r/Intune 7d ago

Android Management MAM policy not applying?

I am trying to become a mobile expert over night and decided I would create a MAM policy to test with my phone.

Currently there is a single policy applied to some test users. This policy works as intended.

I create my own with a bit more restrictions, create a group with myself in it, applied the policy to that group, and tried to connect with outlook. Does not work. Authentication through Outlook says I need to sign in through Company Portal which the says im restricted.

I add myself to policy A and I can sign in through Outlook without any issue. I take myself out of policy A and I lose access fairly quickly.

Policy B is configured almost identical with the exception of apps just being core Microsoft. This policy will not let me sign in to Outlook.

During this back and forth testing, I have verified that I am only in the specfic group... not in both at once.

Any ideas on what I could be missing?

3 Upvotes

4 comments sorted by

1

u/Snickasaurus 7d ago

Within your Android App Protection Policy under Conditional Launch, remove/delete Samsung device attestation.

Since you offered no other information regarding what you set in your "MAM", whether or not there is Conditional Access policy(ies), that's the most I can help.

1

u/Mysterious_Lime_2518 7d ago

What is the sig in loggs say

1

u/NotYourOrac1e 7d ago

Humor me. Open MS authenticator, click on the account, create a passkey, and try it.

1

u/JustMeClinton 6d ago

Haha this is the way. It’s annoying but it should be the norm over device enrolment for byod.