Sunday, June 4, 2017

Intune - MAM Without Enrollment

MAM Without Enrollment

The Intune MAM without enrollment features allow organizations to protect their Office apps on iOS and Android without the need to enroll their devices in Intune MDM. This means for customers who don’t wish to manage their users devices via MDM, they can protect access to Office 365 and company data. 

Features includes cut/copy/paste restrictions, preventing ‘save-as’, jailbreak detection, PIN requirements and the ability to remote wipe MAM protected data.






Key Factors -Value ProPososition

Co-Existance
Supports multi-Identity
TargetGroup
Most Convenient for BYOD Scenario
Easy Deployment with Zero day Vs large Scale
Options to Choose & Select between Apps (inbound / outbound data tranfer)


On the Azure Portal search and Select Intune App protection. 












Select App Policy .




























Click Add Policy





Give a Name and Click Apps to Select Platform you want Click Select reqiired Apps .

























Select App and click ok .




Then Select  Configure Required Setting 










Configure the App Setting 



Prevent iTunes and iCloud backups: Yes, to Disable or No to Allow Backup any information Form the Protected Apps

Allow app to transfer data to other apps:  Specify if this App can send data select One below

Policy managed Apps: Allows data Transfer from other Restricted Apps

All Apps: No Restriction to allow data transfer to any app

None: this setting will restrict all data transfer from any app 


Allow app to receive data from other apps:  Specify if this App can receive data select One below

Policy managed Apps: Allows data to be received from other Restricted Apps

All Apps: No Restriction to receive data transfer to any app

None: This setting will restrict all data receive from any app


Prevent Save As : Yes, to disable saving option and No to allow.


Restrict cut, copy, and paste with other apps :   Specify how cut copy paste work

Block: will not allow any above operation

Policy managed Apps: This allows above operations only between other restricted apps

Policy managed Apps with pasts in: Allow Data to be pasted from and to between restricted apps

Any Aps: No Restriction 


Above was some Policies explained there are lot of Policies how you can protect your app data. This is Category in to two

Data relocation
Access


After selecting the configuration  click OK.

Click Creat .

























After  Creating the Policy will be listed then select it to Add user group as shown below



















This will Enable all users in this  Group  the created MAM Policy . Please note all users will reed EMS or ADPLicense and Azure AD is a must.



No comments:

Post a Comment

Global Vnet Peering

g  Global Vnet Peering Configuration  Ø Global VNet Peering enables peering virtual networks in different Azure regions. Ø Tr...