Managing iOS devices using Microsoft Intune
This was happening for us as well. You need to have Microsoft Authenticator on the device and follow the fix from this link. Scroll down to "Create a single sign-on app extension configuration policy".
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
I have a user who has enrolled his new iPad into Intune. The device shows as enrolled and compliant on both his end and the admin side. He is able to sign into the Outlook mobile app. However, he is not able to add his mail account using the Apple mail client. When he tries to add an account, he gets a message telling him to enroll his device, and if he selects "Continue", he is taken to the Company Portal app, but nothing happens at that point. We have already unenrolled and re-enrolled the device, and we have factory reset the iPad. We do not have any restrictions on using the Apple mail client, and other users are able to use it without issue.
Managing iOS devices using Microsoft Intune
This was happening for us as well. You need to have Microsoft Authenticator on the device and follow the fix from this link. Scroll down to "Create a single sign-on app extension configuration policy".
The behavior indicates that Intune/Company Portal is intercepting the native iOS mail profile setup and enforcing enrollment/compliance, but the flow is stuck in a loop instead of completing. From the provided information, there are two common Intune-side causes to check and remediate:
Action:
This behavior is documented for iOS/iPadOS: Intune detects an existing duplicate email profile based on hostname and email address, and the user-created profile blocks the Intune-created profile. The Company Portal may state that the user is not compliant and prompt for changes until the user-created profile is removed.
Actions:
https://portal.manage.microsoft.com and sign in with the user’s work account to confirm credentials and device visibility.If the Company Portal was corrupted or out of date, this reinstall and re-enrollment typically clears the “enroll your device” loop.
Once duplicate mail profiles are removed and the Company Portal app is healthy and the device is within the allowed device limit, the user should be able to either:
References: