SOLVED
Home

Issue with Intune MAM policies for similar user using multiple policies

%3CLINGO-SUB%20id%3D%22lingo-sub-360703%22%20slang%3D%22en-US%22%3EIssue%20with%20Intune%20MAM%20policies%20for%20similar%20user%20using%20multiple%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-360703%22%20slang%3D%22en-US%22%3E%3CP%3EDoes%20anyone%20faced%20similar%20issue%20below%3F%26nbsp%3B%3C%2FP%3E%3CP%3EI%20deployed%20CORP%20MAM%20policy(doesn't%20have%20app%20level%20passcode)%20to%20an%20Intune%20managed%20device%20only%20option%20for%20User%20%3CSTRONG%3EA%3C%2FSTRONG%3E.%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20then%20deployed%20a%20%22BYOD%20MAM%20policy%20(includes%20app%20level%20passcode)%22%20to%20an%20%22Unmanaged%20device%20option%22%26nbsp%3B%20for%20same%20User%20%3CSTRONG%3EA%3C%2FSTRONG%3E.%26nbsp%3B%3C%2FP%3E%3CP%3ENow%20the%20issue%20is%20that%20when%20%22User%20A%22%20access%20outlook%20on%20his%2Fher%20corporate%20device%2C%20then%20managed%20apps(ex%3A%20Outlook)%20is%20asking%20passcode.%20Ideally%20it%20should%20only%20for%20BYOD%20device%20not%20the%20corporate%20device.%26nbsp%3B%20Now%20sure%20why%20Intune%20is%20not%20able%20to%20recognize%20device%20state.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20provide%20your%20thoughts%20on%20this%20scenario.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-360703%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-362838%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20with%20Intune%20MAM%20policies%20for%20similar%20user%20using%20multiple%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-362838%22%20slang%3D%22en-US%22%3E%3CP%3EAble%20to%20fix%20the%20issue%20by%20following%20below%20steps.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Push%20the%20outlook%20app%20through%20Intune%20managed%20company%20portal.%26nbsp%3B%3C%2FP%3E%3CP%3E2.%20Create%20App%20configuration%20policy%20for%20Outlook%20IOS%20only%20and%20set%20the%20parameters%20as%20%22%20IntuneMAMUPN%20%2C%20String%20and%20configuration%20value%20as%20%3A%26nbsp%3B%3CSPAN%3E%7B%7BUserPrincipalName%7D%7D%26nbsp%3B%20%22.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%3CSPAN%3E3.%20If%20you%20want%20to%20allow%20gmail%20and%20other%20personal%20accounts%20to%20use%20Outlook%20app%20then%20we%20need%20to%20set%20%22Configure%20email%20account%20settings%22%20under%20the%20same%20configuration%20policy%20and%20the%20authentication%20to%20be%20set%20to%20%22Modern%22%20which%20will%20give%20you%20an%20option%20to%20set%20%22Allow%20only%20work%20or%20school%20accounts%22%20at%20which%20you%20can%20set%20it%20as%20%22Not%20configured%22%20.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-631870%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20with%20Intune%20MAM%20policies%20for%20similar%20user%20using%20multiple%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-631870%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F288162%22%20target%3D%22_blank%22%3E%40gadagottiraj%3C%2FA%3E%26nbsp%3BWe%20have%20similar%20issue%20and%20configuring%26nbsp%3B%3CSPAN%3EIntuneMAMUPN%20has%20fixed%20issue%20for%20some%20of%20the%20users%20but%20policy%20didnt%20apply%20to%20all%20users%20apps%20on%20managed%20devices.%20Investigating%20this%20now%20!%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-859020%22%20slang%3D%22en-US%22%3ERe%3A%20Issue%20with%20Intune%20MAM%20policies%20for%20similar%20user%20using%20multiple%20policies%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-859020%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F336519%22%20target%3D%22_blank%22%3E%40prtkdv%3C%2FA%3E%26nbsp%3Bwere%20you%20able%20to%20figure%20out%20this%20issue%3F%20I%20think%20the%20apps%20have%20to%20be%20installed%20through%20Company%20portal%20on%20Managed%20Devices.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
gadagottiraj
Occasional Contributor

Does anyone faced similar issue below? 

I deployed CORP MAM policy(doesn't have app level passcode) to an Intune managed device only option for User A

And then deployed a "BYOD MAM policy (includes app level passcode)" to an "Unmanaged device option"  for same User A

Now the issue is that when "User A" access outlook on his/her corporate device, then managed apps(ex: Outlook) is asking passcode. Ideally it should only for BYOD device not the corporate device.  Now sure why Intune is not able to recognize device state. 

 

Please provide your thoughts on this scenario. 

3 Replies
Solution

Able to fix the issue by following below steps. 

 

1. Push the outlook app through Intune managed company portal. 

2. Create App configuration policy for Outlook IOS only and set the parameters as " IntuneMAMUPN , String and configuration value as : {{UserPrincipalName}}  ". 

3. If you want to allow gmail and other personal accounts to use Outlook app then we need to set "Configure email account settings" under the same configuration policy and the authentication to be set to "Modern" which will give you an option to set "Allow only work or school accounts" at which you can set it as "Not configured" .

@gadagottiraj We have similar issue and configuring IntuneMAMUPN has fixed issue for some of the users but policy didnt apply to all users apps on managed devices. Investigating this now !

@prtkdv were you able to figure out this issue? I think the apps have to be installed through Company portal on Managed Devices.  

Related Conversations
Tabs and Dark Mode
cjc2112 in Discussions on
35 Replies
Extentions Synchronization
Deleted in Discussions on
3 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies