Intune and Shared iPad

Mastering M365 21 Reputation points
2022-07-01T16:45:19.983+00:00

Topic : Intune and shared iPad.

Question 1) Microsoft documentation for Shared iPad says federation as 'required'. What is not clear is if Azure AD federation a mandatory requirement for shared iPad deployment ? Can this be configured without federation such that only a guest user 'temporary sessions' is allowed to login.

https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-shared-ios#important-considerations-when-choosing-a-shared-device-solution-for-ios-and-ipados

Question 2 ) Is there any reason by design, why VPP apps are not available on policy sets ? is it because the apps from VPP are not being deployed from Intune instead come from ABM ?

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 53,991 Reputation points Microsoft External Staff
    2022-07-04T01:46:41.383+00:00

    @Mastering M365 , For your questions, here are my answers for your reference:

    Q1: Microsoft documentation for Shared iPad says federation as 'required'. What is not clear is if Azure AD federation a mandatory requirement for shared iPad deployment ? Can this be configured without federation such that only a guest user 'temporary sessions' is allowed to login.
    A1: For the AAD federation, I think it means if we need users to sign in using their AAD username and password, then the AAD federation is required. In iPadOS 13.4 or later, users is allowed to sign in as Guest account. We can see more details in the following link:
    https://learn.microsoft.com/en-us/mem/intune/enrollment/device-enrollment-shared-ipad#configure-temporary-sessions-on-shared-ipads

    Q2: Is there any reason by design, why VPP apps are not available on policy sets ? is it because the apps from VPP are not being deployed from Intune instead come from ABM ?
    A2: For VPP, the app is purchased using ABM or ASM, then it can sync to Intune to deploy.
    https://learn.microsoft.com/en-us/mem/intune/apps/vpp-apps-ios

    Currently, only the following app types are currently supported by policy sets:

    • iOS/iPadOS store app
    • iOS/iPadOS line-of-business app
    • Managed iOS/iPadOS line-of-business app
    • Android store app
    • Android line-of-business app
    • Managed Android line-of-business app
    • Microsoft 365 Apps (Windows 10)
    • Web link
    • Built-in iOS/iPadOS app
    • Built-in Android app

    And the VPP is not in the list.. For the detailed reason, I am not sure. i didn't find it mention in any official article.
    https://learn.microsoft.com/en-us/mem/intune/fundamentals/policy-sets#policy-sets-known-issues

    But you can feedback to Intune uservoice to see if it can be added in the later future:
    https://feedbackportal.microsoft.com/feedback/forum/ef1d6d38-fd1b-ec11-b6e7-0022481f8472

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.