Setting up the ultimate BYOD configuration for iOS and Android.

Поделиться
HTML-код
  • Опубликовано: 15 янв 2023
  • Ever wondered what you can do to protect your organization data on those devices that are out of the management scope? In this demo I will show you how it's done.
    If you have any question, let me know!
  • НаукаНаука

Комментарии • 63

  • @incendary23
    @incendary23 3 месяца назад

    Exceptional content, easy to understand and follow.

  • @elkyu505
    @elkyu505 Год назад +4

    Thanks for this content, Alex !!!
    Keep it going, please.

  • @MarkJorissenEindhovenNB
    @MarkJorissenEindhovenNB 2 месяца назад

    Great video, did some configuration according to the advise given .. :)
    Very clear. Keep up the good work!

  • @rajnorsk8408
    @rajnorsk8408 8 месяцев назад +1

    Brilliant Video many thanks for your help on this.

    • @azuredude
      @azuredude  8 месяцев назад

      Glad it helped

  • @patrick__007
    @patrick__007 Год назад +1

    Finally new content! Thanks

  • @svsv7882
    @svsv7882 9 месяцев назад +1

    Excellent sir!! Thank you !!!!

    • @azuredude
      @azuredude  9 месяцев назад +1

      Glad you like it

  • @Amir20021
    @Amir20021 5 месяцев назад +1

    very good video, thank you.

  • @MrMarcLaflamme
    @MrMarcLaflamme Год назад

    First time on your channel and I already know I'm going to like it because your company tenant is Dunder Mifflin 😂

    • @azuredude
      @azuredude  Год назад +1

      that is a very good reason!!! :) I love that show

  • @marcellagcher6936
    @marcellagcher6936 Год назад +1

    Tnx Alex. Just the info that’s needed ;-)

  • @sevagmanoukian7906
    @sevagmanoukian7906 10 месяцев назад +1

    Great video Alex!
    Maybe someone has asked this already
    How can we add all apps such as Slack, or other 3rd party apps to be managed with policies also?
    This is referring to Android and iOS devices that sign into our Slack account using our work SSO
    Thank you!

  • @BACKSPIN9ball
    @BACKSPIN9ball 8 месяцев назад +1

    I think you missed on showing us how the Android device is enrolled and signed into but still I enjoy your content.

  • @TheGnygren
    @TheGnygren Год назад +6

    Hi Alex. Do you have a video that covers the MAM app protection policy creation for IOS in a BYOD environment? This video had the steps for creating the policy for Android, but I'm also looking to create one for iOS.

  • @hennibadger5120
    @hennibadger5120 8 месяцев назад

    Great vid. Thanks.
    That handles access / DLP for corporate data.
    But what about the "quality of life" features an MDM would allow for?
    Is there some way to (force) deploy apps or app configurations, shortcuts etc. to unmanaged MAM devices? Greatly appreciated :)

  • @IsmailArici-l2q
    @IsmailArici-l2q 15 дней назад

    Hello Alex,
    Thank you for this great video! It’s very informative! I’d like to ask a couple of questions if that’s okay. I’m failing new to this, so I hope my questions will make sense to you.
    1. For app protection policies, do we need to have separate policies for iOS/iPadOS and Android, or a single policy can be applied to both device users? My concern is that I have all the users in one Entra Group, and I don’t know how it’d work if I assign two policies to the same group.
    2. Can more than one Conditional Access policy be applied to the same group for BYOD? I’m thinking of device restrictions as well as device cleanup rules for devices that have not checked in for a certain number of days.
    Thank you and appreciate it!

  • @runmadhu2161
    @runmadhu2161 2 месяца назад

    We have implemented Compliance Policy, App Protection Policy, Apple MDM Push cert and Conditional Access Policy that "Require Compliant device" to access Office 365. Situation is: users are already using M365 apps. Seems like the MDM enrollment is not being triggered because iOS users can continually use the Teams and Outlook even though they are not yet-MDM-enabled.

  • @GesichtsFernando
    @GesichtsFernando 2 месяца назад

    big up

  • @elkyu505
    @elkyu505 Год назад +2

    Alex, I got a question:
    What would be a recommended way to restrict/block your organization's OneDrive sync in Mac OS for unenrolled devices?
    Are there any reference docs in Microsoft Intune or Conditional Access service that could be used?

    • @azuredude
      @azuredude  Год назад +1

      Check out my other video I released this week.. that one will also handle OneDrive sync

  • @sXRaider91
    @sXRaider91 3 месяца назад

    Looks great. Unfortunately the device type option (min 3:50) disappeared, it's not possible anymore to select unmanaged devices. I guess we have to make custom dynamic EntraID groups to assign the policy to? For example (device.deviceManagementAppId -eq null) and (device.deviceOSType -eq "Android") ?

  • @tpmarkham
    @tpmarkham 4 месяца назад +1

    Funny that Windows Phone is still a choice at the 1:54 mark.

  • @ehababumoailish6574
    @ehababumoailish6574 Месяц назад

    i did the same settings, but i am still able to sign in with third party apps like mail app (iphone) and the policy not yet forcing the users app protection like it asked me to setup PIN code but i still can copy data from corp app to other apps! how long the policy need to be fully replicated?

  • @arjanv
    @arjanv 23 дня назад

    what will happen if a user also used Outlook(or other microsoft apps) with his private mail and also want to use corporate email?

  • @nabeelthetrader
    @nabeelthetrader Год назад

    Hi Alex,
    Thanks for this content it is unbelievably helpful, one question if you dont mind please.
    how can we block access to outlook from outside the work profile in android, for example a byod android device will have a work profile but i do not want to allow users to access emails from the outlook or native mail clients outside the work profile,

    • @azuredude
      @azuredude  Год назад

      yes you can. you would need a conditional access policy for that situation.

  • @sharmajikashubham
    @sharmajikashubham 11 месяцев назад +1

    I am a Business Manager Admin. I want to allow my user to BYOD or User Enrolment. What steps should I follow besides from Intunes.
    Is there any way I can allow my users to enable sign in with their work account on their own device.

  • @javierlujan9249
    @javierlujan9249 3 месяца назад

    Great video! < but for me doesn't work and it's pretty frustrating. Looks like it;s an easy set up, but my outlook on my iphonee will never follow any policies I set up

  • @DicksonNg-dd5xh
    @DicksonNg-dd5xh Месяц назад

    Hello! Does this work so as to prevent users from using the downloaded gmail app but rather use the approved gmail app in InTune?

  • @fortunatefaraz05
    @fortunatefaraz05 Месяц назад

    @Alex de Jong is it possible to block adding Corp and Personal Outlook Or OneDrive account on a iOS BYOD device. Please advise how THanks

  • @PhilCrombieMTB
    @PhilCrombieMTB 6 месяцев назад

    Hey great video. Can you use compliance policies for byod iOS devices and block non compliant with conditional access ? Thanks :)

    • @azuredude
      @azuredude  5 месяцев назад

      compliance policies only work when devices are managed.

  • @TechNomadUK1
    @TechNomadUK1 Год назад

    Hi there. Was wondering if you can help. I sold my HP laptop few days ago and wanted to know if working using Microsoft 365 on an Android tablet is as good or if not better than the online version? Or do you think it's still best to just get a Windows laptop?

    • @azuredude
      @azuredude  Год назад

      I like to have a keyboard present. but for the OS, there is no big difference between the office apps.

  • @noniche1387
    @noniche1387 Год назад

    Hi Alex,
    QUestion: do you need to enroll the device to intune? do you have to do something on the device for this restrictions to take effect on it?

    • @azuredude
      @azuredude  Год назад

      Hi, no the purpose is not to enroll the devices into intune. the devices remain unmanaged.

    • @NjaderTN
      @NjaderTN Год назад

      @@azuredude I followed this guide, but when logging into Outlook mobile app, I got this prompt "Help us keep your device secure" Register your device to continue." forcing me to register the device in Intune.
      PS. Thank you very much for this valuable content. Keep it up, man.

  • @user-zs5ku4yw5r
    @user-zs5ku4yw5r 7 месяцев назад

    explain to us : app configuration policy in Microsoft Intune

  • @patrick__007
    @patrick__007 Год назад

    I found this from the MS Documentation:
    For Android devices, the Company Portal app is required to receive app protection policies.
    This indeed is true. When I open Outlook for the first time with a targeted user there is a message saying that I also need the Company Portal..

    • @azuredude
      @azuredude  Год назад +1

      perfect. by the way, the authenticator app from microsoft would also do

    • @patrick__007
      @patrick__007 Год назад

      @@azuredude How? This MS Authenticator was already there. But didn't work. After installing the CP it did.

    • @NjaderTN
      @NjaderTN Год назад +1

      @@patrick__007 Yeah, same case. It prompts me to install CP though I have MS Authenticator installed.

  • @Timmy-Hi5
    @Timmy-Hi5 10 месяцев назад

    One thing I notice with App PP is when on Android BYOD adding a corp account, all of the photos are getting synced, even though the settings on Android "Camera Backup" show saying "Other accounts are not eligible".
    Example:
    I have a personal OneDrive on Android > I will add a Corp account to the OneDrive app > It will ask me to enable backup, I will skip that > I will take a photo on BYOD device > The photo will get sent/synced to my corp OneDrive :( ... We can repro those steps on 10 test devices... Pixel 7 PRO and Samsung Galaxy 22 ultra...

    • @azuredude
      @azuredude  10 месяцев назад +1

      your corp onedrive is considered a safe place as it is also protected by microsoft365.

  • @elkyu505
    @elkyu505 Год назад

    I have tried the CA policy creation for macOS devices, but got the following error: "MAM policy can only be applied to Android or iOS client platforms."
    What would be the solution to configure this for unenrolled macOS devices?

    • @azuredude
      @azuredude  Год назад

      ruclips.net/video/M24LzPto05E/видео.html

    • @azuredude
      @azuredude  Год назад +1

      This is the macOS version… please let me know if you have any other questions.

  • @Isaaccummins
    @Isaaccummins 10 месяцев назад

    I have set up both an iOS and Android policy and everything is working fine, however the edit function is not working for any Office doc. What have I missed?

    • @azuredude
      @azuredude  10 месяцев назад

      what do you mean with the edit function?

  • @mikeotech
    @mikeotech 5 месяцев назад

    What are you using to remote into your phone

    • @azuredude
      @azuredude  5 месяцев назад

      i use a tool named: reflector by airsquirels.

  • @JayanthD05
    @JayanthD05 10 месяцев назад

    Hey Alex,
    Can we able to block screenshot or screen capture in ios/ipad BYOD? for managed apps only, I tried enforcing through configuration policy, But it enforces to the entire device, I just want to know & i would like to block screen capture only on managed devices BYOD ?
    is that possible ios/ipad devices? just waiting for your reply
    also i'm aware this can be done in andriod

    • @azuredude
      @azuredude  10 месяцев назад +1

      Hi, currently blocking screenshots is not supported for iOS/iPadOS.. it is however supported for Android

    • @jayanthdeebika7906
      @jayanthdeebika7906 10 месяцев назад +1

      @@azuredude thanks for the update, I was mad on this setting from long time.
      Thanks again alex.

    • @JayanthD05
      @JayanthD05 10 месяцев назад

      Also one more question, Do we need a managed google play id for andriod device management. i.e personal owned device?

  • @MKcLTM
    @MKcLTM Месяц назад

    You only focused MAM .. not work/profile and personal enrollment for iOS .. both suitable for BYOD i think

  • @petarmiljanic5658
    @petarmiljanic5658 11 месяцев назад

    Microsoft no longer recommend the use of "Require approved client app", insted they recommend to use " Require app protection policy" or both.. After March 2026, Microsoft will stop enforcing require approved client app control

    • @azuredude
      @azuredude  10 месяцев назад

      correct.. thanks for sharing