MAM policy to encrypt Org data for Android and IOS

A.Elrayes 186 Reputation points
2024-06-27T14:25:27.22+00:00

Hello,

I applied a MAM policy to encrypt organizational data with Microsoft apps on both Android and iOS devices.

I tested this policy on an Android device by saving an attachment (an Excel sheet) from Outlook to internal storage and attempting to open it. The file failed to open as expected. I then transferred the file to a laptop, where it opened but contained symbols, indicating that the encryption was effective.

However, I performed the same test on an iOS device and noticed that I could open and read the file from the iOS internal storage.

Please note that the encryption prompt appeared on iOS which indicates that the policy was applied.

How can I resolve this issue?

Thanks,

Alaa Elrayes

Microsoft Intune iOS
Microsoft Intune iOS
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.iOS: An Apple mobile operating system.
201 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
908 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,640 questions
{count} votes

3 answers

Sort by: Most helpful
  1. Crystal-MSFT 45,486 Reputation points Microsoft Vendor
    2024-06-28T01:55:10.7566667+00:00

    @A.Elrayes, Thanks for posting in Q&A. Based on my understanding, this is by design. For "Encrypt Org data" on Android device, content on the device storage is always encrypted and can only be opened by apps that support Intune's app protection policies and have policy assigned.

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-android#encryption

    For the setting on iOS device, Intune enforces iOS/iPadOS device-level encryption to protect app data.

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-ios#encryption

    Therefore, we get the different behavior on the different platform.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. A.Elrayes 186 Reputation points
    2024-06-28T04:10:02.43+00:00

    Thanks for your reply. I saw both documents before and Istill see the description is not clear specially for IOS. As Imentioned, when I open the attacment in outlook, it opens. However, when I save it localy, I couldn't open it even with MS office for mobile apps and it seems to be opened by MS office desktop apps but the content encrypted. However, IOS, I could open the file even after saveing it locally.


  3. A.Elrayes 186 Reputation points
    2024-06-29T15:14:11.0566667+00:00

    Any ideas ?

    0 comments No comments