Home

Restrict O365 to managed mobile browser

Alistair Trigg
Contributor

Hi

 

I have set up app protection policies for users on unmanaged mobile devices, These work fine but to stop staff getting round the controls I want to restrict their access to our O365 portal from browsers on these devices but not laptops. Is there a simple way to configure this?

6 Replies

Hi Alistair,

 

I would build a Conditional Access rule to require approved apps targeted to your iOS and Android not Windows. This would force people to access your services via the MS apps which includes the Managed Browser:

 

CARequireApprovedApps.png

Approved apps list can be seen here: https://aka.ms/supportedmamapps

 

best,

Oliver

Hi

 

Thanks you have confirmed that I am in the right place but maybe I was looking at it from the wrong angle. So I had selected cloud apps - O365 exchange online, condition - browsers, access control - block.

 

I was assuming that this would block any access to O365 in a browser on a mobile device but it doesn't seem to?

Hm... I never tried it that way but I see another attack vector when designing it with a block rule. If someone builds an app which allows web requests by individual input, a kind of custom browser, this will not be recognized by the block rule. So I would prefer the way to limit the users to approved apps.

Hi

 

Good point and I have found that my rule is now blocking my laptop access to O365 so it doesn't work. i have the apps controlled using app policies but I can't get my head around how I stop a user just adding the portal.office.com url in chrome on the mobile and logging into our tenant. I might be missing something here so apologies

So you want entirely stop users from using the web browser for access? 

I would use the same strategy as described above here to. Force users to allow access only by approved apps and then configure the Intune Managed Browser with an app configuration policy to block everything except what you want them to have. No more browser usage except the managed one and this one is strictly controlled by IT. This would be the way to go I think.

Hi

 

Thanks for that. I'll give it a go

 

Alistair

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies