Microsoft Teams Rooms (MTR) Setup: Step-by-Step Exchange Online, Conditional Access, Intune & TAC Management Guide
When deploying Microsoft Teams Rooms (MTR)—whether running on Windows (Logitech Tap, HP, Lenovo) or Android (Poly Studio X, Neat Bar, Yealink)—the physical hardware is only half the battle. The remaining foundation lives entirely in the Microsoft cloud: configuring an Exchange Online Room Resource Mailbox, tuning automated Calendar Processing rules, configuring Conditional Access location exemptions, and verifying Intune device compliance.
If any cloud configuration is missed, the boardroom console will sit offline with errors like “Cannot fetch calendar”, meeting titles will be stripped and replaced with the organizer’s name, or Intune will mark the device non-compliant and revoke access. This practical runbook walks through an exact, step-by-step enterprise deployment from initial mailbox provisioning to post-onboarding cloud health monitoring.
lon-boardroom4@contoso.comStep 1: Creating the Room Mailbox in Exchange Online
While room mailboxes can be created in the Exchange Admin Center (EAC), configuring an MTR account via Exchange Online PowerShell ensures that required voice, authentication, and password policies are applied consistently without human error.
Optional GUI Verification: Open Exchange Admin Center ➔ Recipients ➔ Resources. The new room will appear with Recipient Type: Room Mailbox.
Step 2: Password Expiration & Pro License Assignment
Autonomous conference room devices must not be locked out by standard 90-day interactive password expiration policies. Connect to Microsoft Graph PowerShell to set the password to never expire:
# Connect to Microsoft Graph
Connect-MgGraph -Scopes "User.ReadWrite.All"
# Query the user object ID
$roomUser = Get-MgUser -UserId "lon-boardroom4@contoso.com"
# Set password policy to Never Expire
Update-MgUser -UserId $roomUser.Id -PasswordPolicies "DisablePasswordExpiration"
# Verify attribute
Get-MgUser -UserId "lon-boardroom4@contoso.com" -Property PasswordPolicies | Select-Object DisplayName, PasswordPolicies
Assigning the License
Navigate to Microsoft 365 Admin Center ➔ Users ➔ Active Users ➔ Select lon-boardroom4@contoso.com ➔ Licenses and apps:
- Assign: Microsoft Teams Rooms Pro (provides Intune Plan 1, Entra ID P1, Teams Phone, dual-display capability, and Pro Management Portal telemetry).
- Caution: Never assign personal user licenses (e.g., E3, E5) to meeting room hardware. Microsoft automated audits flag these accounts and revoke room functionality.
Step 3: The Critical Step — Tuning CalendarProcessing
This is where 90% of MTR deployments fail. By default, Exchange Online is configured for human-managed room calendars, not automated robotic room systems. Out of the box, Exchange Online deletes the meeting subject and overwrites it with the sender’s display name, strips external body comments (destroying the Teams meeting Join coordinates), and blocks external booking.
To enable flawless “One Touch Join” on your Teams Room console, execute this exact PowerShell command block:
Set-CalendarProcessing -Identity "lon-boardroom4@contoso.com" `
-AutomateProcessing AutoAccept `
-DeleteSubject $false `
-AddOrganizerToSubject $false `
-DeleteComments $false `
-RemovePrivateProperty $false `
-ProcessExternalMeetingMessages $true `
-AllowConflicts $false
Before vs. After: What the Touch Screen Actually Shows
Step 4: Conditional Access Policy — Preventing the MFA Lockout
Teams Rooms are autonomous hardware appliances. They cannot click mobile authenticator push notifications or scan QR codes upon reboot. If your organization has an “All Users Must Perform MFA” policy, your room will disconnect.
SG-Teams-Rooms-Accounts and add lon-boardroom4@contoso.com.SG-Teams-Rooms-Accounts.CA-SEC-TeamsRooms-TrustedLocationLock.• Include: Any location
• Exclude: All Trusted Locations (Corporate Egress Public IPs)
Step 5: Physical Device Sign-In (Logitech Tap / Poly TC8)
With the cloud configuration complete, physically sit in front of the MTR touch console:
- Click Sign In.
- The console contacts Entra ID, acquires an OAuth bearer token, establishes an Exchange Web Services (EWS) or Microsoft Graph connection, and syncs the calendar.
- Within 60 seconds, the room name, current time, and upcoming meeting schedule render on the display.
Step 6: Post-Onboarding Verification in Teams Admin Center & Intune
Once the device completes sign-in, you must verify its operational status and compliance across both cloud administrative portals:
1. Verifying Device Health & Peripherals in Teams Admin Center (TAC)
- In Microsoft Teams Admin Center, expand Teams devices:
• For Windows devices (Logitech Tap, HP, Lenovo): Select Teams Rooms on Windows.
• For Android bars (Poly Studio X, Neat, Yealink): Select Teams Rooms on Android. - Find your room:
London 4th Fl - Boardroom (Cap 18). - Verify the health cards:
- Overall Status: Must read Healthy (not Critical or Offline).
- Teams App Status: Displays the installed MTR app version.
- Connected Peripherals: Ensure Camera, Speaker, Microphone, and Ingest display are recognized with green checkmarks.
2. Checking Intune Compliance & Avoiding the “Non-Compliant” Trap
In the Microsoft Intune Admin Center (endpoint.microsoft.com), navigate to Devices ➔ All devices and search for the room name.
The Intune Compliance Trap:
If your organization enforces standard user compliance policies (such as requiring BitLocker encryption with user passwords, complex PIN locks, or TPM 2.0 flags), the Teams Room system will be marked “Not Compliant”. If your Conditional Access policy blocks non-compliant devices, the room will be kicked offline within 24 hours.
The Fix: Create a dedicated MTR Intune Compliance Policy targeted specifically to the SG-Teams-Rooms-Accounts group:
- For MTR on Windows: Only enforce Firewall Enabled, Antivirus Active, and Minimum OS Version. Disable interactive user password requirements.
- For MTR on Android: Enforce device encryption, but disable user PIN locks (since Android bars operate headlessly).
Step 7: Pulling Remote Diagnostic Logs (Without Visiting the Room)
If a room experiences audio glitches or camera dropouts, do not send a field technician with a USB drive. Collect diagnostic logs directly from the cloud:
- In Teams Admin Center ➔ Teams devices ➔ Teams Rooms, click on the affected room.
- In the top toolbar, click Download device logs.
- TAC initiates a background diagnostics collection on the physical console.
- Within 5 minutes, navigate to the History tab to download the complete diagnostic bundle (containing Windows Event logs, MTR app logs, and peripheral firmware telemetry).
The Top 3 Enterprise MTR Gotchas & Diagnostic Fixes
Gotcha 1: “Cannot Fetch Calendar” (HTTP 401 / 403 on EWS)
Symptom: The MTR console signs into Teams successfully, but displays a persistent yellow warning: “Cannot fetch calendar”.
Root Cause: The room mailbox has Basic Authentication disabled (which is correct), but the tenant’s Exchange Online authentication policy blocks modern auth protocol endpoints for EWS.
The Fix: Verify that Modern Authentication is enabled for EWS on the mailbox:
# Verify modern auth policy
Get-AuthenticationPolicy -Identity "BlockBasicAuth"
# Ensure EWS is allowed under modern OAuth for the room mailbox
Set-CASMailbox -Identity "lon-boardroom4@contoso.com" -EwsEnabled $true -EwsAllowMacOutlook $true
Gotcha 2: External Partner Invites Bounce with 550 5.7.1 NDR
Symptom: An external client invites the conference room to their Teams meeting, but receives an automated bounce: “550 5.7.1 Delivery not authorized, message rejected”.
Root Cause: The mailbox’s transport delivery restrictions prohibit messages from unauthenticated senders outside the tenant.
The Fix: Execute both commands in Exchange Online PowerShell:
# 1. Allow unauthenticated senders to submit messages to the room
Set-Mailbox -Identity "lon-boardroom4@contoso.com" -RequireSenderAuthenticationEnabled $false
# 2. Allow calendar engine to process external invitations
Set-CalendarProcessing -Identity "lon-boardroom4@contoso.com" -ProcessExternalMeetingMessages $true
Gotcha 3: Meeting Appears on Screen but Lacks “Join” Button
Symptom: The meeting appears on the MTR touch display, but only shows the meeting title with no green “Join” button.
Root Cause: The meeting invite was created without Microsoft Teams coordinates (e.g., an in-person only invite), or an Exchange transport rule stripped the HTML meeting body because -DeleteComments was left set to $true.
The Fix: Ensure Set-CalendarProcessing -DeleteComments $false is applied, and verify that the user clicked the “Teams Meeting” toggle when creating the invite in Outlook.
Deploying Teams Rooms Across Multiple Corporate Offices?
Our Microsoft-certified UC architects engineer zero-touch MTR provisioning roadmaps, Room Finder hierarchies, Intune compliance bypasses, and enterprise Conditional Access location boundaries.
Frequently Asked Questions (FAQ)
Why does the Teams Room touch console display the organizer’s name instead of the meeting subject?
This happens because Exchange Online Room mailboxes have -DeleteSubject set to $true and -AddOrganizerToSubject set to $true by default. Exchange strips the original meeting title and overwrites it with the sender’s name. Running Set-CalendarProcessing -DeleteSubject $false -AddOrganizerToSubject $false restores the actual meeting subject on the console.
How do you prevent Conditional Access from blocking MTR consoles with MFA prompts?
Group all room accounts into a dedicated security group and exclude them from interactive user MFA policies. Instead, secure room accounts by binding them to Trusted Named Locations (corporate IP ranges) in Conditional Access, ensuring the console can authenticate without MFA while on office premises.
Why is my Teams Room showing as “Not Compliant” in Microsoft Intune?
MTR devices fail compliance when standard user compliance policies (requiring interactive user PINs, TPM checks, or BitLocker password prompts) are applied to them. You must create a dedicated MTR compliance policy that only checks for OS version, firewall, and antivirus, while disabling interactive user password requirements.
How can an administrator download Teams Room diagnostic logs remotely?
In the Teams Admin Center, navigate to Teams devices ➔ Teams Rooms on Windows/Android, select the room, and click “Download device logs”. The system initiates background log collection, and the complete diagnostic ZIP file can be downloaded from the History tab within minutes without visiting the room.
Related Microsoft Teams Rooms & Infrastructure Guides
- Exchange Online Room Finder & Hierarchical Room Lists: Set-Place & PowerShell Guide
- Microsoft Teams Rooms (MTR) Intune & Pro Portal: Custom Compliance Policies, Peripheral Health & Remote Log Analysis
- Cisco Webex Room Kit Integration with Microsoft Teams: Direct Guest Join (WebRTC) & xAPI Setup Guide
- Microsoft Teams SIP Gateway: Onboarding Cisco & AudioCodes Desk Phones
- Microsoft Teams Call Queues & Auto Attendants: Complete Setup Guide
- Teams Dynamic Emergency Calling (E911): RAY BAUM’S Act & Compliance
- Microsoft Entra Password Writeback Failure: Troubleshooting SSPR & Event IDs
- How to Configure AudioCodes SBC for Microsoft Teams Direct Routing
- Teams Direct Routing SIP 403 Forbidden: User Licensing & FQDN Gotchas
