Close Menu
    Facebook X (Twitter) Instagram
    Sunday, October 12
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»Intune»App protection policies»Intune cannot access application (MAM) You can’t get there from here. It looks like you are trying to open this resource with app that hasn’t been approved by your IT department

    Intune cannot access application (MAM) You can’t get there from here. It looks like you are trying to open this resource with app that hasn’t been approved by your IT department

    Eswar KonetiBy Eswar KonetiFebruary 10, 5:26 pm2 Mins Read App protection policies 17,943 Views
    Share
    Facebook Twitter LinkedIn Reddit

    Month ago, user reported issue that , user could not able to access Microsoft Planner application (MAM) from their mobile device. Users are able to access applications like outlook ,onedrive,Microsoft Teams,word,excel etc but not Microsoft Planner.

    Below is the error user get ,when they try to access planner from mobile device.

    You can’t get there from here . It looks like you are trying to open this resource with app that hasn't been approved y your IT department.ask them for a list of approved applications.

    image

    The above clearly says ,microsoft planner is not approved app and this message is coming from conditional access.

    I went to Microsoft Azure portal ,Azure Active Directory ,conditional access ,verified that ,the conditional access policy that is created and applied to users with client approved apps selected for iOS,android devices correctly.

    Few months ago ,Microsoft added new access control in Azure AD conditional access (replacement for App based conditional access that is in Intune app protection policies)  called ‘Require approved client app’

    image

    New App based conditional access block O365 service access to apps that are not protected by Intune SDK.This allow us to block users accessing emails from unapproved (non intune SDK ) apps like native email app or any other unapproved app to access
    We can use this to restrict access to o365 services ,exchange online and SharePoint online from these protected applications that have intune SDK. With this ,only Intune SDK enabled apps will be allowed to access.

    For more information about client approved apps ,refer https://docs.microsoft.com/en-us/azure/active-directory/active-directory-conditional-access-technical-reference#approved-client-app-requirement

    Even though we granted the access to client approved apps in in Conditional access ,user still still get the above error. After some time, identified that ,there is app-based conditional access policies set up and added users into restricted groups.

    Below is what am referring to exchange online- allowed apps  (App based conditional access policy available in Microsoft Intune). Microsoft Planner is not in the intune supported application here but is available in Azure AD CA.

    image

    After removing the user group from this Exchange online restricted user groups,users are able to access Microsoft Planner.

    Access control ‘Require approved client app’ in Azure AD conditional access is replacement for Intune app based conditional access and you no longer need to use App based CA.

    Conclusion:

    Remove the restricted users groups that is configured in app-based conditional access in intune app protection blade to fix the issue.

    CA conditional access exchange online intune Intune conditional access mirosoft planner require approve client app you can't get there from here
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    Export Microsoft Entra ID User Authentication Methods to CSV using PowerShell & Microsoft Graph API

    August 13, 2:08 pm

    Automating Intune Deployment Rings Using Entra ID Dynamic Groups and Regex

    July 01, 10:31 pm

    Exporting Intune Win32 Apps with All Properties Using PowerShell and Microsoft Graph

    June 30, 7:01 pm

    2 Comments

    1. Ambarish on August 16, 2018 10:14 PM

      Hello

      I have similar issues, but couldnt figure out the option to exclude. Could you please advice on which option exactly on the new intune azure portal?

      Thank you

      Reply
      • Eswar Koneti on August 22, 2018 11:12 PM

        it is given in the document on how to fix:

        exchange online- allowed apps (App based conditional access policy available in Microsoft Intune). Microsoft Planner is not in the intune supported application here but is available in Azure AD CA.

        Thanks,
        Eswar

        Reply

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.