Ultimate setup for Windows and MacOS devices a BYOD scenario

Поделиться
HTML-код
  • Опубликовано: 17 окт 2024

Комментарии • 39

  • @AndyMaloneMVP
    @AndyMaloneMVP Год назад +4

    Nice to see you back again 😊

  • @elkyu505
    @elkyu505 Год назад +1

    Alex, thank you for making this episode!
    And Good Luck with an upcoming Marathon !!!

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 месяца назад

    Hello Alex! Why wouldnt we want users to have their personal windows device enrolled/managed by Intune if they are going to be accessing corporate data?

  • @arwendrew3393
    @arwendrew3393 14 дней назад

    Would you still do all this if there are no company provided devices and only BYOD?

  • @nazerbor3i
    @nazerbor3i 2 месяца назад

    Wow this video is gold, i wish you could make a more thorough one with demos

  • @carlcedricksantos5621
    @carlcedricksantos5621 Год назад +1

    This should also work for Android devices, right? For restricting mobile devices to use corporate O365 application, it should be done via conditional access? Thanks! 👌

  • @chuck-kg3zo
    @chuck-kg3zo 4 месяца назад

    Great video. I’ve successfully limited access to O365 through browser and successfully blocked downloads following your advice. Cut/Copy/Paste still works from the browser - how do I block that too? Thanks!

  • @geralddevera6619
    @geralddevera6619 4 месяца назад

    Thank you, Alex! Amazing video! I followed your tutorial and it worked. However, I have an issue viewing PDF files in Outlook Web. When you click a PDF attachment, it automatically downloads it (blocked). Can you suggest any solution for this? Thanks a lot!

  • @CathrynEggers2011
    @CathrynEggers2011 10 месяцев назад

    Does this work if you exclude guest users from the policies? We work with several external vendors and they need access to some but not all cloud apps.

  • @mukmusicdiary
    @mukmusicdiary 11 месяцев назад

    I love your work mate! Keep up the amazing work.

  • @richardblate9505
    @richardblate9505 Год назад +2

    Great Video! Thanks for making it. Scenario- BYOD, Business Premium- want to allow users to use the desktop applications, but not save the data locally. Can that be built? Seems like it can with some modifications to the browser example you used. Thanks!

    • @azuredude
      @azuredude  Год назад +1

      Hi.. you can built it like this, no matter the browser

  • @christinagray9257
    @christinagray9257 Год назад

    Alex, would your block downloads policy also prevent a person from syncing data on a SharePoint site to their computer? I'm trying to prevent that from happening with consultants on unmanaged devices. Thank you for this video.

    • @azuredude
      @azuredude  Год назад

      It will, but you should also block those users from connecting using anything other than a browser. Just to be sure.

    • @christinagray9257
      @christinagray9257 Год назад +1

      Thank you. Yes. I was presuming your earlier steps would have been configured as well.

  • @TakticalTekniq
    @TakticalTekniq 2 месяца назад

    FANTASTIC video. Thank you very much!

  • @jbreezecoleman5345
    @jbreezecoleman5345 2 месяца назад

    I guess Im confused too, you first blocked personal owned devices from being enrolled into Intune, but then you created conditional access/compliance polices and BYOD query rules for personal owned devices. ? Am I missing something?

    • @KibblesExoticBIts
      @KibblesExoticBIts 3 дня назад

      I saw this too, but then it mentioned "Accidental Management" , perhaps the alternative is byod enrolment via Company Portal ?

  • @msmacthankQ
    @msmacthankQ 4 месяца назад

    Thank you for your video. How do you wipe company data when the phone is lost or stolen?

  • @HSITSolutions
    @HSITSolutions 7 месяцев назад

    how can I exclude Azuread joined devices from conditional access? or any method to identify personal and company devices?

  • @ToTCaMbIu
    @ToTCaMbIu 9 месяцев назад

    Maybe it's a silly question.
    You disabled enrolment of personal devices to Intune.
    What is the point of having a conditional access policy that excludes personal devices? Since you disabled personal devices enrolment, you should not have any. Am I missing something?

    • @azuredude
      @azuredude  8 месяцев назад

      the ca policy will exclude managed devices from a policy that blocks things for byod devices.

  • @p1pd1
    @p1pd1 Год назад

    This vid sounds great, however the browser versions of word/excel do not let you encrypt documents with a password. Anyway to bypass that?

  • @andrewa3216
    @andrewa3216 Год назад

    What about a wider range of products? An entire internal intranet is normally what people are connecting to for work. Many different apps than just Microsoft 365. Can you get even more granular than this?

  • @elkyu505
    @elkyu505 Год назад

    I see that downloads of O365 documents on a web browser of an unmanaged device are blocked, this is good!
    But, pdf documents are allowed to be downloaded from the web browser outlook of an unmanaged macOS laptop.
    @Alex, is there a general restriction on web Outlook downloads that could be enforced on unmanaged computers?

    • @azuredude
      @azuredude  Год назад

      Hi elkyu505,
      the main concern is organizational data being stored on unmanaged devices. PDF's can also contain sensitive information. therefor, we can not filter those out. If you want to get that kind of management, the devices needs to be managed by intune/ms defender for endpoint.

    • @elkyu505
      @elkyu505 Год назад

      ​@@azuredude Thank you for your response!
      My web outlook failed to block pdf document download from an unmanaged macOS laptop :(
      Any suggestions why it failed to block the download of a pdf?

    • @andrewmedcraft
      @andrewmedcraft Год назад

      @@elkyu505 Alex mentioned in the video something about needed E5 license so might want to check that. Are other downloads being blocked?

    • @azuredude
      @azuredude  Год назад

      thank you Andrew. Yes you need e5 for that to work. It is the integration of ca with defender for cloud apps that makes this possible.

    • @elkyu505
      @elkyu505 Год назад

      @@andrewmedcraft - on a BYOD and unenrolled macOS, the pdf attachments on web outlook are NOT blocked, even with E5.
      But, Office 365 documents and pictures are blocked.

  • @Egimatic
    @Egimatic Месяц назад

    Can i setup step 4 without a e5 license?

  • @mustafashawer6677
    @mustafashawer6677 Год назад

    Great Video Really appreciated
    I need to force any Windows devices to be managed ( MDM ) not registered ( How can i do this ) please

  • @RenanRusso-g1d
    @RenanRusso-g1d 14 дней назад

    Good Video

  • @e2matt
    @e2matt Год назад

    Great video!