Forum Discussion

JD1234535's avatar
JD1234535
Copper Contributor
Jun 28, 2022

iOS Devices can manually unenroll and still access corporate resource (Outlook app not removed)

We are looking to migrate to Intune for MDM on our phone but are having an issue with iOS. 

 

With Android, if you try to un-enroll your device it forces you to wipe the work profile.  This means that the phone is always managed and can be wiped if the employee leaves or it is wiped automatically if the employee decides to remove the Company Portal app from their device.

 

With iOS, you can remove the device management profile under settings and you can remove the Company Portal and Authenticator app from the device without it also removing the applications like Outlook and Teams which were installed and managed by Intune.  There must be a configuration somewhere to force these applications to be removed if a phone is un-enrolled from Intune.  Otherwise, there is no way to wipe corporate data off a device since it is no longer managed.  Even if you manually block active sync for email, change their password or remove their account all that cached data is still present on the device.

Thanks

 

6 Replies

  • Oktay Sari's avatar
    Oktay Sari
    Iron Contributor

    Hi JD1234535, Can you share a little more details on your scenario?

     

    1. Are we talking corp owned or BYOD?
    2. Do you by any chance use Apple Business Manager (DEP) or Apple Configurator to MDM enroll corp iOS devices? If you do, you can set your iOS devices to supervised mode. In this mode, un-enrollment can be blocked. That should solve your problem. 

     

     

     

    • JD1234535's avatar
      JD1234535
      Copper Contributor

      Oktay Sari 

      BYOD.  No we do not use Apple Business Manager.  After speaking with Apple this didnt seem to work for BYOD and was really for corp owned devices.

       

      • Oktay Sari's avatar
        Oktay Sari
        Iron Contributor

        Hi JD1234535

        I'm guessing here but please fill me in with more info along the way so we can help you better.

        1. What is the reason to MDM enroll and Intune manage personal devices?
        2. Do you have a conditional access policy requiring devices to be compliant (forced enrollment)?
        3. How do users enroll? (if not because of CA.. Q2 above)

        Finally;

        Do you have an app protection policy (APP) configured for managed apps? I assume you do, since you mentioned apps are installed using Intune (therefore are managed apps) and you're not able do do a wipe (assuming you mean a wipe on app level). When a user removes the management profile, authenticator and Intune company portal app, the device becomes unmanaged and with that, the applications are now unmanaged too. I did not test this fully but I believe that's the reason you're not able to do a selective wipe using the app protection policy, because it was targeting managed apps.

         

        Since these are personal devices, what you can consider is not to install the outlook app using Intune, but have the user install it from the store. Where am I going with this you may ask...

         

        Well, if the apps are unmanaged, you can use app protection policies for unmanaged apps. This way, the device state does not matter (basically falling back to MAM and not MDM) . However, you're still able to have the devices MDM managed if that is a requirement. Now, in this scenario, if devices become unmanaged, the app is still managed. And this gives you options like selective wipe or conditional launch to automatically wipe corporate data under certain conditions. What ever comes first. 

         

        Please note that in the example below I've deliberately set some settings to 1 minute/day...

         


        What I did not try is to create an APP for managed and unmanaged apps, and see if the app picks up the APP for unmanaged apps after becoming an unmanaged app/device. (still with me?) You could give that a try too.

         

        Hope this helps but if this does not meet your business requirements, please give as much information as you can.

         

        Regards

        Oktay 

Resources