Problem with supervised mode and MFA Text

%3CLINGO-SUB%20id%3D%22lingo-sub-830070%22%20slang%3D%22en-US%22%3EProblem%20with%20supervised%20mode%20and%20MFA%20Text%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-830070%22%20slang%3D%22en-US%22%3E%3CP%3EOn%20occasion%20when%20I%20setup%20a%20new%20iPhone%20that%20is%20supervised%2C%20I%20am%20noticing%20that%20the%20MFA%20text%20never%20comes%20through%20and%20you%20cannot%20jump%20out%20of%20the%20app%20to%20go%20to%20text.%20Even%20when%20you%20choose%20another%20option%20and%20do%20a%20phone%20call%2C%20I%20cannot%20actually%20answer%20the%20phone%2C%20since%20the%20Company%20Portal%20app%20is%20in%20the%20foreground%20and%20cannot%20be%20exited.%26nbsp%3B%20What%20can%26nbsp%3B%20I%20do%20to%20fix%20this%20issue%3F%20Anyone%20else%20experienced%20this%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-830070%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1003358%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20supervised%20mode%20and%20MFA%20Text%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1003358%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F6398%22%20target%3D%22_blank%22%3E%40Jeff%20Harlow%3C%2FA%3E%2C%20are%20you%20still%20experiencing%20this%20issue%3F%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ECould%20you%20also%20expand%20on%20how%20the%20devices%20are%20enrolled%20and%20configured%3F%3A%3C%2FP%3E%0A%3COL%3E%0A%3CLI%3EEnrollment%20Method%20used%3COL%3E%0A%3CLI%3EDEP%20with%2Fwithout%20User%20Affinity%3C%2FLI%3E%0A%3CLI%3EApple%20Configurator%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3C%2FLI%3E%0A%3CLI%3EAre%20you%20deploying%20a%20Device%20Restriction%20profile%20such%20as%20Single%20App%20Mode%2FKiosk%3F%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLI%3E%0A%3C%2FOL%3E%0A%3CP%3EThanks!%3C%2FP%3E%0A%3CP%3EIntune%20Support%20Team%3CBR%20%2F%3E%5EMS%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1005177%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20supervised%20mode%20and%20MFA%20Text%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1005177%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20am%20using%20DEP%20with%20User%20Affinity.%20I%20actually%20received%20a%20response%20from%20Microsoft%20stating%20this%20was%20not%20supported%20with%20the%20user%20account%20has%20MFA%20enabled.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1007182%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20supervised%20mode%20and%20MFA%20Text%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1007182%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F6398%22%20target%3D%22_blank%22%3E%40Jeff%20Harlow%3C%2FA%3E%2C%20thanks%20for%20the%20clarification!%3CBR%20%2F%3E%3CBR%20%2F%3EToday%2C%20MFA%20is%20not%20supported%20for%20DEP%20during%20the%20enrollment%20process%20as%20there%20is%20no%20way%20to%20send%20an%20MFA%20prompt%20to%20the%20device%20during%20the%20setup%20assistant.%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FP%3E%0A%3CP%3ESorry%20that%20this%20isn't%20available%20yet%20today%2C%20and%26nbsp%3BI'm%20sure%20you%20know%20that%20we're%20always%20improving%20the%20service.%20There%20is%20an%20existing%20Intune%20UserVoice%20item%20you%20may%20want%20to%20add%20your%20vote%20to%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fmicrosoftintune.uservoice.com%2Fforums%2F291681-ideas%2Fsuggestions%2F17163317-mfa-doesn-t-work-with-apple-dep-with-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fmicrosoftintune.uservoice.com%2Fforums%2F291681-ideas%2Fsuggestions%2F17163317-mfa-doesn-t-work-with-apple-dep-with-intune%3C%2FA%3E.%3CBR%20%2F%3E%3CBR%20%2F%3EAs%20a%20possible%20workaround%2C%20using%20the%20Company%20Portal%20as%20an%20authentication%20method%20may%20work%20in%20instances%20where%20you'd%20like%20to%20use%20MFA%2C%26nbsp%3Bprompt%20users%20who%20need%20to%20change%20their%20password%20when%20they%20first%20sign%20in%2C%20or%20prompt%20users%20to%20reset%20their%20expired%20passwords%20during%20enrollment.%3C%2FP%3E%0A%3CP%3EMore%20information%20can%20be%20found%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fenrollment%2Fdevice-enrollment-program-enroll-ios%23create-an-apple-enrollment-profile%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ECreate%20an%20Apple%20enrollment%20profile%3C%2FA%3E.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EHope%20this%20helps!%3CBR%20%2F%3EIntune%20Support%20Team%3C%2FP%3E%0A%3CP%3E%5EMS%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1008439%22%20slang%3D%22en-US%22%3ERe%3A%20Problem%20with%20supervised%20mode%20and%20MFA%20Text%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1008439%22%20slang%3D%22en-US%22%3E%3CP%3EActually%20you%20cannot%20use%20the%20Company%20Portal%20solution%20either%20when%20isolating%20it%20with%20a%20MFA%20account.%20The%20MFA%20text%20message%20or%20phone%20call%20will%20not%20be%20visible%20or%20answerable%20when%20the%20Company%20Portal%20app%20is%20open%20and%20since%20you%20cannot%20switch%20the%20app%2C%20it%20renders%20that%20solution%20as%20invalid.%20This%20has%20been%20confirmed%20by%20Intune%20Support.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F226779%22%20target%3D%22_blank%22%3E%40Intune%20Support%20Team%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

On occasion when I setup a new iPhone that is supervised, I am noticing that the MFA text never comes through and you cannot jump out of the app to go to text. Even when you choose another option and do a phone call, I cannot actually answer the phone, since the Company Portal app is in the foreground and cannot be exited.  What can  I do to fix this issue? Anyone else experienced this? 

4 Replies
Highlighted

Hi @Jeff Harlow, are you still experiencing this issue?

 

Could you also expand on how the devices are enrolled and configured?:

  1. Enrollment Method used
    1. DEP with/without User Affinity
    2. Apple Configurator
  2. Are you deploying a Device Restriction profile such as Single App Mode/Kiosk?

Thanks!

Intune Support Team
^MS

Highlighted

@Intune Support Team 

 

I am using DEP with User Affinity. I actually received a response from Microsoft stating this was not supported with the user account has MFA enabled. 

Highlighted

Hi @Jeff Harlow, thanks for the clarification!

Today, MFA is not supported for DEP during the enrollment process as there is no way to send an MFA prompt to the device during the setup assistant.

Sorry that this isn't available yet today, and I'm sure you know that we're always improving the service. There is an existing Intune UserVoice item you may want to add your vote to: https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/17163317-mfa-doesn-t-work-with....

As a possible workaround, using the Company Portal as an authentication method may work in instances where you'd like to use MFA, prompt users who need to change their password when they first sign in, or prompt users to reset their expired passwords during enrollment.

More information can be found here: Create an Apple enrollment profile.

 

Hope this helps!
Intune Support Team

^MS

Highlighted

Actually you cannot use the Company Portal solution either when isolating it with a MFA account. The MFA text message or phone call will not be visible or answerable when the Company Portal app is open and since you cannot switch the app, it renders that solution as invalid. This has been confirmed by Intune Support. @Intune Support Team