Endpoint protection manager

JMN-2253 576 Reputation points
2021-12-16T14:04:56.51+00:00

Hello,

I've asked few questions for this same scenario related to iOS enrollment in endpoint protection manager as company owned.

Earlier status: iOS devices was not managed and users were accessing emails, teams and one drive

Enrollment process I followed:
1-The scenario I followed is to add iOS serial number to enrollments
2-Created the required Apps /Policies to be pushed
3-Install Intune Company Portal manually and enroll the devices

Everything went smoothly and it was really promising till this week, when I discovered that approximately 30 employees just uninstall Intune Company Portal! Now is as before, they still able to open mails, teams and one drive
and I don't have any control.

I will re-enroll them again, but how can I block their abilities from uninstall Intune Company Portal?

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
874 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,248 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,336 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Timmy Andersson 411 Reputation points MVP
    2021-12-16T14:13:23.567+00:00

    Conditional Access is the easiest way (in my opinion) to force users to have their device managed and enrolled to allow them to get access to resources like email, teams etc.

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview

    If you are using Apple Business Manager and ADE (Automated device enrollment) I think there's a setting you can configure to block unenrollment as well.

    0 comments No comments

  2. JMN-2253 576 Reputation points
    2021-12-16T14:53:29.727+00:00

    @Timmy Andersson I have the policy in place. Would you mind advising what is wrong with my policy:

    Policy Configuration:

    Name: Enforce MFA for all users

    Users or workload identities: assigned to a group that include all users "Not the services account" - No Excludes.

    Cloud apps or actions: Selected Apps: Office 365, Microsoft Intune Enrollment

    Conditions:
    Device platforms: Not configured
    Locations: Any location - Exclude 2: MFA Trusted IPs & Company HO "which is our LAN"
    Client apps: Not configured
    Device state (Preview): Not configured
    Filter for devices: Not configured

    Access controls:
    Grant access: the only selected one is: Require multi-factor authentication
    Session: 0 controls selected

    Enable policy: On

    0 comments No comments

  3. JMN-2253 576 Reputation points
    2021-12-16T18:03:25.043+00:00
    0 comments No comments

  4. Mr Sbaa 356 Reputation points
    2021-12-16T22:48:35.23+00:00

    Hi @JanNuaman-2253

    The conditional access policy configured will not force users to have Company Portal installed on their mobile device. If you want to achieve that, you have to use app protection policies which will require the user to also install the company portal app. You can then also configure conditional access policies to require the app protection policy on these devices. Users will then be forced to install the company portal app.

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy

    https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/concept-conditional-access-grant#require-app-protection-policy