iOS managed contacts - how to deal with that?

%3CLINGO-SUB%20id%3D%22lingo-sub-1473555%22%20slang%3D%22en-US%22%3EiOS%20managed%20contacts%20-%20how%20to%20deal%20with%20that%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1473555%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethe%20last%20years%20i've%20already%20tried%20to%20solve%20the%20problem%20with%20the%20managed%20contacts.%3C%2FP%3E%3CP%3EBecause%20this%20was%20not%20possible%20earlier%20i%20forgot%20about%20that.%3C%2FP%3E%3CP%3ENow%20i%20want%20to%20readress%20this%20issue.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20very%20important%20article%20i've%20found%20is%20this%20one%3A%3C%2FP%3E%3CP%3E%3CA%20title%3D%22Techcommunity%20Success%3A%20New%20contact%20sync%20scenario%20available%20with%20Outlook%20for%20iOS%20on%20enrolled%20devices%22%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fnew-contact-sync-scenario-available-with-outlook-for-ios-on%2Fba-p%2F1063632%22%20target%3D%22_blank%22%3ETechcommunity%20Success%3A%20New%20contact%20sync%20scenario%20available%20with%20Outlook%20for%20iOS%20on%20enrolled%20devices%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20this%20thread%20i%20would%20like%20to%20discuss%20some%20unanswered%20questions%20of%20myself.%3C%2FP%3E%3CP%3EI%20would%20really%20appreaciate%20any%20answer%20of%20you%20guys.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGoals%3A%3C%2FP%3E%3CUL%3E%3CLI%3EBusiness%20contacts%20should%20be%20able%20to%20be%20read%20through%20contacts%20app%20(because%20of%20caller-id)%3C%2FLI%3E%3CLI%3E3rd%20Party%20Messengers%20should%20not%20see%20these%20business%20contacts%3C%2FLI%3E%3C%2FUL%3E%3CP%3EThesises%3A%3C%2FP%3E%3COL%3E%3CLI%3EIt%20is%20not%20possible%20to%20achive%20this%20with%20Outlook%20for%20iOS%20and%20it's%20contact%20sync%20feature%2C%20right%3F%20(Because%20of%20these%20contacts%20are%20going%20to%20be%20synced%20through%20icloud%2C%20therefore%20these%20contacts%20are%20marked%20as%20%22unmanaged%20contacts.)%3C%2FLI%3E%3CLI%3EIt%20is%20possible%20to%20achive%20these%20goals%20by%20using%3A%3COL%3E%3CLI%3Ean%20device%20configuration%20profile%20which%20configures%20an%20active%20sync%20account%20which%20only%20synchronizes%20the%20contacts%20of%20the%20users%20mailbox.%20These%20contacts%20are%20considdered%20as%20%22managed%20contacts%22%3C%2FLI%3E%3CLI%3Ean%20app%20configuration%20profile%20which%20disables%20the%20%22sync%20contacts%22%20feature%20for%20%22outlook%20for%20ios%22%3C%2FLI%3E%3CLI%3EAn%20App%20protection%20policy%20which%20disables%20%22Viewing%20corporate%20documents%20in%20unmanaged%20apps%3C%2FLI%3E%3C%2FOL%3E%3C%2FLI%3E%3CLI%3EBecause%20of%20the%20fact%20this%20is%20only%20working%20for%20enrolled%20and%20managed%20devices%2C%20we%20need%20to%20tell%20the%20users%3A%20Caller%20identification%20is%20only%20possible%20if%20you%20enroll%20your%20device%20in%20Intune.%20(in%20relation%20to%20the%20previous%20points)%3C%2FLI%3E%3C%2FOL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20far%2C%20so%20good%2C%20but%20the%20bad%20news%20is%3A%3C%2FP%3E%3CUL%3E%3CLI%3EBecause%20of%20the%20incopatibility%20with%20conditional%20access%20policies%2C%20we're%20hence%20not%20able%20to%20restrict%20the%20user%20from%20using%20other%20apps%20to%20connect%20their%20EXO%20account.%20Right%3F%3C%2FLI%3E%3C%2FUL%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20would%20be%20very%20thankful%20if%20anyone%20can%20discuss%20this%20with%20me.%3C%2FP%3E%3CP%3E(I%20think%20the%20best%20way%20to%20adress%20the%20different%20topics%20is%20to%20quote%20my%20post%20and%20answer%20inline.)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGreetings%2C%3C%2FP%3E%3CP%3EPatrick%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1473555%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EConditional%20Access%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EiOS%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3Emanaged%20contacts%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547359%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20managed%20contacts%20-%20how%20to%20deal%20with%20that%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547359%22%20slang%3D%22en-US%22%3E%3CP%3ENo%20one%3F%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EThere%20must%20be%20oppinions%20out%20there.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547682%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20managed%20contacts%20-%20how%20to%20deal%20with%20that%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547682%22%20slang%3D%22en-US%22%3EOne%20option%20would%20be%20to%20turn%20off%20legacy%20authentication.%3CBR%20%2F%3EConfigure%20Exchange%20Active%20Sync%20rules%20to%20only%20allow%20Active%20Sync%20for%20the%20default%20mail%20app%20on%20iPhone.%3CBR%20%2F%3ETurn%20off%20enterprise%20app%20user%20consent%20so%20that%20users%20can't%20add%20any%20third%20party%20apps.%3CBR%20%2F%3E%3CBR%20%2F%3EHaven't%20tested%20this%20scenario%20though%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1549745%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20managed%20contacts%20-%20how%20to%20deal%20with%20that%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1549745%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F186539%22%20target%3D%22_blank%22%3E%40Thijs%20Lecomte%3C%2FA%3E%26nbsp%3BHi%20and%20thank%20you%20for%20your%20reply.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMy%20concerns%20are%20not%20about%20legacy%20or%20modern%20(by%20the%20way%20we%20disabled%20legacy%20authentication)%20but%20on%20how%20to%20deal%20with%20contacts.%3C%2FP%3E%3CP%3EAndroid%20is%20managing%20this%20one%20perfect%3A%3C%2FP%3E%3COL%3E%3CLI%3EThere%20is%20a%20managed%20contacts%20app%20with%20all%20the%20corporate%20exchange%20contacts%20of%20the%20user%20in%20it.%3C%2FLI%3E%3CLI%3EThe%20user%20can%20browse%20this%20contacts%20app%20or%20the%20native%20one%20and%20can%20dial%20a%20number%20right%20out%20of%20here.%3C%2FLI%3E%3CLI%3EThird%20party%20apps%20like%20Whatsapp%20or%20others%20are%20not%20able%20to%20look%20into%20these%20managed%20contacts.%3C%2FLI%3E%3C%2FOL%3E%3CP%3EFor%20iOS%20this%20must%20be%20possible%2C%20too%2C%20isn't%20it%3F%3C%2FP%3E%3CP%3EAt%20the%20moment%20where%20the%20user%20enables%20the%20contact%20sync%20from%20the%20outlook%20for%20ios%20app%2C%20the%20contacts%20are%20going%20to%20be%20transfered%20throught%20the%20icloud%20into%20the%20native%20contacts%20app.%3C%2FP%3E%3CP%3EThe%20Problem%20with%20this%20is%2C%20even%20if%20they're%20read-only%2C%20that%203rd%20party%20apps%20as%20mentioned%20before%20are%20able%20to%20see%20them.%3C%2FP%3E%3CP%3EWe%20don't%20want%20to%20disable%20contact%20sync%20at%20all%20(because%20of%20caller-id%20for%20incoming%20calls)%20but%203rd%20party%20apps%20shouldn't%20be%20able%20to%20read%20them.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDid%20i%20stated%20this%20clearly%3F%20(Hopefully%20%3A)%3C%2Fimg%3E%20)%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1553298%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20managed%20contacts%20-%20how%20to%20deal%20with%20that%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1553298%22%20slang%3D%22en-US%22%3EI%20understand%20your%20point.%20this%20might%20be%20possible%20with%20iOS%20User%20Enrollment%2C%20as%20this%20is%20the%20alternative%20for%20Work%20Profile.%20Have%20you%20checked%20this%20out%3F%3CBR%20%2F%3E%3CBR%20%2F%3EI%20haven't%20tested%20this%20scenario%20though%3C%2FLINGO-BODY%3E
Regular Contributor

Hi everyone,

 

the last years i've already tried to solve the problem with the managed contacts.

Because this was not possible earlier i forgot about that.

Now i want to readress this issue.

 

A very important article i've found is this one:

Techcommunity Success: New contact sync scenario available with Outlook for iOS on enrolled devices 

 

With this thread i would like to discuss some unanswered questions of myself.

I would really appreaciate any answer of you guys. :)

 

Goals:

  • Business contacts should be able to be read through contacts app (because of caller-id)
  • 3rd Party Messengers should not see these business contacts

Thesises:

  1. It is not possible to achive this with Outlook for iOS and it's contact sync feature, right? (Because of these contacts are going to be synced through icloud, therefore these contacts are marked as "unmanaged contacts.)
  2. It is possible to achive these goals by using:
    1. an device configuration profile which configures an active sync account which only synchronizes the contacts of the users mailbox. These contacts are considdered as "managed contacts"
    2. an app configuration profile which disables the "sync contacts" feature for "outlook for ios"
    3. An App protection policy which disables "Viewing corporate documents in unmanaged apps
  3. Because of the fact this is only working for enrolled and managed devices, we need to tell the users: Caller identification is only possible if you enroll your device in Intune. (in relation to the previous points)

 

So far, so good, but the bad news is:

  • Because of the incopatibility with conditional access policies, we're hence not able to restrict the user from using other apps to connect their EXO account. Right?

 

I would be very thankful if anyone can discuss this with me.

(I think the best way to adress the different topics is to quote my post and answer inline.)

 

Greetings,

Patrick

4 Replies

No one? :)

There must be oppinions out there. 

One option would be to turn off legacy authentication.
Configure Exchange Active Sync rules to only allow Active Sync for the default mail app on iPhone.
Turn off enterprise app user consent so that users can't add any third party apps.

Haven't tested this scenario though

@Thijs Lecomte Hi and thank you for your reply.

 

My concerns are not about legacy or modern (by the way we disabled legacy authentication) but on how to deal with contacts.

Android is managing this one perfect:

  1. There is a managed contacts app with all the corporate exchange contacts of the user in it.
  2. The user can browse this contacts app or the native one and can dial a number right out of here.
  3. Third party apps like Whatsapp or others are not able to look into these managed contacts.

For iOS this must be possible, too, isn't it?

At the moment where the user enables the contact sync from the outlook for ios app, the contacts are going to be transfered throught the icloud into the native contacts app.

The Problem with this is, even if they're read-only, that 3rd party apps as mentioned before are able to see them.

We don't want to disable contact sync at all (because of caller-id for incoming calls) but 3rd party apps shouldn't be able to read them.

 

Did i stated this clearly? (Hopefully :) )

I understand your point. this might be possible with iOS User Enrollment, as this is the alternative for Work Profile. Have you checked this out?

I haven't tested this scenario though