Futuristic cybersecurity scene with servers, encrypted messages, smartphones, cloud computing, and a glowing lock.
Microsoft has announced expanded Outlook client support for AD FS Modern Authentication in Exchange Server, including Outlook for iOS and Outlook for Android. For organizations that run Exchange entirely on-premises, that is a significant documentation change: Microsoft’s current deployment guidance now lists the mobile Outlook apps as supported with AD FS-based Modern Authentication.

The qualification is that this is neither a simple app update nor a universal solution for every Exchange design. Microsoft positions AD FS Modern Authentication for pure on-premises Exchange environments, while recommending Hybrid Modern Authentication (HMA) with Microsoft Entra ID for organizations running Exchange hybrid. The same current deployment article that lists mobile support also documents a configuration-specific situation in which Outlook for iOS and Android fall back to Basic authentication.

That means the announcement expands the documented client matrix, but administrators should approach it as a bounded identity, topology, and client-management project. A successful mobile sign-in alone does not establish that the client completed the intended AD FS Modern Authentication flow.

What Microsoft announced​

The Exchange Team published its expanded Outlook-client announcement on September 8, 2026. Microsoft’s current on-premises Exchange Modern Authentication guidance says that Modern Authentication through AD FS is available in Outlook for iOS and Outlook for Android. At the app level, the stated prerequisite is to install the latest available Outlook app on a mobile operating-system version currently supported by Outlook.

The addition matters primarily to organizations that have retained Exchange Server on-premises and use Active Directory Federation Services rather than a hybrid identity design. It establishes a documented route to include Microsoft’s mobile Outlook apps in an AD FS Modern Authentication deployment alongside supported desktop clients and other supported access paths.

Yet “supported” should be read carefully. The support listing says the apps can be used with AD FS Modern Authentication; it does not, on its own, guarantee that every authentication-policy combination causes every connection to use Modern Authentication.

A configuration-specific mobile caveat​

Microsoft’s current deployment article contains two statements that administrators need to consider together.

It explicitly lists Outlook for iOS and Outlook for Android as supporting Modern Authentication through AD FS. In a later client-behavior table, however, it says both apps fall back to Basic authentication in a defined scenario: Modern Authentication is enabled for the user, while Block Modern Auth is applied as the organization’s DefaultAuthenticationPolicy.

Microsoft has not reconciled this configuration-specific inconsistency in the current documentation. The prudent conclusion is neither that the announced mobile support is invalid nor that Outlook mobile will invariably complete an AD FS Modern Authentication flow under every policy design. The actual outcome must be tested against the organization’s user settings and default authentication policy.

This is more than a wording issue. A pilot should establish the authentication behavior achieved by the intended configuration, rather than merely establish that Outlook for iOS or Android reaches a mailbox. A connection that falls back to Basic authentication is materially different from the Modern Authentication outcome an organization may be seeking.

A separate, older Microsoft mobile-client page adds context but not resolution. Last updated on April 30, 2025, it says that Outlook for iOS and Android support Basic authentication and Hybrid Modern Authentication in on-premises Exchange. That page predates the September 2026 announcement. Its continued availability does not override the current AD FS deployment guidance, but it underscores why administrators should validate the precise design they intend to deploy.

Pure on-premises Exchange versus hybrid​

Microsoft draws a firm architectural boundary. AD FS Modern Authentication is intended for pure on-premises Exchange deployments. For Exchange hybrid organizations, Microsoft recommends Hybrid Modern Authentication using Microsoft Entra ID, whether the organization already uses HMA or is considering a new deployment.

That distinction should guide architecture decisions. An IT team should not select AD FS Modern Authentication simply because it has Exchange servers on-premises if it also operates an Exchange hybrid configuration. Microsoft’s recommended model in that situation is HMA, rather than a parallel AD FS-focused approach.

There is also a planning concern for organizations that are entirely on-premises today but expect to become hybrid. Microsoft says that an organization which configures Exchange Hybrid after using AD FS Modern Authentication should transition to HMA. Detailed migration steps have not yet been published, however; Microsoft says they will appear in a future version of the deployment documentation.

That leaves a real planning gap. AD FS Modern Authentication may meet an immediate need, but organizations expecting a near-term hybrid move should account for a future authentication transition before committing heavily to the design.

Server, topology, and Windows prerequisites​

Updating Outlook mobile is the visible part of the change. The deployment prerequisites reach across Exchange, AD FS, Windows, Outlook clients, and configuration.

On the server side, client-connection servers must run Exchange Server 2019 CU13 or later. AD FS must run on Windows Server 2019 or later. Microsoft also says that deploying AD FS on an Exchange server is unsupported, requiring the messaging and federation roles to remain separate.

Mixed Exchange environments face additional boundaries. Exchange 2013 mixed deployments are unsupported for this configuration. In Exchange 2016 and Exchange 2019 mixed deployments, Exchange 2019 servers must handle client-access and front-end connections. For organizations retaining older servers for applications, management, or migration work, those limits can determine whether the project is feasible.

Windows desktop support brings its own requirements. Microsoft requires supported Outlook client and build combinations, Windows 11 version 22H2 or later with KB5023706, configured AD FS trusted-domain registry keys, and EnableExchangeOnPremModernAuth.

The operational lesson is that this is a coordinated client-access and identity change, not a setting to enable after applying a cumulative update. Before activation, teams should inventory Exchange versions, identify every server accepting front-end client connections, confirm the AD FS operating system and role layout, and assess desktop Outlook, Windows, and mobile-app eligibility.

Protocol support is the real scope boundary​

AD FS Modern Authentication supports MAPI/HTTP, Exchange ActiveSync, Exchange Web Services, and Offline Address Book. Microsoft also lists Outlook on the web (OWA) and the Exchange admin center (ECP) as supported through AD FS claims-based authentication.

OWA and ECP deserve separate treatment from Outlook clients. Microsoft says that the OAuth setup used for other clients does not change how OWA and ECP are configured. Administrators should therefore not assume those web and administrative paths necessarily use the same OAuth or authentication-policy behavior described for Outlook clients.

Several established access methods remain outside the feature’s scope. Outlook Anywhere, also called RPC/HTTP, is unsupported, as are IMAP and POP.

For Windows users, MAPI/HTTP is especially relevant because it is the protocol path associated with supported desktop Outlook use in this deployment. But many organizations have more than Outlook: line-of-business tools, scan-to-email devices, shared-mailbox utilities, legacy mail clients, and mobile applications may depend on excluded protocols. Moving to AD FS Modern Authentication therefore calls for an application and protocol audit, not simply an Outlook readiness check.

Desktop and Mac client limits still matter​

Expanded mobile support does not make every Outlook edition eligible. Microsoft’s guidance identifies exclusions that matter in mixed Windows estates.

For new Outlook for Windows, Microsoft documents a specific failure case rather than a product-wide compatibility verdict. When Modern Authentication is enabled for the user and Block Modern Auth is applied as the organization’s DefaultAuthenticationPolicy, new Outlook for Windows tries Modern Authentication but fails. That documented behavior should be evaluated in the same policy-specific pilot that examines Outlook mobile fallback.

Outlook 2016, Outlook 2019, and Outlook 2021 Volume are also unsupported. Organizations using those clients should not treat the mobile expansion as a reason to enable AD FS Modern Authentication before addressing the desktop client estate.

Mac support is similarly constrained. Microsoft supports AD FS Modern Authentication in Microsoft 365 Outlook for Mac build 16.106 (26020821) or later, on macOS Sequoia or later, with Exchange Server SE and the December 2025 or later Security Update. Standalone Outlook 2024 for Mac is not supported.

These requirements make client management a deployment gate rather than a follow-up task. A typical organization may have eligible mobile clients while some Windows or Mac desktop users remain ineligible. Missing that split can lead to inconsistent sign-in experiences, support calls, and pressure to restore legacy authentication behavior for affected users.

A practical pilot plan​

The available guidance supports a staged implementation rather than a broad switch. Start by establishing the required on-premises topology, Exchange and AD FS versions, Windows updates, registry settings, and supported Outlook builds. Then validate a controlled group that reflects the actual environment: eligible Windows Outlook, Outlook for iOS, Outlook for Android, OWA, ECP, and supported Mac deployments where applicable.

The pilot should test more than whether mail opens. For Outlook clients, it should confirm the authentication behavior produced by the exact user and authentication-policy configuration. This is particularly important for mobile Outlook because the current documentation both lists the apps as AD FS Modern Authentication-supported and records Basic-authentication fallback under the stated default-policy scenario.

At the same time, identify users and applications relying on unsupported paths: Outlook 2016, Outlook 2019, Outlook 2021 Volume, Outlook Anywhere, IMAP, POP, unsupported mixed Exchange topology, and any excluded Mac client. Those groups need an alternative plan before a policy change creates an outage or prompts an emergency rollback.

What the change means​

The expansion is meaningful for a narrow but important audience: organizations committed to a pure on-premises Exchange architecture that want current Outlook mobile clients included in an AD FS Modern Authentication plan. Microsoft’s current deployment guidance supplies a support basis for Outlook on iOS and Android that the older April 2025 mobile-client page does not describe.

It is not a reason to blur AD FS Modern Authentication with Hybrid Modern Authentication. Hybrid organizations should follow Microsoft’s HMA direction with Microsoft Entra ID. Pure on-premises organizations still need to satisfy Exchange, AD FS, Windows, Outlook, topology, protocol, and configuration prerequisites.

Most importantly, the mobile support finding should be confirmed in the organization’s own policy design. Until Microsoft reconciles the mobile support listing with the documented Basic-authentication fallback in the specified default-policy configuration, a careful pilot is the most reliable way to turn the September 8 announcement into a dependable deployment.