SOLVED

Outlook sign-in issue with Intune on Windows 10

%3CLINGO-SUB%20id%3D%22lingo-sub-182882%22%20slang%3D%22en-US%22%3EOutlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182882%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20just%20discovered%20the%20following%20issue%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E1.%20Added%20my%20Windows%2010%201803%20machine%20to%20Intune%20MDM%20from%20my%20Azure%2FOffice%20365%20tenant.%3C%2FP%3E%3CP%3E2.%20Logged%20into%20the%20machine%20with%20my%20Office%20365%20account.%3C%2FP%3E%3CP%3E3.%20Installed%20Outlook%20(16.0.9126.2152)%26nbsp%3B%3C%2FP%3E%3CP%3E4.%20Tried%20to%20setup%20my%20Office%20365%20account%20(same%20as%20Intune)%3C%2FP%3E%3CP%3E5.%20The%20account%20setup%20fails%20because%20Outlook%20uses%20the%20Windows%20log-in%20prompt%20for%20authentication%20against%20O365%20and%20not%20the%20required%20Browser-prompt%20with%20MFA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20setup%20app%20passwords%20as%20a%20preliminary%20measure%2C%20but%20I%20don't%20think%20this%20is%20the%20intentional%20experience.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-182882%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20Apps%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProPlus%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-183021%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-183021%22%20slang%3D%22en-US%22%3E%3CP%3EI%20just%20disabled%20and%20enabled%20Modern%20auth%20and%20now%20its%20working.%20Strange%20things...%20Thanks%20for%20your%20support!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-182966%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182966%22%20slang%3D%22en-US%22%3E%3CP%3EWindows%2010%20with%20Office%202016%2F365%20leverage%20modern%20authentication%20and%20doesn't%20require%20to%20have%20an%20app%20password%20for%20authentication.%20I%20assume%20you're%20getting%20a%20pop%20up%20message%20as%20you're%20trying%20to%20setup%20outlook%20profile%20from%20outlook%20startup%20window%2C%20can%20you%20try%20to%20configure%20email%20profile%20from%20Control%20panel%20%26gt%3B%20Mail%2C%20New%20Profile%20option%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-182943%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182943%22%20slang%3D%22en-US%22%3EIs%20there%20any%20Conditional%20Access%20policy%20in%20place%3F%20Or%20maybe%20an%20application%20protection%20policy%3F%3CBR%20%2F%3E%3CBR%20%2F%3EBest%20regards%2C%3CBR%20%2F%3ERuud%20Gijsbers%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-182892%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182892%22%20slang%3D%22en-US%22%3EI%20also%20tried%20this%20setting%2C%20but%20Outlook%20doesn't%20seem%20to%20care%20in%20this%20case%3A%20%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F3126599%2Foutlook-prompts-for-password-when-modern-authentication-is-enabled%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-us%2Fhelp%2F3126599%2Foutlook-prompts-for-password-when-modern-authentication-is-enabled%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-182891%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182891%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3Ei%20just%20checked%20and%20yes%20Modern%20auth%20is%20enabled.%20Account%20setup%20works%20in%20the%20expected%20fashion%20on%20another%20machine%20that%20is%20not%20part%20of%20Intune%20MDM%20and%20I%20can%20setup%20an%20account%20from%20a%20different%20O365%20tenant%20with%20MFA%20without%20a%20problem.%3CBR%20%2F%3E%3CBR%20%2F%3EGreetings%3CBR%20%2F%3EJohannes%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-182889%22%20slang%3D%22en-US%22%3ERe%3A%20Outlook%20sign-in%20issue%20with%20Intune%20on%20Windows%2010%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-182889%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Johannes%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDid%20you%20enable%20Modern%20Autjentication%20on%20Exchange%20Online%3F%20This%20is%20needed%20if%20your%20using%20Outlook%20in%20combination%20with%20MFA.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20can%20check%20this%20bu%20running%20the%20following%20command%20in%20Echange%20online%20Powershell%3A%3C%2FP%3E%3CP%3E%3CEM%3EGet-OrganizationConfig%20%7C%20fl%20OAuth2ClientProfileEnabled%3C%2FEM%3E%3C%2FP%3E%3CP%3EIf%20the%20outcome%20of%20the%20command%20is%20false%2C%20you%20can%20set%20it%20to%20true%20with%20the%20following%20command%3A%3C%2FP%3E%3CP%3E%3CEM%3ESet-OrganizationConfig%20-OAuth2ClientProfileEnabled%20%24true%3C%2FEM%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20regards%2C%3C%2FP%3E%3CP%3ERuud%20Gijsbers%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

Hey everyone,

 

i just discovered the following issue:

 

1. Added my Windows 10 1803 machine to Intune MDM from my Azure/Office 365 tenant.

2. Logged into the machine with my Office 365 account.

3. Installed Outlook (16.0.9126.2152) 

4. Tried to setup my Office 365 account (same as Intune)

5. The account setup fails because Outlook uses the Windows log-in prompt for authentication against O365 and not the required Browser-prompt with MFA.

 

Any ideas?

 

I have setup app passwords as a preliminary measure, but I don't think this is the intentional experience.

6 Replies
Highlighted
Solution

Hi Johannes,

 

Did you enable Modern Autjentication on Exchange Online? This is needed if your using Outlook in combination with MFA.

 

You can check this bu running the following command in Echange online Powershell:

Get-OrganizationConfig | fl OAuth2ClientProfileEnabled

If the outcome of the command is false, you can set it to true with the following command:

Set-OrganizationConfig -OAuth2ClientProfileEnabled $true

 

Best regards,

Ruud Gijsbers

Highlighted
Hi,

i just checked and yes Modern auth is enabled. Account setup works in the expected fashion on another machine that is not part of Intune MDM and I can setup an account from a different O365 tenant with MFA without a problem.

Greetings
Johannes
Highlighted
Highlighted
Is there any Conditional Access policy in place? Or maybe an application protection policy?

Best regards,
Ruud Gijsbers
Highlighted

Windows 10 with Office 2016/365 leverage modern authentication and doesn't require to have an app password for authentication. I assume you're getting a pop up message as you're trying to setup outlook profile from outlook startup window, can you try to configure email profile from Control panel > Mail, New Profile option?

Highlighted

I just disabled and enabled Modern auth and now its working. Strange things... Thanks for your support!