Tenant setup 10 β Mobile app protection
π Complete tenant-setup cookbook in one PDF This article is part of the series. Full series + screenshots in one document: download PDF . (PDF is currently in Czech.
This article is part of the series. Full series + screenshots in one document: download PDF. (PDF is currently in Czech.)
Last time I walked you through auto-installing O365 apps on Windows. Today we'll look at protecting mobile O365 apps and the data inside them. The first question that probably comes to mind: why bother with phones? And the second: are we doing this on PCs too?
The first answer is simple: almost everyone has a mobile phone, and not every company hands out a corporate one. That brings the personal-device problem β you can't manage the device fully, but you still need to secure corporate data and accounts. Several options exist: an enrollment profile that creates a separate "work profile" on the device and prevents copying between work and personal β great solution, but Android-only. So we'll create an App Protection Policy, which lets us granularly control what users can and can't do inside O365 apps.
To create the policy: Intune β Apps β Protection. Click Create β iOS/iPadOS. Name the policy, click Next, target All Microsoft Apps. Settings are on the lighter side here β start gentle if you're rolling this out: backup org data to iCloud β Block; send org data to other apps β Policy managed apps; encryption β Require. Set a numeric PIN (4+ digits, biometrics allowed). Under Conditional launch set wipe data after 180 days of offline grace as a safety net. Target the policy at users β they don't need to be on iOS for this assignment to work.
The Android policy is configured similarly. Same pattern: name β All Microsoft Apps β encryption required, screen capture blocked, paste between policy-managed apps only. Pin + biometrics. Wipe after 180 days of offline. Target users.