question

Eduards-Grebezs avatar image
0 Votes"
Eduards-Grebezs asked Crystal-MSFT commented

iOS User Enrollment - Remove device from intune

Hello,

We got such problem. I have iOS devices enrolled to intune using User Enrollment. I have create conditional access policy and deployed it to ios user groups so that users who doesn't enroll they device can't get to the company resource.

The problem.

When i delete ios device from intune. On the device:
1) Deletes management profile;
2) Signs out from company portal and informs user that his device was removed;
3) But if users was logged in outlook, onedrive, teams etc. - he could access company resources.

After 1 hour, if they try to reach company resource -> they receive notification in application that they need to enroll theirs device . So it's means that after deleting ios device from intune, conditional access policy applies only after 1 hour, but no immediately.

Maybe you got some suggestions? Or maybe there something need to be changed in configuration?

Thank you!

intune-generalintune-device-configuration
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

EswarKoneti-MVP avatar image
1 Vote"
EswarKoneti-MVP answered

The delay could be because of the access token that is valid for an hour. If you want to speed this up, you can try to perform the device wipe which will revoke the data (only corporate data).



Regards,
Eswar
www.eskonr.com

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Eduards-Grebezs avatar image
0 Votes"
Eduards-Grebezs answered Crystal-MSFT commented

So in my case in iOS User Enrollment i need to use selective wipe?

Because in user enrollment scenario, device cannot be wiped.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@EduardsGrebes-8297, Your understanding is correct. We can try selectively wipe to remove corporate app data by creating a wipe request. The following link for the reference:
https://docs.microsoft.com/bs-cyrl-ba/mem/intune/apps/apps-selective-wipe#create-a-wipe-request

Hope it can help.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 Votes 0 ·
EswarKoneti-MVP avatar image
0 Votes"
EswarKoneti-MVP answered

You can try the retire option which removes only the corporate data/apps etc. Please read https://docs.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#retire for more about the retire option.

Thanks,
Eswar

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Eduards-Grebezs avatar image
0 Votes"
Eduards-Grebezs answered Crystal-MSFT commented

Hello

I used selective wipe on device and then delete it.

Everything runned successfully.

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@EduardsGrebes-8297,Thanks for the update. I am glad to hear that it is working by using selective wipe. If there's anything we can help in the future, feel free to post in our Q&A.

Again thanks for your time and have a nice day!

1 Vote 1 ·