Office 365 MFA Enabled Users and the Apple Mail app for iOS Concern

Iron Contributor

Office 365 MFA and the Apple Mail app for iOS concern? We ourselves and several customers using Office 365 have noticed a recent issue with the Apple Mail app for iOS when Office 365 MFA is enabled. When users are out of a known or trusted location and required to MFA to sign in or access Office 365 resources the Apple Mail app for iOS is asking for the user's password. This should NOT happen if MFA is enabled and an App Password has been created to be used for the Mail app. The Mail app then prompts the user to enter their Office 365 password which confuses the end user because they try to re-enter the generated App Password which it then fails to sign in because it actual requires the user's standard password. Has there been recent changes to that platform and the Apple Mail app for iOS? I'm thinking that Apple finally updated the Mail app to support modern authentication, if so why hasn't documentation for it been updated?  I can see that Apple introduced the capability in 11.0 but we could not get it to work out of the gate and found it to be NOT 100% reliable.  So if they finally got this to work in the latest release of iOS what is the recommendation?  Have all the current users update their passwords in the app from the App Password to their standard password or can we continue to use the App Password?  We have noticed the increase in support requests from customers about this issue in the past 2 weeks or less.

34 Replies
I never saw that before. Thanks, I’m looking into the sync function.

@Alex Melching 

 

I just enabled MFA and I have the same recurring iOS password request. I loaded the Outlook app but I later found the work around for this issue. Like most people, I didn't write down the App Password. Here's how you generate another one. When you enter it in the password field instead of your mail password, the popup goes away and the mail loads. I saved it this time so that I'll have it in the future.

 

https://www.hendrix.edu/HelpDesk/Computers_and_Devices/Mobile_Devices/Set-Up_Email_Access_with_MFA_(...

 

I'm revisiting my own post as I see this is still a problem.  Onboarded new customer and users prefer the native Mail app. Still continuous prompts with MFA enforced or if the Security Defaults is enabled. The app password is not 100% reliable.

 

So anyone figure out a decent work around?  Still seems like broken promises from Apple that they have resolved this issues with Microsoft 365...

You have to go into Office 365 and turn on Modern Authentication. Microsoft says in their literature its enabled by default but it’s not.

Turn on Modern authentication for your organization

For most subscriptions modern authentication is automatically turned on, but if you purchased your subscription a long time ago, it might not be. This has to be turned on before MFA works appropriately with Office apps.

In the Microsoft 365 admin center, in the left nav choose Settings > Org settings.
Under Services tab, choose Modern authentication, and in the Modern authentication pane, make sure Enable Modern authentication is selected. Choose Save changes.
Oh it’s enabled... This isn’t my first rodeo with this problem...

@Alex Melching We have the same issue here.  Users work fine in the Outlook mobile app, but the handful using the native iOS mail client repeatedly receive the prompt for password/edit settings.  I haven't been able to find a solution to this anywhere other than forcing people to use Outlook Mobile.  We have been using Conditional Access for some time.  Everyone is properly licensed and our org is enabled globally for modern auth.  I'm not exactly sure where to go from here.  There's a disconnect somewhere.

Have you seen this article within 'iOS Mail'. Depending on how you configure the iOS mail app, modern or basic auth is selected
https://help.duo.com/s/article/4614?language=en_US

I also have a client where I enabled Microsoft MFA. In reading through this thread and several others, Apple's included. I have found that the easiest fix was to allow Exchange ActiveSync clients in the Client apps section within the Conditional Access policy. Once I enabled Exchange ActiveSync clients, my users that used the default Apple Mail app were once again able to access their email.

 

Hopefully, this will work for others and save them a little bit of time.

@JQ_IT_Admin Please somebody correct me if I'm wrong, but wouldn't allowing ActiveSync open up a security hole (since it's a basic authentication method)?

 

I have a couple of iOS users who are having the same issue since enabling MFA and disabling basic authentication methods. Some but not all. I have also been recommending the Outlook app & appreciate @vortiz posting the link about syncing contacts through the app.

 

I may take this up with MS support to see if I can get any further. Will update the thread if I do!

The Apple Mail app supports Modern Auth since iOS 11. But when configuring the accout, be sure to use 'Sign-in' and not 'setup manually'. Setup manually will cause basic auth

I can confirm what Thijs Lecomte said. We enabled MFA across the company on 9/1/2021. Many but not all iPhone users had this problem where the built-in mail app kept asking for the password. We found the solution was this:
1. Delete the exchange account from mail settings.
2. Add the mail account back again.
3. Choose "Microsoft Exchange" NOT Outlook.com (Important)
4. Enter email address. The default description of "Exchange" is fine.
5. When prompted for "Configure Manually" or "Sign In" choose "Sign In". This is the critical thing. the “Sign In” option supports MFA authentication, “Configure Manually” does not.
6. Enter your password and do the MFA approval.
7. After verification, you’re good to go.


Our conditional access policy still has this:

DarthMS_0-1630614008237.png

 

Anyone know if there is a fix for this yet using MDM? Currently I have to allow Exchange Active Sync in order for the native email apps to work on user phones since Company Portal pushes the mail profile to connect with basic auth. I was under the impression that basic is going away... Anyway, yes, using outlook fixes the issue for mail, but the mail profile from the mdm will still ask for the password constantly and users don't like that.

I worked round the MDM issue on an iPad as follows:
1. Temporarily excluded the user account from enforced MDM using Classic Policies at https://aad.portal.azure.com/#blade/Microsoft_AAD_IAM/ConditionalAccessBlade/ClassicPolicies
2. Removed the management profile from the iPad - which removed the non-working Mail account
3. Added the email account to Apple's mail client manually, including MFA.

4: Used Company Portal to download a new profile and installed it. Because the email account was already there, the profile did not add a non-working one.

5. Restored the MDM configuration in Azure AD

6. Removed the email account, and then put it back.

 

Step 6 is needed because the Mail account was created before the profile was installed, so the login was from a context which is no longer valid on the server. It will fail after some hours and you must reinstall it to get a valid login. Do not leave it without any account for any substantial time. If you do, the downloaded profile will cause the system to create a non-removable mail account that cannot use modern authentication, and you are back to Step 1.

You can recognise an account that came from the downloaded profile - the option to remove it it missing from its properties.


I also tried downloading the profile from an account that has full Intune on the license instead of the O365 MDM, and in this case it did not try to create the Mail account at all. Hence, with that option you never hit a problem because you manually add the Mail account after downloading the profile.

Does anyone have any new advice for using Office 365 MDM to deploy iOS management profiles, now that Basic Authentication is turned off? It is still deploying EAS mail for me, how can I get it to deploy mail using Modern Auth?