Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices
Microsoft has recently introduced changes to Conditional Access (CA) policy enforcement that may affect authentication flows using Microsoft Entra ID. As a result, some Workspot users accessing the platform from devices that are not Microsoft Entra ID joined, Hybrid Entra ID joined, or compliant devices may experience token-related authentication issues if Conditional Access policies are configured to enforce device-based requirements.
Reference Link: Enforcement for baseline scopes in Conditional Access - Microsoft Entra ID
Potential Symptoms
Users may experience one or more of the following:
Workspot Client activation failures
"Invalid or Expired Microsoft Entra ID Token" errors
Repeated authentication prompts
Desktop or application launch failures
Token validation errors during authentication
Workspot Client Control Error 712 or similar authentication-related failures
Possible Cause
Conditional Access policies that require:
Compliant devices
Microsoft Entra ID joined devices
Hybrid Entra ID joined devices
Multi-factor authentication (MFA)
Other grant controls
may now be evaluated for authentication flows that were previously excluded or not enforced. Users connecting from unmanaged or non-Entra joined devices may therefore encounter new authentication challenges or token issuance failures.
Recommendations for Workspot Customers
To assess potential impact, Workspot recommends the following:
Review all Conditional Access policies targeting All Resources.
Verify whether the Workspot Enterprise Application or related applications are explicitly excluded from those policies.
Consider testing policy changes in Report-only mode before enabling enforcement.
Review Microsoft Entra Sign-in Logs → Conditional Access to determine whether Workspot authentication requests are being evaluated by the policy.
Validate the following user workflows after any Conditional Access change:
Workspot Client activation
Workspot Client reset/re-activation
Desktop launch
Application launch
Browser-based authentication
Workspot Recommendation
If users begin experiencing authentication or token-related errors following a Conditional Access policy update, engage your Microsoft Entra ID administration team to review Conditional Access evaluation results and determine whether device-based access controls are preventing successful token issuance required for the Workspot authentication flow.
Note: Workspot authentication relies on Microsoft Entra ID token issuance. Conditional Access policies that enforce device compliance, device join requirements, or other access controls may affect client activation and access to Workspot resources if the authentication token cannot be successfully issued or validated.