Samsung Email - Need Admin Approval

Copper Contributor

Hello,

 

Recently we are running into a few issues with the native mail client on Samsung devices. These devices are still device admin (I know, I know). Heres what we are seeing:

 

1. Users device working fine.

2. User updates their password

3. Email account prompts for the new password

4. After password is entered they get MFA challenge and accept

5. User is brought to a page that says "Samsung Email needs Admin approval"

6. User deletes email profile from device

7. User syncs device through Company portal

8. Email profile comes down and user signs in without issue

 

Is there anyway to fix this from occurring? I understand Managing user content, but why does this prompt not come up when users sign into the email app the initial time and why when updating their password?

3 Replies

@kkeirstead 

 

Do you have the App (Samsung Email) listed under your Azure AD - Enterprise Apps? If yes, go ahead and Grant Admin Consent to your tenant under Permissions tab (screenshot 2).

If not listed, enable the user request Workflow in Azure AD - Enterprise Application - User Setting (screenshot 1) to justify the access, then look for the app under Enterprise Apps and Grant Admin Consent to your tenant under permissions tab (screenshot 2).


Hope this helps!
Moe

 

https://docs.microsoft.com/en-gb/azure/active-directory/manage-apps/grant-admin-consent

 

@Moe_Kinani ios and non-Samsung native mail apps don't need it, why should Samsung?

@Kovachit 

 

All mail 3rd party apps need to consent except Outlook. You can change your tenant consent setting to allow users to consent, which is not recommended at all.

 

Moe