MAM Policies - App

karthik palani 1,036 Reputation points
2024-07-14T11:02:57.3866667+00:00

Hi All,

I need your suggestions on below clarifications pls

  1. We don't want to enroll devices directly in Intune, but wanted to manage unenrolled devices. In this case, what user scope should i set

MAM.png

  1. For app protection policy to get applied on the device, should i deploy outlook app to unenrolled devices and only then it will get applied. Should i configure something under app configuration profile.
  2. Can i apply conditional access policies in unenrolled devices.

Please advice

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
939 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,030 questions
0 comments No comments
{count} votes

Accepted answer
  1. Rahul Jindal [MVP] 9,966 Reputation points MVP
    2024-07-14T11:40:21.3033333+00:00

    “For app protection policy to get applied on the device, should i deploy outlook app to unenrolled devices and only then it will get applied. Should i configure something under app configuration profile.” - You can only deploy apps to a managed device. What you need is to setup App protection and app configuration policies to apply through MAM channel.

    “Can i apply conditional access policies in unenrolled devices.” - Yes you can by using APP as the condition in CA. For this to work, you will obviously need to make sure that the App you want to manage supports Intune SDK in order to apply APP through MAM channel in the first place.


1 additional answer

Sort by: Most helpful
  1. Xenia-MSFT 2,180 Reputation points Microsoft Vendor
    2024-07-15T02:33:19.5466667+00:00

    @karthik palani Thanks for posting in our Q&A.

    “We don't want to enroll devices directly in Intune but wanted to manage unenrolled devices. In this case, what user scope should I set”

    ----Yes, you can configure as it shows in the picture. Based on my experience, what "MDM user scope" you configured will not affect MAM.

    Hope it will helpful.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.