Documentation Index

Fetch the complete documentation index at: https://docs.workspot.com/llms.txt

Use this file to discover all available pages before exploring further.

Customer Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices

Prev Next

Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices

Microsoft has recently introduced changes to Conditional Access (CA) policy enforcement that may affect authentication flows using Microsoft Entra ID. As a result, some Workspot users accessing the platform from devices that are not Microsoft Entra ID joined, Hybrid Entra ID joined, or compliant devices may experience token-related authentication issues if Conditional Access policies are configured to enforce device-based requirements.

Reference Link: Enforcement for baseline scopes in Conditional Access - Microsoft Entra ID

Potential Symptoms

Users may experience one or more of the following:

  • Workspot Client activation failures

  • "Invalid or Expired Microsoft Entra ID Token" errors

  • Repeated authentication prompts

  • Desktop or application launch failures

  • Token validation errors during authentication

  • Workspot Client Control Error 712 or similar authentication-related failures

Possible Cause

Conditional Access policies that require:

  • Compliant devices

  • Microsoft Entra ID joined devices

  • Hybrid Entra ID joined devices

  • Multi-factor authentication (MFA)

  • Other grant controls

may now be evaluated for authentication flows that were previously excluded or not enforced. Users connecting from unmanaged or non-Entra joined devices may therefore encounter new authentication challenges or token issuance failures.

Recommendations for Workspot Customers

To assess potential impact, Workspot recommends the following:

  1. Review all Conditional Access policies targeting All Resources.

  2. Verify whether the Workspot Enterprise Application or related applications are explicitly excluded from those policies.

  3. Consider testing policy changes in Report-only mode before enabling enforcement.

  4. Review Microsoft Entra Sign-in Logs → Conditional Access to determine whether Workspot authentication requests are being evaluated by the policy.

  5. Validate the following user workflows after any Conditional Access change:

  • Workspot Client activation

  • Workspot Client reset/re-activation

  • Desktop launch

  • Application launch

  • Browser-based authentication

Workspot Recommendation

If users begin experiencing authentication or token-related errors following a Conditional Access policy update, engage your Microsoft Entra ID administration team to review Conditional Access evaluation results and determine whether device-based access controls are preventing successful token issuance required for the Workspot authentication flow.

Note: Workspot authentication relies on Microsoft Entra ID token issuance. Conditional Access policies that enforce device compliance, device join requirements, or other access controls may affect client activation and access to Workspot resources if the authentication token cannot be successfully issued or validated.