Hybrid Migration - Mobile devices quarantine automatically

Jason Kowalczyk 6 Reputation points
2021-04-07T20:35:38.903+00:00

We are performing a hybrid migration to 365 from Exchange 2013. We are still in testing phases moving test mailboxes. Whenever we move a mailbox that has a mobile device connected that device goes to quarantine. When we allow the mobile device it goes back to quarantine after briefly showing us "access granted - Pending"

In powershell we see, deviceaccessstate: Allowed - Yet in the gui it's quarantined. Currently, for testing, we have no mobile device policies that would be quarantining, i'm just looking for it to work at this point.

I'm guessing this has something to do with the Azure Security default being enabled, but i'm also unwilling to just disable them. Unless it's the only way and i can clearly define why

Currently I have a around 200 users, mostly Business Standard and Business Basic. But... i do have a couple powerusers licensed E5. So I'm not really licensed for conditional access policies, not in any widespread meaningful way.

We have a case open with Microsoft, but it's been radio silence since Friday.. leaving us stalled. If anyone has any ideas. I've attached multiple screenshots below PowerShell and Gui.

85390-ps1.png

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,350 questions
Microsoft Exchange Hybrid Management
Microsoft Exchange Hybrid Management
Microsoft Exchange: Microsoft messaging and collaboration software.Hybrid Management: Organizing, handling, directing or controlling hybrid deployments.
1,886 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,473 questions
0 comments No comments
{count} vote

2 answers

Sort by: Most helpful
  1. Andy David - MVP 141.6K Reputation points MVP
    2021-04-07T20:52:04.28+00:00

    Yea, I would say its the security Defaults which enforce MFA and block basic authentication.

    If a new profile is created on the phone or you use Outlook Mobile, does it work?

    1 person found this answer helpful.

  2. Lucas Liu-MSFT 6,161 Reputation points
    2021-04-08T06:34:47.8+00:00

    Hi @Jason Kowalczyk ,
    Yes, Azure Security default may affect mobile devices. According to similar situations in the past, as Andy said, reconfiguring the account profile is a very effective way.

    For how to set the login behavior of different versions of Offcie client apps, this official article gives detailed registry keys and their impact. Please refer to: How modern authentication works for Office 2013, Office 2016, and Office 2019 client apps

    ----------

    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.