Can you deploy an app to personal mobiles if they use it for work?

%3CLINGO-SUB%20id%3D%22lingo-sub-1359436%22%20slang%3D%22en-US%22%3ECan%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359436%22%20slang%3D%22en-US%22%3E%3CP%3EYesterday%20we%20mass%20deployed%20Cisco%20umbrella%20to%20all%20iOS%20devices%20currently%20in%20Intune.%3C%2FP%3E%3CP%3EUp%20until%20now%20we%20only%20do%20fully%20managed%20devices%20(with%20and%20without%20user%20affinity)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ELeadership%20team%20has%20expressed%20a%20potential%20desire%20to%20also%20deploy%20the%20Cisco%20umbrella%20app%20to%20personal%20mobile%20phones%20IF%20they%20are%20using%20it%20to%20access%20company%20resources.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20problem%20here%20is%20I%20do%20not%20know%20how%20I%20would%20even%20stop%20users%20from%20accessing%20Outlook%2C%20Teams%2C%20Onedrive%20from%20their%20personal%20mobiles%20and%20if%20they%20wanted%20to%20had%20to%20accept%20some%20security%20policies%20and%20the%20Cisco%20umbrella%20app%20to%20be%20deployed.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ECould%20anyone%20help%20me%20out%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1359436%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359450%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359450%22%20slang%3D%22en-US%22%3EThis%20should%20be%20done%20with%20Intune%20and%20Conditional%20Access%3A%3CBR%20%2F%3E%3CBR%20%2F%3E-%20I%20would%20advise%20to%20look%20into%20Android%20Work%20Profiles%20and%20iOS%20User%20Enrollment%20and%20set%20that%20one%20up%3CBR%20%2F%3E-%20Configure%20Conditional%20Access%20to%20require%20a%20compliant%20device%20when%20accessing%20Exchange%2FTeams%2FSharepoint...%3CBR%20%2F%3E-%20Setup%20Cisco%20Umbrella%20application%20push%20to%20all%20devices%3CBR%20%2F%3E%3CBR%20%2F%3EUsers%20will%20need%20to%20enroll%20when%20they%20try%20to%20access%20from%20a%20personal%20device%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359475%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359475%22%20slang%3D%22en-US%22%3E%3CP%3EWould%20i%20need%20to%20do%20anything%20with%20MAM%20for%20this%20one%20%3F%20in%20Azure%20AD%20there%20is%20this%20MAM%20%26amp%3B%20MDM%20section%20where%20you%20can%20turn%20them%20on%20or%20off.%20mine%20currently%20has%20MDM%20on%20and%20MAM%20off.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359488%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359488%22%20slang%3D%22en-US%22%3EIt%20really%20depends%20on%20how%20you%20want%20to%20setup%20personal%20devices.%3CBR%20%2F%3EHow%20much%20do%20you%20want%20to%20manage%20those%20personal%20devices%3F%3CBR%20%2F%3E%3CBR%20%2F%3EFYI%2C%20these%20MAM%20%26amp%3B%20MDM%20settings%20are%20only%20for%20W10%20-%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-enroll%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fenrollment%2Fwindows-enroll%3C%2FA%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359575%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359575%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BI%20dont%20really%20want%20to%20manage%20personal%20devices%20in%20great%20detail.%20It%20sounds%20like%20we%20just%20want%20to%20make%20sure%20that%20if%20they%20want%20to%20access%20corporate%20data%20that%20they%20are%20to%20some%20extend%20managed%20so%20that%20we%20can%20make%20sure%20they%20are%20in%20compliance%20and%20our%20data%20is%20secure.%20If%20a%20user%20leave%20we%20should%20be%20able%20to%20remove%20just%20corporate%20data%20off%20the%20device.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359599%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359599%22%20slang%3D%22en-US%22%3EThen%20you%20should%20look%20into%20implementing%20mobile%20application%20management%20without%20enrollment%20(%3CA%20href%3D%22https%3A%2F%2Fallthingscloud.blog%2Fmanage-byod-devices-with-intune-mam-without-enrollment%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fallthingscloud.blog%2Fmanage-byod-devices-with-intune-mam-without-enrollment%2F%3C%2FA%3E)%3CBR%20%2F%3E%3CBR%20%2F%3EThen%20you%20can%20manage%20only%20corporate%20data%20on%20the%20phones%3CBR%20%2F%3EDo%20note%3A%20then%20you%20cannot%20push%20the%20Cisco%20application%3CBR%20%2F%3E%3CBR%20%2F%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359620%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359620%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3B%20In%20which%20case%20then%20what%20i%20want%20is%20not%20correct%20%3A)%3C%2Fimg%3E%20So%20im%20back%20to%20Android%20Work%20Profiles%20and%20IOS%20user%20enrolment%20right%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1359624%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1359624%22%20slang%3D%22en-US%22%3ECorrect%20%3A)%3C%2Fimg%3E%20You%20need%20to%20manage%20the%20device%20if%20you%20want%20to%20publish%20applications%20to%20them%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1369660%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1369660%22%20slang%3D%22en-US%22%3E%3CP%3EHey%2C%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Eif%20we%20talk%20about%20push%20it%20is%20not%20possible%20to%20do%20so%20if%20a%20device%20is%20not%20enrolled%2C%20If%20we%20talk%20about%20a%20App%20Store%20functionality%20it%20is%20possible%20to%20provide%20users%20apps%20even%20without%20enrollment.%20The%20key%20thing%20there%20is%20to%20assign%20them%20to%20users%20not%20devices%2C%20only%20user%20assignment%20is%20working%20and%20then%20using%20the%20company%20portal.%20The%20web%20version%20of%20the%20company%20portal%20(%3CA%20href%3D%22https%3A%2F%2Fportal.manage.microsoft.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fportal.manage.microsoft.com%2F%3C%2FA%3E)%20will%20even%20allow%20you%20to%20install%20your%20custom%20LOB%20iOS%20apps%20for%20example.%20You%20need%20to%20confirm%20a%20few%20prompts%20but%20finally%20you%20can%20have%20a%20company%20in-house%20developed%20iOS%20app%20target%20to%20your%20users%20(without%20enrollment)%20via%20Company%20Portal%20and%20let%20them%20install%20the%20LOB%20app.%20Just%20go%20ahead%2C%20upload%20a%20app%20and%20assign%20it%20to%20the%20user%20and%20go%20to%20the%20web%20Company%20Portal.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EYes%20it%20is%20no%20push%2C%20but%20self-service%20app%20store%20style%20is%20possible.%20For%20app%20updates%20it%20is%20the%20same%20they%20will%20not%20be%20pushed%2C%20the%20user%20would%20need%20to%20go%20again%20to%20the%20Company%20Postal%20to%20install%20the%20update.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1369679%22%20slang%3D%22en-US%22%3ERe%3A%20Can%20you%20deploy%20an%20app%20to%20personal%20mobiles%20if%20they%20use%20it%20for%20work%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1369679%22%20slang%3D%22en-US%22%3E%3CP%3EYour%20initial%20request%20to%20bring%20more%20security%20to%20the%20unenrolled%20devices%20is%20done%20in%20the%20MS%20concept%20by%20using%20MTD%20connectors.%20This%20is%20available%20for%20unenrolled%20devices%20as%20well.%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fmtd-add-apps-unenrolled-devices%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fmtd-add-apps-unenrolled-devices%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThere%20are%20a%20few%20vendors%20supported%20but%20Cisco%20is%20not%20listed%20there.%20See%20here%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fmobile-threat-defense%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fprotect%2Fmobile-threat-defense%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EAll%20this%20would%20give%20you%20the%20ability%20to%20to%20even%20more%20security%20checks%20on%20the%20device%20before%20allowing%20Outlook%2C%20Teams%2C%20etc.%20I%20think%20this%20is%20the%20intention%20of%20your%20initial%20ask.%20So%20if%20your%20leadership%20is%20okay%20to%20maybe%20switch%20the%20vendor%20here%20you%20might%20want%20to%20have%20a%20look%20at%20this.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3Ebest%2C%3C%2FP%3E%0A%3CP%3EOliver%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Yesterday we mass deployed Cisco umbrella to all iOS devices currently in Intune.

Up until now we only do fully managed devices (with and without user affinity)

 

Leadership team has expressed a potential desire to also deploy the Cisco umbrella app to personal mobile phones IF they are using it to access company resources.

 

My problem here is I do not know how I would even stop users from accessing Outlook, Teams, Onedrive from their personal mobiles and if they wanted to had to accept some security policies and the Cisco umbrella app to be deployed.

 

Could anyone help me out?

9 Replies
This should be done with Intune and Conditional Access:

- I would advise to look into Android Work Profiles and iOS User Enrollment and set that one up
- Configure Conditional Access to require a compliant device when accessing Exchange/Teams/Sharepoint...
- Setup Cisco Umbrella application push to all devices

Users will need to enroll when they try to access from a personal device

Would i need to do anything with MAM for this one ? in Azure AD there is this MAM & MDM section where you can turn them on or off. mine currently has MDM on and MAM off.

It really depends on how you want to setup personal devices.
How much do you want to manage those personal devices?

FYI, these MAM & MDM settings are only for W10 - https://docs.microsoft.com/en-us/mem/intune/enrollment/windows-enroll

@Thijs Lecomte I dont really want to manage personal devices in great detail. It sounds like we just want to make sure that if they want to access corporate data that they are to some extend managed so that we can make sure they are in compliance and our data is secure. If a user leave we should be able to remove just corporate data off the device.

Then you should look into implementing mobile application management without enrollment (https://allthingscloud.blog/manage-byod-devices-with-intune-mam-without-enrollment/)

Then you can manage only corporate data on the phones
Do note: then you cannot push the Cisco application

@Thijs Lecomte  In which case then what i want is not correct :) So im back to Android Work Profiles and IOS user enrolment right?

Correct :) You need to manage the device if you want to publish applications to them

Hey,

 

if we talk about push it is not possible to do so if a device is not enrolled, If we talk about a App Store functionality it is possible to provide users apps even without enrollment. The key thing there is to assign them to users not devices, only user assignment is working and then using the company portal. The web version of the company portal (https://portal.manage.microsoft.com/) will even allow you to install your custom LOB iOS apps for example. You need to confirm a few prompts but finally you can have a company in-house developed iOS app target to your users (without enrollment) via Company Portal and let them install the LOB app. Just go ahead, upload a app and assign it to the user and go to the web Company Portal. 

Yes it is no push, but self-service app store style is possible. For app updates it is the same they will not be pushed, the user would need to go again to the Company Postal to install the update.

 

best,

Oliver

Your initial request to bring more security to the unenrolled devices is done in the MS concept by using MTD connectors. This is available for unenrolled devices as well. 

 

https://docs.microsoft.com/en-us/mem/intune/protect/mtd-add-apps-unenrolled-devices

 

There are a few vendors supported but Cisco is not listed there. See here: https://docs.microsoft.com/en-us/mem/intune/protect/mobile-threat-defense

 

All this would give you the ability to to even more security checks on the device before allowing Outlook, Teams, etc. I think this is the intention of your initial ask. So if your leadership is okay to maybe switch the vendor here you might want to have a look at this.

 

best,

Oliver