Personal IOS device gently remove MDM while switching to MAM

mpls 80 Reputation points
2024-01-30T01:22:15.7866667+00:00

We mistakenly allowed BYOD android and IOS devices to be enrolled into Intune. We have since blocked enrollment while enabling MAM. For the previously registered devices (especially iOS), what is the least disruptive way to remove the device from Intune MDM to switch to MAM? I believe deleting the personal iOS device will not affect data but the end user may need to reinstall company apps?

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
879 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 43,316 Reputation points Microsoft Vendor
    2024-01-30T02:58:55.1533333+00:00

    @mpls, Thanks for posting in Q&A. To remove a personal iOS device from Intune MDM to switch to MAM, the user can simply remove the device from the Intune portal. This will remove the device from MDM management, The next time the device checks in, any company data on it will be removed as Intune also retires a device when deleting it from the admin center. For iOS devices, apps that are pinned to the management profile, all app data and the apps are removed. These apps include apps originally installed from App Store and later managed as company apps unless the app is configured to not be uninstalled on device removal.

    You can check what data is removed in the following link:

    https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#effect-of-the-retire-action-on-data-that-remains-on-the-device

    But the user will still be able to access company apps that are protected with MAM policies. However, the user may need to reinstall company apps if they were previously installed through MDM.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful