How to block the Outlook desktop application using Windows Information Protection WIP

%3CLINGO-SUB%20id%3D%22lingo-sub-195892%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20block%20the%20Outlook%20desktop%20application%20using%20Windows%20Information%20Protection%20WIP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195892%22%20slang%3D%22en-US%22%3E%3CP%3EIf%20you%20want%20to%20block%20them%20from%20accessing%20Outlook%20on%20*any*%20location%2C%20use%20the%20Set-CasMailbox%20cmdlet%3A%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EGet-CASMailbox%20user%40domain.com%20-MAPIEnabled%20%24false%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20want%20to%20block%20it%20from%20outside%20of%20the%20corporate%20network%20only%2C%20Conditional%20Access%20or%20AD%20FS%20claims%20rules%20are%20your%20only%20options.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-195847%22%20slang%3D%22en-US%22%3EHow%20to%20block%20the%20Outlook%20desktop%20application%20using%20Windows%20Information%20Protection%20WIP%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-195847%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20need%20to%20block%20a%20group%20of%20users%20from%20using%20the%20Outlook%20desktop%20application.%20We%20want%20them%20to%20only%20access%20company%20emails%20using%20the%20Internet%20browser%20version%20of%20Outlook.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20tried%20to%20achieve%20this%20by%20using%20an%3CSPAN%3E%20Azure%20Conditional%20Access%20policy%20(with%20Office%20365%20Exchange%20Online).%20The%20problem%20is%20using%20Azure%20Conditional%20will%20also%20effect%20MS%20Teams%20and%20Skype%20for%20Business%20as%20explained%20on%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-conditional-faqs%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Factive-directory-conditional-faqs%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EMy%20question%20is%2C%20is%20there%20another%20way%20we%20can%20block%20the%20Outlook%20desktop%20application%20using%20another%20Intune%20feature%20like%20Windows%20Information%20Protection%20(WIP)%3F%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EThanks%3CBR%20%2F%3EColin%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-195847%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%20App%20Protection%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Contributor

Hi All,

 

We need to block a group of users from using the Outlook desktop application. We want them to only access company emails using the Internet browser version of Outlook.

 

I have tried to achieve this by using an Azure Conditional Access policy (with Office 365 Exchange Online). The problem is using Azure Conditional will also effect MS Teams and Skype for Business as explained on https://docs.microsoft.com/en-us/azure/active-directory/active-directory-conditional-faqs

 

My question is, is there another way we can block the Outlook desktop application using another Intune feature like Windows Information Protection (WIP)?

 

Thanks
Colin

1 Reply

If you want to block them from accessing Outlook on *any* location, use the Set-CasMailbox cmdlet:

 

Get-CASMailbox user@domain.com -MAPIEnabled $false

 

If you want to block it from outside of the corporate network only, Conditional Access or AD FS claims rules are your only options.