iPhone private(BYOD) phone can be wiped..

Jeroen F 146 Reputation points
2021-07-22T11:40:47.573+00:00

Hello,

Somehow when we want to enroll a personal device like an iPad or iPhone, and we are logging in to the Company Portal.
And see the (Device Management and your privacy) page CAN: Reset lost or stolen device to factory settings...

I really don't want to have that option in Intune to reset a full personal device..

Any ideas or solutions for this?

I cant find much about it.
Normally you could only wipe the company data, but not the whole device.

Regards Jeroen

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Jason Sandys 31,161 Reputation points Microsoft Employee
    2021-07-22T18:13:30.427+00:00

    Any ideas or solutions for this?

    Yes, don't enroll the device in MDM management and only use App Protection Policies (APP) -- aka Mobile Application Management (MAM). See https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

    0 comments No comments

  2. Lu Dai-MSFT 28,356 Reputation points
    2021-07-23T04:52:16.117+00:00

    @Jeroen F Thanks for posting in our Q&A. From your description, did you mean that you want to only delete the company data and keep the personal date on iOS devices? If there is any misunderstanding, feel free to let us know.

    Based on my understanding, the "Retire" action will meet the requirement. It will remove managed app data (where applicable), settings, and email profiles that were assigned by using Intune. And it will leave the user's personal data on the device. We can read the following article to get more detailed information:
    leaves the user's personal data on the device.
    https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#retire

    Hope the above information will help.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Jeroen F 146 Reputation points
    2021-07-23T06:49:26.813+00:00

    Thank you for your respons @Lu Dai-MSFT

    Also i dont understand why it needed a Managed Apple ID(Azure login) normally it would use the AppleID thats signed in to the Apple Store etc..


  4. Jason Sandys 31,161 Reputation points Microsoft Employee
    2021-07-27T13:41:13.38+00:00

    No, there is no way to force cert enrollment when using APP although that's not normal for BYOD.

    As for User Enrollment, as I initially called out, that's a newer enrollment method that Apple recently introduced that we don't generally recommend using yet because it lacks some capabilities and has some rough spots. The requirement of the managed Apple ID you see there is their requirement and not Intune's.

    0 comments No comments