Can you configure iOS app permissions via Intune / Endpoint?

PiersMH 41 Reputation points
2020-10-14T12:31:25.55+00:00

Hi,
Deploying DEP-enrolled iOS devices via Endpoint.

Specifically looking at the MS Comp Portal app, can it's permissions such as Location be configured in Endpoint? If it's Location preferences are set to "Only While in use" on an iOS device, then that device reports non-compliance. Since this is the most fundamental app, it seems an appropriate app to do this with.
Is anyone aware of any app config policy settings for this?

If it's also possible on other apps, would appreciate that info too.

Am fully aware this is the type of thing Apple say should only be owned by a user, but then again these are corporate devices...

Thanks,
Piers

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
894 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,485 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. CiciWu-MSFT 1,206 Reputation points
    2020-10-15T07:01:38.217+00:00

    I have done a lot of research and found it’s possible for some app by using app configuration policies for managed apps that also have an app protection policy applied.
    https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-ios
    Here is a sample with Outlook:
    https://learn.microsoft.com/en-us/exchange/clients-and-mobile-in-exchange-online/outlook-for-ios-and-android/outlook-for-ios-and-android-configuration-with-microsoft-intune

    However, for Company Portal app, there seems to be no such information to configure the permission. Here is the supported token that can be used in XML when configuring the Company Portal app.

    Reference: https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-ios#configure-the-company-portal-app-to-support-ios-and-ipados-dep-devices

    0 comments No comments

  2. PiersMH 41 Reputation points
    2020-10-20T14:36:49.52+00:00

    Hi CiciWu,
    Thanks, we already have the Outlook appconfig in place and working (successfully).

    I'd seen the page about the XML, but we've never had a problem with the Portal app, and since there is nothing in there about permissions it didn't seem relevant. I've tested it nonetheless and it's made no difference - all continues to work as before.

    I know Apple don't allow apps to force/configure permissions, but wondered since this was MS's own app controlled by MDM, whether there was a way purely for the enterprise? It would not surprise me if not but wanted to ask if anyone knew.

    Thanks,
    Piers

    0 comments No comments