Skip to content
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile

Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile

Written By Anoop C Nair
Last Updated October 9, 2025
Posted In Intune
SHARE

Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile. Microsoft Intune is commonly used by organizations to protect corporate data on employee-owned Android devices by applying strict application protection and data transfer policies.

These policies help you to control how apps within the Work Profile communicate with each other and often restrict any form of data exchange with non-approved or unmanaged applications. These policies help maintain compliance and prevent accidental data leakage, but they can also interfere with legitimate workflows that depend on inter-app communication.

In this scenario, the user installs the MatterMost application within the Android Work Profile and is attempting to authenticate using the organization’s Single Sign-On (SSO) provider. Instead of handling the login directly, MatterMost delegates the authentication process to Microsoft Edge, which is recognized as a trusted browser under Intune policy.

Edge opens the SSO login page, the user enters valid credentials, and the identity provider successfully verifies the session. Normally, at this point, the authentication flow would return control back to MatterMost using a custom URI callback such as mmauth://callback?MMAUTHTOKEN=&MMCSRF=, allowing the app to complete the login process.

Patch My PC
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile - Fig.1
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile – Fig.1

Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile

Due to the restrictive Intune App Protection Policies, Edge is not permitted to pass the callback URL back to MatterMost. MatterMost is not classified as a fully managed or approved app under the policy configuration. Intune treats the incoming callback as an attempt to transfer potentially sensitive data to an untrusted destination.

  • As a result, Edge displays a message stating that no allowed apps are available to open the content, effectively blocking the final step of the SSO.
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile - Fig.2
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile – Fig.2

Workaround for the Issue

When Intune blocks deep-link callbacks from Microsoft Edge to MatterMost, users cannot complete SSO authentication within the Work Profile. To address this without reducing overall security, administrators can configure targeted exceptions.

WorkaroundDetails
Add MatterMost to Managed AppsSet MatterMost as a trusted application within Intune, allowing controlled data transfer from Edge.
Configure Data Transfer ExemptionsIn the App Protection Policy, adjust Data Transfer Settings to allow specific URI schemes like mmauth://.
Whitelist Callback URIEnsure only the required deep link is permitted, preventing broader data transfer between apps.
Test Authentication FlowVerify that the SSO login now completes successfully without triggering “No available apps” errors.
Maintain Policy ComplianceConfirm that all other app restrictions remain enforced to protect corporate data.
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile – Table 1
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile - Fig.3
Intune Policies Blocking Edge Browser Callback during SSO Authentication on Android Work Profile – Fig.3

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read