Jump to content

Recommended Posts

Posted

Hope you can help.

 

We do not use MS InTune (as yet).

 

Had a email from a parent asking why we are managing his laptop with InTune.

The device has never been attached to my wireless. This device is totally a personal device.

 

So far as I understand it, they had downloaded the MS Teams app, then signed in with the daughter’s office 365 account.

Apparently they are having trouble signing out of Teams. On his investigations the laptop is registered and managed by our InTune. Also Intune has a copy of his BitLocker recovery key.

 

Checking my Azure AD and drilling down to the devices I can see that a copy of the BitLocker recovery keys are there.

device.png

key.png

 

I am guessing that when they have signed into the Teams App they have left the tick in the box “allow my origination to manage my device”

team.png

 

If they did leave the tick in the box, there is no warning about what info they would give (ie the Bit Locker key)

 

Quite rightly the father is not happy about the fact I now have his bit locker recovery key.

 

Is there a way to stop the grabbing of the recovery key?

What have I done wrong, all the setting are out of the box.

 

Any pointer greatly appreciated

 

Cheers

Posted

Just done a couple of tests with a couple of virtual machines.

Signing into Teamsn and "allow my origination to manage my device” creates an device entry in endpoint,microsoft.com.

 

The OS is Bit Lockered and the key saved to desktop. The key does not show against the device.

If i go into Bit locker and click "backup your recovery key" click " save to your cloud domain account" it immediately saves and is viewable against the device in endpoint. The same as i saw against the parents device.

 

So now thinking the parent has done the same. ie the signing in with a O365 account will not automatically grab the Bit Locker key. Its just that they have save to the key to the domain account.

 

Cheers

Posted

you can stop personal Windows devices from being enrolled into Intune by going to:

 

Endpoint Manager> Devices> Enrol Devices> Enrolment Restrictions> Device Type Restrictions

 

Click on All users and then go to Properties. Under Windows (MDM), change personally owned to block. Here are my settings, not reason to worry about iOS, Android or Mac in my testing so far. Users should get an error if they leave the box ticked to say the device couldn't be enrolled, but please test.

 

Restriction.jpg

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...