Forum Discussion

Kamran Ahmed's avatar
Kamran Ahmed
Brass Contributor
Nov 16, 2017
Solved

Conditional Access - Require multi-factor authentication

I have setup Conditional Access for MFA, i'm sure I read somewhere native mobile apps on Android/iOS are not supported unless App password option is enabled? We don't have the app password option ena...
  • Kamran Ahmed's avatar
    Kamran Ahmed
    Nov 21, 2017

    Thanks for going the extra mile Kent. I have found the same results, the CA policy doesn't work as it should. I was expecting the native clients to stop working when 'require approved client app' access control was selected, however this doesn't work. I believe this feature only works with Intune app protection.

     

    To address this issue i have created a device rule to block all active sync clients and allow Outlook, since we're on Outlook 2016 and this supports Modern Auth this works well for us. Microsoft really need to make things clear on their CA policies, pros and cons.

Resources