Prevent existing app(s) removal in Intune iOS User Enrolment for BYOD scenario when retired.

DaveK 1,846 Reputation points
2021-12-03T10:26:49.153+00:00

Hi, I'm doing some config as a proof of concept for iOS BYOD using iOS User Enrolment and although for the most part I'm making progress, I've hit a bit of a problem and I'm not sure if its expected behaviour or misconfiguration on my part.

On each application I have the deployment set to a specific AD group (I'll call it iOS_BYOD), 'License Type' User and have set the 'Uninstall on device removal' to No. On retiring a device from enrolment in Endpoint manager I'm finding that the app is still removed from the users BYOD device.

This is an issue where say an end user has Outlook installed and configured with a personal email profile before enrolment into BYOD. On enrolment the App polocies take effect and a Exchange 365 config is pushed to Outlook so the user now has both their personal mail account (Google for instance) and their Exchange 365 mailbox. I would expect the behaviour to be that retirement of a device removes only the corporate data in Outlook but not the whole application so the end user looses there personal email too. I understand it all likelyhood they wouldn't actually 'loose' anything but the inconvenience of having to download the apps again and sign into things again isn't really acceptable in my eyes.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,720 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
874 questions
0 comments No comments
{count} votes

Accepted answer
  1. Lu Dai-MSFT 28,346 Reputation points
    2021-12-06T06:34:45.897+00:00

    @DaveK Thanks for posting in our Q&A. From your description, did you mean that the retire action uninstalled the apps that you deployed via intune? If there is anything misunderstanding, please correct me.

    In our official article, it shows that the app will not remove when it is configured to not be uninstalled on device removal.
    https://learn.microsoft.com/en-us/mem/intune/remote-actions/devices-wipe#ios

    Honestly, I tried the retire action in my iOS BYOD device and set the 'Uninstall on device removal' to No, it doesn't uninstall the apps managed by intune.

    Given this situation, it is needed to do the log analysis to find the root cause why the app is uninstalled. With Q&A limitation, it is better to create an online support ticket to get more effective help. Here is the support link:
    https://learn.microsoft.com/en-us/mem/get-support

    Hope it will help.


    If the answer is the right solution, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


0 additional answers

Sort by: Most helpful