Intune iOS device is managed and compliant / but Application is not managed

Borut Puhar 66 Reputation points
2020-12-20T12:17:50.573+00:00

Hi,
First to mention we are speaking iOS devices and App protection policies and app configuration policies.
Everything is working if device is managed (all are) and if user managed apps installed from company portal. Those apps are also / have app protection policy and configuration policy with “IntuneMAMUPN“ key.

Issue that I have is, that I have one device. Device is managed and compliant. User has installed Outlook, but not from company portal. He is receiving app protection policy for unmanaged devices. If I apply app configuration policy with “IntuneMAMUPN“. In diagnostic section I can see that policy is assign to user/device, but when I dig to config it is saying “not applicable”. Because of that user receive app protection policy for “device type” unmanaged devices. I would like that user receive app protection policy for managed devices.
The easy way, probably would be to told the user to install outlook from company portal. But I would like to find solution even if user does not installed application from company portal.
And yes, if I look application for effected device outlook is not listed as managed application.

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
895 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Crystal-MSFT 44,416 Reputation points Microsoft Vendor
    2020-12-21T01:22:41.187+00:00

    @Borut Puhar , From your description, it seems a managed and compliant device can't apply app configuration policy with error "not applicable". If there's any misunderstanding, please let us know.

    Firstly, could you let us know the device enrollment type we configured for the app configuration policy? Did we choose Managed device? Selecting Managed apps as the Device Enrollment Type specifically refers to apps configured by Intune configuration policies on a device that is not enrolled in device management, whereas Managed devices applies to apps deployed through the MDM channel and thus are managed by Intune. We can see more details in the following link:
    https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview#apps-that-support-app-configuration

    Hope it can help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.