How to stop users connecting to things with their work account from personal mobile

%3CLINGO-SUB%20id%3D%22lingo-sub-1480226%22%20slang%3D%22en-US%22%3EHow%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480226%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ENot%20entirely%20sure%20how%20to%20word%20the%20title%2Fsubject%20but%20just%20wondered.%20If%20i%20wanted%20to%20stop%20myself%20from%20opening%20up%20my%20work%20email%20and%20calendar%20from%20the%20Outlook%20app%20on%20my%20personal%20mobile%20(because%20its%20not%20enrolled%20in%20Intune)%20how%20do%20i%20do%20that%3F%3C%2FP%3E%3CP%3EI'm%20guessing%20its%20something%20to%20do%20with%20MAM%3F%20but%20unsure%20on%20what%20i%20need%20to%20set%20it%20up%20or%20if%20we%20did%20want%20it%20how%20do%20we%20keep%20control%20over%20that%20bit%3F%20like%20delete%20data%20if%20a%20person%20leaves%20the%20company%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1480226%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1480331%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480331%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632351%22%20target%3D%22_blank%22%3E%40RippieUK%3C%2FA%3E%26nbsp%3BHey!%20I%20don't%20work%20with%20CA%2FIntune%20as%20we%20have%20a%20separate%20unit%20for%20that%2C%20but%20if%20I%20understand%20your%20question%20correct%20I%20believe%20you%20should%20use%20the%20Grant%20section%20in%20the%20policy%20and%20%22require%20device%20to%20be%20marked%20as%20compliant%22%20or%20%22require%20approved%20client%20app%22%20for%20example%2C%20to%20have%20them%20registered%20in%20AAD.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fconcept-conditional-access-grant%23%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fazure%2Factive-directory%2Fconditional-access%2Fconcept-conditional-access-grant%23%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1480412%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480412%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F551905%22%20target%3D%22_blank%22%3E%40bec064%3C%2FA%3E%26nbsp%3Bso%20CA%20is%20considered%20but%20not%20all%20our%20users%20are%20on%20a%20license%20that%20allow%20them%20CA%20hence%20why%20i%20wanted%20to%20know%20how%20to%20do%20this%20without%20CA.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBut%20if%20people%20want%20to%20set%20up%20work%20email%20on%20their%20personal%20phones%2C%20then%20at%20least%20we%20need%20to%20make%20sure%20its%20secure.%20%3A)%3C%2Fimg%3E%20hence%20why%20i%20thought%20of%20MAM%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1480757%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1480757%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632351%22%20target%3D%22_blank%22%3E%40RippieUK%3C%2FA%3E%26nbsp%3BHello!%20OK%2C%20you%20didn't%20mention%20all%20users%20aren't%20eligible%20for%20CA.%20Have%20you%20looked%20at%20this%20then%3F%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fmam-faq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fmam-faq%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20just%20to%20put%20it%20out%20there%20you%20also%20have%20the%20built-in%20MDM%20in%20Office%20365%20and%20in%20that%20case%20you%20would%20end%20up%20with%26nbsp%3BOffice%20365%20MDM%20Coexistence%20and%20the%26nbsp%3Bmanagement%20authority%20being%20defined%20based%20on%20the%20license%20assigned%20to%20the%20user.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Foffice%2Fset-up-mobile-device-management-mdm-in-microsoft-365-dd892318-bc44-4eb1-af00-9db5430be3cd%3Fui%3Den-us%26amp%3Brs%3Den-gb%26amp%3Bad%3Dgb%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.microsoft.com%2Fen-gb%2Foffice%2Fset-up-mobile-device-management-mdm-in-microsoft-365-dd892318-bc44-4eb1-af00-9db5430be3cd%3Fui%3Den-us%26amp%3Brs%3Den-gb%26amp%3Bad%3Dgb%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1482568%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1482568%22%20slang%3D%22en-US%22%3ERippieUK%2C%3CBR%20%2F%3E%3CBR%20%2F%3EMAM%20should%20be%20the%20best%20fit%20for%20your%20scenario.%20You%20can%20assign%20PIN%20for%20all%20company%20apps%2C%20you%20can%E2%80%99t%20wipe%20the%20apps%20remotely%20but%20you%20can%20disable%20their%20users%20from%20O365%20which%20prevent%20them%20from%20log%20in.%3CBR%20%2F%3E%3CBR%20%2F%3EIn%20Android%2C%20it%20forces%20them%20to%20install%20the%20Company%20Portal%20(They%20have%20to%20postpone%20without%20enrolling%20MDM)%20to%20all%20access%20to%20company%20data.%3CBR%20%2F%3E%3CBR%20%2F%3EGood%20luck!%3CBR%20%2F%3EMoe%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1482773%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1482773%22%20slang%3D%22en-US%22%3EHello%20Moe!%20Glad%20I%20pointed%20towards%20MAM%20then!%20I%20know%20this%20is%20your%20area%20of%20expertise%20%3A)%3C%2Fimg%3E%20Thanks%20for%20the%20input!%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1485628%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20stop%20users%20connecting%20to%20things%20with%20their%20work%20account%20from%20personal%20mobile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1485628%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F632351%22%20target%3D%22_blank%22%3E%40RippieUK%3C%2FA%3E%26nbsp%3BMAM%20is%20indeed%20a%20good%20way%20to%20go%2C%20but%20you%20need%20something%20to%20make%20sure%20those%20App%20protection%20(MAM)%20policies%20are%20applied%20to%20the%20mobile%20apps.%20For%20example%20to%20Outlook%20mobile%20when%20the%20users%20opens%20the%20mailbox%2C%20because%20that%20app%20supports%20these%20kind%20of%20policies.%20Most%20third-party%20mail%20apps%20don%60t%20support%20these%20kind%20of%20policies.%20And%20that%60s%20why%20CA%20policies%20are%20needed.%3CBR%20%2F%3E%3CBR%20%2F%3EMore%20on%20that%20can%20be%20found%20on%20my%20blog%20post%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.inthecloud247.com%2Fazure-ad-conditional-access-explained-android-and-ios%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.inthecloud247.com%2Fazure-ad-conditional-access-explained-android-and-ios%2F%3C%2FA%3E%3CBR%20%2F%3EIf%20you%20have%20any%20questions%2C%20let%20me%20know!%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

Hi all, 

 

Not entirely sure how to word the title/subject but just wondered. If i wanted to stop myself from opening up my work email and calendar from the Outlook app on my personal mobile (because its not enrolled in Intune) how do i do that?

I'm guessing its something to do with MAM? but unsure on what i need to set it up or if we did want it how do we keep control over that bit? like delete data if a person leaves the company?

6 Replies

@RippieUK Hey! I don't work with CA/Intune as we have a separate unit for that, but if I understand your question correct I believe you should use the Grant section in the policy and "require device to be marked as compliant" or "require approved client app" for example, to have them registered in AAD.

 

https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-acces...

 

 

@ChristianBergstrom so CA is considered but not all our users are on a license that allow them CA hence why i wanted to know how to do this without CA. 

 

But if people want to set up work email on their personal phones, then at least we need to make sure its secure. :) hence why i thought of MAM

@RippieUK Hello! OK, you didn't mention all users aren't eligible for CA. Have you looked at this then? https://docs.microsoft.com/en-us/mem/intune/apps/mam-faq

 

And just to put it out there you also have the built-in MDM in Office 365 and in that case you would end up with Office 365 MDM Coexistence and the management authority being defined based on the license assigned to the user.

 

https://support.microsoft.com/en-gb/office/set-up-mobile-device-management-mdm-in-microsoft-365-dd89...

RippieUK,

MAM should be the best fit for your scenario. You can assign PIN for all company apps, you can’t wipe the apps remotely but you can disable their users from O365 which prevent them from log in.

In Android, it forces them to install the Company Portal (They have to postpone without enrolling MDM) to all access to company data.

Good luck!
Moe
Hello Moe! Glad I pointed towards MAM then! I know this is your area of expertise :) Thanks for the input!

@RippieUK MAM is indeed a good way to go, but you need something to make sure those App protection (MAM) policies are applied to the mobile apps. For example to Outlook mobile when the users opens the mailbox, because that app supports these kind of policies. Most third-party mail apps don`t support these kind of policies. And that`s why CA policies are needed.

More on that can be found on my blog post https://www.inthecloud247.com/azure-ad-conditional-access-explained-android-and-ios/
If you have any questions, let me know!