Edit

Share via


Intune-licensed users are prompted for enrollment when they try to access Microsoft 365 resources

This article discusses a by design behavior that users are unexpectedly prompted to enroll in Microsoft Intune when they try to access Microsoft 365 resources and are targeted by Basic Mobility and Security for Microsoft 365 security policies.

Symptoms

Consider the following scenario:

In this scenario, users are unexpectedly prompted to enroll in Intune when they try to access Microsoft 365 resources.

Cause

This behavior is by design.

This behavior occurs if Basic Mobility and Security security policies are still deployed to a group that contains the affected users. When users are targeted by Basic Mobility and Security security policies, Conditional Access will be evaluated by Microsoft Entra authentication services. These services check a user's group membership. Microsoft Entra authentication services don't check the user authority (Intune instead of Microsoft 365) when they enforce Conditional Access.

Solution

To change this behavior, remove the affected users from any groups that are still assigned a Basic Mobility and Security security policy. Or, remove the Basic Mobility and Security security policy if it's no longer needed.