Not removing Outlook account from iOS device after retiring device from Endpoint Portal

2021-12-30T09:29:52.787+00:00

Hello,

When we are retiring a iOS enrolled device ( BYOD MDM) from Endpoint portal, we have observed the below behavior.

Please confirm below is the expected behavior or how to resolve it ?

  1. After retiring a iOS device from Endpoint portal, device Intune configuration and MDM profile was removed device. But users still able to see new and old emails from Outlook and it worked the same at least for 24 hours.
  2. After more than 24 hours, we have observed users got prompt "Data Removal" on Outlook app but when user is getting any new email for that account still able to get notification and when he click on email notification it routes on Outlook app but he didn't seen the new email.
  3. Is it possible that after retiring device the outlook and other O365 apps configuration must be removed from device and users should not get any new email notification and users should not be able to view old and new emails ?

Regards,
Surendra

Outlook Management
Outlook Management
Outlook: A family of Microsoft email and calendar products.Management: The act or process of organizing, handling, directing or controlling something.
4,887 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
874 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,248 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Timmy Andersson 411 Reputation points MVP
    2021-12-30T11:06:28.657+00:00

    The best approach in my opinion here would be to use Conditional Access and create a policy that requires devices to be marked as compliant when accessing email.
    This would block the user from accessing their email account if the device is not enrolled and compliant.

    https://learn.microsoft.com/en-us/mem/intune/protect/create-conditional-access-intune


  2. Lu Dai-MSFT 28,346 Reputation points
    2021-12-31T03:32:45.453+00:00

    @Surendrasingh Chaupawat (APMEA - iCORE-CIS) Thanks for posting in our Q&A.

    For remove outlook account, it shows that retire action will remove mail accounts that were provisioned by Intune on windows 10 devices.

    For iOS devices, if the microsoft app is protected by intune, when we do the retire action, the next time the app is launched, it will remove the protected work or school account data. For more details, please refer to the following article:
    https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#ios
    161490-image.png

    So, based on my understanding, if you deploy an app protection policy to the work or school account and add Outlook as managed app, when you retire the iOS device, it may also remove the account on Outlook.

    Hope it will give you some ideas.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Lu Dai-MSFT 28,346 Reputation points
    2022-01-04T07:04:40.91+00:00

    @Surendrasingh Chaupawat (APMEA - iCORE-CIS) Thanks for your efforts to do some tests.

    For this issue, I have done the test as my said before. In my test, I didn't have the conditional access policy and I only deploy an app protection policy to my user group. Outlook is a managed app in the app protection policy.

    When I retire the iOS device successfully and wait for some time, I will get the message in Outlook and my account is removed from Outlook. When I try to send an email to the my account, I didn't get a new email notification.
    162095-image.png

    Hope it will help.