SOLVED
Home

Exchange Activesync and iOS 12.3.1

%3CLINGO-SUB%20id%3D%22lingo-sub-662153%22%20slang%3D%22en-US%22%3EExchange%20Activesync%20and%20iOS%2012.3.1%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-662153%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20goal%3A%20Allow%20users%20with%20personally%20owned%20iOS%20devices%20to%20be%20able%20to%20use%20both%20Outlook%20for%20iOS%20and%20the%20native%20mail%20app%20to%20access%20work%20email.%20iOS%20devices%20are%20required%20to%20be%20at%20iOS%20version%2012.0%20at%20least.%20Exchange%20ActiveSync%20will%20be%20turned%20off%20completely%20eventually.%3C%2FP%3E%3CP%3EFrom%20what%20I%20have%20read%2C%20iOS%2011%20and%20newer%20use%20Modern%20Auth.%3C%2FP%3E%3CP%3EIn%20my%20testing%2C%20when%20I%20have%20EAS%20enabled%20for%20a%20user%2C%20the%20user%20continues%20to%20get%20work%20email%20from%20the%20iOS%20mail%20app%20and%20Outlook%20for%20iOS.%20The%20device%20has%20iOS%2012.3.1%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhen%20I%20disable%20EAS%20for%20the%20user%20account%2C%20work%20email%20no%20longer%20works%20in%20the%20iOS%20mail%20app%2C%20but%20continues%20to%20work%20in%20the%20Outlook%20for%20iOS.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIsn't%20iOS%20mail%20app%20version%2011%20or%20newer%20no%20longer%20dependent%20on%20EAS%3F%20Should%20it%20use%20Modern%20Auth%20instead%3F%3C%2FP%3E%3CP%3EAre%20there%20other%20ways%20to%20shutdown%20EAS%20but%20allow%20users%20with%20newer%20iOS%20devices%20to%20access%20work%20email%20from%20the%20native%20Apple%20app%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20in%20advance.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-662153%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-665687%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Activesync%20and%20iOS%2012.3.1%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-665687%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F6110%22%20target%3D%22_blank%22%3E%40Emy%20Loanzon%3C%2FA%3E%26nbsp%3B%20Correct%2C%20iOS%2011%20or%20higher%20%3CSTRONG%3Esupports%3C%2FSTRONG%3E%20Modern%20Auth.%20However%2C%20I%20believe%20Exchange%20Online%20email%20is%20still%20delivered%20to%20the%20native%20Mail%20app%20using%20EAS%20vs%20REST%20with%20the%20Outlook%20mobile%20app.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-673561%22%20slang%3D%22en-US%22%3ERe%3A%20Exchange%20Activesync%20and%20iOS%2012.3.1%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-673561%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F6110%22%20target%3D%22_blank%22%3E%40Emy%20Loanzon%3C%2FA%3E%26nbsp%3B%3CBR%20%2F%3Eyou%20need%20to%20separate%20mail%20protocol%20and%20auth%20methods.%3CBR%20%2F%3EEAS%2FREST%20are%20protocols%20to%20get%20mails%20and%20EAS%20is%20used%20by%20native%20iOS%20mail%20client%2C%20REST%20used%20by%20Outlook%20for%20iOS.%3CBR%20%2F%3ELegacy%2FModern%20auth%20is%20a%20way%20to%20authenticate%20in%20services%2C%20but%20it%20doesn't%20affect%20way%20of%20getting%20messages.%3CBR%20%2F%3E%3CBR%20%2F%3EiOS%2011%20started%20to%20support%20Oauth%202.0%20(modern%20auth)%20but%20it%20still%20uses%20EAS%20to%20get%20your%20messages.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%2C%20for%20now%20there%20is%20no%20way%20to%20let%20users%20use%20native%20mail%20client%20without%20using%20EAS.%3CBR%20%2F%3EIf%20you%20really%20need%20to%20have%20native%20mail%20client%2C%20i%20would%20recommend%20to%20use%20Conditional%20Access%20policy%20to%20block%20legacy%20auth%2C%20so%20everyone%20will%20be%20using%20modern%20auth%20even%20if%20native%20mail%20client.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Emy Loanzon
Contributor

 

Our goal: Allow users with personally owned iOS devices to be able to use both Outlook for iOS and the native mail app to access work email. iOS devices are required to be at iOS version 12.0 at least. Exchange ActiveSync will be turned off completely eventually.

From what I have read, iOS 11 and newer use Modern Auth.

In my testing, when I have EAS enabled for a user, the user continues to get work email from the iOS mail app and Outlook for iOS. The device has iOS 12.3.1

 

When I disable EAS for the user account, work email no longer works in the iOS mail app, but continues to work in the Outlook for iOS.

 

Isn't iOS mail app version 11 or newer no longer dependent on EAS? Should it use Modern Auth instead?

Are there other ways to shutdown EAS but allow users with newer iOS devices to access work email from the native Apple app?

 

Thank you in advance.

 

 

2 Replies

@Emy Loanzon  Correct, iOS 11 or higher supports Modern Auth. However, I believe Exchange Online email is still delivered to the native Mail app using EAS vs REST with the Outlook mobile app.

Solution

@Emy Loanzon 
you need to separate mail protocol and auth methods.
EAS/REST are protocols to get mails and EAS is used by native iOS mail client, REST used by Outlook for iOS.
Legacy/Modern auth is a way to authenticate in services, but it doesn't affect way of getting messages.

iOS 11 started to support Oauth 2.0 (modern auth) but it still uses EAS to get your messages.

So, for now there is no way to let users use native mail client without using EAS.
If you really need to have native mail client, i would recommend to use Conditional Access policy to block legacy auth, so everyone will be using modern auth even if native mail client.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies