How to best deny mail access to third party apps?

Brass Contributor



What would be the best way to deny mail access to third party apps? I'm about to deploy Microsoft Intune to protect our data and I've noticed that when retrieving mail data from a device it will fail to do so with third party apps.


Is it possible for a 365 account to be able to access mail only by using Outlook?


Thank you,



2 Replies



I would recommended looking at Conditional Access in Azure AD:


With Conditional Access you could create policies depending on the platform (Windows, Mac, iOS, Android), what type of application (Exchange Online, SharePoint, etc.) and if the application needs to be an approved application (Microsofts own applications), device is compliance in Intune and/or require MFA.



If you are only concerned about email, you can block specific apps and protocols via the corresponding controls for Set-CasMailbox:


In addition, the mobile device policies can control access for any ActiveSync apps. The newly released Client Access Rules can also help:


Intune or Conditional Access offer additional options, but those come at a price.