Thanks for the response. I am not familiar with either Google Auth of MDM. The token is installed with a suite of Microsoft apps such as Outlook and Teams.
I definitely assume work provided devices are logged and I've been told work provided cell phones are logged, but I don't know if that extends to personal devices. Of course best case would be to try and find out if there is a way to use an external token generator to keep work off a personal device.