Forum Discussion
dave.a.florek
Jan 30, 2018Copper Contributor
Locking down mobile O365 apps to prevent company data exfiltration
I set a Mobile App Protection Policy in Microsoft Intune for Azure to lock down what users are able to do within Outlook mobile for iPhones (BYOD), however I'm running into an issue where I can still...
VasilMichev
Jan 30, 2018MVP
Which setting did you configure for Allow app to transfer data to other apps?
And what do you mean by move files, the actual process of copying the file? Or copy/pasting from within the file?
- dave.a.florekJan 30, 2018Copper Contributor
Hi Vasil, I set it to Policy Managed Apps. Even with this setting in place though, I can still export data out of there via an "Open In..." button on the top right of the file I opened or through another O365 mobile app allowed by the policy itself.
- VasilMichevJan 31, 2018MVP
That's my point - I don't believe the policies apply on the "whole file" level. For such scenarios, you can use file-level encryption, as in Azure Identity Protection.