Home

Azure AD Join and Windows 10/Outlook 2016 and EXO conditional Access

%3CLINGO-SUB%20id%3D%22lingo-sub-68269%22%20slang%3D%22en-US%22%3EAzure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-68269%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%20recently%20enforced%26nbsp%3BExchange%20Online%20(EXO)%20conditional%20Access%20to%20Outlook%202016%20clients%20on%20Windows%20Machines%20(%20that%20use%20Modern%20Authentication)%20to%20allow%20access%20%26nbsp%3Bonly%20to%20Azure%20AD%20Joined%20devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAfter%20this%20change%2C%20a%26nbsp%3Bfew%26nbsp%3Busers%20have%20reported%20issues%20in%20connecting%20Outlook.%20%26nbsp%3BWe%20have%20seen%20on%20these%20machines%20where%20Outlook%20have%20connection%20issues%2C%20the%20below%20event%20is%20recorded%20in%26nbsp%3Bthe%20event%20log%3A%20Application%20%26amp%3B%20Service%20Logs%20-%26gt%3B%20Microsoft-Windows-User%20Device%20Registration%2FAdmin.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CEM%3EThis%20Device%20is%20joined%20to%20Azure%20AD%2C%20however%2C%20the%20user%20did%20not%20sign-in%20with%20an%20Azure%20AD%20account.%20Microsoft%20Passport%20provisioning%20will%20not%20be%20enabled.%20User%3A%20S-1-5-21-xxxxxxxxx-xxxxxxx-xxxxxxxxxx-xxxxxx%E2%80%9D%20%3C%2FEM%3Elogged%20in.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20the%20user%20is%20not%20having%20issues%20to%20login%20to%20o365%20services%20with%20his%2Fher%20Azure%20AD%20account.%20Only%20Outlook%20on%20Windows%2010%20machines%20which%20is%20enforced%20for%20EXO%20conditional%20access%20policy%20is%20having%20issue.%3C%2FP%3E%3CP%3EWe%20have%20seen%20in%20a%20few%20cases%20that%20recreating%20the%20Windows%20Profile%20fixes%20the%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20idea%20what%20is%20causing%20this%20event%20log%20or%20what%20might%20be%20the%20issue%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-68269%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-140828%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-140828%22%20slang%3D%22en-US%22%3E%3CP%3ESame%20issue%20here%20since%20a%20few%20weeks%2C%20double%20checked%20our%20ADFS%20and%20actually%20the%20Device%20Registration%20works.%20The%20problems%20seems%20to%20be%20caused%20by%20the%20User%20State%3A%3C%2FP%3E%0A%3CP%3E%2B----------------------------------------------------------------------%2B%3CBR%20%2F%3E%7C%20User%20State%20%7C%3CBR%20%2F%3E%2B----------------------------------------------------------------------%2B%3C%2FP%3E%0A%3CP%3ENgcSet%20%3A%20NO%3CBR%20%2F%3EWorkplaceJoined%20%3A%20NO%3CBR%20%2F%3EWamDefaultSet%20%3A%20NO%3CBR%20%2F%3EAzureAdPrt%20%3A%20NO%3C%2FP%3E%0A%3CP%3E%2B----------------------------------------------------------------------%2B%3CBR%20%2F%3E%7C%20Ngc%20Prerequisite%20Check%20%7C%3CBR%20%2F%3E%2B----------------------------------------------------------------------%2B%3C%2FP%3E%0A%3CP%3EIsUserAzureAD%20%3A%20NO%3CBR%20%2F%3EPolicyEnabled%20%3A%20NO%3CBR%20%2F%3EDeviceEligible%20%3A%20YES%3CBR%20%2F%3ESessionIsNotRemote%20%3A%20YES%3CBR%20%2F%3EX509CertRequired%20%3A%20NO%3CBR%20%2F%3EPreReqResult%20%3A%20WillNotProvision%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EMicrosoft%20support%20has%20so%20far%20not%20being%20useful..%20Case%20is%20still%20ongoing.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-129959%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-129959%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F10122%22%20target%3D%22_blank%22%3E%40Raj%20Krishnan%3C%2FA%3E%26nbsp%3BMake%20sure%20users%20are%20on%20at%20least%26nbsp%3Bversion%201607%26nbsp%3Bof%20win10.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI'm%20getting%20this%20error%20as%20well.%20Any%20ideas%20anyone%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70794%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70794%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20also%20find%20occassionally%26nbsp%3B%3CSPAN%3Ereinstalling%20MS%20Office%20365%20Pro%20Plus%20did%20not%20fix%20the%20issue.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20are%20getting%20this%20pop-up%20message%20also.%20%22You%20can't%20get%20there%20from%20here..%22%20.%20See%20attached%20screen%20shot.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EWe%20checked%20dsregsmd%20%2Fstatus%2C%20Device%20status%20in%20Azure%20AD%20%2C%20Ms-Org%20certs%20and%20they%20all%20seem%20to%20be%20fine.%20The%20computer%20is%20Windows%2010%20%26nbsp%3BOS%20and%20running%26nbsp%3BMS%20Office%20365%20Pro%20Plus%2016.0.x%20version.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EAny%20help%20on%20what%20else%20we%20can%20check%20to%20identify%20the%20issue.%20%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70443%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70443%22%20slang%3D%22en-US%22%3E%3CP%3EAlso%20we%20found%20that%20reinstalling%20MS%20Office%20365%20Pro%20Plus%20%26nbsp%3Bseems%20to%20fix%20this%20issue.%3C%2FP%3E%3CP%3EBut%20still%20not%20sure%20what%20is%20that%20causing%20the%20issue%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-70329%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-70329%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Vasil%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EClearing%20the%20credentials%20did%20not%20work.%3C%2FP%3E%3CP%3EAny%20thing%20else%20you%20can%20think%20of%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-68651%22%20slang%3D%22en-US%22%3ERe%3A%20Azure%20AD%20Join%20and%20Windows%2010%2FOutlook%202016%20and%20EXO%20conditional%20Access%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-68651%22%20slang%3D%22en-US%22%3E%3CP%3EYou%20probably%20have%20stored%20credentials%20under%20Cred%20manager%20that%20Outlook%20reuses.%20Try%20removing%20them%2C%20see%20what%20happens.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Raj Krishnan
Contributor

Hi,

 

We have recently enforced Exchange Online (EXO) conditional Access to Outlook 2016 clients on Windows Machines ( that use Modern Authentication) to allow access  only to Azure AD Joined devices.

 

After this change, a few users have reported issues in connecting Outlook.  We have seen on these machines where Outlook have connection issues, the below event is recorded in the event log: Application & Service Logs -> Microsoft-Windows-User Device Registration/Admin.

 

"This Device is joined to Azure AD, however, the user did not sign-in with an Azure AD account. Microsoft Passport provisioning will not be enabled. User: S-1-5-21-xxxxxxxxx-xxxxxxx-xxxxxxxxxx-xxxxxx” logged in.

 

But the user is not having issues to login to o365 services with his/her Azure AD account. Only Outlook on Windows 10 machines which is enforced for EXO conditional access policy is having issue.

We have seen in a few cases that recreating the Windows Profile fixes the issue.

 

Any idea what is causing this event log or what might be the issue?

 

Thanks

6 Replies

You probably have stored credentials under Cred manager that Outlook reuses. Try removing them, see what happens.

Hi Vasil,

 

Clearing the credentials did not work.

Any thing else you can think of ?

 

 

Also we found that reinstalling MS Office 365 Pro Plus  seems to fix this issue.

But still not sure what is that causing the issue?

We also find occassionally reinstalling MS Office 365 Pro Plus did not fix the issue.

 

We are getting this pop-up message also. "You can't get there from here.." . See attached screen shot.

 

We checked dsregsmd /status, Device status in Azure AD , Ms-Org certs and they all seem to be fine. The computer is Windows 10  OS and running MS Office 365 Pro Plus 16.0.x version.

 

Any help on what else we can check to identify the issue.

@Raj Krishnan Make sure users are on at least version 1607 of win10.

 

I'm getting this error as well. Any ideas anyone?

Same issue here since a few weeks, double checked our ADFS and actually the Device Registration works. The problems seems to be caused by the User State:

+----------------------------------------------------------------------+
| User State |
+----------------------------------------------------------------------+

NgcSet : NO
WorkplaceJoined : NO
WamDefaultSet : NO
AzureAdPrt : NO

+----------------------------------------------------------------------+
| Ngc Prerequisite Check |
+----------------------------------------------------------------------+

IsUserAzureAD : NO
PolicyEnabled : NO
DeviceEligible : YES
SessionIsNotRemote : YES
X509CertRequired : NO
PreReqResult : WillNotProvision

 

Microsoft support has so far not being useful.. Case is still ongoing.

Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies