How to best deny mail access to third party apps?

Ion Zubia



What would be the best way to deny mail access to third party apps? I'm about to deploy Microsoft Intune to protect our data and I've noticed that when retrieving mail data from a device it will fail to do so with third party apps.


Is it possible for a 365 account to be able to access mail only by using Outlook?


Thank you,



2 Replies



I would recommended looking at Conditional Access in Azure AD:


With Conditional Access you could create policies depending on the platform (Windows, Mac, iOS, Android), what type of application (Exchange Online, SharePoint, etc.) and if the application needs to be an approved application (Microsofts own applications), device is compliance in Intune and/or require MFA.




If you are only concerned about email, you can block specific apps and protocols via the corresponding controls for Set-CasMailbox: https://technet.microsoft.com/en-us/library/bb125264(v=exchg.160).aspx


In addition, the mobile device policies can control access for any ActiveSync apps. The newly released Client Access Rules can also help: https://technet.microsoft.com/en-us/library/mt842508(v=exchg.150).aspx


Intune or Conditional Access offer additional options, but those come at a price.

Related Conversations