Conditional Access - MaM-WE - Users without Intune license can access corporate emails

David 211 Reputation points
2021-10-26T13:21:16.547+00:00

Hi everyone,

I am getting a bit confused about Conditional Access in the context of Intune MaM Without Enrollment.
Our employees use their own mobile phones (BYOD). Once users are assigned to a group that is targeted by the Intune license (E5), they are (after a while)
blocked from accessing emails with other apps than Outlook mobile, which is fine.

However, users not having an Intune license/not being part of this group for this purpose, can still access corporate emails via other apps.

How can I prevent access to corporate emails with other apps by default? Meaning that employees will only access them when they are "compliant" with Intune MaM-WE.
This could lead to a scenario where an employee not in being in the group (by mistake) use another email mobile app without us knowing and not benefit from our policies.

Any help with this?

Thank you very much.

Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,298 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,381 questions
0 comments No comments
{count} votes

Accepted answer
  1. David 211 Reputation points
    2021-11-01T15:01:04.97+00:00

    Hi LuDaiMSFT, thank you very much for your help.

    I fixed my issue last week by:

    • creating a first policy to block all cloud apps (exclusion set on 365 apps only)
    • creating a second policy to require MFA and app protection

    All working now.

    Thank you very much


2 additional answers

Sort by: Most helpful
  1. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-10-26T15:52:36.507+00:00

    Without knowing your full config, not much can truly be said here other than the issue is not Intune licensing as CA is not even a feature of Intune, it's a feature of AAD. I suspect that you are creating your rules backwards where you are allowing by default but should instead be blocking by default but as noted, with in depth or hand on analysis of your rules, that's just a guess and nothing more can be said.

    0 comments No comments

  2. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-10-26T16:05:47.463+00:00

    CA is also not designed to be app specific either as CA is a gate on authentication to AAD.

    But, as noted, without seeing the entire configuration I can only guess as to how you have things misconfigured, but it is probably a combination of what I noted above (allowing implicitly instead of blocking implicitly) and using the approved clients apps setting (which we generally discourage).