Third party user accounts and MDM

%3CLINGO-SUB%20id%3D%22lingo-sub-1486206%22%20slang%3D%22en-US%22%3EThird%20party%20user%20accounts%20and%20MDM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1486206%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESo%20we%20already%20know%20that%20Intune%20on%20Android%20doesn't%20allow%20the%20user%20to%20add%20a%20Google%20Account%20to%20a%20Work%20Profile.%20Painful%20and%20silly%2C%20but%20nothing%20we%20can%20do%20about%20it%20until%20MS%20removes%20this%20restriction.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETaking%20another%20approach%20I've%20tried%20using%20Google's%20MDM%20for%20Android%20devices%20which%20is%20fine%20if%20annoying%20at%20having%20to%20pay%20for%20two%20different%20solutions.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%20there's%20no%20way%20to%20make%20the%20user's%20Azure%20AD%20account%20only%20be%20usable%20within%20a%20Google%20managed%20Work%20Profile.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThis%20got%20me%20thinking%20about%20MDM%20on%20phones.%20As%20far%20as%20I%20can%20tell%2C%20whatever%20MDM%20solution%20you%20use%2C%20you've%20no%20way%20of%20forcing%20any%20other%20corporate%20accounts%20that%20the%20user%20may%20have%20to%20be%20only%20available%20within%20that%20work%20profile.%3C%2FP%3E%3CP%3EAnd%20as%20you%20can%20only%20have%20one%20work%20profile%2C%20as%20an%20Administrator%20I%20can%20either%20control%20the%20Azure%20AD%20account%20on%20the%20phone%20or%20the%20Google%20Account.%20I%20can't%20do%20both%20which%20seems%20like%20a%20massive%20gap.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20by%20some%20miracle%20you've%20managed%20to%20make%20everything%20SSO%2C%20you're%20OK%2C%20but%20given%20how%20many%20companies%20charge%20a%20massive%20premium%20if%20you%20want%20to%20use%20Azure%20as%20SSO%2C%20it's%20often%20not%20practical.%3C%2FP%3E%3CP%3EPlus%20you%20can%20log%20into%20websites%20with%20the%20credentials%20in%20the%20personal%20part%20of%20your%20phone%20anyway.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20else%20run%20into%20this%3F%20Am%20I%20missing%20something%3F%20Or%20is%20it%20just%20the%20way%20it%20is%2C%20MDM%20is%20a%20little%20Emperors%20new%20clothes%20from%20a%20security%20perspective%20but%20simply%20a%20convenient%20way%20of%20not%20crossing%20the%20streams%20between%20work%20and%20personal%20from%20an%20end%20users%20perspective%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1486206%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Highlighted
Occasional Contributor

Hi all,

 

So we already know that Intune on Android doesn't allow the user to add a Google Account to a Work Profile. Painful and silly, but nothing we can do about it until MS removes this restriction.

 

Taking another approach I've tried using Google's MDM for Android devices which is fine if annoying at having to pay for two different solutions.

 

However there's no way to make the user's Azure AD account only be usable within a Google managed Work Profile.

 

This got me thinking about MDM on phones. As far as I can tell, whatever MDM solution you use, you've no way of forcing any other corporate accounts that the user may have to be only available within that work profile.

And as you can only have one work profile, as an Administrator I can either control the Azure AD account on the phone or the Google Account. I can't do both which seems like a massive gap.

 

If by some miracle you've managed to make everything SSO, you're OK, but given how many companies charge a massive premium if you want to use Azure as SSO, it's often not practical.

Plus you can log into websites with the credentials in the personal part of your phone anyway.

 

Anyone else run into this? Am I missing something? Or is it just the way it is, MDM is a little Emperors new clothes from a security perspective but simply a convenient way of not crossing the streams between work and personal from an end users perspective?

0 Replies