Conditional Access: Block Exchange Online Registration, If device is not Registered to Intune or has Company Portal installed

Jayd 171 Reputation points
2020-12-03T13:58:51.987+00:00

Hello Community,

we using Conditonal for our Mobile Devices. Goal is, that Users are only possible to Log into EXO when their phone is registered in Intune and has the Company Portal installed. Outlook should be the only App which is allowed to connect to EXO, when the devices is registered.
I followed the Technet Guide: https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/secure-outlook-for-ios-and-android

I set up everthing accordingly.

What works is, when i log into the Outlook APP, it says i have to first download the Company Portal. Otherwise i cant connect. So thats works fine.

But when i use Gmail for example i can Login into EXO without any issue. It doesnt block me or asks for the App to be downloaded.
To block the Gmail registration, i found out that blocking the legacy Authenticiation should be the way to go. I also read to wait few hours because it could take some time until the Policy is active. But the day after i was still possible to register.
Is there anything else i need to set up to Block other 3rd Party Application to connect to EXO.

Thanks a lot for your Help.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 43,381 Reputation points Microsoft Vendor
    2020-12-04T07:35:15.667+00:00

    @Jayd , Based on my test, when I create another conditional access policy which block legacy authentication. The Gmail access is prevented. Here is the policy I create:

    Cloud apps or action: office 365 exchange online
    Conditions->Device platform :iOS and Android
    Client apps: Other clients
    Grant: Block access.

    Maybe we can create a similar conditional access for some test users to see if we get the same result.

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

1 additional answer

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,151 Reputation points MVP
    2020-12-03T23:24:51.92+00:00

    Hi,

    Did you also enable required approved client app in grant controls? I blogged about this recently which you can read over here.

    conditional-access-restrict-office-365.html

    1 person found this answer helpful.