Block Access from private Devices to Microsoft Apps.

%3CLINGO-SUB%20id%3D%22lingo-sub-1640632%22%20slang%3D%22de-DE%22%3EBlock%20Access%20from%20private%20Devices%20to%20Microsoft%20Apps.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1640632%22%20slang%3D%22de-DE%22%3E%3CP%3EHello%3C%2FP%3E%3CP%3Ei%20got%20a%20question%3A%3C%2FP%3E%3CP%3EWe%20are%20planning%20to%20Buy%20Microsoft%20365%20Business%20Premium%20and%20Microsoft%20365%20Business%20Standard%20%2B%20Intune%20Device%20License.%3C%2FP%3E%3CP%3EMy%20problem%20is%20that%20our%20company%20doesn't%20want%20to%20have%20Access%20to%20Mail%2FOnedrive%2FMicrosoft%20Applications%20...%20on%20private%20devices.%20%3CBR%20%2F%3E%20How%20can%20i%20block%20the%20Access%3F%20The%20Devices%20will%20be%20Managed%20by%20Intune%2C%20Win10%20Pro%2C%20IOS%20and%20maybe%20some%20Samsung%20Galaxy's.%3C%2FP%3E%3CP%3EIs%20There%20an%20option%20to%20only%20allow%20managed%20devises%20to%20Access%20Microsoft%20Data%3F%20And%20Do%20i%20need%20some%20additional%20Lisense%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Regards%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPhil%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1640632%22%20slang%3D%22de-DE%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMicrosoft%20Intune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1640878%22%20slang%3D%22en-US%22%3ERe%3A%20Block%20Access%20from%20private%20Devices%20to%20Microsoft%20Apps.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1640878%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F527362%22%20target%3D%22_blank%22%3E%40RauschNaut%3C%2FA%3E%26nbsp%3BHi%2C%20as%20far%20as%20I%20understand%20from%20the%20service%20description%20for%20M365%20Business%20Premium%20you%20should%20be%20all%20set%20with%20the%20licenses%20(CA%20and%20Intune).%20There%20are%20a%20lot%20of%20experts%20in%20the%20community%20on%20MDM%2FMAM%20so%20you'll%20probably%20get%20additional%20answers%20but%20yes%2C%20you%20can%20achieve%20what%20you%20want.%20I'd%20like%20to%20direct%20you%20to%20the%20docs%20for%20guidance%20so%20maybe%20start%20here%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fwhat-is-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Ffundamentals%2Fwhat-is-intune%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1677319%22%20slang%3D%22en-US%22%3ERe%3A%20Block%20Access%20from%20private%20Devices%20to%20Microsoft%20Apps.%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1677319%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551905%22%20target%3D%22_blank%22%3E%40bec064%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20and%20Thanks%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20think%20i%20can%20block%20the%20access%20to%20Cloud%20apps.%20But%20can%20i%20also%20block%20the%20Access%20on%20iOS%20Mail-App%20or%20installed%20Outlook%20Client%20on%20a%20PC%2C%20which%20is%20not%20registered%20in%20Intune%2FAzre%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBest%20Regards%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello,

i got a question:

We are planning to Buy Microsoft 365 Business Premium and Microsoft 365 Business Standard + Intune Device License.

My problem is that our Company doesn´t want to have Access to Mail/Onedrive/Microsoft Applications ... on private Devices.
How can i block the Access? The Devices will be Managed by Intune, Win10 Pro, IOS and maybe some Samsung Galaxy´s.

Is There an option to only allow managed devises to Access Microsoft Data? And Do i need some additional Lisense?

 

Best Regards,

 

Phil

 

 

4 Replies

@RauschNauti Hi, as far as I understand from the service description for M365 Business Premium you should be all set with the licenses (CA and Intune). There are a lot of experts in the community on MDM/MAM so you'll probably get additional answers but yes, you can achieve what you want. I'd like to direct you to the docs for guidance so maybe start here?

 

https://docs.microsoft.com/en-us/mem/intune/fundamentals/what-is-intune

 

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/require-managed-devices

@ChristianBergstrom 

Hi and Thanks, 

 

i think i can block the access to Cloud apps. But can i also block the Access on iOS Mail-App or installed Outlook Client on a PC, which is not registered in Intune/Azre?

 

Best Regards :)

@RauschNauti Hello! As mentioned I usually don't configure these settings, but see the tutorial and the other link for step-by-step guidance.

 

"Learn about using app protection policies with Conditional Access to protect Exchange Online, even when devices aren't enrolled in a device management solution like Intune."

https://docs.microsoft.com/en-us/mem/intune/protect/tutorial-protect-email-on-unmanaged-devices

 

'Block all email apps except Outlook for iOS and Android using conditional access'

https://docs.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-... 

 

There are a couple of different approaches as you will see.

Hi @RauschNauti,

As mentioned in this thread, the easiest way to block access is to use Conditional Access. Set a rule for Office 365 and set the grant condition to "require the device to be marked as compliant", an un-managed device will never be compliant. 

If you want to ensure that your users are only using approved apps, consider adding the "Require approved client app" to your grant policy as well (only applies to iOS and Android).

Think this link has already been shared, but I'll add it anyways. Conditional Access require managed device - Azure Active Directory | Microsoft Docs

 

This goes without saying, but test on a small scale before deploying company-wide. :)

 

You will need Azure Active Directory Premium P1 or P2 to use Conditional Access.