Forum Discussion

Eric-Labc's avatar
Eric-Labc
Copper Contributor
Apr 17, 2019

MDM VS MAM

Hello,

 

Many users in my company are using their private phone to connect to company e-mail etc ...

and they are also using a company laptop for everyday work.

So I want to have full control on their laptop (MDM and MAM) and only MAM on their phone.

How can I do this for a same user?

 

Thanks.

5 Replies

  • Hi Eric-Labc,

     

    it's exactly what Alexander said you need to look for app-based conditional access for your mobile phones and device-based conditional access for your Windows 10 Laptops that require them to be compliant. See references here:

     

    App-based conditional access with Intune
    https://docs.microsoft.com/en-us/intune/app-based-conditional-access-intune

     

    How To: Require managed devices for cloud app access with conditional access
    https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/require-managed-devices

     

    best,

    Oliver

    • Eric-Labc's avatar
      Eric-Labc
      Copper Contributor

      Oliver Kieselbach 

      Hello Olivier,

      Thanks for the answer.

       

      But it is not clear for me.

      My case is :

      1. the user phone is a personal device, so I have to put user id in MAM group

      2. the laptop device is a organistion device, so I have to put user id in MDM group.

       

      So how does Intune react if I put the same user id in MDM and MAM group?

      How does he know in my case here that I want only MAM for the phone and not MDM?

       

      What is confusing me with Intune is that in the security group it's always a reference to user id and not to a device id.

       

      Eric.

       

       

       

      • Hi Eric, you only need one group for the user as Intune sees if the phone is enrolled or not into MDM. Where you in the MAM policy can adapt the settings to fit both if the phone is enrolled or not.  Eric-Labc 

  • Well, at first there is no MAM capabilities for Windows. There are some things you can do with AIP/WIP, but it's not exactly MAM as it works with mobile devices.

     

    Check out information about conditional access policies. You can create policies based on device types and requeire device to be managed for PCs and use of MAM enabled apps for mobiles.

Resources