Introduction
Microsoft Defender for Endpoint (MDE) is a unified endpoint security platform that helps protect your devices from advanced threats. MDE on iOS/iPadOS devices provides protection again...
Thank you arnabmitra! I struggled through this on my own due to sporadic documentation and no real clarity on how to best do this. Your post will make it easy for admins so thank you.
Question: is there a minimum iOS version for this process to work? We've seen issues with older iOS devices.
I have done it slightly differently so I was wondering if you could review and let me know if you see any issues with doing it differently?
1. For the App Configuration policy, I target All Managed iOS Devices. Some older ones are unsupervised but most new ones are Supervised. Is it ok to target all Intune enrolled iOS devices?
2. Within the app config policy, I also make other changes. Is it ok to use these other settings in the same policy as the issupervised flag? Here's what i currently set:
3. For iOS device configuration policies, I have one for supervised and another one for unsupervised. I target them appropriately.
Supervised devices get the *zerotouch.mobileconfig settings
Unsupervised devices, mine matches up with yours but I also added a second key under Base VPN. I set SingleSignOn to true.
I appreciate you taking a look at this. There don't appear too many experts out there and things are scattered in the docs.