question

AndrewWilkins-1073 avatar image
0 Votes"
AndrewWilkins-1073 asked AndrewWilkins-1073 commented

Azure AD personal device enrollment without remote wipe / erase.

Hi
I have azure AD and have the endpoint security which allows anyone in my company to join a personal windows PC or mac if they install the company portal app.

This enforces security setting that most staff are comfortable with, but remote wipe is something most people are not comfortable with and i can't say i blame them.
I am never going to wipe anyone's personal device deliberately, so i would much rather this was never an option.

Is there a way i can setup a profile or policy so that permissions to remote wipe / erase is never set on a personal devices?
I am particularly interested in doing this for MacOS but it would also be useful on windows too.

azure-ad-device-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

vipulsparsh-MSFT avatar image
0 Votes"
vipulsparsh-MSFT answered

@AndrewWilkins-1073 Thanks for reaching out and we understand your concern.

When endpoint security allows you to push down certain policies, files, email profile , certificates etc, it keeps a secure option of removing everything it pushed in case user leaves company or the device gets stolen. That Retire option comes by default and never really touches the personal files and settings of the users.

There is no policy which you can create to remove that Retire option. You can try to educates users, that endpoint security will not touch any of their files.
The retire option only does the following on a MAC OS :

101412-image.png

Feel free to raise this as a idea at our feedback page here. Other people can upvote your idea and if many people need this idea, may be the Product group can check further to work towards this.



If the suggested response helped you resolve your issue, please do not forget to accept the response as Answer and "Up-Vote" for the answer that helped you for benefit of the community.




image.png (26.2 KiB)
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

AndrewWilkins-1073 avatar image
0 Votes"
AndrewWilkins-1073 answered AndrewWilkins-1073 commented

Thank you
The retire option sound perfect, i'm happy to keep that as an option. What I am after is being able to have a policy where remote wipe is not an option.
What i am after is getting rid of the wipe option on windows and erase on macOS, these seem to be there by default.

I have taken over this domain from someone else so it is possible they have set something which means we don't have the default polices but i could not see anywhere on any of the polices we have that mention anything about remote wipe to enable / disable it, nor could i see how to setup any new polices which would not have it.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@AndrewWilkins-1073 It is not possible currently to remove the WIPE option from Device blade. There is a user voice for this already, https://microsoftintune.uservoice.com/forums/291681-ideas/suggestions/16727287-allow-organizations-to-remove-the-full-wipe-option

I will try to get the status on that, but for now there is no such option to get rid of it. I understand the situation and apologies as there is no way around it for now.

0 Votes 0 ·

Thanks thats great you have saved me a lot of time continuing to look for a feature that isn't there.
I'll add an up vote to the suggestion.

0 Votes 0 ·