iOS Configuration setting - Viewing corporate documents in unmanaged apps - Question

Mike 1 Reputation point
2020-09-13T11:29:02.577+00:00

Hi,

We currently have conditional access configured to grant access to our O365 resources from an Intune compliant mobile device when it's not on our network, pretty standard and simple. We're looking to lock down the ability for users to connect to our O365 resources from only our defined Intune managed applications, which have an application protection policy assigned so we can ensure our data is protected. It was advised that if we set the setting under "Viewing corporate documents in unmanaged apps" to block, this should give us what we're looking for, however it does not. I currently have this enforced, and don't have the SharePoint application defined anywhere(not under apps, no app protection policies assigned, etc) but am still able to connect without an issue.

I'm trying to determine what's considered an unmanaged app, by this configuration because it doesn't appear to function as I'd expect.

Thanks,
Mike

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,730 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. CiciWu-MSFT 1,201 Reputation points
    2020-09-14T04:02:32.557+00:00

    Firstly, the unmanaged app is an app that doesn’t have Intune app protection policies applied to it.
    https://learn.microsoft.com/zh-cn/mem/intune/apps/app-protection-policy
    After that, we can check which app has been targeted in app protection policy, as below sample: Outlook and Word apps are the policy managed apps:

    In addition, only for apps have been integrated with the Intune SDK or wrapped by the Intune App Wrapping Tool can be managed using Intune app protection policies. There is the official list of Microsoft Intune protected apps that has been built using these tools and are available for public use.

    For your request that to lock down the ability for users to connect to our O365 resources from only our defined Intune managed applications, which have an application protection policy assigned so we can ensure our data is protected. How about selecting multiple controls in Conditional access policies: Require device to be marked as compliant, Require approved client app and Require app protection policy (Preview)?

    0 comments No comments

  2. Mike Chabot 1 Reputation point
    2020-09-14T14:53:14.73+00:00

    Hi,

    Thanks, so much for the response. Your first line mentions how I'd expect the setting to work, but I set the "view corporate documents, in unmanaged apps" and the configuration was pushed down. I don't have the SharePoint application defined anywhere, but I was still able to sign into the app and access company resources without issue. Maybe I'm missing something here?

    Thanks for the information about the conditional access policy and applying the approved client app and app protection policy, but it's still in preview and don't want to use that option till it's production ready.

    Thanks,
    Mike


  3. Rahul Jindal [MVP] 9,151 Reputation points MVP
    2020-11-21T18:36:08.74+00:00

    What you should do is enable the grant control of requiring app protection policies as well. That way your MAM scenario will get covered.

    0 comments No comments