← Back to blog
Security

Teams Rooms passwordless: Entra Resource Accounts remove passwords from meeting room devices

By Zarioh Digital Solutions5 min read
Share
Teams Rooms passwordless: Entra Resource Accounts remove passwords from meeting room devices

Every meeting room has a resource account that rarely changes its password. Microsoft now has a fix: Entra Resource Accounts make Teams Rooms, Panels, and Common Area Phones passwordless through hardware-bound credentials. Here is how it works and how to migrate.

Every office with a meeting room shares the same problem: the resource account powering a Teams Room, a Teams Panel, or a shared phone has been signed in with the same password for months or years. Most IT teams set that account up and forget about it. The device works, the calendar syncs, and nobody asks questions — until that account becomes part of a security incident.

Microsoft made a structural solution generally available in August 2026: Entra Resource Accounts for Teams devices. Instead of a password that needs periodic rotation, the device uses hardware-bound credentials that cannot be stolen or reused on another system.

The password problem with shared meeting room devices

Resource accounts are Entra ID identities linked to a device, not to a person. They have access to Teams, Exchange Online for calendar management, and sometimes SharePoint. That makes them attractive to attackers: an account with broad permissions and a password that rarely changes.

In practice there are two risk scenarios. With credential stuffing, attackers try leaked credentials from other data breaches on business accounts. Resource accounts with passwords that are years old or derived from a standard naming convention are vulnerable to this type of attack. The second risk involves Conditional Access blind spots: Conditional Access policies are built around users and their behaviour. A resource account behaves differently and falls outside many common policy rules unless that is explicitly configured.

Additionally, resource accounts in many environments are excluded from MFA because Teams Rooms then fails to sign in correctly. This makes them a weak point from a security perspective, even if they are not the most obvious attack target.

What Entra Resource Accounts change

Entra Resource Accounts for Teams devices replace password-based authentication with hardware-bound credentials. On Windows devices, the built-in TPM-protected storage is used; on Android, that is the secure Keystore. This separates the device identity from a traditional user account with password.

The practical result is that the device authenticates via the TPM chip, not via a password stored or transmitted somewhere. That credential is device-specific: it cannot be copied, exported, or reused on another machine. Credential theft becomes pointless because there is no password to steal.

The resource account itself remains in Entra ID and retains its permissions on Teams and Exchange. What changes is the device sign-in method. Existing Microsoft 365 licences and Teams Rooms licences continue to apply.

Supported devices

The current release supports Teams Rooms on Windows, Teams Rooms on Android, Teams Panels, and Common Area Phones. That covers most meeting rooms and reception setups organisations have in use today.

There is one known exception: Crestron Teams Rooms on Windows are not currently supported. Organisations using Crestron hardware will need to wait for a future update before they can migrate those devices.

The migration procedure

Migration is optional and entirely admin-driven. Microsoft forces nothing; existing resource accounts continue to work until you convert them yourself. The process runs through the Teams Rooms Pro Management Portal.

Navigate to Planning, then Resource Accounts, then Migration. There you find a built-in migration wizard and a progress dashboard where you can track the conversion status per device and location. Microsoft recommends a phased approach: start with one location or room, validate the result, and then scale up.

The required admin role is User Administrator or Global Administrator in Entra ID. The relevant resource accounts must have a Teams Rooms licence. After migration, the device automatically signs back in using the hardware credential. Users of the meeting room notice nothing: the room works as before, the calendar syncs, and Teams calls proceed normally.

What changes for IT after migration?

The direct operational gain is that resource accounts no longer need to be given a new password manually. This eliminates a maintenance task that most organisations were not performing systematically anyway, and it removes the associated risk.

From the Entra portal, migrated devices are visible as managed devices with a clear status per device, making monitoring easier. Conditional Access policies can be adjusted so that devices with hardware-bound credentials are explicitly marked as compliant. Management tasks such as re-linking a device to a resource account take place via the Pro Management Portal or PowerShell, with a workflow that differs little from the current approach but with significantly stronger authentication.

How to start the roll-out

Start by inventorying all resource accounts in the Entra tenant. Look in the Entra portal for accounts of type 'Room', or use PowerShell to export an overview. Pay attention to accounts that have been unchanged for a long time and accounts whose password has never been rotated — those are the highest-risk cases.

Choose one meeting room as a pilot, preferably a room where a temporary issue would have limited operational impact. Run the migration via the wizard and validate that the room functions normally: calendar visible, calls working, no sign-in issues. After a successful pilot, plan the roll-out per wing, floor, or location. Exclude Crestron devices from your planning for now.

Shared devices and Zero Trust

Teams Rooms are not the only type of shared device in an organisation. Common Area Phones, reception tablets, kiosks, shared workstations — all of these have an identity that is typically managed less carefully than a personal user account. The introduction of hardware-bound credentials for Teams devices fits into a broader movement: shared devices are getting a stronger identity layer, similar to what Windows Hello for Business already provides for personal endpoints.

For IT teams working on a Zero Trust strategy, this is a concrete improvement point. Passwordless resource accounts align directly with an approach where every access point in the environment is secured, including the meeting room on the second floor that typically falls outside the security radar. Want help inventorying resource accounts, planning the migration, or adjusting Conditional Access policies for devices? Zarioh guides organisations through the complete Microsoft 365 and security setup. Get in touch for a no-obligation conversation.

Z

Zarioh Digital Solutions

IT specialists from Utrecht, the Netherlands. We help businesses with Microsoft 365, AI agents, hosting and telephony — and share what we learn in practice. Follow us on LinkedIn

Related articles

← Back to all articles
Share