Share via

Troubleshooting MAM-WE / App Protection Policies on personal Android devices

Alexandre Blanchette 0 Reputation points
2024-06-03T13:53:04.55+00:00

We're trying to deploy App Protection Policies / MAM on the personal devices of our employees and we're having a problem on many devices. Once the policy is enforced by a conditional access rule, the targeted apps on the device (tried it with Teams and Outlook) flashes "Confirming app status" many times and it ends up with an error message.

If I delete the corporate account from outlook and try to add it back, I see Confirming app status again and it ends up with "Unable to log-in" "This Account can't be added because Outlook isn't configured correctly".

The conditional launch section of the policy looks like this:

Setting Value Action
Max PIN attemps 10 Reset PIN
Offline grace period 720 Block access (minutes)
Offline grace period 7 Wipe data (days)
Disabled account Wipe data
Jailbroken / rooted devices Block access
Min OS version 12.0 Warn
Min OS version 11.0 Block access
Min OS version 10.0 Wipe data

If I remove all the Min OS version clauses and the Disabled account clause, adding the corporate account to Outlook works again, but the policy doesn't seem to be applied: the device is not asking to setup a PIN, is not forcing the links to be opened with Edge, and is not limiting the amount of data that can be copy-pasted.

One of the device I'm trying to debug is a Google Pixel 7 running Android 14, and I have no reason to beleive it's jailbroken/rooted. Company portal is installed on the device, but the device is not enrolled.

What are the next steps to troubleshoot this? Where can I get some logs to see what's wrong?

Microsoft Security | Intune | Microsoft Intune Android
Microsoft Security | Intune | Application management
0 comments No comments

4 answers

Sort by: Most helpful
  1. Shorty 0 Reputation points
    2025-09-16T14:04:32.15+00:00

    Same here. On a complete blank pixel device with only Outlook and Teams installed we are getting / having exactly the same error message / behavior.

    Was this answer helpful?

    0 comments No comments

  2. Jeffrey 96 Reputation points
    2025-09-02T08:45:10.5133333+00:00

    @Alexandre Blanchette

    i also have the same issue. do you manage to find the fix without needing to remove min os version and disabled account in conditional launch?

    Was this answer helpful?

    0 comments No comments

  3. Alexandre Blanchette 0 Reputation points
    2024-06-05T13:06:37.0766667+00:00

    The vast majority of the devices have only those two apps, this is what I tested. I confirm Outlook, Teams, Company Portal and the OS are up to date.

    Was this answer helpful?

    0 comments No comments

  4. Rahul Jindal 11,631 Reputation points
    2024-06-03T21:28:41.5333333+00:00

    Is the issue only with Outlook, Teams? Can you confirm if the Office apps, Company Portal and OS security patches are up to date?

    Was this answer helpful?


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.