---
title: "Customer Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices"
slug: "customer-advisory-potential-microsoft-entra-id-token-issues"
updated: 2026-07-31T06:45:13Z
published: 2026-07-31T06:45:13Z
canonical: "docs.workspot.com/customer-advisory-potential-microsoft-entra-id-token-issues"
---

> ## Documentation Index
> Fetch the complete documentation index at: https://docs.workspot.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Customer Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices

**Advisory: Potential Microsoft Entra ID Token Issues for Non-Entra Joined Devices**

Microsoft recently introduced a change to Conditional Access enforcement for policies that target**"All Resources"** and contain application exclusions. Following this change, authentication requests that previously bypassed Conditional Access evaluation may now be subject to MFA, device-compliance, or other access controls, even when an application exclusion exists. As a result, some Workspot users accessing the platform from devices that are not Microsoft Entra ID joined, Hybrid Entra ID joined, or compliant devices may experience token-related authentication issues if Conditional Access policies enforce device-based requirements. This behaviour is consistent with Microsoft's documented Conditional Access enforcement changes.

**Reference:** [Microsoft Learn – Enforcement for baseline scopes in Conditional Access](https://learn.microsoft.com/en-us/entra/identity/conditional-access/concept-enforcement-resource-exclusions)

**Potential Symptoms**

Users may experience one or more of the following:

- Workspot Client activation failures
- "Invalid or Expired Microsoft Entra ID Token" errors
- Repeated authentication prompts
- Desktop or application launch failures
- Token validation errors during authentication
- Workspot Client Control Error 712 or similar authentication-related failures

**Possible Cause**

Conditional Access policies that require:

- Compliant devices
- Microsoft Entra ID joined devices
- Hybrid Entra ID joined devices
- Multi-factor authentication (MFA)
- Other grant controls

may now be evaluated for authentication flows that were previously excluded or not enforced. Users connecting from unmanaged or non-Entra joined devices may therefore encounter new authentication challenges or token issuance failures.

**Recommendations for Workspot Customers**

To assess potential impact, Workspot recommends the following:

1. Review all Conditional Access policies targeting **All Resources**.
2. Verify whether the **Workspot Enterprise Application** or related applications are explicitly excluded from those policies.
3. Consider testing policy changes in **Report-only** mode before enabling enforcement.
4. Review **Microsoft Entra Sign-in Logs → Conditional Access** to determine whether Workspot authentication requests are being evaluated by the policy.
5. Validate the following user workflows after any Conditional Access change:

- Workspot Client activation
- Workspot Client reset/re-activation
- Desktop launch
- Application launch
- Browser-based authentication

**Workspot Recommendation**

If users begin experiencing authentication or token-related errors following a Conditional Access policy update, engage your Microsoft Entra ID administration team to review Conditional Access evaluation results and determine whether device-based access controls are preventing successful token issuance required for the Workspot authentication flow.

**Note:** Workspot authentication relies on Microsoft Entra ID token issuance. Conditional Access policies that enforce device compliance, device join requirements, or other access controls may affect client activation and access to Workspot resources if the authentication token cannot be successfully issued or validated.
