SOLVED

User's can delete Company Portal app on DEP / ABM Supervised Devices

%3CLINGO-SUB%20id%3D%22lingo-sub-1105617%22%20slang%3D%22en-US%22%3EUser's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1105617%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20a%20recent%20UAT%2C%20it%20is%20noticed%20that%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUser's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20this%20by%20design%3F%20Any%20way%20to%20prevent%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegards%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1105617%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1108185%22%20slang%3D%22en-US%22%3ERe%3A%20User's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1108185%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%20You%20can%20configure%20%22Block%20app%20removal%22%20in%20the%20restrictions%20policy%20to%20block%20the%20removal%20of%20apps%2C%20but%20this%20takes%20effect%20for%20all%20apps%20on%20the%20device.%20Instead%2C%20I've%20configured%20Comp%20Portal%20as%20a%20required%20VPP%20app%20(device%20license)%2C%20so%20if%20it's%20removed%20by%20the%20end-user%20it%20will%20reinstall.%20This%20has%20been%20the%20better%20option%20for%20our%20organization.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1108341%22%20slang%3D%22en-US%22%3ERe%3A%20User's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1108341%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254026%22%20target%3D%22_blank%22%3E%40eglockling%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHi%20Buddy%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20Block%20App%20removal%20may%20be%20ok.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnytime%20I%20set%20the%20Intune%20CP%20VPP%20app%20to%20auto%20deploy%20from%20Intune%20a%20%22Guided%20access%20unavailable%22%20error%20appears%20on%20the%20device.%20Remove%20Intune%20CP%20VPP%20assignment%20and%20it%20goes%20away.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20ideas%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1109164%22%20slang%3D%22en-US%22%3ERe%3A%20User's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1109164%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDo%20you%20have%20%22Run%20Company%20Portal%20in%20single%20app%20mode%20until%20authentication%3D%20YES%22%3F%20Change%20it%20to%20NO%20and%20see%20if%20you%20still%20see%20the%20error.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIn%20addition%20to%20Block%20app%20removal%2C%20use%20lock%20enrollment%20to%20disable%20users%20from%20removing%20Management%20profiles%20from%20Setting.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EMoe%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1113622%22%20slang%3D%22en-US%22%3ERe%3A%20User's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1113622%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F503735%22%20target%3D%22_blank%22%3E%40Moe_Kinani%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EUnfortunately%20the%20CP%20in%20Single%20App%20Mode%20is%20a%20client%20requirement%20as%20well%20as%20the%20CP%20not%20being%20removed%20from%20the%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDoes%20enabling%20the%20CP%20in%20Single%20App%20Mode%20and%20a%20Required%20deployment%20of%20the%20CP%20VPP%20app%20work%20nice%20together%3F%20Does%20the%20%22Guided%20Access%20Unavailable%22%20message%20eventually%20go%20away%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1115425%22%20slang%3D%22en-US%22%3ERe%3A%20User's%20can%20delete%20Company%20Portal%20app%20on%20DEP%20%2F%20ABM%20Supervised%20Devices%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1115425%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%20Having%20Company%20Portal%20set%20as%20a%20required%20VPP%20app%20works%20well%20for%20enforcing%20automatic%20app%20updates.%20%3CSPAN%3EAccording%20to%20Microsoft%20the%20message%20should%20go%20away%20after%20about%2045-60%20seconds.%20Apparently%20they%20have%20a%20feature%20request%20in%20with%20Apple%20to%20customize%20the%20message%20(last%20updated%209%2F21%2F18).%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsupport-tip-navigating-the-new-single-app-mode-for-company%2Fba-p%2F280173%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fintune-customer-success%2Fsupport-tip-navigating-the-new-single-app-mode-for-company%2Fba-p%2F280173%3C%2FA%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E
Regular Contributor

Hi All

 

On a recent UAT, it is noticed that:

 

User's can delete Company Portal app on DEP / ABM Supervised Devices.

 

Is this by design? Any way to prevent this?

 

Regards

5 Replies

@Stuart King  You can configure "Block app removal" in the restrictions policy to block the removal of apps, but this takes effect for all apps on the device. Instead, I've configured Comp Portal as a required VPP app (device license), so if it's removed by the end-user it will reinstall. This has been the better option for our organization.

@eglockling 

 

Hi Buddy

 

The Block App removal may be ok.

 

Anytime I set the Intune CP VPP app to auto deploy from Intune a "Guided access unavailable" error appears on the device. Remove Intune CP VPP assignment and it goes away.

 

Any ideas?

Hi @Stuart King,

 

Do you have "Run Company Portal in single app mode until authentication= YES"? Change it to NO and see if you still see the error. 

 

In addition to Block app removal, use lock enrollment to disable users from removing Management profiles from Setting.

 

Moe 

@Moe_Kinani 

 

Unfortunately the CP in Single App Mode is a client requirement as well as the CP not being removed from the device.

 

Does enabling the CP in Single App Mode and a Required deployment of the CP VPP app work nice together? Does the "Guided Access Unavailable" message eventually go away?

best response confirmed by Stuart King (Regular Contributor)
Solution

@Stuart King  Having Company Portal set as a required VPP app works well for enforcing automatic app updates. According to Microsoft the message should go away after about 45-60 seconds. Apparently they have a feature request in with Apple to customize the message (last updated 9/21/18).

 

https://techcommunity.microsoft.com/t5/intune-customer-success/support-tip-navigating-the-new-single...