Ipad and Iphone having issues after enabling MFA on office.com

Copper Contributor

Hi All,

 

I have recently enabled MFA for office.com for limited set of users and we have been getting cases specific to iphone and ipad where users who are using the mobile app for Excel , dropbox  are getting HTTP 1.1 / Service Unavailable post MFA authentication.

 

Does anyone else has this issue? Does Microsoft has a solution ?

 

 

Thanks,

Parin Das

6 Replies

we are also experiencing issues with ios devices.   Users prompted to approve, via ms auth app.  click approve then are prompted over and over!

 

Is there an issue MS?

Yes, same issue here.... MS???
Hello!

What ios version are the iphones and ipads running? Also can a screen shot be provided?

IPads all IOS11 + .. we are aware that modern authentication does not work on older IOS versions.

 

My thoughts are either that it is a firewall issue.   However Networking confirms all MS URLs / Ports are added (firewall has a MS application service)

 

Mobileiron (MDM) is pushing down password periodically and breaking something.

 

All users are using the MS authenticator app.   I have contacted MS for correct Firewall bypass Hosts and ports, but nobody can provide.

 

We have the option to manually configure the exchange config (rather than MDM pushing) also use Outlook App (however this will not go down well with some users)

 

So far manually configuring the exchange settings seems to be working.   However this is additional step we would prefer not to do.    Android enterprise setup is very nice and quick!

 

@ericjk4 

After reading more about Mobileiron and issues it has with IOS I stumble across this webpage from them:
https://www.mobileiron.com/en/blog/lets-get-technical-ios-11s-oauth-20-office-365

The closing paragraph summarizes two things that could be causing the issue and it does talk about the http message and how it should be redirected. Maybe something in this article will help!

yes, I think this line sums it up 'OAuth 2.0 email creation is a user-driven feature in iOS 11 and currently Apple has not provided MDM controls to deploy this new authentication flow to managed email accounts.'

 

Previously email was pushed requiring no user input.   If left like this users get issues / prompts for passwords / authentication. 

 

I have only been testing for a week .. but manually configuring seems to work. 

 

I'll update if I experience any new issues whilst manually configuring.