iOS Outook sync to Contact app, protection from non managed apps

%3CLINGO-SUB%20id%3D%22lingo-sub-2154337%22%20slang%3D%22en-US%22%3EiOS%20Outook%20sync%20to%20Contact%20app%2C%20protection%20from%20non%20managed%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2154337%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Eis%20it%20possible%20to%20protect%20synced%20contacts%20on%20a%20iOS%20device%3F%26nbsp%3B%3C%2FP%3E%3CP%3ELets%20say%20I%20have%20a%20byod%20iPhone%20or%20a%20company%20owned%20one.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnd%20all%20my%20apps%20like%20Outlook%20etc.%20are%20managed%20and%20have%20app%20protection%20policies%20assigned.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20it%20possible%20to%20use%20the%20native%20iOS%20contacts%20%2B%20calling%20app%20without%20giving%20other%20apps%20like%20Whatsapp%20or%20Facebook%20access%20to%20the%20contacts%20which%20were%20synced%20by%20the%20company%20Outlook%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWhats%20the%20most%20convenient%20way%20to%20use%20an%20iOS%20device%20while%20also%20protecting%20company%20data%20as%20good%20as%20possible%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20to%20anyone%20helping.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-2154337%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Application%20Management%20(MAM)%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2155438%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20Outook%20sync%20to%20Contact%20app%2C%20protection%20from%20non%20managed%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2155438%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F454391%22%20target%3D%22_blank%22%3E%40nirispa%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHmm%2C%20I%20feel%20like%20there%20no%20easy%20way%20to%20do%20this%20without%20disabling%20the%20whole%20Contact%20sync%20with%20Native%20apps.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWith%20App%20Protection%20policy%20you%20can%20Block%20the%26nbsp%3B%3CSTRONG%3ESync%20policy%20managed%20app%20data%20with%20native%20apps%20%3C%2FSTRONG%3Esetting%20that%20will%20keep%20the%20company%20Contacts%20within%20Outlook%20app%20which%20might%20be%20pretty%20inconvenient%20for%20most%20users%20but%20will%20definitely%20guarantee%20the%20contact%20security.%26nbsp%3B%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EReferred%20Docs%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmem%2Fintune%2Fapps%2Fapp-protection-policy-settings-ios%23functionality%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EiOS%2FiPadOS%20app%20protection%20policy%20settings%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOther%20option%20would%20be%20to%20make%20a%20compliance%20policy%20for%20Unwanted%20apps%20and%20just%20mark%20the%20device%20as%20incompliant%20and%20block%20access%20to%20cloud%20resources%20with%20Conditional%20Access%20policy%20until%20the%20user%20removes%20the%20violating%20app.%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2157175%22%20slang%3D%22en-US%22%3ERe%3A%20iOS%20Outook%20sync%20to%20Contact%20app%2C%20protection%20from%20non%20managed%20apps%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2157175%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F41545%22%20target%3D%22_blank%22%3E%40Alo%20Press%3C%2FA%3E%26nbsp%3BHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20found%20this%20link%20which%20seems%20to%20make%20it%20work%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fblog.daveinfotech.com.au%2F2019%2F01%2Fintune-unable-to-see-managed-contacts.html%23%3A~%3Atext%3DClick%2520on%2520Block%2520%252D%2520%2527the%2520Viewing%2Cunmanaged%2520apps%2527%2520to%2520Not%2520configured.%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EHow%20to%20enable%20iOS%20unmanaged%20apps%20to%20read%20managed%20contacts%20%26amp%3B%20write%20unmanaged%20contacts%20without%20compromising%20security%20using%20Microsoft%20Intune%20(daveinfotech.com.au)%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20will%20try%20this%20tomorrow%20to%20see%20if%20this%20works%20and%20reply%20back%20later.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20this%20Link%20is%20interesting%3A%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fconfigmgrblog.com%2F2019%2F01%2F12%2Fios-12-1-allows-managed-contacts-to-be-written-from-managed-apps-to-native-contacts-app%2F%3Funapproved%3D626546%26amp%3Bmoderation-hash%3D52c752b4450496dd3f029be1c7bd6bd4%23comment-626546%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3EiOS%2012.1%20allows%20managed%20contacts%20to%20be%20written%20from%20managed%20apps%20to%20native%20contacts%20app%20%7C%20Enterprise%20Mobility%20and%20Enterprise%20Client%20Management%20Blog%20(configmgrblog.com)%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22%3CSTRONG%3EGreat%20news!%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3C%2FSTRONG%3E%3CSPAN%3EWith%20the%20release%20of%20iOS%2012.1%20Apple%20created%20two%20settings%20that%20allow%20you%20to%20control%20if%20contacts%20can%20be%20written%20to%20the%20contacts%20app%20by%20managed%20apps%20and%20a%20setting%20that%20allows%20you%20to%20control%20if%20unmanaged%20apps%20can%20read%20the%20managed%20contacts%20accounts.%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EDo%20you%20have%20any%20idea%20if%20this%20is%20ture%3F%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello,

 

is it possible to protect synced contacts on a iOS device? 

Lets say I have a byod iPhone or a company owned one.

 

And all my apps like Outlook etc. are managed and have app protection policies assigned.

 

Is it possible to use the native iOS contacts + calling app without giving other apps like Whatsapp or Facebook access to the contacts which were synced by the company Outlook?

 

Whats the most convenient way to use an iOS device while also protecting company data as good as possible?

 

Thanks in advance to anyone helping.

5 Replies

Hello @nirispa 

 

Hmm, I feel like there no easy way to do this without disabling the whole Contact sync with Native apps.

 

With App Protection policy you can Block the Sync policy managed app data with native apps setting that will keep the company Contacts within Outlook app which might be pretty inconvenient for most users but will definitely guarantee the contact security.  

 

Referred Docs: iOS/iPadOS app protection policy settings

 

Other option would be to make a compliance policy for Unwanted apps and just mark the device as incompliant and block access to cloud resources with Conditional Access policy until the user removes the violating app. 

@Alo Press Hello,

 

I have found this link which seems to make it work:
How to enable iOS unmanaged apps to read managed contacts & write unmanaged contacts without comprom...

 

I will try this tomorrow to see if this works and reply back later.

 

Also this Link is interesting:
iOS 12.1 allows managed contacts to be written from managed apps to native contacts app | Enterprise...

 

"Great news! With the release of iOS 12.1 Apple created two settings that allow you to control if contacts can be written to the contacts app by managed apps and a setting that allows you to control if unmanaged apps can read the managed contacts accounts."

 

Do you have any idea if this is ture?

Hi @nirispa 

 

Good find! Not sure, and the wording has changed a little but I suggest you try a limited scope profile on your own user to find out, it does sound like it could be what you were looking for. 

 

Check out the MS Docs: iOS/iPadOS device settings in Microsoft Intune - Azure | Microsoft Docs

 

Block viewing non-corporate documents in corporate apps: Yes prevents viewing non-corporate documents in corporate apps. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow any document to be viewed in corporate managed apps. Yes also prevents contact export synchronization in Outlook for iOS/iPadOS.

 

For more information on the specific values that can be configured I suggest you take a closer look at this Support Tip: Support Tip: Enabling Outlook iOS/iPadOS Contact Sync with iOS12 MDM Controls.

@nirispa Hi nirispa, maybe you can take a look at the discussion here: New contact sync scenario available with Outlook for iOS on enrolled devices - Microsoft Tech Commun... it´s basically the same requirement from what I understood in your post.

 

Regarding your link to iOS 12.1:

The main issue here is even though you can sync from managed (MEM) Outlook to contacts app, once the contacts are synced to the contacts app of iOS they are in an unmanaged app, meaning that you can´t control any further if e.g. WhatsApp gets access to them or not.

The second setting just controls, wether unmanaged apps can directly access contacts within a managed app like Outlook, which is not very useful for our case IMHO.

 

Mike

 

Hello Mike,

this seems like a solution. I have tried to deploy it but I get this error:
-2016341112 (iOS device is currently busy)
Also, my Company Portal keeps telling me that it can't set up my company mail because I still need to remove my company mail, even doe I am using a fresh setup iPhone with no email configured, Outlook was not installed before downloading the Company Portal (deploy Outlook and other apps).

I will keep trying and update this thread if I find a solution for this issue...

Thanks for the article as it helps and sheds light on the situation.

Br,
Stefan