Limit Office 365 access to work provided devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1355775%22%20slang%3D%22en-US%22%3ELimit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1355775%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20a%20small%20not-for-profit%20organisation%20with%20a%20Microsoft%20365%20Business%20Basic%20subscription.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOur%20users%20currently%20use%20Windows%2010%20Professional%20devices%26nbsp%3Bjoined%20to%20an%20on-premises%20Windows%20Server%202016%20domain%2C%20running%20Microsoft%20365%20for%20email%20and%20Office%202013%20for%20office%20apps.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECurrently%20they%20use%20Outlook%202013%20to%20access%20their%20email%20and%20the%20mail%20profile%20contains%20their%20username%20and%20password.%26nbsp%3B%20They%20just%20start%20Outlook%20and%20are%20logged%20in%20automatically.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELooking%20for%20suggestions%20as%20to%20how%20we%20can%20enforce%20users%20can%20only%20login%20to%20Microsoft%20365%20using%20a%20work%20provided%20device%20to%20login%20via%20a%20browser%20to%20Microsoft%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOne%20possible%20method%20would%20be%20to%20have%20the%20Office%20365%20login%20credentials%20stored%20in%20a%20file%20created%20by%20Powershell%20using%20Get-Credential%2C%20however%20I%20cannot%20find%20a%20way%20to%20get%20a%20browser%20session%20to%20use%20a%20credential%20file%20to%20authenticate%20login%20to%20Microsoft%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%3C%2FP%3E%3CP%3ENigel%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1355775%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1356031%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1356031%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F367901%22%20target%3D%22_blank%22%3E%40Kayak2%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%2C%20the%20features%20you%20are%20looking%20for%20are%20not%20included%20within%20Microsoft%20365%20Business%20Basic%20I'm%20afraid.%20%26nbsp%3B%20You%20would%20need%20Device%20Based%20Conditional%20Access%20which%20comes%20with%20Intune%20and%20Azure%20AD%20Premium%20P1%20to%20achieve%20this.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1356151%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1356151%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F367901%22%20target%3D%22_blank%22%3E%40Kayak2%3C%2FA%3E%26nbsp%3BYou%20can%20also%20have%20a%20look%20at%26nbsp%3BMicrosoft%20365%20Business%20Standard%20that%20includes%20built-in%20MDM%20capabilities.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-ie%2Foffice%2Fcapabilities-of-built-in-mobile-device-management-for-microsoft-365-a1da44e5-7475-4992-be91-9ccec25905b0%3Fui%3Den-us%26amp%3Brs%3Den-ie%26amp%3Bad%3Die%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-ie%2Foffice%2Fcapabilities-of-built-in-mobile-device-management-for-microsoft-365-a1da44e5-7475-4992-be91-9ccec25905b0%3Fui%3Den-us%26amp%3Brs%3Den-ie%26amp%3Bad%3Die%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20noticed%20that%20you're%20using%20Outlook%202013%20so%20a%20heads%20up%20that%26nbsp%3B%3CSPAN%3EOffice%202013%20clients%20connections%20to%20commercial%20Office%20365%20services%20will%20not%20be%20supported%20after%20October%2013%2C%202020.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%22Microsoft%20will%20not%20take%20any%20active%20measures%20to%20block%20older%20Office%20clients%2C%20such%20as%20Office%202013%20and%20Office%202010%2C%20from%20connecting%20to%20Office%20365%20services.%20However%2C%20legacy%20clients%20attempting%20to%20connect%20to%20a%20modern%2C%20always%20up-%20to-%20date%20cloud%20service%20may%20experience%20performance%20and%20reliability%20issues.%20Customers%20will%20face%20an%20increased%20security%20risk%2C%20and%20may%20find%20themselves%20out%20of%20compliance%20depending%20on%20specific%20regional%20or%20industry%20requirements.%22%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1356162%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1356162%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551905%22%20target%3D%22_blank%22%3E%40bec064%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20built%20in%20MDM%20is%20decent%20but%20has%20far%20less%20capabilities%2C%20and%20as%20per%20the%20link%20you%20have%20provided%20for%20this%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSTRONG%3E**%20Access%20control%20for%20Windows%2010%20requires%20a%20subscription%20that%20includes%20Azure%20AD%20Premium%20and%20the%20device%20needs%20to%20be%20joined%20to%20Azure%20Active%20Directory.%3C%2FSTRONG%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1356165%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1356165%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3BHello%2C%20I%20know%20you%20cannot%20compare%20it%20with%20Intune%2C%20but%20a%20%22small%20non-profit%20org%22%20maybe%20want%20have%20a%20look%20at%20some%20of%20the%20options%20available%20at%20least.%20But%20fair%20enough%20regarding%20the%20W10%20devices%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1356169%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1356169%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551905%22%20target%3D%22_blank%22%3E%40bec064%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOh%20definitely%20worth%20mentioning%20it.%20%26nbsp%3BGood%20shout.%20%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Fhtml%2Fimages%2Femoticons%2Fsmile_40x40.gif%22%20alt%3D%22%3Asmile%3A%22%20title%3D%22%3Asmile%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1369336%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1369336%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F616707%22%20target%3D%22_blank%22%3E%40PeterRising%3C%2FA%3E%26nbsp%3BIt%20looks%20like%20our%20best%20option%20might%20be%20upgrading%20to%20Microsoft%20Business%20Premium%20which%20is%20about%20to%20get%26nbsp%3BAzure%20Active%20Directory%20Premium%20P1%20see%20this%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fsmall-and-medium-business-blog%2Fazure-active-directory-premium-p1-is-coming-to-microsoft-365%2Fba-p%2F1275496%22%20target%3D%22_blank%22%20rel%3D%22noopener%22%3Eannouncement%3C%2FA%3E%3C%2FP%3E%3CH1%20id%3D%22toc-hId-442516815%22%20id%3D%22toc-hId-442516815%22%20id%3D%22toc-hId-442516815%22%3E%26nbsp%3B%3C%2FH1%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1369348%22%20slang%3D%22en-US%22%3ERe%3A%20Limit%20Office%20365%20access%20to%20work%20provided%20devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1369348%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F367901%22%20target%3D%22_blank%22%3E%40Kayak2%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYes%20I%20agree%2C%20this%20would%20be%20a%20good%20option%20for%20you.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Occasional Contributor

We are a small not-for-profit organisation with a Microsoft 365 Business Basic subscription.

 

Our users currently use Windows 10 Professional devices joined to an on-premises Windows Server 2016 domain, running Microsoft 365 for email and Office 2013 for office apps.

 

Currently they use Outlook 2013 to access their email and the mail profile contains their username and password.  They just start Outlook and are logged in automatically.

 

Looking for suggestions as to how we can enforce users can only login to Microsoft 365 using a work provided device to login via a browser to Microsoft 365.

 

One possible method would be to have the Office 365 login credentials stored in a file created by Powershell using Get-Credential, however I cannot find a way to get a browser session to use a credential file to authenticate login to Microsoft 365.

 

Thanks in advance

Nigel

 

7 Replies
Highlighted

@Kayak2 

 

Hi, the features you are looking for are not included within Microsoft 365 Business Basic I'm afraid.   You would need Device Based Conditional Access which comes with Intune and Azure AD Premium P1 to achieve this.

Highlighted

@Kayak2 You can also have a look at Microsoft 365 Business Standard that includes built-in MDM capabilities.

https://support.microsoft.com/en-ie/office/capabilities-of-built-in-mobile-device-management-for-mic...

 

I noticed that you're using Outlook 2013 so a heads up that Office 2013 clients connections to commercial Office 365 services will not be supported after October 13, 2020.

 

"Microsoft will not take any active measures to block older Office clients, such as Office 2013 and Office 2010, from connecting to Office 365 services. However, legacy clients attempting to connect to a modern, always up- to- date cloud service may experience performance and reliability issues. Customers will face an increased security risk, and may find themselves out of compliance depending on specific regional or industry requirements."

Highlighted

@bec064 

 

The built in MDM is decent but has far less capabilities, and as per the link you have provided for this;

 

** Access control for Windows 10 requires a subscription that includes Azure AD Premium and the device needs to be joined to Azure Active Directory.

Highlighted

@PeterRising Hello, I know you cannot compare it with Intune, but a "small non-profit org" maybe want have a look at some of the options available at least. But fair enough regarding the W10 devices ;)

Highlighted

@bec064 

 

Oh definitely worth mentioning it.  Good shout.  :smile:

Highlighted

@PeterRising It looks like our best option might be upgrading to Microsoft Business Premium which is about to get Azure Active Directory Premium P1 see this announcement

 

Highlighted

@Kayak2 

 

Yes I agree, this would be a good option for you.