company Portal/Authenticator logs immediately after reproduction and open an Intune case if the same device ID is compliant in Intune but absent from the sign-in. Retire/re-enroll only as a last step after preserving those logs.