Microsoft Intune is a Mobile Device Management (MDM) solution. When used with iOS devices, it may conflict with Salesforce Mobile App authentication.
Customers using Microsoft Intune as their Mobile Device Management (MDM) solution for iOS devices report that their users are unable to log in to the Salesforce Mobile App or Salesforce Field Service Mobile App.
The authentication process fails because Intune's security policies are configured to require the use of the Microsoft Edge browser for all authentication flows. The Salesforce mobile apps, following Apple's platform requirements, use the native iOS web authentication service, which is based on Safari. This creates a direct policy conflict, blocking login.
This issue is not a bug in the Salesforce Mobile App. It is a fundamental incompatibility between Microsoft's Intune policy enforcement and Apple's iOS security architecture. Salesforce is positioned between these two differing vendor philosophies.
Microsoft Intune is a Mobile Device Management (MDM) solution that allows IT administrators to manage and secure corporate devices and apps. When Intune is configured to require Microsoft Edge for all authentication flows, it conflicts with Apple's iOS security model, which requires all apps to use the native ASWebAuthenticationSession API — a service tied to Safari and its underlying WebKit engine. Apple does not allow app developers to substitute a third-party browser for this secure authentication session.
A. Apple's iOS Security Model:
B. Microsoft's Intune MDM Policy:
C. Salesforce's Position: Trust is Our #1 Value
Customers have three primary paths to resolve this issue. The first two are long-term industry change requests, while the third provides immediate, actionable solutions.
Path 1: Petition Microsoft
Path 2: Petition Apple
Path 3: Create an Intune Policy Exception & Apply Compensating Controls (Recommended)
Certificate-Based Authentication (Most Secure): The MDM can provision a unique, trusted device certificate onto all managed iOS devices.
Q: Other apps on our devices work with Intune's Edge requirement. Why can't Salesforce?
Q: Is Salesforce planning to add support for Edge on iOS in a future release?
005225693

We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.