Intune App Protection policy. How to block native iOS app sign-in without registration request.

Tommie van Lent 0 Reputation points
2025-03-04T15:31:35.1466667+00:00

We have configured Intune with App Protection Policies to require an app PIN for all Microsoft apps.

This works great, but when users want to add their M365 mail account to the native iOS Mail app, they are prompted to "register" their device.

When they click "register," the Company Portal app opens with no additional information.

We have blocked user enrollment, so it is working as expected.

Is there any way to block sign-in on the iOS Mail app?

Microsoft Security | Intune | Microsoft Intune iOS
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 17,165 Reputation points Microsoft External Staff
    2025-03-05T02:23:57.81+00:00

    @Tommie van Lent, Thanks for posting in Q&A.

    From your description, I know you want to block sign-in on iOS Mail app.

    Based on my research, we can create a conditional access policy to achieve this, here are steps you can refer to.

    Require approved client apps or app protection policy with mobile devices https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-policy-approved-app-or-app-protection#require-approved-client-apps-or-app-protection-policy-with-mobile-devices

    Block Exchange ActiveSync on all devices:

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-policy-approved-app-or-app-protection#block-exchange-activesync-on-all-devices

    Hope above information can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.