Managing Android devices using Microsoft Intune
Outlook on Android is enforcing security requirements that are defined on the mail server for the work mailbox. When those policies require device-level controls (such as encryption, strong screen lock, or the ability to wipe data), Outlook will prompt to enable device administration or similar management on the phone.
Key points from the documented behavior:
- Security requirements come from the email administrator
- The message and enforcement are triggered because the mailbox is subject to security policies set by the email administrator, not by Outlook itself.
- The documentation states that the device must be compliant with security requirements set by the email administrator; Outlook/Mail/Calendar apps simply apply or enforce those policies.
- Typical requirements that cause these prompts
For mobile devices, the policies can include actions such as:
- Encrypting all partitions on the mobile device with encryption software.
- Rebooting and then re-syncing after encryption is enabled.
- What to do if this is a personal device and granting control is not acceptable
- Because the policies originate from the email administrator, the only way to avoid granting device-level control while still using the work mailbox on this device is for the administrator to change or relax the mailbox/device policies on the server side.
- If the organization does not want or intend to enforce such controls, the administrator must review and adjust the security policies applied to that mailbox so that Outlook no longer requires device administration or encryption.
- If the administrator will not or cannot change those policies, the only compliant options are:
- Do not add the work account to this personal device; or
- Use a different access method that the organization allows without device management (for example, if they permit browser-only access with fewer device controls).
- Why IT might say “it’s not them”
- Even if IT believes they are not enforcing device management, the behavior is driven by whatever policies are configured on the mail server for that account. Outlook is not independently deciding to require Device Administrator; it is responding to those configured policies.
In summary, the requirement to grant Device Administrator is a consequence of security policies tied to the work mailbox. To avoid giving work full device control, IT must adjust those policies, or the work account should not be configured in Outlook on this personal phone.
References: