Home

Conditional Access - Allow Non Enrolled Devices to use Outlook Mobile App Only

%3CLINGO-SUB%20id%3D%22lingo-sub-201208%22%20slang%3D%22en-US%22%3EConditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-201208%22%20slang%3D%22en-US%22%3E%3CP%3EI'm%20looking%20for%20some%20assistance%20with%20a%20couple%20Conditional%20Access%20policies%20we%20built%20to%20do%20the%20following%3A%3C%2FP%3E%3CP%3EIf%20a%20user%20of%20our%20organization%20sets%20up%20email%20on%20their%20mobile%20devices%20native%20mail%20app%20using%20EAS%20(exchange%20active%20sync)%20or%20modern%20auth%20they%20will%20receive%20an%20email%20stating%20that%20they%20must%20either%20enroll%20their%20device%20in%20the%20company%20Intune%20portal%20or%20download%20and%20use%20the%20Outlook%20app.%26nbsp%3B%20I%20created%20two%20Conditional%20Access%20policies%20for%20this%20and%20all%20works%20as%20planned%20until%20a%20non-enrolled%20user%20tries%20to%20log%20in%20to%20the%20Outlook%20mobile%20app.%26nbsp%3B%20It%20prompts%20them%20that%20they%20need%20to%20install%20the%20Microsoft%20Authenticator%20app%2C%20which%20they%20do%20then%20it%20errors%20out%20when%20trying%20to%20sign%20in%20to%20Outlook.%26nbsp%3B%20Below%20is%20the%20screenshot%20error.%26nbsp%3B%20I%20confirmed%20it's%20not%20specifically%20an%20authenticator%20app%20error%20by%20enrolling%20my%20device%20and%20the%20app%20worked%20fine.%26nbsp%3B%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBelow%20is%20my%20modern%20auth%20policy%20which%20is%20the%20one%20that%20basically%20says%20your%20device%20does%20not%20need%20to%20be%20enrolled%20but%20you%20must%20use%20an%20approved%20app.%26nbsp%3B%20My%20immediate%20thought%20is%20that%20this%20does%20not%20work%20because%20Microsoft%20Authenticator%20is%20actually%20not%20on%20the%20list%20of%20'%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-conditional-access-technical-reference%23approved-client-app-requirement%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Eapproved%20apps%3C%2FA%3E'.%26nbsp%3B%20Thoughts%3F%26nbsp%3B%20Can%20anyone%20think%20of%20another%20way%20to%20set%20this%20up%20or%20why%20when%20installing%20the%20Outlook%20mobile%20app%20on%20our%20non%26nbsp%3Benrolled%20mobile%20apps%20it%20requires%20the%20authenticator%20app%20in%20the%20first%20place%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20603px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F35469i74D2818CA5DA4D73%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22approvedapps.png%22%20title%3D%22approvedapps.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20217px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F35468iFC12742CA10F5ED7%2Fimage-dimensions%2F217x386%3Fv%3D1.0%22%20width%3D%22217%22%20height%3D%22386%22%20alt%3D%2220180606_040555675_iOS.png%22%20title%3D%2220180606_040555675_iOS.png%22%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-caption%22%20onclick%3D%22event.preventDefault()%3B%22%3EError%20Message%20after%20attempting%20to%20sign%20into%20Outlook%20app%20with%20authenticator%20app%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-201208%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-217387%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-217387%22%20slang%3D%22en-US%22%3E%3CP%3ENot%20sure%20how%20it%20will%20be%20working%20without%20MFA.%20In%20our%20case%20outlook%20client%20is%20asking%20to%20have%20Authenticator%20app%20configured.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-217373%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-217373%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20for%20the%20reply.%20I%20haven't%20selected%20the%20device%20option.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20I%20also%20have%20to%20ensure%20that%20the%20MS%20authenticator%20app%20is%20installed%20and%20configured%20on%20each%20device%20even%20though%20we%20aren't%20at%20this%20stage%20rolling%20out%202FA.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlistair%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-217334%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-217334%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20CA%20policy%20you%20just%20need%20to%20require%20both%20device%20to%20be%20compliant%20and%20to%20use%20approved%20client%3CBR%20%2F%3E%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20310px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F37963i2D19A38B40B07F78%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22CA.JPG%22%20title%3D%22CA.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-216433%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-216433%22%20slang%3D%22en-US%22%3E%3CP%3EHi%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20is%20something%20I%20am%20trying%20to%20set%20up.%20Could%20you%20provide%20the%20details%20on%20the%20two%20compliance%20conditions%20I%20need%20to%20create%20to%20stop%20users%20accessing%20the%20native%20app.%20I%20have%20configured%20the%26nbsp%3Bapproved%20apps%20but%20need%20to%20stop%20the%20native%20mail%20apps%20from%20working.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlistair%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-211008%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-211008%22%20slang%3D%22en-US%22%3E%3CP%3EInteresting%20I%20stumbled%20across%20this%20in%20my%20test%20lab.%20I%20solved%20it%20there%20in%20the%20following%20way%20(reconstruction%20from%20my%20memories).%20Instead%20of%20clicking%20on%20the%20existing%20account%20(displayed%20via%20email%20address)%20in%20Mobile%20Outlook%20I%20choose%20%22other%20account%22%20(Office%20365)%20and%20typed%20in%20the%20same%20email%20address%20(same%20account)%2C%20basically%20I%20re-created%20the%20same%20login.%20Suddenly%20then%20it%20was%20going%20through.%20So%20maybe%20something%20bad%20with%20the%20existing%20account%20handling.%20I%20got%20this%20problem%20after%20a%20password%20reset.%20Can%20you%20verify%20if%20this%20helps%20in%20your%20environment%20too%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%2C%3C%2FP%3E%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-201273%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20-%20Allow%20Non%20Enrolled%20Devices%20to%20use%20Outlook%20Mobile%20App%20Only%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-201273%22%20slang%3D%22en-US%22%3E%3CP%3EHey%2C%20i%20have%20almost%20the%20same%20setup%20and%20that%20was%20working%20fine%20untill%20yesterday.%20Now%20my%20new%20user%20is%20receiving%20the%20same%20error%20message%20in%20Outlook%20on%20authorization%20steps.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Mike Messer
Occasional Contributor

I'm looking for some assistance with a couple Conditional Access policies we built to do the following:

If a user of our organization sets up email on their mobile devices native mail app using EAS (exchange active sync) or modern auth they will receive an email stating that they must either enroll their device in the company Intune portal or download and use the Outlook app.  I created two Conditional Access policies for this and all works as planned until a non-enrolled user tries to log in to the Outlook mobile app.  It prompts them that they need to install the Microsoft Authenticator app, which they do then it errors out when trying to sign in to Outlook.  Below is the screenshot error.  I confirmed it's not specifically an authenticator app error by enrolling my device and the app worked fine.   

 

Below is my modern auth policy which is the one that basically says your device does not need to be enrolled but you must use an approved app.  My immediate thought is that this does not work because Microsoft Authenticator is actually not on the list of 'approved apps'.  Thoughts?  Can anyone think of another way to set this up or why when installing the Outlook mobile app on our non enrolled mobile apps it requires the authenticator app in the first place?

 

approvedapps.png

 

20180606_040555675_iOS.pngError Message after attempting to sign into Outlook app with authenticator app

6 Replies

Hey, i have almost the same setup and that was working fine untill yesterday. Now my new user is receiving the same error message in Outlook on authorization steps.

Interesting I stumbled across this in my test lab. I solved it there in the following way (reconstruction from my memories). Instead of clicking on the existing account (displayed via email address) in Mobile Outlook I choose "other account" (Office 365) and typed in the same email address (same account), basically I re-created the same login. Suddenly then it was going through. So maybe something bad with the existing account handling. I got this problem after a password reset. Can you verify if this helps in your environment too?

 

Best,

Oliver

Hi

 

This is something I am trying to set up. Could you provide the details on the two compliance conditions I need to create to stop users accessing the native app. I have configured the approved apps but need to stop the native mail apps from working.

 

Thanks

 

Alistair

In CA policy you just need to require both device to be compliant and to use approved client

CA.JPG

Hi

 

Thanks for the reply. I haven't selected the device option.

 

Do I also have to ensure that the MS authenticator app is installed and configured on each device even though we aren't at this stage rolling out 2FA. 

 

Alistair

Not sure how it will be working without MFA. In our case outlook client is asking to have Authenticator app configured.

Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
How to Prevent Teams from Auto-Launch
chenrylee in Microsoft Teams on
29 Replies