AD password change not reflected in Intune managed devices.

Geraint Williams 21 Reputation points
2021-05-04T05:01:19.657+00:00

Hi,

I can see a similar question has been asked previously however the thread has been archived without a solution that resolves my issue.

I have inherited an Intune setup which manages numerous iOS devices and it has become apparent that when a users AD password is changed then MS Office applications stop syncing but there's no prompt for a password change. Historically what has been happening after AD password changes is that users have had to hand their iPhones over to their manager who then gives authority for the phone to be moved into an open security group whilst he/she [manager] enters the new Outlook password [or the password is entered under their supervision]. The phone is then moved back into the original security group before being handed back to the user.

This seems convoluted to me and I would have thought that I should be able to configure it so that the user can change their MS Office password without opening the phone to undue risk.

I would be grateful for any advice or thoughts on where this could be configured, is it 'Block modification of account settings'? If so, what vulnerabilities would this also present? I have a phone I can test with but I thought I would ask here before heading off in a possible wrong direction.

Thank you

Microsoft Security Microsoft Entra Microsoft Entra ID
Microsoft Security Intune Other
{count} votes

4 answers

Sort by: Most helpful
  1. Cici Wu-MSFT 1,191 Reputation points
    2021-05-04T09:21:57.137+00:00

    Basically, after the password is changed, it is the expected behavior that Outlook will continue using the old cached credentials. But after a time, Outlook will prompt you to update your password.

    How long did you wait after the password was changed?

    Is this a Windows Outlook app, or Outlook for mobile device?


  2. Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
    2021-05-04T15:49:07.977+00:00

    As a supplemental note here, Intune plays no part in authentication or password changes. This is purely AAD.


  3. Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
    2021-05-04T15:49:08.017+00:00

    As a supplemental note here, Intune plays no part in authentication or password changes. This is purely AAD.

    0 comments No comments

  4. Jason Sandys 31,406 Reputation points Microsoft Employee Moderator
    2021-05-04T15:49:08.17+00:00

    As a supplemental note here, Intune plays no part in authentication or password changes. This is purely AAD.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.