SOLVED

App protection policy not applying

%3CLINGO-SUB%20id%3D%22lingo-sub-2183346%22%20slang%3D%22en-US%22%3EApp%20protection%20policy%20not%20applying%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2183346%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3EI'm%20trying%20to%20configure%20an%20iOS%20app%20protection%20policy%20for%20a%20client%20but%20I'm%20failing%20to%20get%20it%20applied%20on%20a%20iPhone%20XR%20with%20a%20fully%20licensed%20user.%3C%2FP%3E%3CP%3EI%20deployed%20the%20app%20config%20policy%20with%20the%20IntuneMAMUPN%20key%2C%20currently%20only%20testing%20with%20the%20Outlook%20app%2C%20which%20is%20set%20as%20required%20in%20the%20portal.%20I%20reseted%20my%20phone%2C%20even%20created%20an%20Itunes%20account%20with%20my%20company%20test%20mail%20address%2C%20after%20configuring%20my%20phoen%20for%20the%20first%20time%20I%20installed%20the%20Intune%20portal%20App%20a%20go%20through%20the%20device%20registration%20process.%3C%2FP%3E%3CP%3EMy%20phone%20gets%20an%20compliant%20status%2C%20marked%20as%20personally%2C%20even%20if%20changed%20to%20company%20owned%20no%20change%20until%20now%2C%20Outlook%20config%20policy%20is%20applied%20but%20not%20the%20protection%20policy.%3C%2FP%3E%3CP%3EWhen%20I%20check%20the%20monitor%20view%20I%20get%20the%20warning%20%22This%20user%20is%20blocked%20by%20user-level%20wipe.%22%20and%20I%20can't%20find%20article%20about%20this%20error%5E%5E%3C%2FP%3E%3CP%3ECan%20anyone%20give%20me%20a%20hint%20to%20solve%20this%20nasty%20issue%3F%3CBR%20%2F%3EThanks.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2183346%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3Eapp%20policy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EApp%20Protection%20Policy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EApps%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eblocked%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOutlook%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Eprotection%20policy%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Euser-level%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Ewipe%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2183902%22%20slang%3D%22en-US%22%3ERe%3A%20App%20protection%20policy%20not%20applying%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2183902%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F634066%22%20target%3D%22_blank%22%3E%40Julian12%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhere%20exactly%20are%20you%20seeing%20that%20error%20from%3F%20I%20usually%20use%20the%20following%20report%20to%20make%20sure%20whether%20or%20not%20my%20policy%20has%20applied%3A%20%3CSTRONG%3EApps%20%26gt%3B%20Monitor%20%26gt%3B%20App%20protection%20status%20%26gt%3B%20Reports%20%26gt%3B%20User%20report%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhat%20is%20your%26nbsp%3B%3CSTRONG%3ETarget%20to%20apps%20on%20all%20device%20types%3C%2FSTRONG%3E%20selection%3F%20If%20it%20is%20not%20set%20to%20Yes%20or%20both%20types%20that%20cause%20some%20issues%2C%20the%20type%20state%20is%20a%20bit%20fiddly%20to%20pinpoint%20and%20thus%20its%20more%20simple%20to%20target%20both%2C%20more%20about%20that%20in%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fapp-protection-policies%23create-an-iosipados-or-android-app-protection-policy%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ECreating%20an%20iOS%20app%20protection%20policy%3C%2FA%3E%20docs.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOwnership%20type%20should%20not%20matter%20when%20it%20comes%20to%20App%20Protection%20policies.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi,

I'm trying to configure an iOS app protection policy for a client but I'm failing to get it applied on a iPhone XR with a fully licensed user.

I deployed the app config policy with the IntuneMAMUPN key, currently only testing with the Outlook app, which is set as required in the portal. I reseted my phone, even created an Itunes account with my company test mail address, after configuring my phoen for the first time I installed the Intune portal App a go through the device registration process.

My phone gets an compliant status, marked as personally, even if changed to company owned no change until now, Outlook config policy is applied but not the protection policy.

When I check the monitor view I get the warning "This user is blocked by user-level wipe." and I can't find article about this error^^

Can anyone give me a hint to solve this nasty issue?
Thanks.

5 Replies

Hi @Julian12 

 

Where exactly are you seeing that error from? I usually use the following report to make sure whether or not my policy has applied: Apps > Monitor > App protection status > Reports > User report

 

What is your Target to apps on all device types selection? If it is not set to Yes or both types that cause some issues, the type state is a bit fiddly to pinpoint and thus its more simple to target both, more about that in Creating an iOS app protection policy docs. 

 

Ownership type should not matter when it comes to App Protection policies.

Hi @Alo Press,

I see that error in the same reporting tool:

Julian12_0-1614847376804.png

Currently I set the target devices to managed only, tried for a short time with Both but wasn't working too. Will test this again..

Edit: Not sure if this is a problem but atm my test phone has no SIM card or any mobile number attached to it.

best response confirmed by Julian12 (Contributor)
Solution

@Julian12 Are the apps that you are trying to Protect managed? Meaning are they published through the Intune Company Portal or are you just testing App Store apps and waiting until they apply? 

 

In some cases Signing into the app might be needed for the Protection to trigger as the app is assuming the protection from Your specific MDM - this is more relevant with multi-identity enabled apps. 

 

Also, is there anything special about that test account? What licenses have you enabled to it or is it a DEM account? There is probably a lot of things that might not work quite right for DEM accounts. 

 

Regarding the user-level wipe.. it might have something to do with pending App selective wipe, if you have any pending delete the requests. Docs here on how to Delete a device wipe request.

Frickin hell, there was really a selective wipe in place for this account, so obvious^^
I deleted that request and reset my device, hopefully it is working now..
Many thanks for this hint, seems too easy :\

Yeah, its working now, thanks for your help :)
Have a nice day!