ios
61 TopicsIOS - Embedded Webkit - Not Reporting Correct Device info
It appears that with the latest iOS versions (26.3.1 through 26.4), applications that rely on an embedded WebKit for sign-in are no longer reporting accurate device details within Device Info. Users have company-issued phones that are successfully enrolled in Intune, but when they attempt to sign in to Apple Mail, Conditional Access is denying the login. After reviewing the logs, iOS is reporting the OS version as 18.7.0 to Intune, even though the device is actually running iOS 26.4. Additionally, the device information is coming through as blank, so attributes are not being evaluated. When looking at other logins via the outlook app on that device it all appears normal and works. Has anyone else observed this behavior where WebKit is sending incorrect data to Intune? Does anyone know of a workaround other than relaxing Conditional Access policies?Solved832Views1like7CommentsHave OneDrive or SharePoint files/folders on home screen of iPad without internet connection?
This. I'm on a big iOS project. We have several users who need files on an ipad when traveling, and be able to open them when there is no internet connectivity. These files aren't intended to be edited, just 'read only.' These files do not contain any sensitive corporate data. The content lives in SharePoint online and I'm using OneDrive as a bridge to their sharepoint site. BUT the files can only be viewed on the ipad within the OneDrive app without internet access. These are devices using user affinity enrollment. Initially, the solution for users was to use the 'Mark Offline' feature within the OneDrive iOS app. I used Power Automate to have it fetch new files found in OneDrive and move them to the teams SharePoint site. These shared devices are locked down (an understatement). These will be used by the least computer savy/literate people and so having them dive through OneDrive folder after folder, even offline, is a tall order to ask. I totally get it and don't want them doing that either. So now I have to move onto plan B. How can we put the files that live within OneDrive/Sharepoint onto the home screen without an internet connection when the ipad is 'out in the field.?' This would make it infinitely easier for them. The key here is to not have end users manually moving files around. We don't want them to even have to go into OneDrive and mark folders/files offline, if possible. We don't have the SharePoint app on them. I tried the SP app a while back, and it is a hot mess of garbage. I could revisit it. Whatever I can get to work of course we'll have to modify our Intune polices. Thoughts?41Views0likes0CommentsIntune MAM - Restrict Application Access to Specific Biometric Profiles
We want our employees to be able to restrict access to company apps on private devices to only specific biometric profiles on the devices. If needed: Are you working together with Apple to make this possible? (e.g. via tiered device control levels / admin password in iOS)104Views1like1CommentIntune - Issues with Account-Driven User Enrollment Issues on iOS 18.5
Hello everyone, Since the release of iOS 18, Apple has deprecated profile-based user enrollment via the Company Portal app, requiring the use of Account-Driven User Enrollment. While this change enhances user experience, I'm encountering challenges in implementing it. Steps Taken: Apple Business Manager (ABM) Account: Created and linked the ABM account to Intune using the token. Corporate devices are successfully appearing in Intune. MDM Server Configuration: Set Intune as the default MDM server for all devices in ABM. Domain Federation: Established Entra ID federation in ABM to synchronize all users. Intune Enrollment Profile: Created an 'Enrollment Type Profile' of type 'Account-Driven User Enrollment.' MDM Push Certificate: Configured and validated the MDM Push certificate. Issue Encountered: According to https://support.apple.com/guide/deployment/account-driven-enrollment-methods-dep4d9e9cd26/web, starting with iOS 18.2, hosting a service discovery file on a web server is no longer mandatory. The device should automatically contact the ABM organization associated with the Managed Apple ID if no web server is found. On an iOS 18.5 device, I navigate to: Settings > General > VPN & Device Management > Sign in to Work or School Account After entering my Microsoft email address (which matches my Managed Apple ID due to federation), I consistently receive the error: "Your Apple ID does not support the expected services on this device." In ABM, under "Access Management" > "Apple Services," all services are activated. Could I be missing a crucial step in the configuration? Any guidance or insights would be greatly appreciated. Thank you in advance for your help. Best regards,2.1KViews1like8CommentsHow best to configure ipad as kiosk for single web page?
I know I can configure Kiosk mode through intune to lock the ipad to a single app, but if that single app is Safari I need to restrict it to accessing a specified web site or sites. Is this possible via Intune? If not, does anyone have experience with a 3rd party browser for iOS with these capabilities that they would recommend?Solved26KViews0likes6CommentsRemove iOS device from assigned enrollment profile
Dear forum members, We all know we could assign a supervised device with a enrollment profile. In the https://go.microsoft.com/fwlink/?linkid=2109431, choose Devices > iOS > iOS enrollment > Enrollment Program Tokens > choose a token in the list. Choose Devices > choose devices in the list > Assign profile. Under Assign profile, choose a profile for the devices > Assign But how do you remove the device from a certain profile? When you select the device, you option is to choose which enrollment profile you want to assign to, but you can't choose blank. You have to choose a profile for the device. What I have been doing is delete the device from Intune and run the sync between ABM and Intune again to bring it back. This is obviously not ideal and probably not the right way to do. Can anyone please advise? Thank you!Solved25KViews0likes7CommentsVPP Apps Not Installing via Intune – Error 0x87D127DB Despite Valid Configuration
Hi everyone, We’re currently using Microsoft Intune in combination with Apple Business Manager (ABM) to provision iPhones in our organization. Our setup has worked reliably until recently: in April/May, we successfully deployed 50 iPhones without any issues. However, for the past 10 days, we’ve encountered a persistent issue: VPP apps are no longer installing automatically on newly enrolled devices. ✅ What’s working: Device registration in ABM Syncing devices from ABM to Intune Device renaming, resetting, and syncing via Intune Uninstall Apps using uninstall group of the deployment configuration on existing devices) Disabling devices in ABM and syncing changes to Intune Purchasing new apps in ABM and syncing them to Intune App license counts (total, used, available) are correctly shown in Intune ❌ What’s not working: VPP apps are not being installed. Only one or two icons appear on the home screen with a cloud symbol. Tapping them prompts a message that the app must be downloaded from the App Store. Intune consistently shows the following error: “App installation failed. 0x87D127DB (Unknown)” Occasionally, a message appears stating that VPP licenses could not be found, although all apps have sufficient licenses and Intune reflects this correctly. Troubleshooting steps taken: Devices have been reset multiple times New apps were purchased and assigned with a minimal configuration (one required group) All certificates (MDM push, VPP token, enrollment token, Apple SCIM token) are valid Apple Business Support confirms their services are operational Microsoft Support has not provided a resolution and suspects the issue lies with Apple Apple, in turn, refers us back to Microsoft At this point, we’re stuck between both vendors and are hoping someone in the community has encountered this issue or found a workaround. Has anyone else experienced this behavior or found a solution for the 0x87D127DB error with VPP apps in Intune? Thanks in advance for your help!Solved3.5KViews0likes7CommentsMake Required applications visible in Intune Company Portal on iOS
Hi everyone, I'm new to Intune and have a question. Is it possible to make required applications visible in the Intune Company Portal on iOS (supervised devices)? Currently, only "available" apps are shown. This would be really helpful because if a user deletes a required app, the automatic re-installation can sometimes take a long time. Thanks!651Views0likes4CommentsMobile keyboard issue: "Your organizations data cannot be pasted here" - Intune App Protection
I have an ongoing issue where I've setup an Intune app protection policy for unmanaged devices to restrict the ability to copy company data outside of company managed apps into personal apps. Whilst this feature works in respect to managed apps and non-managed apps, there is a UI issue on both Android and iOS where the keyboard clipboard shows straight after you copy text in a managed app: "Your organizations data cannot be pasted here". How do you stop this annoying popup that seems to relate to mobile keyboard clipboards? It's an annoying issue as users think they can't copy/paste between work apps. We have to tell them every time that if they just press down on screen then press paste, it pastes correctly. Example of our iOS policy is per below. Please help! There is also a good post here on it, will nil reply: https://www.androidenterprise.community/t5/general-discussions/issue-with-copy-paste-restriction-in-intune-mdm-on-android/m-p/86371.8KViews0likes0CommentsiOS 18.2 Configuration - App Store (settings) disappears in iOS settings
Hello, in our compandy we deploy our iOS devices using a device restrictions configuration in Intune. We have app store blocked, but until iOS 18.2 , the option of the settings for the app store was still available in the iOS settings. Now the app store disappers (on a private iPhone the app store moved under Apps). Unfortunately we need this option to configure the automatic downloads option via mobile network (and not asked for Apps over 200MB). Are there changes we can make that block the app store, yet still allow automatic updates over cellular data for managed apps? Thank you.275Views0likes0Comments