question

AlexanderHenket-6641 avatar image
3 Votes"
AlexanderHenket-6641 asked tech-0880 published

iOS 14 + Mail/Calendar + Multi Factor Authentication fails

As of iOS 14 I am unable to use Mail/Calendar for our Office365 business account because iOS Settings fails for Multi Factor Authentication (MFA).

All Microsoft apps work fine on MFA, so I temporarily fell back to Microsoft Outlook.app on iOS. Also using mobile Safari I can go to outlook.com no problem.

When I use iOS Settings > Mail > Accounts however the procedure takes me to microsoftonline.com which redirects into the regular company site, which redirects into microsoftonline.com to show me the attached screen. [would love to upload picture but upload feature is broken here] -- The 'error' says "Administrator approval required for Apple Internet Accounts"

I noticed that iOS beta 6 fixed something in OAuth/Exchange, but for me that did not solve the issue. Anyone else experiencing this?

Removal and recreation of account in Microsoft Authenticator did not help. My sysops initially told me that the problem is in an incompatibility between Apple Internet Accounts OAuth behavior under iOS 14 and Microsoft Intune. With the final release of iOS 14 around the corner it sounds important to have that fixed at either end.

mem-intune-enrollment
· 7
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Seems like a wide spread issue as I am seeing it at my company as well. We actually opened up a case with Apple instead of Microsoft but I am sure we will loop in MS at some point. Seems like some users are able to turn off Cross track and the other security settings in Settings > Safari and then sign in again. While others are reporting they needed to delete their account and try to add it back in multiple times in order for it to work. Someone at Apple said: One thing to be on the lookout for: iOS and iPadOS use randomized MAC addresses for privacy now. Can disable manually in Settings on a per network basis or via MDM. So if your network expects certain MAC addresses you may have trouble.

Just thought I’d share. Good luck!

2 Votes 2 ·

If I saw this earlier I would not of upgraded. Public release and now no access to Corp email

1 Vote 1 ·

What was the fix for this ? I have an end user with IOS 14.1

0 Votes 0 ·

Managed to fix it by adding the admin consent in AAD (https://docs.microsoft.com/answers/answers/104889/view.html gave the hint)

The name somehow changed from 'iOS Accounts' to 'Apple Internet Accounts' afterwards and users on iOS 14 are now able to connect.

0 Votes 0 ·

In my tenant, I can see "iOS Accounts" but not "Apple Internet Accounts". Guess why? Admin consent to "iOS Accounts" is not enabling users to configure iOS apps like mail and calendar. They are getting the message "Unable to verify account information".
Even generating app passwords, they still get the same message.

0 Votes 0 ·
tech-0880 avatar image tech-0880 NicolasAverseng-3589 ·

THANK YOU!! This worked for me as well.

0 Votes 0 ·

I'm not sure which step (or both) made it work but here is what I did and now iPad is able to add an account and receive email when it previously didn't. iPad is iOS 14.2.

First step:
1. Sign into Azure AD as an admin, navigate to Enterprise Applications and click on iOS Accounts.
2. In iOS Accounts Overview, click Permissions (in the Security section).
3. Click "Grant admin consent for <company name>".

Second step:
1. On iPad, install either Chrome or Edge.
2. Make Chrome/Edge the default browser.
A. Open Settings on your iPad
B. Swipe down to find the third-party browser you’d like to set as the default.
C. Choose Default Browser App.
D. Tap either Chrome/Edge.
E. Do not restart device.
3. Go to iPad Mail app and add account. This time the Auth request will open Chrome/Edge where the authentication is allowed to complete.
4. Change default browser back to desired default.




0 Votes 0 ·
BudgetScience2000-5554 avatar image
0 Votes"
BudgetScience2000-5554 answered tech-0880 commented

I had multiple users affected by this, all after the iOS 14 update. We use MFA and require consent for Azure apps to access company data, which are both definitely a good idea.

Eventually I got a device running iOS 14 and added my account to the Mail app. I'm the admin for our Microsoft 365 tenancy. After doing this I noticed the Apple-related Azure enterprise application had been updated: its name changed from 'iOS Accounts' to 'Apple Internet Accounts', and it picked up an additional permission. This seems to have fixed the problem.

Here's a screen shot of how it looks now in the Azure admin center, under Enterprise applications > Apple Internet Accounts > Permissions.

27382-screen-shot-2020-09-23-at-112925-am.png




· 12
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Hey, so the action you had to take was to log in with your admin account, and that's it?

0 Votes 0 ·

Did that bring up a consent screen that you had to accept?

0 Votes 0 ·

I can't remember if there was a separate consent screen or not, but yes, that was all I had to do. I did have to approve the login via the Authenticator app like usual.

0 Votes 0 ·

We have "iOS Accounts" already with the admin consent and registered as an enterprise application in Azure with these same permissions and yet we see the mails not syncing in the native mail app.

0 Votes 0 ·

Yes, it's all a bit mysterious to me how this worked. If it helps, here's the audit log from when the Azure application got updated. You can see the name and permission changes.

27661-screen-shot-2020-09-23-at-15612-pm.png


0 Votes 0 ·

Did you have "iOS Accounts" registered as an Enterprise Application in Azure before or was it done on 23rd September 2020? If you go to "Enterprise Applications" in your Azure tenant, do you still see search result for "iOS Accounts" or has it been changed to "Apple Internet Accounts" now?

0 Votes 0 ·
Show more comments

In my tenant, I can see "iOS Accounts" but not "Apple Internet Accounts". Guess why? Admin consent to "iOS Accounts" is not enabling users to configure iOS apps like mail and calendar. They are getting the message "Unable to verify account information".

0 Votes 0 ·

THANK YOU!! This worked for me as well.

0 Votes 0 ·
JeremyLawson-8490 avatar image
0 Votes"
JeremyLawson-8490 answered EddieQurious-8524 commented

My fix / workaround to this was to avoid MFA by using an "App Password" - those single-use passwords you can generate to support apps which don't handle MFA well.

You can create one on your account page:
https://mysignins.microsoft.com/security-info

Then when you're adding an Exchange account in iOS, enter your email & name and it takes you to a website. Cancel that, and it lets you enter a password directly - enter your new App Password into here.

(I tried this, because stuff suggested elsewhere like deleting/re-adding, using another browser, trying other sign-in methods, none of that worked for me. And I don't think my azure admin will be ok with just authorizing new apps willy nilly)

· 5
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Does not works for me :(

0 Votes 0 ·

you can avoid it all you want with an app password but next year (was supposed to be now) Microsofti s going to disable legacy authentication which is what your app password is, then your email is going to stop working again.

1 Vote 1 ·

Exactly, all this mess can be avoided by switching to basic auth but that's not the way forward! Microsoft pushing for Oauth and it not working seamlessly in the backend is frustrating for all. When Microsoft makes it mandatory with this half-cooked stuff at the backend, it will be chaos worldwide!

0 Votes 0 ·

Even with app password it does not works.
We have a wildcard certificate - also read it could be also because of that!
Changing back to basic auth is not an option for me.
A mess!!

0 Votes 0 ·

This actually worked!!!

When creating the app password, be sure to record the password before hitting the done button.

I followed the directions exactly. This is great!

I will spread the word.

0 Votes 0 ·
SaboEric-4606 avatar image
0 Votes"
SaboEric-4606 answered LeviJay-4660 commented

Does anyone know if IOS 14.1 will resolve this issue - the release notes doesn't really say it address anything with the built in mail app.

· 4
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

It did not for me

0 Votes 0 ·

14.2.1 still did not resolve this.

Here's hoping 14.3 does.

1 Vote 1 ·

Still not fixed..

Here's hoping 14.4 does!

0 Votes 0 ·
Brownmattc avatar image
0 Votes"
Brownmattc answered

As of yesterday 20% of my iPhone users are having this issue. The Password Incorrect box keeps popping up and the password does not work. Their accounts do not lock which means they are not entering an incorrect password.

Configuration:
- Office 365 and Intune.
- iOS profile is pushed out via an Intune policy. Uses outlook.office365.com as the email server. OAuth disabled.
- No MDM.
- Outlook app works, native iOS app does not work.

This thread has a lot of talk about an Azure Active Directory Enterprise Application. We do not have any Enterprise Apps related to iOS. The only Apple related app we have is Apple Business Manager.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndyGriggs-0987 avatar image
0 Votes"
AndyGriggs-0987 answered

We have managed to work around this issue on a number of devices by running the following procedure. It handles issues caused by two IOS bugs. The whole thing can be done from the user's webmail and ios device. I have provided these in case end-users without access to the EAC or Endpoint Manager console stumble upon this post.

IOS bugs: An old EAS account is not deleted properly and a security issue in Safari causing problems with OAuth.

This fix includes a tip from @BrianDavis-2755 that worked with the Safari issue affecting the mail app we were experiencing on some devices.

Procedure 1 – Start Here
1. Unenroll the device and check the management profile has been removed (Settings | General |Device Management)
2. Check mail accounts and check that the EAS account has been deleted. If it is still there, attempt to delete it manually. Regardless of whether the account could be deleted, continue steps.
3. Enrol the device as normal
4. Give a little time and check to see if device can sync mail, calendar, etc
5. If ok, GREAT, it was an old EAS account causing the problem and deleting it fixed the issue
6. If not ok, follow Procedure 2

Procedure 2 -Account could not be deleted AND/OR the device still can’t Sync
1. The device should still be enrolled.
2. Install MS Edge app on the device and set it as the default browser (Settings, scroll down to Edge and select, change default browser app from Safari to Edge)
3. Restart phone - test
4. If still not syncing, open Webmail (https://outlook.office.com/) on the user’s PC.
5. Click the Settings cog at the top right
6. At the bottom of the list, select View all Outlook settings.
7. Select General and Mobile Devices
8. Select device having issues (probably Quarantined)
9. Select the Wipe icon
10. IMPORTANT: Select "Wipe only data related to this account". Do NOT select Wipe all data as that will delete all personal data.
11. User should get an email in Outlook saying data is wiped. Once received, from the same Mobile Device screen in Webmail, select the trashcan option the for device to delete it
12. Once deleted, Open Company Portal
13. Select the Device and touch Check Status
14. Within a minute or so the user may be prompted on their device to enter the password for the Exchange account. Enter it and follow instructions if prompted to install certificates.
15. If not prompted, on the device go to Settings | Mail |Accounts |<EAS Account> | Tap Re-enter password.
16. Hopefully fixed.

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.