Microsoft has announced a change in Intune mobile application management (MAM) for iOS/iPadOS userless devices, where automatic configuration of app values will simplify the admin experience. However, users may face blocking issues if configurations are incorrect, particularly affecting core apps like Teams and Outlook. Microsoft is working on a fix.2. *:

Understanding the Intune MAM User Block Issue
Microsoft recently highlighted an important support tip regarding Intune Mobile Application Management (MAM) for iOS/iPadOS userless devices. This issue could potentially affect users, so it’s essential to stay informed.
What’s New?
As of the September 2024 service release, Microsoft has streamlined the configuration process for Intune MAM. Previously, administrators needed to manually set values like IntuneMAMUPN, IntuneMAMOID, and IntuneMAMDeviceID. Now, these values are automatically sent to managed applications on enrolled iOS devices.
“We’ve begun to automatically send these values to managed applications on Intune enrolled iOS devices.”
This change applies to popular apps such as Microsoft Excel, Outlook, PowerPoint, Teams, and Word. Microsoft plans to expand this feature to more managed applications soon.
Major Updates
Despite these improvements, a specific issue has arisen. Users may encounter a “Misconfiguration Alert” when trying to log in to certain applications. This alert occurs if the app protection policy is enforced for a user on a device that is “Enrolled without User Affinity.”
“Your organization’s support team wants you to login with this account. But you tried to login with [email protected].”
As of now, there is no workaround for this problem. Microsoft is actively working to resolve it, but users should be aware of the potential for disruption, especially with core applications like Teams and Outlook.
What’s Important to Know?
For administrators, it’s crucial to ensure that app protection policies are correctly applied. If user-targeted policies are set for “unmanaged” devices, users will transition to a “no policy” state. Consequently, app protection policies won’t be enforced.
Additionally, the APPOpen-in management data transfer settings will now correctly apply to Intune MAM users. Review your organization’s MDM data sharing settings to ensure compliance and functionality.
In summary, while Microsoft has made significant strides in simplifying Intune MAM management, users should remain vigilant about potential issues. Stay tuned for further updates from the Intune support team as they work to resolve these challenges.
From the Intune Customer Success articles