Securing emails

%3CLINGO-SUB%20id%3D%22lingo-sub-1640613%22%20slang%3D%22en-US%22%3ESecuring%20emails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1640613%22%20slang%3D%22en-US%22%3E%3CP%3EHello%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHopefully%2C%20this%20is%20posted%20in%20the%20correct%20place.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20currently%20in%20the%20process%20of%20mowing%20our%20estate%20from%20on-prem%20to%20365.%20We%20have%20a%20conditional%20access%20setup%20within%20azure%20intune%20that%20will%20block%20active%20sync.%20This%20means%20that%20all%20our%20users%20can%20only%20use%20the%20outlook%20app%20on%20respective%20phones%20to%20access%20the%20emails%2C%20which%20is%20great.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20question%20I%20have%20that%20so%20far%20I%20was%20unable%20to%20find%20answers%20to%20is%20how%20I%20can%20further%20help%20us%20with%20regards%20to%20managing%20the%20app%20and%20the%20content.%20What%20I%20mean%20here%20is%20if%20a%20person%20were%20to%20leave%20our%20organization%20is%20there%20a%20way%20I%20can%20make%20their%20outlook%20app%20wipe%20all%20of%20its%20data%3F%20If%20this%20is%20not%20possible%20is%20there%20a%20way%20to%20lock%20users%20out%20from%20seeing%20all%20of%20the%20data%2C%20emails%2C%20etc%20cached%20within%20the%20app%20as%20soon%20as%3F%20We%20have%20experimented%20with%20changing%20passwords%20and%20taking%20away%20licences%20but%20that%20still%20allows%20user%20to%20see%20all%20the%20emails%20already%20cached%20on%20the%20device%20and%20it%20asks%20for%20a%20password.%20Any%20assistance%20would%20be%20appreciated.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20a%20look%20at%20setting%20up%20some%20policies%20with%20intune%20but%20nothing%20enrolls.%20I%20am%20not%20going%20to%20lie%20I%20am%20super%20new%20to%20365.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EMarek%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1640613%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EContent%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EEmail%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EUser%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1641645%22%20slang%3D%22en-US%22%3ERe%3A%20Securing%20emails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1641645%22%20slang%3D%22en-US%22%3E%3CP%3EGo%20over%20this%20document%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fclients-and-mobile-in-exchange-online%2Foutlook-for-ios-and-android%2Fsecure-outlook-for-ios-and-android%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fexchange%2Fclients-and-mobile-in-exchange-online%2Foutlook-for-ios-and-android%2Fsecure-outlook-for-ios-and-android%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1643317%22%20slang%3D%22en-US%22%3ERe%3A%20Securing%20emails%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1643317%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3BHi%20thank%20you%20for%20the%20link.%20I%20had%20a%20look%20and%20if%20I%20am%20not%20mistaken%20we%20need%20to%20have%20intune%20as%20otherwise%20we%20cannot%20delete%20the%20apps%20or%20their%20content.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20being%20said%20the%20article%20also%20mentioned%20that%20some%20of%20it%20should%20be%20possible%20with%20AAD%20premium%20license.%20We%20currently%20have%26nbsp%3B%3CSPAN%3EAzure%20AD%20Premium%20P1.%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20a%20quick%20play%20around%20and%20myself%20who%20is%20on%20a%20higher%20license%20M365%20is%20able%20to%20be%20managed%20with%20intune%2C%20apps%20pushed%20to%20the%20user%2C%20and%20correctly%20registered%20on%20the%20portal%20as%20a%20personal%20device%2C%20etc.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20second%20test%20user%20with%20an%20O365%20license%20is%20able%20to%20enroll%20but%20he%20is%20not%20receiving%20any%20of%20the%20company%20apps%2C%20namely%20emails%2C%20and%20on%20the%20portal%2C%20most%20of%20the%20details%20show%20as%20unknown.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20had%20a%20look%20at%20this%20option%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fapp-based-conditional-access-intune%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fapp-based-conditional-access-intune%3C%2FA%3E%26nbsp%3Bbut%20I%20cannot%20figure%20out%20how%20I%20would%20then%20remove%20the%20data%20from%20the%20user%20device.%20I%20guess%20i%20can%20stop%20the%20user%20from%20accessing%20the%20emails%20and%20the%20365%20as%20he%20will%20not%20meet%20the%20condition%20of%20being%20a%20member%20of%20allowed%20group%2C%20but%20how%20I%20would%20remove%20the%20emails%20already%20cached%20on%20his%20device%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHave%20I%20missed%20something%20obvious%20here%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%2C%3C%2FP%3E%3CP%3EMarek%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello 

 

Hopefully, this is posted in the correct place.

 

We are currently in the process of mowing our estate from on-prem to 365. We have a conditional access setup within azure intune that will block active sync. This means that all our users can only use the outlook app on respective phones to access the emails, which is great. 

 

The question I have that so far I was unable to find answers to is how I can further help us with regards to managing the app and the content. What I mean here is if a person were to leave our organization is there a way I can make their outlook app wipe all of its data? If this is not possible is there a way to lock users out from seeing all of the data, emails, etc cached within the app as soon as? We have experimented with changing passwords and taking away licences but that still allows user to see all the emails already cached on the device and it asks for a password. Any assistance would be appreciated. 

 

I had a look at setting up some policies with intune but nothing enrolls. I am not going to lie I am super new to 365.

 

Regards,

Marek

3 Replies

@Vasil Michev Hi thank you for the link. I had a look and if I am not mistaken we need to have intune as otherwise we cannot delete the apps or their content. 

 

That being said the article also mentioned that some of it should be possible with AAD premium license. We currently have Azure AD Premium P1.

 

I had a quick play around and myself who is on a higher license M365 is able to be managed with intune, apps pushed to the user, and correctly registered on the portal as a personal device, etc. 

 

The second test user with an O365 license is able to enroll but he is not receiving any of the company apps, namely emails, and on the portal, most of the details show as unknown. 

 

I had a look at this option: https://docs.microsoft.com/en-us/mem/intune/protect/app-based-conditional-access-intune but I cannot figure out how I would then remove the data from the user device. I guess i can stop the user from accessing the emails and the 365 as he will not meet the condition of being a member of allowed group, but how I would remove the emails already cached on his device?

 

Have I missed something obvious here? 

 

Regards,

Marek

Hello

 

After following the earlier mentioned guide and setting it all up as it mentioned in the guide I have tried to access emails on my device. It is not allowing me to add them in Gmail but it seemed to have work with the outlook app. 

 

It asked me to install Microsoft corporate intune app which I have and when I try to open outlook now and add an email address to it it gives me error message "this account cannot be added because the outlook isn't configured correctly".

 

What have I missed? I have outlook from both google play and google play for work added to the managed apps within my intune/aad

 

Regards,

Marek