Hello
Here is couple steps for your request:
Create App Protection Policies
- Login to Intune:
- Go to the Microsoft Endpoint Manager admin center (https://endpoint.microsoft.com/).
- Configure App Protection Policies:
- Navigate to Apps > App protection policies > Create policy.
- Choose iOS/iPadOS as the platform and click Next.
- Policy Settings:
- Configure the policy according to your organization's requirements, focusing on settings that apply to data protection, access requirements, and other relevant configurations.
- Permissions for App Settings:
- Under Permissions, ensure that the necessary permissions required by the M365 apps (Teams, Outlook, etc.) are allowed or set to prompt only once so users are not repeatedly asked to grant permissions.
- Navigate to Apps > App protection policies > Create policy.
B. Assign Users
- Assign the app protection policy to a group that represents the users who will use the shared iPad.
- Configure the Managed App Configuration
To pre-configure specific app permissions (mic, camera, etc.) for M365 apps, you can use app configuration policies in Intune:
- Create Configuration Policy:
- In Intune, go to Apps > App configuration policies.
- Click on Add and choose Managed apps.
- Select the App:
- Select the Microsoft Teams app (and any other M365 apps you plan to configure).
- Configuration Settings:
- In the settings, you can provide specific configurations. However, note that not all permissions can be set via Intune due to Apple's privacy and security model. The settings that can be changed should be chosen based on what’s applicable.
- Assign the Configuration:
- Assign the configuration policy to the same group as the app protection policy.
- In Intune, go to Apps > App configuration policies.
- App Request Settings
- If you want to ensure that permissions are not repeatedly requested, ensure that users are provisioned in a way that allows them to authenticate seamlessly (using Azure AD, SSO, etc.). Create App Protection Policies
- Login to Intune:
- Go to the Microsoft Endpoint Manager admin center (https://endpoint.microsoft.com/).
- Configure App Protection Policies:
- Navigate to Apps > App protection policies > Create policy.
- Choose iOS/iPadOS as the platform and click Next.
- Policy Settings:
- Configure the policy according to your organization's requirements, focusing on settings that apply to data protection, access requirements, and other relevant configurations.
- Permissions for App Settings:
- Under Permissions, ensure that the necessary permissions required by the M365 apps (Teams, Outlook, etc.) are allowed or set to prompt only once so users are not repeatedly asked to grant permissions.
- Assign the app protection policy to a group that represents the users who will use the shared iPad.
- Configure the Managed App Configuration
- Create Configuration Policy:
- In Intune, go to Apps > App configuration policies.
- Click on Add and choose Managed apps.
- Select the App:
- Select the Microsoft Teams app (and any other M365 apps you plan to configure).
- Configuration Settings:
- In the settings, you can provide specific configurations. However, note that not all permissions can be set via Intune due to Apple's privacy and security model. The settings that can be changed should be chosen based on what’s applicable.
- Assign the Configuration:
- Assign the configuration policy to the same group as the app protection policy.
- App Request Settings
- If you want to ensure that permissions are not repeatedly requested, ensure that users are provisioned in a way that allows them to authenticate seamlessly (using Azure AD, SSO, etc.).
- Login to Intune: