SOLVED

Conditional Access MFA Outlook 2016 question

%3CLINGO-SUB%20id%3D%22lingo-sub-725176%22%20slang%3D%22en-US%22%3EConditional%20Access%20MFA%20Outlook%202016%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-725176%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20just%20set%20up%20conditional%20access%20and%20when%20trying%20to%20authenticate%20users%20in%20Outlook%202016%2C%20it%20just%20continues%20to%20prompt%20for%20a%20password%20and%20will%20not%20work.%20I%20had%20to%20turn%20off%20conditional%20access%20for%20the%20affected%20users%2C%20then%20they%20could%20authenticate.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20have%202%20policies%20for%20conditional%20access.%3C%2FP%3E%3CP%3EThe%20first%20one%20blocks%20the%20log%20in%20to%20any%20apps%20or%20web%20apps%20to%20anyone%20in%20the%20company%20except%20if%20the%20users%20are%20in%20the%20excluded%20group%20and%20they%20must%20be%20located%20at%20one%20of%20our%20offices%20using%20a%20trusted%20IP.%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20second%20forces%20the%20users%20in%20the%20excluded%20group%20from%20the%20policy%20above%20to%20use%20MFA%20irregardless%20of%20where%20they%20are%20if%20they%20aren't%20at%20one%20of%20our%20offices.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20configuration%20will%20not%20allow%20the%20users%20to%20use%20Outlook%202016%20on%20their%20laptops%20when%20not%20at%20our%20office.%20It%20continuously%20prompts%20for%20a%20password%2C%20but%20nothing%20ever%20happens.%20I%20read%20that%20conditional%20access%20MFA%20does%20not%20use%20app%20passwords%2C%20so%20that%20is%20not%20an%20option.%20Outlook%202016%20is%20supposed%20to%20be%20able%20use%20modern%20authentication.%20So%20where%20am%20I%20going%20wrong%3F%20I%20need%20to%20have%20these%20user's%20accounts%20protected%20when%20away%20from%20the%20office%2C%20but%20I%20also%20need%20them%20to%20be%20able%20to%20use%20their%20email%20in%20Outlook.%20Please%20help.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-725484%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20MFA%20Outlook%202016%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-725484%22%20slang%3D%22en-US%22%3E%3CP%3EMake%20sure%20Modern%20auth%20is%20enabled%20on%20the%20client%2C%20as%20well%20as%20service-side.%20What%20you%20are%20describing%20looks%20like%20the%20good%20old%20basic%20auth%20prompt%20-%20it%20will%20not%20work%20once%20MFA%20is%20enabled%20for%20an%20account.%20And%20forget%20about%20app%20passwords%2C%20they%20should%20be%20avoided%20wherever%20possible.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-725865%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20MFA%20Outlook%202016%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-725865%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BThank%20you%20for%20your%20help.%20After%20reading%20your%20response%2C%20it%20prompted%20me%20to%20check%20Exchange%20online%20to%20see%20if%20it%20had%20modern%20authentication%20enabled.%20I%20had%20read%20this%20was%20enabled%20by%20default.%20However%2C%20when%20I%20checked%20ours%2C%20it%20was%20disabled.%20I%20enabled%20it%20and%20things%20started%20working%20after%20that.%20Thank%20You%20for%20your%20help!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-729011%22%20slang%3D%22en-US%22%3ERe%3A%20Conditional%20Access%20MFA%20Outlook%202016%20question%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-729011%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F192608%22%20target%3D%22_blank%22%3E%40Chris%20Varner%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20encountered%20the%20same%20issue%20on%20my%20machine%2C%20I%20deleted%20cached%20credentials%20under%20Credential%20Manager%20for%20Outlook%20and%20reset%20my%20MFA.%20I%20was%20running%20Windows%2010%20machine%20and%20Office%202016%20on%20mine.%20It%20worked%20and%20hope%20it%20helps.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

We just set up conditional access and when trying to authenticate users in Outlook 2016, it just continues to prompt for a password and will not work. I had to turn off conditional access for the affected users, then they could authenticate.

 

We have 2 policies for conditional access.

The first one blocks the log in to any apps or web apps to anyone in the company except if the users are in the excluded group and they must be located at one of our offices using a trusted IP. 

The second forces the users in the excluded group from the policy above to use MFA irregardless of where they are if they aren't at one of our offices. 

 

This configuration will not allow the users to use Outlook 2016 on their laptops when not at our office. It continuously prompts for a password, but nothing ever happens. I read that conditional access MFA does not use app passwords, so that is not an option. Outlook 2016 is supposed to be able use modern authentication. So where am I going wrong? I need to have these user's accounts protected when away from the office, but I also need them to be able to use their email in Outlook. Please help. 

3 Replies
best response confirmed by Chris Varner (New Contributor)
Solution

Make sure Modern auth is enabled on the client, as well as service-side. What you are describing looks like the good old basic auth prompt - it will not work once MFA is enabled for an account. And forget about app passwords, they should be avoided wherever possible.

@Vasil Michev Thank you for your help. After reading your response, it prompted me to check Exchange online to see if it had modern authentication enabled. I had read this was enabled by default. However, when I checked ours, it was disabled. I enabled it and things started working after that. Thank You for your help!

@Chris Varner 

 

I had encountered the same issue on my machine, I deleted cached credentials under Credential Manager for Outlook and reset my MFA. I was running Windows 10 machine and Office 2016 on mine. It worked and hope it helps.