Android Fully Managed devices treated as personal after AD password change

Damian Masalski 0 Reputation points
2026-07-13T07:35:54.2+00:00

Hello!

We have a huge problem...

We have recently observed an issue in our organization affecting Android Fully Managed devices.

After users change their domain password, within 1–3 days Conditional Access starts blocking access to Outlook and Teams. The system appears to treat the device as non-corporate, even though in Intune the device is still present, marked as corporate, and fully functional. It synchronizes both manually and automatically, and remote actions can be executed without any issues.

However, when users open Outlook or Teams, they receive messages such as “We need to secure your device” and “Install the Intune app from Google Play,” which does not make sense because Intune is already installed on the device.

When opening the Intune app, users see a “Update your password” prompt. After selecting it, they are redirected to a device registration screen.

Previously, it was sometimes possible to complete this process (although we did not understand why it was required), but recently re-registration consistently fails. The user clicks “Register,” and the process spins indefinitely without completing.

This issue is very difficult to troubleshoot. Device logs are not particularly helpful, and all users have Microsoft Authenticator configured. The problem appears randomly across users with no clear pattern—some devices were enrolled over a year ago, others just a month ago.

The only clue we have found so far points to a potential issue with the broker authentication token, but we do not know how to verify or resolve this, nor why it is happening in the first place.

We have been experiencing this issue since around January this year, but we noticed a significant increase in cases this month. In addition, there are more and more devices that can no longer be re‑registered from within the Intune app.

Has anyone encountered a similar issue or can provide guidance on how to investigate or fix this?

Microsoft Security | Intune | Microsoft Intune Android
0 comments No comments

1 answer

Sort by: Most helpful
  1. Christos Panagiotidis 3,301 Reputation points
    2026-07-14T17:56:19.04+00:00

    Hi Damian, the ownership flag is probably not changing; the sign-in is more likely losing the broker/device compliance claim after the password change. Pick one affected user and compare the Entra sign-in log before and after the failure: device ID, managed, compliant, authentication broker, Conditional Access result, and any duplicate device objects. On the phone, confirm Android Device Policy/Company Portal and Microsoft Authenticator are current, the work profile account can refresh its token, and Google Play services are healthy. Also review the Intune compliance record and enrollment token type, because Fully Managed devices should not be sent through a personal registration flow. Collect Company Portal/Authenticator logs immediately after reproduction and open an Intune case if the same device ID is compliant in Intune but absent from the sign-in. Retire/re-enroll only as a last step after preserving those logs.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.