Anyone out there using O365 & Multi-Factor Auth (MFA) with the iOS Mail.app for Exchange email?
I am getting ready to enable/require MFA for O365. I'm having issues getting MFA to work on iOS devices that are managed with a Exchange MDM profile.
Example:
Currently, if I deploy a Meraki Exchange Profile to an iOS 11 device, users who has been set up for MFA in O365 never get prompted for MFA (other than filling out his/her password string). Therefore, users won't receive email because the Apple Mail.app is not trusted.
However, if that same user manually creates his/her Exchange O365 account in Mail.app, he/she will get challenged via MFA to complete the app trust as expected.
My environment:
-All iOS devices are running iOS 11.
-All iOS devices are managed in Cisco's Meraki MDM (migrating to Jamf...eventually).
-Our devices are not Supervised.
-We use Apple's iOS Mail.app (not the MS Outlook app).
-Users can choose to use SMS or the MS Authenticator app for MFA.
-IT director does not want to use App Passwords (too messy and complicated), so we must use OAuth.
-My MDM profile provisions devices with the user's name, email address, server information, and password criteria.
Does anyone have any suggestions on how to manage iOS Exchange accounts in MDM and enable O365 MFA?
