Intune and Application Protection without enrollment

%3CLINGO-SUB%20id%3D%22lingo-sub-852853%22%20slang%3D%22en-US%22%3EIntune%20and%20Application%20Protection%20without%20enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-852853%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20All%2C%3C%2FP%3E%3CP%3Ei've%20some%20questions%20about%20Intune%20%2F%20MAM%20%2F%20Application%20Protection%20Policys%20without%20Enrollment%2C%3C%2FP%3E%3CP%3Eas%20displayed%20in%20the%20screenshots%20the%20Device%20isnt%20managed%20by%20the%20Company%20its%20a'private%20one'%20but%20i%20want%20to%20use%20some%20cloud%20apps%20with%20protected%20corporate%20data.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131554iF9A0B7DE5934FE4A%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22APPS.jpg%22%20title%3D%22APPS.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131553i0A52A31A707937CF%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22checkin.jpg%22%20title%3D%22checkin.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131552i8DA3A8D585B8030B%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22dd_gruppe.jpg%22%20title%3D%22dd_gruppe.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20200px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131556i5DDF2E591C59463B%2Fimage-size%2Fsmall%3Fv%3D1.0%26amp%3Bpx%3D200%22%20alt%3D%22device.jpg%22%20title%3D%22device.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131559iCBCD5E606D62FA01%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22DLP.jpg%22%20title%3D%22DLP.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131558i0CCC36196822267E%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22groups.jpg%22%20title%3D%22groups.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131560i152B02F49133A884%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22intune_lizenz.jpg%22%20title%3D%22intune_lizenz.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-center%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F131561iFA2E690008411D33%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22pin_access.jpg%22%20title%3D%22pin_access.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEverything%20should%20be%20blocked%20and%20at%20starting%20the%20app%20a%20pin%20prompt%20should%20start%20up.%3C%2FP%3E%3CP%3EIt%20only%20shows%20the%20Data%20will%20be%20managed%20by%20the%20company%20dialog%20but%20its%20still%20possible%20to%20save%20the%20Documents%20local%20on%20the%20iPhone.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMaybe%20someone%20can%20figure%20out%20what%20its%20missing%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EKind%20regards%20-%20Thorsten%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-852853%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-854203%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20and%20Application%20Protection%20without%20enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-854203%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F408043%22%20target%3D%22_blank%22%3E%40ThorstenLubos%3C%2FA%3E%26nbsp%3BHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ewhen%20you%20open%20the%20App%20and%20create%20a%20new%20document%2C%20this%20unsaved%20document%20is%20not%20in%20corporate%20context.%20Because%20of%20this%2C%20you%20can%20save%20this%20NOT-Corp%20Document%20wherever%20you%20want.%20Only%20if%20you%20save%20the%20document%20in%20the%20company%20area%20(e.g.%20onedrive%20or%20sharepoint%20itself)%20the%20policy%20would%20be%20applied.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-856459%22%20slang%3D%22en-US%22%3ERe%3A%20Intune%20and%20Application%20Protection%20without%20enrollment%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-856459%22%20slang%3D%22en-US%22%3E%3CP%3EEverything%20should%20be%20blocked%20and%20at%20starting%20the%20app%20a%20pin%20prompt%20should%20start%20up.--%26gt%3B%3CSTRONG%3EFor%20this%20%2Cyou%20set%20PIN%20in%20MAM%20policy%20with%20time%20out%20of%20x%20min.%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapp-protection-policy-settings-ios%23access-requirements%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3ESo%20every%20x%20min%20if%20the%20app%20is%20idle%20then%20pin%20will%20be%20prompted.%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EIt%20only%20shows%20the%20Data%20will%20be%20managed%20by%20the%20company%20dialog%20but%20its%20still%20possible%20to%20save%20the%20Documents%20local%20on%20the%20iPhone.%20--You%20need%20to%20select%26nbsp%3B%3CSTRONG%3ESave%20copies%20of%20Org%20data%20to%20onedrive%20if%20you%20want%20users%20to%20store%20the%20data%20or%20allow%20local.%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapp-protection-policy-settings-ios%23data-protection%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fapp-protection-policy-settings-ios%23data-protection%3C%2FA%3E%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSTRONG%3ERefer%20the%20MAM%20FAQS%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fmam-faq%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fmam-faq%3C%2FA%3E%26nbsp%3B%3C%2FSTRONG%3E%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EEswar%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22http%3A%2F%2Fwww.eskonr.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ewww.eskonr.com%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Visitor

Hey All,

i've some questions about Intune / MAM / Application Protection Policys without Enrollment,

as displayed in the screenshots the Device isnt managed by the Company its a'private one' but i want to use some cloud apps with protected corporate data.

 

APPS.jpg

 

checkin.jpg

 

dd_gruppe.jpg

 

device.jpg

 

DLP.jpg

 

groups.jpg

 

intune_lizenz.jpg

 

pin_access.jpg

 

Everything should be blocked and at starting the app a pin prompt should start up.

It only shows the Data will be managed by the company dialog but its still possible to save the Documents local on the iPhone.

 

Maybe someone can figure out what its missing?

 

Kind regards - Thorsten

 

2 Replies

@ThorstenLubos Hi,

 

when you open the App and create a new document, this unsaved document is not in corporate context. Because of this, you can save this NOT-Corp Document wherever you want. Only if you save the document in the company area (e.g. onedrive or sharepoint itself) the policy would be applied.

Everything should be blocked and at starting the app a pin prompt should start up.-->For this ,you set PIN in MAM policy with time out of x min. So every x min if the app is idle then pin will be prompted.

It only shows the Data will be managed by the company dialog but its still possible to save the Documents local on the iPhone. --You need to select Save copies of Org data to onedrive if you want users to store the data or allow local. https://docs.microsoft.com/en-us/intune/app-protection-policy-settings-ios#data-protection

 

Refer the MAM FAQS https://docs.microsoft.com/en-us/intune/mam-faq 

Thanks,

Eswar

www.eskonr.com