Apr 28 2022 11:38 AM
Hi Team. I have a doubt, I have assign MFA for Outlook and Teams clients?
In Conditional Access policy, Conditions - Device platforms - Select Windows.
In Client Apps select Mobile apps and desktop clients.
This option, apply for Outlook and Teams clients?
Or exist other option for configure MFA in this clients?
Regards,
Thanks,
Apr 28 2022 11:58 PM
Apr 30 2022 08:41 AM
Apr 30 2022 09:35 AM - edited May 01 2022 04:55 AM
Hi @CarlosMorales ,
This is what I would do. Make sure you use Modern authentication.
This is not ideal situation with Exchange Online App, but adding Device platfrom - Windows, Client apps - Mobile apps and Desktop clients plus enabling Modern authentication is the closest you can get.
I just tested in my environment and it will require MFA for Outlook client on Windows (if modern enabled), it does not ask you for MFA on other devices. It will not require MFA in browsers.
Good luck
Please see below, testing environment with the policy from above.
Apr 30 2022 02:05 PM
Apr 30 2022 10:58 PM
May 01 2022 03:48 AM - edited May 01 2022 04:58 AM
Hi @mikhailf ,
Thanks for the contribution. That is the main reason I excluded Browser. I just update behavior from the test environment.
May 01 2022 05:44 AM
May 01 2022 05:55 AM
May 01 2022 09:30 AM
May 01 2022 09:37 AM
Hi @CarlosMorales ,
thanks for the reply.
Keep in mind that in this particular setup, you have to disable Legacy authentication and enable Modern authentication.
You can accomplish this by additional additional Conditional Access. see below.
Also you can do this by disabling Basic authentication from Admin center.
May 01 2022 09:40 AM
May 01 2022 09:44 AM
May 01 2022 10:59 AM
May 01 2022 02:45 PM
Hi @CarlosMorales ,
you can uncheck everything but I would suggest also creating a CA policy and block legacy.
If you decide to uncheck from Admin portal - see below my environment.
If you decide to do CA policy, you can Assign to test user, Cloud apps to All Cloud Apps, and Conditions under Client apps set to Yes, and check both under Legacy authentication clients. Under Grant set to Block.
Good luck. Make sure your Outlook client is the latest version to support Modern authentication. You can read about it here - Modern Authentication configuration requirements for transition - Exchange | Microsoft Docs
May 02 2022 08:51 AM
Hi @Adin_Calkic
Perform both settings: block legacy authentication and create CA policy.
Cannot working MFA in Outlook Client, the client version is 2203 Build 15028.20204
May 02 2022 09:27 AM
Hi @CarlosMorales ,
check here on how to force modern authentication for Outlook client. You can set in registry.
Modern Authentication configuration requirements for transition - Exchange | Microsoft Docs