MDM on Windows 10: Office 365 installation unenlightened

Adam_4_DL 1 Reputation point
2020-09-07T13:58:32.22+00:00

MDM Enrollment

We are deploying MDM. All users have the same license assigned.

New equipment with Windows 10 Enterprise

Some Devices simply refuse to enroll in MDM and enroll in MAM instead

Devices are Hybrid AD joined. Some of these machines work beautifully and all our apps become enlightened

Every time a work file is opened in Outlook, regardless of type this is received
23017-opens-personal-files-only.png

Exclusion policies make no difference, checking Enterprise context simply lists Personal. On the machines, where the MDM enrollment works the same apps (same version etc.) are listed as enlightened.

Event Viewer is of no help, some of the machines enroll and never list into Endpoint Device Management

...

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,507 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. CiciWu-MSFT 1,206 Reputation points
    2020-09-08T03:29:16.817+00:00

    From your description, it seems those device use the MAM without device enrollment, or MAM-WE to access corporate resources. For such kind of MAM, it allows IT administrators to manage apps using MAM and app protection policies on devices not enrolled with Intune MDM. So when you use app protection policies, please make sure that the office suite apps have been added to Allowed apps blade, and there is no restriction settings to corporate data in Advance settings part.
    23166-090801.jpg

    Here is a sample for MAM-WE with app protection policy, just for your reference.

    https://www.petervanderwoude.nl/post/windows-10-mam-we-and-office-desktop-apps/


    If an Answer is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.