Forum Discussion
MDM VS MAM
Hello,
Many users in my company are using their private phone to connect to company e-mail etc ...
and they are also using a company laptop for everyday work.
So I want to have full control on their laptop (MDM and MAM) and only MAM on their phone.
How can I do this for a same user?
Thanks.
5 Replies
Hi Eric-Labc,
it's exactly what Alexander said you need to look for app-based conditional access for your mobile phones and device-based conditional access for your Windows 10 Laptops that require them to be compliant. See references here:
App-based conditional access with Intune
https://docs.microsoft.com/en-us/intune/app-based-conditional-access-intuneHow To: Require managed devices for cloud app access with conditional access
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/require-managed-devicesbest,
Oliver
- Eric-LabcCopper Contributor
Hello Olivier,
Thanks for the answer.
But it is not clear for me.
My case is :
1. the user phone is a personal device, so I have to put user id in MAM group
2. the laptop device is a organistion device, so I have to put user id in MDM group.
So how does Intune react if I put the same user id in MDM and MAM group?
How does he know in my case here that I want only MAM for the phone and not MDM?
What is confusing me with Intune is that in the security group it's always a reference to user id and not to a device id.
Eric.
Hi Eric, you only need one group for the user as Intune sees if the phone is enrolled or not into MDM. Where you in the MAM policy can adapt the settings to fit both if the phone is enrolled or not. Eric-Labc
- Alexander VanyurikhinIron Contributor
Well, at first there is no MAM capabilities for Windows. There are some things you can do with AIP/WIP, but it's not exactly MAM as it works with mobile devices.
Check out information about conditional access policies. You can create policies based on device types and requeire device to be managed for PCs and use of MAM enabled apps for mobiles.