Forum Discussion
Windows App - you can't get there from here
This is Conditional Access blocking the password-reset flow launched by Windows App, not an AVD host-pool or Graph outage. The Windows 365 Client failure against Microsoft Graph is the clue: excluding only the AVD client does not cover a downstream resource evaluated by Conditional Access. In the affected sign-in, open the Conditional Access tab and identify the exact policy and failed grant control. Test a scoped change with a pilot group and Report-only mode; do not exclude Microsoft Graph tenant-wide. If users can complete SSPR from a compliant device or trusted location, have them reset there, then sign out of Windows App and authenticate again. Also review any policy targeting the Register security information user action. If the same policy still blocks a fully compliant device, capture the correlation ID, policy result, Windows App version, and timestamp for Microsoft support. Returning to the retired client only postpones this policy conflict.