SOLVED

Intune-Managed Devices Can Suddenly Connect to O365 Mail Outside Of Container. What Changed?

%3CLINGO-SUB%20id%3D%22lingo-sub-138542%22%20slang%3D%22en-US%22%3EIntune-Managed%20Devices%20Can%20Suddenly%20Connect%20to%20O365%20Mail%20Outside%20Of%20Container.%20What%20Changed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-138542%22%20slang%3D%22en-US%22%3E%3CP%3EWe're%20an%20E5%2FEMS%20org%20and%20use%20Intune%20Hybrid%20to%20manage%20our%20mobile%20devices.%26nbsp%3B%20MDM%20Authority%20is%20SCCM.%3C%2FP%3E%0A%3CP%3EA%20long%20time%20ago%20we%20disabled%20ActiveSync%20and%20forced%20users%20to%20go%20with%20the%20containerized%20Outlook%20Client%20we%20pushed%20to%20them.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20AM%20I%20was%20notified%20by%20our%20Infosec%20dept%20that%20he%20was%20able%20to%20add%20his%20O365%20company%20email%20acct%20to%20his%20GMail%20and%20send%2Freceive.%26nbsp%3B%20I%20confirmed%20that%20this%20is%20true%20by%20adding%20my%20acct%20as%20a%202ndary%20acct%20to%20my%20Android%20phone.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EUntil%20today%20this%20was%20not%20possible.%26nbsp%3B%20Has%20something%20changed%3F%26nbsp%3B%20There%20was%20a%20notification%20in%20my%20Tenant%20Messages%20that%20my%20Intune%20Service%20had%20been%20upgraded%20to%20the%20latest%20server%20build%2C%20but%20nothing%20in%20the%20'what's%20new'%20sites%20mentioned%20anything%20about%20this.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20anyone%20can%20replicate%20or%20let%20me%20know%20what%20may%20have%20changed%20I'd%20appreciated.%26nbsp%3B%20Also%20contacting%20PSS.%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EJohn%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-138542%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompliance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EManage%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-141647%22%20slang%3D%22en-US%22%3ERe%3A%20Intune-Managed%20Devices%20Can%20Suddenly%20Connect%20to%20O365%20Mail%20Outside%20Of%20Container.%20What%20Changed%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-141647%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20to%20follow%20up%2C%20I%20worked%20with%20the%20Intune%20Team%20on%20this%2C%20and%20the%20answer%20was%20that%20we%20had%20not%20disabled%20POP3%2FIMAP%20for%20every%20mailbox%2C%20and%20thus%20anyone%20could%20use%20it%20to%20connect%20their%20device%20to%20their%20mailbox.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThis%20may%20be%20a%20huge%20oversight%20on%20my%20part%2C%20but%20IDK.%26nbsp%3B%20We%20long%20ago%20disabled%20ActiveX%2C%20but%20nowhere%20did%20I%20ever%20see%20that%20POP3%2FIMAP%20were%20also%20vulnerable%20holes.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThe%20product%20team%20was%20pretty%20sheepish%20about%20this%20huge%20security%20gap%20in%20the%20product%2C%20saying%20that%20it's%20'umm....%20not%20very%20well-documented.'%26nbsp%3B%20I%20took%20that%20to%20mean%20that%20it's%20a%20known%20weakness%20in%20the%20product%20that%20they%20don't%20advertise.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAnyway%2C%20there%20are%20remediation%20steps%20for%20existing%20mailboxes%20via%20'set-casmailbox%20-popenabled%20%24false%20-imapenabled%20%24false'%26nbsp%3B%20Easy%20enough%20to%20do%20for%20all%20of%20your%20MBX's.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20NEW%20users%2Fmailboxes%2C%20you%20have%20to%20either%20do%20it%20as%20part%20of%20your%20provisioning%2C%20or%20modify%20the%20setting%20in%20the%20'casmailboxplan'.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%0A%3CP%3EI%20found%20info%20here%3A%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fblogs.technet.microsoft.com%2Fpraveenkumar%2F2017%2F06%2F09%2Fhow-to-diable-popimap-protocol-for-all-users-by-default-in-office-365%2F%26nbsp%3B%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fblogs.technet.microsoft.com%2Fpraveenkumar%2F2017%2F06%2F09%2Fhow-to-diable-popimap-protocol-for-all-users-by-default-in-office-365%2F%26nbsp%3B%3C%2FA%3E%3C%2FP%3E%0A%3CP%3EThx%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

We're an E5/EMS org and use Intune Hybrid to manage our mobile devices.  MDM Authority is SCCM.

A long time ago we disabled ActiveSync and forced users to go with the containerized Outlook Client we pushed to them.

 

This AM I was notified by our Infosec dept that he was able to add his O365 company email acct to his GMail and send/receive.  I confirmed that this is true by adding my acct as a 2ndary acct to my Android phone.  

 

Until today this was not possible.  Has something changed?  There was a notification in my Tenant Messages that my Intune Service had been upgraded to the latest server build, but nothing in the 'what's new' sites mentioned anything about this.

 

If anyone can replicate or let me know what may have changed I'd appreciated.  Also contacting PSS.

Thanks,

John

 

 

1 Reply
best response confirmed by Deleted
Solution

Just to follow up, I worked with the Intune Team on this, and the answer was that we had not disabled POP3/IMAP for every mailbox, and thus anyone could use it to connect their device to their mailbox. 

 

This may be a huge oversight on my part, but IDK.  We long ago disabled ActiveX, but nowhere did I ever see that POP3/IMAP were also vulnerable holes.  

 

The product team was pretty sheepish about this huge security gap in the product, saying that it's 'umm.... not very well-documented.'  I took that to mean that it's a known weakness in the product that they don't advertise.  

 

Anyway, there are remediation steps for existing mailboxes via 'set-casmailbox -popenabled $false -imapenabled $false'  Easy enough to do for all of your MBX's.

 

For NEW users/mailboxes, you have to either do it as part of your provisioning, or modify the setting in the 'casmailboxplan'.  

I found info here: 

 https://blogs.technet.microsoft.com/praveenkumar/2017/06/09/how-to-diable-popimap-protocol-for-all-u...

Thx