iOS User Enrollment - Remove device from intune

Anonymous
2020-10-09T08:35:17.23+00:00

Hello,

We got such problem. I have iOS devices enrolled to intune using User Enrollment. I have create conditional access policy and deployed it to ios user groups so that users who doesn't enroll they device can't get to the company resource.

The problem.

When i delete ios device from intune. On the device:

  1. Deletes management profile;
  2. Signs out from company portal and informs user that his device was removed;
  3. But if users was logged in outlook, onedrive, teams etc. - he could access company resources.

After 1 hour, if they try to reach company resource -> they receive notification in application that they need to enroll theirs device . So it's means that after deleting ios device from intune, conditional access policy applies only after 1 hour, but no immediately.

Maybe you got some suggestions? Or maybe there something need to be changed in configuration?

Thank you!

Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Other
0 comments No comments
{count} votes

Accepted answer
  1. ESWARARAJU KONETI 2,206 Reputation points MVP Volunteer Moderator
    2020-10-09T09:41:20.157+00:00

    The delay could be because of the access token that is valid for an hour. If you want to speed this up, you can try to perform the device wipe which will revoke the data (only corporate data).

    Regards,
    Eswar
    www.eskonr.com

    1 person found this answer helpful.
    0 comments No comments

3 additional answers

Sort by: Most helpful
  1. Anonymous
    2020-10-09T10:27:27.167+00:00

    So in my case in iOS User Enrollment i need to use selective wipe?

    Because in user enrollment scenario, device cannot be wiped.


  2. ESWARARAJU KONETI 2,206 Reputation points MVP Volunteer Moderator
    2020-10-10T08:06:38.6+00:00

    You can try the retire option which removes only the corporate data/apps etc. Please read https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#retire for more about the retire option.

    Thanks,
    Eswar

    0 comments No comments

  3. Anonymous
    2020-10-13T07:54:52.167+00:00

    Hello

    I used selective wipe on device and then delete it.

    Everything runned successfully.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.