mobile device access rules

MasterBlaster 156 Reputation points
2021-03-01T20:27:10.817+00:00

Hi Team, When iphone is configured with Outlook for iOS access to exchange online is allowed, same device gets quarantined when using iPhone native mail app? why? I have a rule with Characterstic "devicetype" , QueryString set to "Iphone" and Accesslevel set to "allow". Activesyncorganizationsettings , "Defaultaccesslevel" is set to allow. Why when using native app on iPhone my app gets quarantined with reason "AadBlockDuetoAccessPolicy" and remains in quanrantinepending state when allowed. Please advise. Thanks, Harshit Malhotra

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,369 questions
0 comments No comments
{count} votes

Accepted answer
  1. MasterBlaster 156 Reputation points
    2021-03-03T09:32:56.807+00:00

    Hi Andy,

    Hope you are doing good.

    We found out that there was no Conditional Access Policy.

    We isolated the issue, After we disabled Security Defaults, Iphone was again configured with Native App and it was allowed to go through.

    Thanks for your help.

    Regards,
    Harshit Malhotra

    1 person found this answer helpful.

2 additional answers

Sort by: Most helpful
  1. Andy David - MVP 142.3K Reputation points MVP
    2021-03-01T20:36:38.96+00:00

    AadBlockDuetoAccessPolicy = Means you have a conditional access policy that is blocking it.
    Check the Azure Sign in logs for that user to see what CA policy blocked it


  2. Yuki Sun-MSFT 40,871 Reputation points
    2021-03-02T03:08:29.127+00:00

    Hi @MasterBlaster ,

    Agree with Andy that from the quarantine reason "AadBlockDuetoAccessPolicy", it's most likely to be related to the Conditional Access policy.

    Additionally, I found the following thread which discusses a similar situation. According to the comments there, it was resolved by removing the account from the device first, then approving in exchange quarantine and add the account again in the native Mail app on the device:

    Issue with security defaults - activesync clients get quarantined


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.