Microsoft 365 features that help users manage their subscriptions, account settings, and billing information.
This weekend I did a deep cleaning of all Microsoft software and credentials from my phone.
I removed my (my company) account from Authenticator. When I did it popped up a 2 digit number (authentication request screen). I backed out. In authenticator I saw the message
"Update your security info
One of your sign-in methods wasn't deleted from your account. So you'll need to delete it at https://aka.ms/mysecurityinfo"
With noted exceptions I forced stopped, cleared data and cache, and uninstalled the following:
Outlook
OneDrive: Uninstalled updates, unable to fully uninstall preloaded software.
Edge: Had to go to Manage Data and Clear data instead of normal android menu.
Teams
Excel
OneNote
Company Profile
Authenticator
(should have also cleared Office, but did not)
Checked my phone Settings>Accounts and Backup>Manage Accounts: Cleared account starting with "work-3F..."
Google Play store: Force stop, clear data, clear cache
Android System WebView: clear data, clear cache
Pass (samsung): Force stop, clear data, clear cache
Autofill with Samsung Pass: Clear data, clear cache
Google Play Services: (Left alone)
Restarted phone
Set up screen lock pin
Install Company portal
Logged in
Company Portal says device does not meet (my company) Requirements. Lists Device Settings Status as Unknown.
Restarted
Open Company Portal, status same.
In Company Portal>Settings>Management Policy hit SYNC
No changes.
Gemini suggests the following causes:
Cause 1: Your company blocks personal Android devices (Most Likely)
During tenant migrations, IT administrators frequently restrict enrollment to company-owned devices by default. If they haven’t explicitly whitelisted personally owned Android devices (known as BYOD, or Bring Your Own Device) in the new tenant's Enrollment Device Platform Restrictions, any personal Android phone attempting to enroll will be hit with an immediate block, returning an "Unknown" status.
Cause 2: A lingering stale registration in the Microsoft Cloud
Even though you completely wiped your phone locally, your phone's unique hardware identifier (Device ID) might still be registered to your old company tenant up in the Microsoft cloud. When the new tenant tries to claim and register your device hardware, Microsoft sees the conflict, drops the handshake, and reports the configuration status as "Unknown".
I then cleared all data from Company Profile again.
I also investigated other Android sandbox options. I searched my phone for "profile" and found a built-in method to set up a work profile. This app is looking for a code from my IT department. Gemini suggests that this code will be automatically injected into my system from Company Portal, but only if the Company Portal app properly accepts my device. It suggests that the work profile setup would have actually been kicked off upon proper device registration.
Currently it seems that the Tenant configuration is doing one or more of the following:
Blocking device registration of non-company devices
Failing to whitelist OneNote in Company Portal
Reserving my device registration on the old Calvary Tenant
After all the deep cleaning mentioned below, I opened OneDrive. It warned me that data was deleted by my company. I then STILL saw BOTH old tenants and (new tenant) accounts listed. I cleared data from OneDrive again then closed and reopened OneDrive. Now I do not see any accounts.
After clearing data in OneDrive for a 2nd time...
Sign in to OneDrive
Got "Help us keep your device secure" prompt
Registered device
Prompted me to install Company Portal > Installed
Signed in, saw only current company
Saw Get Access page with checkmarks showing green on
- Recently Connected
- Device is supported
- Everything's up to date
- Device is healthy
Set up PIN for Company Portal
Now able to see OneDrive files
Select a OneNote notebook within OneDrive
Prompted to get the app
Linked to Google Play Store for "Microsoft OneNote: Save Notes" app
Installed, opened
OneNote screen saying "All Done" then see my company account listed. Logged in.
OneNote notebooks now work.
Opened Company Portal
Signed in (somehow wasn't?)
Can now see Play Store inside Company Portal.
Install Teams from Company Portal
Open Teams, log in with current company account shown.
"Get Access" screen, again all green.
Allowed nearby devices and approximate location while using the app.
Teams works.
From Company portal, install Edge
Open Edge
Did NOT choose as default browser
Sign-in with latest company credentials shown
Sync with company
"Get Access" screen, all green.
From Company Portal install Outlook
Open Outlook
Add Account > Current company credentials > Continue > OK
Got popup about "A new way to sign in" asking if I wanted to have Outlook approve sign ins. Tried to learn more then backed out. Option gone. Not enabled.
Went to inbox, Outlook works.
Noticed that "Office" was still installed and was not on list of apps cleared.
Without opening app, cleared data.
Apps in working state. 2FA via Authenticator is not yet re-enabled though text codes are. Currently afraid that resetting 2FA will break everything again.