Forum Discussion

6 Replies

    • StuartK73's avatar
      StuartK73
      Steel Contributor

      Moe_Kinani 

       

      Yes, that's the method I'm using.

       

      Do you know what the UX is here? Especially if the device is an iOS DEP / Supervised one?

       

      Client is expecting the device to stay in Single App Mode if a user outwith the enrollment group tries to enroll.

       

      Info appreciated

      • Moe_Kinani's avatar
        Moe_Kinani
        Bronze Contributor
        I would recommend use the policy without single app mode, as I didn’t have great experience with Single App mode.

        Haven’t test it but expect this what happens with Single app mode:

        You will boot the device to Portal app, you enter user and password, then you get message that you can’t enroll then you get stuck.

        Curious to know your experience with single app mode, thanks Stuart!
  • Hey StuartK73,

     

    you can restrict the MDM user scope to a AAD group:

     

     

    This way only users in that AAD groups can enroll into MDM (Intune).

     

    best,

    Oliver