Thanks and glad to hear this is being addressed (the current state is news to me anyway). I have a hopefully quick question, about the current state, and I guess the same question applies to the future state.
Today, if you configure any conditional access policy (regardless of its applicability to mobile devices), Exchange Online will skip mobile device access rules’ processing for Outlook for iOS and Android devices.
By "any", does that mean, even regardless of any other conditions. What I mean is, does the policy at least have to apply to Exchange Online as the cloud app?
I'm assuming yes, but I'm not sure exactly how Exchange Online and Azure AD are talking back and forth about this stuff. I assume the response/token that AAD gives the user when sending them back to Exchange Online (after authenticating through Azure AD) must contain info that tells EXO what grant controls were required? Or does Exchange Online do some kind of recurring analysis of AAD Conditional Access policies?
Thanks in advance.