web
You’re offline. This is a read only version of the page.
close
Skip to main content

Notifications

Announcements

No record found.

Community site session details

Community site session details

Session Id :
Small and medium business | Business Central, N...
Suggested Answer

Shared Emailbox error

(6) ShareShare
ReportReport
Posted on by 526
Hello, 
 
All users have the correct send on behalf permissions to the shared email box. However, one user is receiving the following error message when sending the email from the shared email box in Business Central. 
 
 
LicenseServiceNonTransientException: Service resource is gone. Exception details : Status code returned: 'Gone', HTTP request error: Unknown, Message: "[AuthenticationHandler.AcquireTokenSilentWithLoginHintAsync with certificate] threw MsalClaimsChallengeException with errorCode: invalid_grant, correlationId: e15a907c-37bc-4815-850b-e2fc05cb486a, details: AADSTS53009: Application needs to enforce Intune protection policies. For additional info on how to handle claims related to multifactor authentication, Conditional Access, and incremental consent, see https://aka.ms/msal-conditional-access-claims. If you are using the On-Behalf-Of flow, see https://aka.ms/msal-conditional-access-claims-obo for details.".
 
 
The users have exchange license and MFA enabled, but the shared email does not have MFA. 
I have the same question (0)
  • Suggested answer
    Jainam M. Kothari Profile Picture
    15,631 Super User 2025 Season 2 on at
    Hello,
     
    Microsoft Conditional Access policies are blocking the user's attempt to send emails from the shared mailbox in Business Central due to non-compliance with Intune App Protection requirements. Even though the user has the correct permissions and MFA enabled, their device or app may not meet the organization's Intune compliance standards.
     
    You need to ensure the user's device is enrolled in Intune, the app used supports Intune policies, and review Conditional Access settings in Azure AD to confirm the correct enforcement rules are in place.
  • Suggested answer
    Andrés Arias Profile Picture
    4,188 Super User 2025 Season 2 on at
    Hello,

    Could you check if the affected user is using a compliant device (Azure AD or logged into Intune)?
     
    I would also check the Conditional Access policy for BC.
     
    I hope to be able to help.
     
    Regards,
     
    Andres
  • Gerardo Rentería García Profile Picture
    25,169 Most Valuable Professional on at
  • Suggested answer
    Sohail Ahmed Profile Picture
    11,136 Super User 2025 Season 2 on at
    The error is due to a Conditional Access policy requiring Intune protection or compliant devices. Even with correct permissions, the user is blocked because the policy applies stricter rules for shared mailboxes in Business Central.
     
    ✅ Check Azure AD Conditional Access settings and either adjust the policy or exclude Business Central from it.
     
     
    ✅ Mark this answer as verified if it helps you.
     
     

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Neeraj Kumar – Community Spotlight

We are honored to recognize Neeraj Kumar as our Community Spotlight honoree for…

Leaderboard > Small and medium business | Business Central, NAV, RMS

#1
OussamaSabbouh Profile Picture

OussamaSabbouh 3,143

#2
Jainam M. Kothari Profile Picture

Jainam M. Kothari 1,694 Super User 2025 Season 2

#3
YUN ZHU Profile Picture

YUN ZHU 1,067 Super User 2025 Season 2

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans