I've been facing a strange issue with new iPhone deployments at work lately. Since Monday, our users can't sign into the native mail app, which also syncs contacts and calendars. They get prompted to log in with Office 365 credentials, but it fails. In Entra, it shows that the Apple Internet Accounts application is being blocked by conditional access due to the device being non-compliant, despite it being compliant in Intune. The logs indicate that the sign-in attempt is from mobile Safari on an unmanaged device.
Interestingly, all affected phones are using the App Store version of the company portal app, which shouldn't be installed on any devices. No configurations have changed, and all tokens are up to date. It also affects multiple versions of iOS, like 26.3, 26.3.1, and iOS 18. I'm looking for anyone who has encountered this sudden issue. My temporary workaround involves removing users from conditional access, allowing them to sign in, and then putting them back—though this hasn't fully resolved the issue. Update: Putting them back in CA hasn't helped either. I've noted similar experiences with another user.
5 Answers
Check out the solutions mentioned in this thread for similar issues: [Link to Discussions]. Also, Microsoft has some guidance on setting up single sign-on that might help.
Have you tried using Mobile Outlook instead of the native Mail app? From what I've seen, it’s often a better approach for securing company emails. It also gives us better control over managing access and wiping data if needed.
Is it possible that this is related to the iCloud Private Relay feature? It sometimes complicates compliance by routing requests through a private network, impacting sign-ins. But this issue seems to be more recent.
We’re experiencing the exact same problem! Our conditional access policy blocks unknown devices too, and it shows 'Device Type Unknown' in the logs, even when the device appears to be properly enrolled.
We have similar problems sporadically, mainly in BYOD situations. It's occurred on different iOS versions, starting from the 27th. Native mail just won't connect, although everything else seems to work fine.

Related Questions
Can't Load PhpMyadmin On After Server Update
Redirect www to non-www in Apache Conf
How To Check If Your SSL Cert Is SHA 1
Windows TrackPad Gestures