Intune MAM Policies(Android/iOS) not applying to Onpremises mailbox users

%3CLINGO-SUB%20id%3D%22lingo-sub-2907537%22%20slang%3D%22en-US%22%3EIntune%20MAM%20Policies(Android%2FiOS)%20not%20applying%20to%20Onpremises%20mailbox%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2907537%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%2C%3C%2FP%3E%3CP%3EWe%20have%20exchange%20hybrid%20environment%20and%20most%20of%20the%20mailboxes%20are%20on%20on-premises%20exchange.%3C%2FP%3E%3CP%3EAlso%20we%20have%20enabled%20Hybrid%20modern%20authentication%20for%20on-premises%20exchange%20hybrid.%3C%2FP%3E%3CP%3EWe%20have%20configured%20below%20things.%3C%2FP%3E%3CP%3E1.%20Configured%20HMA%20for%20Onprem%20Exchange%3C%2FP%3E%3CP%3E2.%20Assigned%20microsoft%20E5%20License%20including%20Intune%20License%3C%2FP%3E%3CP%3E3.%20Configured%20below%20Azure%20AD%20conditional%20access%20policies%3C%2FP%3E%3COL%3E%3CLI%3ECreate%20a%20conditional%20access%20policy%3C%2FLI%3E%3CLI%3ECreate%20an%20Intune%20app%20protection%20policy%3C%2FLI%3E%3CLI%3EEnable%20hybrid%20Modern%20Authentication%3C%2FLI%3E%3C%2FOL%3E%3CP%3E4.%20Configured%20App%20Protection%20policy%20for%20Android%20and%20iOS%20devices%20and%20assigned%20to%20the%20Intune%20license%20users.%3C%2FP%3E%3CP%3EIt%20is%20working%20fine%20for%20cloud%20mailbox%20users%20only%20having%20issue%20with%20Onprem%20mailbox%20users.%3C%2FP%3E%3CP%3ELet%20us%20know%20if%20any%20advance%20configuration%20we%20need%20to%20do%20from%20exchange%20on-premises.%3C%2FP%3E%3CP%3EReference%20Articles%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2FExchange%2Fclients%2Foutlook-for-ios-and-android%2Fuse-hybrid-modern-auth%3Fview%3Dexchserver-2019%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EUsing%20hybrid%20Modern%20Authentication%20with%20Outlook%20for%20iOS%20and%20Android%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fenterprise%2Fhybrid-modern-auth-overview%3Fview%3Do365-worldwide%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EHybrid%20Modern%20Authentication%20overview%20and%20prerequisites%20for%20use%20with%20on-premises%20Skype%20for%20Business%20and%20Exchange%20servers%20-%20Microsoft%20365%20Enterprise%20%7C%20Microsoft%20Docs%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2907537%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2908853%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20MAM%20Policies(Android%2FiOS)%20not%20applying%20to%20Onpremises%20mailbox%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2908853%22%20slang%3D%22en-US%22%3EWhat%20client%20are%20they%20using%20%3F%20They%20need%20to%20be%20using%20Outlook%20as%20far%20as%20I%20understand.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2908884%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20MAM%20Policies(Android%2FiOS)%20not%20applying%20to%20Onpremises%20mailbox%20users%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2908884%22%20slang%3D%22en-US%22%3EYes%20they%20are%20using%20Microsoft%20Outlook.%3C%2FLINGO-BODY%3E
Contributor

Hi All,

We have exchange hybrid environment and most of the mailboxes are on on-premises exchange.

Also we have enabled Hybrid modern authentication for on-premises exchange hybrid.

We have configured below things.

1. Configured HMA for Onprem Exchange

2. Assigned microsoft E5 License including Intune License

3. Configured below Azure AD conditional access policies

  1. Create a conditional access policy
  2. Create an Intune app protection policy
  3. Enable hybrid Modern Authentication

4. Configured App Protection policy for Android and iOS devices and assigned to the Intune license users.

It is working fine for cloud mailbox users only having issue with Onprem mailbox users.

Let us know if any advance configuration we need to do from exchange on-premises.

Reference Articles

Using hybrid Modern Authentication with Outlook for iOS and Android | Microsoft Docs

Hybrid Modern Authentication overview and prerequisites for use with on-premises Skype for Business ...

 

2 Replies
What client are they using ? They need to be using Outlook as far as I understand.
Yes they are using Microsoft Outlook.