Forum Discussion
Windows App - you can't get there from here
This is Conditional Access blocking the password-reset flow launched by Windows App, not an AVD host-pool or Graph outage. The Windows 365 Client failure against Microsoft Graph is the clue: excluding only the AVD client does not cover a downstream resource evaluated by Conditional Access. In the affected sign-in, open the Conditional Access tab and identify the exact policy and failed grant control. Test a scoped change with a pilot group and Report-only mode; do not exclude Microsoft Graph tenant-wide. If users can complete SSPR from a compliant device or trusted location, have them reset there, then sign out of Windows App and authenticate again. Also review any policy targeting the Register security information user action. If the same policy still blocks a fully compliant device, capture the correlation ID, policy result, Windows App version, and timestamp for Microsoft support. Returning to the retired client only postpones this policy conflict.
I'm surprised more people have not come across this issue.
So basically the policy includes the resource 'All Cloud Apps' (Set by the company) we have excluded Azure Virtual Desktop etc and that allows the personal devices to connect through Windows App.
Windows App on password reset seems to use Microsoft Graph in the background, this falls outside of the exclusion and the personal device is then caught by it. By selecting sign out and sign in as a different user with the same account then resolves the issue as its using Windows App Sign in rather than Microsoft Graph. The old client never used Microsoft Graph for the password reset mechanism.
I'm actually a bit stuck on a solution for this, there is no specific exclusions for Microsoft Graph that I can see.