Skip to main content

11 août 2026

Shared Device Mode (SDM) for Microsoft Azure Conditional Access Policies on Android Devices

This section discusses Shared Device Mode for Microsoft Azure Conditional Access Policies on Fully Managed Android devices.

This feature allows customers to alert Azure of which user is currently using a shared device and the current compliance status of that device. This allows customers using Azure Conditional Access to configure policies which allow access to certain Microsoft productivity applications under certain conditions, based on any compliance rules supported by Workspace ONE UEM.

Since a device registered in shared device mode allows for access to company resources based on the device compliance, without the need for each user to go through the remediation and registration process, a one-time registration occurs. The device are registered and grants all users logging into that device access to Microsoft 365 apps upon sign-in to their corporate account.

Requirements to use Microsoft Azure Conditional Access Policies on Shared Devices

  • Workspace ONE UEM version 23.06 or later
  • Workspace ONE Intelligent Hub version 23.07 or later
  • Workspace ONE Launcher version 23.02 or later
    • If you are using Launcher, download v23.02 from the Resource portal if it is not already seeded in your console: Resource Portal Download

Setup

To get started, follow the steps pertaining to Android listed in Use Compliance Data in Azure AD Conditional Access Policies then perform a sync with the following steps:

  • In Workspace ONE UEM, perform a sync of Azure Services under Settings > System > Enterprise Integration > Directory Services > Sync Azure Services.

Configure Shared Device Mode

Devices must be enrolled in Android Enterprise Fully Managed mode. Workspace ONE Launcher is compatible with Shared Device Mode in the following configurations:

  • On the sign-in screen in Check-in/Check-out (CICO) mode
  • Single App mode (for use with 3rd party launcher applications)

In the Workspace ONE UEM Console

  1. Navigate to Settings > Devices & Users > Android > Intelligent Hub Settings and turn on Register as Shared Device with Azure for Conditional Access.
  2. Add Microsoft Authenticator as a Public App (from Google Play) and add a new, or configure an existing, assignment.
  3. Within the assignment, go to the Application Configuration tab and apply following configuration:
    • Shared Device Mode: Enable
    • Prefill UPN in Shared Device Mode: Leave this field blank.
    • Shared Device Mode Tenant Identifier: Enter your Microsoft Tenant ID.
    • Shared Device Mode Registration token: Enter the lookup value.
      {SharedDeviceRegistrationToken}
      This value will be replaced automatically with the correct key by Workspace ONE UEM.
  4. Ensure the app is assigned to devices targeted for Shared Device Mode
  5. If you are using an Android Restrictions profile, ensure the setting Allow adding/deleting accounts is set to Enable.

New Device Setup

During enrollment, Microsoft Authenticator is launched automatically after it is installed. It will wait to receive the registration token (this may take up to one minute). Once the token is received, registration completes and the device compliance status is relayed to Microsoft. Once the process is complete, and the device is marked as Shared and Compliant in Azure, users are able to login to Microsoft apps.

Note:This registration and setup flow only needs to occur one time per device.

Existing Device Setup

On devices that are already enrolled, Microsoft Authenticator will be launched for SDM registration after the configuration steps are completed.There are two different scenarios based on the home screen launcher that is used:

Workspace ONE UEM Launcher with Check-in/Check-out enabled: Microsoft Authenticator launches automatically to complete the registration after the device is checked in (user signs out) so that the user is not disrupted.

Workspace ONE UEM Launcher in Single App Mode: This scenario is primarily for the use of custom launchers as the primary end user interface. Microsoft Authenticator launches automatically after receiving the configuration to perform the registration.

Note: It is possible to migrate from Launcher Multi-App mode to Single App mode and then kick of the Shared Device Mode registration with Microsoft Authenticator, in the case that Check-in/Check-out is not activated. Just make sure to add Microsoft Authenticator as a hidden app in the Launcher configuration.

After the device is registered, it is listed in your Azure tenant and marked as a Shared Device with the current Compliance status. Users will then be able to sign into Microsoft Apps without any additional remediation steps.

Troubleshooting

This section covers common issues you might run into while provisioning shared devices with Microsoft Conditional Access:

  • Microsoft Authenticator App shows expired authentication error
    The app configuration must be pushed to that device again. This can be done by re-pushing the app to the device from the Workspace ONE UEM console. The app will not be reinstalled, but receives the configuration again.
  • The user is not able to sign into any Microsoft app
    Admins should check the Azure tenant to make sure that the device record exists and is marked as ‘Shared’ and ‘Compliant'. If the device record shows this, ask the user to try signing in again. If it shows the wrong status, then check the following:
    • Event Log in the Workspace ONE UEM console
    • Device side ADB logs
    • Checking server logs via support
  • Any other registration failure is encountered (device side or server-side)
    • Admins can check the following:
    • Event Log in the Workspace ONE UEM console
    • Device side ADB logs
    • Checking server logs via support

Cette page vous a-t-elle été utile ?

Envoyer un commentaire sur cette rubrique

Cette rubrique vous a-t-elle été utile ?

N'indiquez aucune information personnelle ou confidentielle.

Génération du lien…