[Security: MS Teams] Device-bound Token (Password-less) And Shared Space Device Resource Accounts

07-10-2026

In this blogpost we're going to talk about the new security feature regarding creating a password-less device bound resource account credential for your Teams shared space device resource accounts. 


1. What's New?

In September Microsoft released a new option to enable password-less device bound token to Teams devices and resource accounts. This is a great new feature to ensure the device doesn't have a stored username/password credential. 

Couple of benefits:

  • No cached credentials;

  • Device bound token to communicate between the endpoint and MS365;

  • End users won't notice this change;

  • No need to manually sign into the device anymore.


2. Requirements

The following requirements/prerequisites are needed (source MSLearn):

  • Teams Resource Account created and signed into your Teams device.

  • The resource account can be Entra ID only or synchronized from Active Directory.
  • Third party federated identity providers are supported.
  • The Teams resource account must be licensed to convert it to password-less:
  • Teams Rooms on Windows and Teams Rooms on Android require a Teams Rooms license
  • Teams panels and Teams phones require a Teams Shared Space license
  • Teams device and Resource Account are both visible in the Teams Rooms Pro Management Portal.
  • Teams Rooms need to be Entra Joined;
  • Supported Teams Devices: Teams Rooms on Windows, Teams Rooms on Android, Teams panel and Teams phone
  • Administrative access required to transition devices to password-less: Teams Administrator
  • Administrative access required to use the Cleanup Password wizard: User Administrator or Global Administrator

Software versions:

Teams Rooms Android:

  • Android OS 10 or higher;

  • Teams Rooms on Android app 1449/1.0.96.2026129709 or higher;

  • Authenticator app 6.2605.3066 or higher;

  • Teams Admin Agent app 1.0.0202606082157 or higher.

Teams panel:

  • Android OS 10 or higher;

  • Teams panels app 1449/1.0.97.2026164101 or higher;

  • Authenticator app 6.2605.3066 or higher;

  • Teams Admin Agent app 1.0.0202606082157 or higher.

Teams phone:

  • Android OS 10 or higher;

  • Teams phone app 1449/1.0.94.2026104705 or higher;

  • Authenticator app 6.2605.3066 or higher;

  • Teams Admin Agent app 1.0.0202606082157 or higher.


3. How To Migrate?

Follow these simple steps to migrate to password-less.

Browse to the Teams Rooms Pro Management Portal (https://portal.rooms.microsoft.com/)

Select Planning -> Resource Accounts 

From the Resource Accounts screen select "Migration". Here you will see all your resource accounts and which account are eligible to be migrated to password-less sign in. 

Select a few accounts that you want to migrate. I recommend to test this out first on resource accounts that hasn't much impact in your organization.

After you selected your account(s), select "Schedule migration" 

From the migration wizard you could choose to apply the migration immediately and complete the wizard.

After the migration has finished, you will need to manually cleanup the stored password on the device/panel. From the same "Migration" screen you will see "Cleanup password". Select the just migrated resource account(s) and select this option.

You now will see that "Auth mode" is set to "Passwordless", now that we successfully migrated the device and cleaned up the password located on the device.

*Note: The password cleanup will only be successful when using a cloud only resource account. Hybrid synchronized account can be scrambled / reset without impacting the password-less auth token.


4. Wrap up

This is a great addition to your security landscape. With this new option we are able to secure our Teams devices without having to worry about cached credentials. Sometimes these devices can be placed in a public area, where we want to have the max security right? With device bound resource account credentials we ensure a by default device deployment mechanism. 

Share