snagrat Posted August 16, 2021 Posted August 16, 2021 Due to enable MFA for Office 365 using Conditional Access. Currently users will be accessing email via a number of desktop or phone apps. I wondered how these will behave when MFA is forced on?
Roberto Posted August 16, 2021 Posted August 16, 2021 That rather depends on what, exactly, you’ve set in conditional access. But in broad terms, if they are required to have a valid MFA token to log in via that app then they will have to register for MFA and then complete the MFA challenge the next time their credentials are checked.
snagrat Posted August 16, 2021 Author Posted August 16, 2021 Initially we are enforcing MFA for all cloud apps, with no Trusted IPs. I may have to experiment but do not have access to all types of hardware. Just wondered for example how iOS Mail app would behave when we enable MFA. Does the account need removing and re-adding or does it just give a password prompt with MFA follow up?
Roberto Posted August 16, 2021 Posted August 16, 2021 Initially we are enforcing MFA for all cloud apps, with no Trusted IPs. I may have to experiment but do not have access to all types of hardware. Just wondered for example how iOS Mail app would behave when we enable MFA. Does the account need removing and re-adding or does it just give a password prompt with MFA follow up? Again, this depends on the specifics of your conditional access policies as to when and if they get challenged at all, but your users will just be asked to complete a MFA challenge (and also may have to sign in generally again). I’m assuming that as you’ve not mentioned it, you have not blocked apps at all, just required MFA.
thimon Posted August 16, 2021 Posted August 16, 2021 Email accounts may need to be deleted and re added to the iOS Mail App if they were originally added using legacy authentication. The iOS mail app will either show an error message at the bottom of the screen or a pop up will appear when MFA is required. Clicking on the error message will take you to the Settings mail app screen for that account, asking you to re enter the account password, which should open up the MFA App. If you get a pop up it should do something similar or take you straight to the MFA App. Either way, after you have authenticated, when you go back to the Mail App the account should then be authenticated.
Roberto Posted August 16, 2021 Posted August 16, 2021 Email accounts may need to be deleted and re added to the iOS Mail App if they were originally added using legacy authentication. That’s true, if the OP has actually blocked legacy authentication. Merely enabling MFA with the kind of rules an (with all due respect to the OP, based on their post and answers) inexperienced admin has set up won’t do that. 1
free780 Posted August 17, 2021 Posted August 17, 2021 Yep be aware on iOS if you allow the built in apps like Mail. Mail supports OAUTH but calendar uses Exchange Active Sync which is only single factor. Also older versions of iOS can use Exchange Active Sync. Ideally you want users to use the Outlook app as MAM can be used.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now