If you want to enroll for Azure MFA the users need to go through these steps. When you enforce or enable MFA the user will be prompted for MFA enrollment. This is best done in a browser.
Note on these settings, I have 3 users in the CA Exchange Online Mobile group. Rest of my users are in the NO CA group and that group is set to Except. I do this to ensure that nothing is enforced globally to all users. The 3 users in the first group have not had Azure MFA Enabled or Enforced but is set to Disabled.
You do not have to enable MFA globaly for this to work
I always add an Except group with the remaining users.
This is what the user will see now.
He will see the normal login but be required to enter a second factor. If he navigates to outlook og Onedrive there will be no such requirement.
You share a Azure RMS protected document with one user lg@haukeberg.com. If you now remove that user and add Samsung@haukeberg.com
-> What happens?
NOTHING.
Each share on the file creates a new instance in Azure RMS, hence if you want to remove user lg@haukeberg.com access you need to revoke access to the document completly.
Note: once you revoke access to a document, all the users will loose access.
Hence if the user lg@haukeberg.com quits and you revoke access to a document which also Samsung@haukberg.com has access to then both loose access.
What will the user see if he puts a Azure RMS protected file on SharePoint online?
Setup:
Azure RMS account and document owner: hsh@haukeberg.com
SharePoint Online accont: hhauk@microsoft.com
Document shared with hhauk@microsoft.com read only
Do not worry about language (you can get this software in your language)
Here is what happens:
In a sharepoint siteIRM (Azure RMS) disclamer. So NO Office webappsNormal open promptChecking for RMS client (you must have this)If you are not logged in, you need to do soModern loginMFA gateway for accessYour current access credentialsIf yo do not have access then the owner will get this mail.
This is how you both join Azure AD and enroll for MDM. Your admin need to have configured Automatic MDM enrollment into intune over at http://manage.windowsazure.com for this to work.
Disclamer from WindowsNote how my icon and text have been pulled Down from Office 365Azure MFA gatewayCustomizable Policy template for Your org
If you enable conditional Access in Intune then Your devices will have to be enrolled with Intune in order to read mail. If they are not enrolled or otherwise compliant they will be blocked.
-You can relax these demands as you see fit, but that would kinda defeat its purpose.
This is how Outlook behaves
Add Your account as usualModern Auth PromptConditional Access checkpoint
This user will not be allowed to Complete the mail setup.
Note that you have to enable ADAL on Exchange Online and use Outlook 2013-2016 With ADAL in order for this to work. Click here to se how to set up Exchange Online with ADAL
How to enroll Your Windows 10 Machine in Intune to get back mail?
If you have Outlook 2016 or Outlook 2013 and want to use Azure MFA but you do not want to use Application Passwords there are one thing you need to do.
You must be logged in to post a comment.