Forum Discussion
Outlook for mobile doesn't via APM doesn't work with Modern Authenication
Hello
I configured Modern Authentication for Microsoft Exchange Server, which is published via F5 APM. We applied an APM policy for OWA to enforce MFA. To streamline authentication, we bypassed Autodiscover and ActiveSync from APM, directing traffic to the Exchange pool for Modern Authentication. While Outlook for desktop and native mail clients on iOS and Android worked seamlessly with Modern Authentication, Outlook for mobile continued to redirect to Basic Authentication. Interestingly, when APM is disabled, Outlook for mobile functions correctly with Modern Authentication. We've attempted to disable APM through iRules, but so far, none of our efforts have resolved the issue. Has anyone encountered a similar problem and found a solution?
Thanks.
- JmtaylorModerator
Can you tell us what version of the APM you are using and what MFA solution?
- MajedAltocumulus
the version of APM is 15.1.8. I want to apply Microsoft Azure MFA.
- BellaAbzug1Nimbostratus
Outlook for mobile may experience issues when attempting to connect via Adaptive Privilege Management (APM) with Modern Authentication enabled. This problem often stems from misconfigurations in the APM settings or the mobile device’s authentication requirements. If the APM does not properly support Modern Authentication, users might be unable to authenticate successfully, leading to connectivity issues. To resolve this, ensure that the APM policies are configured to accommodate Modern Authentication protocols and verify that the mobile devices are updated and properly set up for access. Reviewing logs can also provide insights into any specific authentication errors encountered.
- MajedAltocumulus
Modern Authentication works fine except for Outlook for mobile. Even the Outlook for Mobile uses Autodiscover to detect the configuration and APM is disabled for Autodiscover, other apps used Autodiscover are working except Outlook for Mobile. I think there is specific iRule for Outlook for mobile to detect the connection and bypass to exchange pool.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com