how to redirect user to sign into Company portal app in IOS device when user clicks Outlook

Louie, Andy (TIS) 1 Reputation point
2021-10-28T21:16:28.923+00:00

I am using the enrollment profile Setup Assistant with modern authentication. It works but the user has to manually open up the Company Portal app and sign in to make the device compliant. With this enrollment policy it doesn't force the user to sign in to company portal. I want to make it where if the user clicks on the Outlook app, Company portal opens up first and force the user to sign in then it opens the Outlook app.
I am looking at App based Conditional access. I am at the part of Cloud apps or action and in select the app. Do I select Office 365 Exchange?
In the Conditions in Device Platform I selected IOS and Client apps I selected Browser and Mobile apps and Desktop
What do I select for Access Control and Sessions

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,725 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,252 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Crystal-MSFT 43,126 Reputation points Microsoft Vendor
    2021-10-29T03:22:43.843+00:00

    @Louie, Andy (TIS) , Thanks for the reply. For app-based Conditional Access, it will redirect to broken app. For iOS it is Microsoft Authenticator. Here is a link for the reference:
    https://learn.microsoft.com/en-us/mem/intune/protect/app-based-conditional-access-intune

    If we want to try, for the cloud app for email access, I think it can be "office 365" or "Exchange Online".
    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-cloud-apps
    For the Grant field, we can configure "Require approved client app" and "Require app protection policy".
    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-grant

    Thanks for the understanding and have a nice day!


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Louie, Andy (TIS) 1 Reputation point
    2021-10-29T03:42:52.117+00:00

    Hello based on this article here it says
    https://techcommunity.microsoft.com/t5/intune-customer-success/setup-assistant-with-modern-authentication-for-ade-intune-public/ba-p/2279061

    Company Portal Redirection
    A new improvement we’ve made to our onboarding experience helps guide users to complete that second Azure AD authentication by automatically redirecting to the iOS/iPadOS Company Portal when the user attempts to access corporate data.

    If users open any managed iOS/iPadOS applications that are protected by Conditional Access and they haven't completed the additional Azure AD sign in to the iOS/iPadOS Company Portal, they will be redirected to the Company Portal from those other apps as part of this new change. This way, users are guided to complete that last step before they can access resources protected by Conditional Access.
    But the article doesn't give me the instructions how to do this?


  3. Louie, Andy (TIS) 1 Reputation point
    2021-11-04T18:12:28.893+00:00

    Hello I created the Conditional Access Policy
    for the Cloud app I choose Office 365.
    For Conditions I choose in Device Platform I choose IOS. But in the section Client apps in Conditions what do I choose for Modern authentication clients the only choices I have are Browser, Mobile apps and Desktop clients, another section Legacy authentication clients-which is exchange ActiveSync clients, other clients.
    146606-screen-shot-2021-11-04-at-110643-am.png

    As a test I clicked on Mobile apps in the Modern authetication clients section and open up Outlook, it didn't direct my to company portal to sign in it redirected me to download the authenicator app from Microsoft. Since this is a managed device in I thought I wouldn't the Microsoft Authenicator app.


  4. Louie, Andy (TIS) 1 Reputation point
    2021-11-05T05:53:07.757+00:00

    yes for my testing this is a ADE device that I factory wiped and enrolled it using Enrollment profile Setup assistant with Modern authenication, this is a managed device. I didn't make any App protection policy just FYI.


  5. Louie, Andy (TIS) 1 Reputation point
    2021-11-08T22:09:20.157+00:00

    Hello I opened up the Outlook app, and this Outlook is a managed application. I already have a conditional access including in this screen shot that blocks the user from using the Native Apple E-mail account and forces the user to open up Outlook. I clicked on Outlook and it doesn't do the redirection. During the Setup Assistant I did login to with my test e-mail account to authenicate, but after that when I click on Outlook it doesn't do the re-direction.147449-out2.jpg147340-out1.jpg