Home

Blocking of Outlook desktop using Conditional Access also effects Skype for Business and MS Teams.

%3CLINGO-SUB%20id%3D%22lingo-sub-195451%22%20slang%3D%22en-US%22%3EBlocking%20of%20Outlook%20desktop%20using%20Conditional%20Access%20also%20effects%20Skype%20for%20Business%20and%20MS%20Teams.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195451%22%20slang%3D%22en-US%22%3E%3CDIV%3EHi%20All%2C%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EI%20need%20to%20block%20users%20using%20their%20Outlook%20desktop%20application%20using%20Azure%20Conditional%20Access%20(Office%20365%20Exchange%20Online%20Mobile%20apps%20and%20desktop%20clients).%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EThe%20problem%20I%20am%20having%20is%20the%20blocking%20of%20Outlook%20desktop%20also%20effects%20Skype%20for%20Business%20and%20MS%20Teams.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FDIV%3E%3CDIV%3EIs%20there%20a%20way%20I%20can%20block%20Outlook%20desktop%20without%20effecting%20%3CSPAN%3ESkype%20for%20Business%20and%20MS%20Teams%3F%3C%2FSPAN%3E%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FDIV%3E%3CDIV%3EAlso%2C%20I%20need%20a%20list%20of%20what%20effects%20of%20enabling%20Conditional%20Access%20will%20have%20on%20applications.%20For%20Example%2C%20enabling%20of%20Office%20365%20Exchange%20Online%20Conditional%20Access%20will%20effect%20Outlook%2C%20Skype%20for%20business%2C%20and%20MS%20Teams.%3C%2FDIV%3E%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%3CDIV%3EI%20hope%20you%20can%20help.%20Thanks.%3CBR%20%2F%3EColin%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-195451%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAzure%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-260900%22%20slang%3D%22en-US%22%3ERe%3A%20Blocking%20of%20Outlook%20desktop%20using%20Conditional%20Access%20also%20effects%20Skype%20for%20Business%20and%20MS%20Team%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-260900%22%20slang%3D%22en-US%22%3E%3CP%3EI%20Have%20not%20been%20able%20to%20block%20access%20without%20affecting%20skype%2C%20teams%20and%20sharepoint.%26nbsp%3B%20It%20appears%20logging%20from%20mobile%20device%20is%20not%20possible%20once%20conditional%20access%20is%20used%20to%20block%20O365%20exchange%20application.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195519%22%20slang%3D%22en-US%22%3ERe%3A%20Blocking%20of%20Outlook%20desktop%20using%20Conditional%20Access%20also%20effects%20Skype%20for%20Business%20and%20MS%20Team%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195519%22%20slang%3D%22en-US%22%3E%3CP%3EBoth%20SfB%20and%20Teams%20depend%20on%20Outlook%20for%20certain%20functionalities%2C%20so%20those%20will%20not%20be%20available%20if%20you%20have%20blocked%20access.%20However%20it%20should%20not%20prevent%20users%20from%20actually%20logging%20to%20SfB%2FTeams.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-430497%22%20slang%3D%22en-US%22%3ERe%3A%20Blocking%20of%20Outlook%20desktop%20using%20Conditional%20Access%20also%20effects%20Skype%20for%20Business%20and%20MS%20Team%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-430497%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F113252%22%20target%3D%22_blank%22%3E%40C%20Edwards%3C%2FA%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%20I%20would%20like%20to%20add%20in%20here%20that%20the%20reverse%20holds%20true.%26nbsp%3B%20We%20have%20enacted%20conditional%20access%20for%20Teams%20on%20mobile%20devices%20for%20select%20users-%20granting%20access%20to%20mobile%20devices%20which%20meet%20the%20requirements.%26nbsp%3B%20This%20prevents%20users%20from%20receiving%20email%20on%20their%20devices%20until%20they%20sign%20into%20Intune%20and%20set%20up%20the%20company%20portal.%26nbsp%3B%20%26nbsp%3BGenerally%2C%20this%20wouldn't%20be%20a%20big%20deal.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20we%20are%20migrating%20users%20from%20on-prem%20to%20365%2C%20and%20we%20do%20not%20set%20up%20Intune%20on%20devices%20until%20the%20mailbox%20is%20migrated.%26nbsp%3B%20Therefore%2C%20this%20policy%20effectively%20halted%20email%20to%20a%20number%20of%20phones%20for%20users%20who%201)%20had%20not%20installed%20Teams%20on%20their%20phone%20yet%2C%202)%20had%20email%20already%20on%20their%20devices%2C%20and%203)%20should%20not%20have%20been%20made%20aware%20of%20any%20background%20change.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20suppose%20a%20valid%20workaround%20would%20be%20to%20create%20a%20new%20AD%20group%20which%20users%20are%20moved%20into%20after%20being%20migrated%2C%20and%20then%20configure%20Intune%20to%20manage%20this%20group-%20but%20this%20information%20should%20be%20provided%20upfront%20(i.e.%20the%20applications%20are%20interdependent%2C%20and%20if%20one%20is%20blocked%20so%20shall%20be%20others%2C%20etc.).%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E*editing%20-%20Is%20it%20certain%20that%20Teams%20cannot%20be%20managed%20by%20conditional%20access%20without%20affecting%20mail%20flow%20as%20well%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
C Edwards
Contributor
Hi All,
 
I need to block users using their Outlook desktop application using Azure Conditional Access (Office 365 Exchange Online Mobile apps and desktop clients).
 
The problem I am having is the blocking of Outlook desktop also effects Skype for Business and MS Teams.

Is there a way I can block Outlook desktop without effecting Skype for Business and MS Teams?

Also, I need a list of what effects of enabling Conditional Access will have on applications. For Example, enabling of Office 365 Exchange Online Conditional Access will effect Outlook, Skype for business, and MS Teams.
 
I hope you can help. Thanks.
Colin
3 Replies

Both SfB and Teams depend on Outlook for certain functionalities, so those will not be available if you have blocked access. However it should not prevent users from actually logging to SfB/Teams.

I Have not been able to block access without affecting skype, teams and sharepoint.  It appears logging from mobile device is not possible once conditional access is used to block O365 exchange application.

 

@C Edwards @Vasil Michev I would like to add in here that the reverse holds true.  We have enacted conditional access for Teams on mobile devices for select users- granting access to mobile devices which meet the requirements.  This prevents users from receiving email on their devices until they sign into Intune and set up the company portal.   Generally, this wouldn't be a big deal.

 

However, we are migrating users from on-prem to 365, and we do not set up Intune on devices until the mailbox is migrated.  Therefore, this policy effectively halted email to a number of phones for users who 1) had not installed Teams on their phone yet, 2) had email already on their devices, and 3) should not have been made aware of any background change.

 

I suppose a valid workaround would be to create a new AD group which users are moved into after being migrated, and then configure Intune to manage this group- but this information should be provided upfront (i.e. the applications are interdependent, and if one is blocked so shall be others, etc.).

 

 

*editing - Is it certain that Teams cannot be managed by conditional access without affecting mail flow as well?

Related Conversations
Extentions Synchronization
ChirmyRam in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies