Jump to content

Recommended Posts

Posted (edited)

Hi all

 

I'm looking to tighten up our staff access to Workspace accounts from personal mobiles. I've always been an Android user, so have been able to get Work profiles (which I love!) and app allowlisting all sorted out for Android.

 

I'm after some guidance on the iOS front, since I don't have ready access to device to test policies with.

 

Basically, how does a 'managed' app behave on iOS? If I were to set the Gmail iOS app as managed for staff, would that:

  • provide them with a second, separate instance of the app to use with their Workspace account, entirely separate from any personal instance that they might have?

or:

  • leave them with just a single instance of the app for all of their Google accounts (be they work or private) but one that would get uninstalled when the management profile disappears from their device?

Nothing I've found online is clear about it.

Edited by jthompson
Posted

If you don't use shared ipads setup (I've not done this so can't fully advise) my understanding is that on IOS devices there is only one copy of an app so all the school accounts will be alongside any personal gmail, google accounts. If the devices are school own and supervised then you can limit what accounts can be used on these devices but as you talk about personal devices this is not likely.

 

If you do push the apps via MDM to the device if they are supervised you can remove the app and therefore access to the data. If the app is pushed to an unsupervised device then the app asks for credentials and is associated with the user itunes account you may be able to deleted it but if this is a personal account things can get messy especially if it is already installed before you add it. You can block a device in the google admin console so should be able to restrict access that way as well.

Posted

Thanks. By the sounds of it, I don't want to be setting any managed apps on personal devices, then.

 

What I'm really hoping to achieve is to prevent users from copy/pasting Workspace data over to personal apps/data on their device. Android work profiles allow me to do that, but the Google Admin setting "Devices > Mobile and endpoints > Settings > iOS > Data sharing > Data actions" has me a bit puzzled. It suggests that it apply such a restriction, but I'm not clear exactly on the mechanism by which Google Workspace is able to achieve that on the device.

Posted
Thanks. By the sounds of it, I don't want to be setting any managed apps on personal devices, then.

 

What I'm really hoping to achieve is to prevent users from copy/pasting Workspace data over to personal apps/data on their device. Android work profiles allow me to do that, but the Google Admin setting "Devices > Mobile and endpoints > Settings > iOS > Data sharing > Data actions" has me a bit puzzled. It suggests that it apply such a restriction, but I'm not clear exactly on the mechanism by which Google Workspace is able to achieve that on the device.

It's likely that Google Admin does not support "User Enrolment" for iOS, which Jamf Pro does very easily allowing you to push out Managed Apps to them so you can completely control what data access you give users and remove the ability to copy and paste any data from institutional apps to personal apps. The data on devices is kept separate and you can wipe institution data from a device leaving personal data in tact when you users leaves the school.

 

You will need to set up Managed Apple ID's alongside each users Personal Apple ID in ASM.

 

https://docs.jamf.com/10.27.0/jamf-pro/administrator-guide/User-Initiated_Enrollment_for_Mobile_Devices.html

  • Thanks 1
Posted
If the app is pushed to an unsupervised device then the app asks for credentials and is associated with the user itunes account you may be able to deleted it but if this is a personal account things can get messy especially if it is already installed before you add it. You can block a device in the google admin console so should be able to restrict access that way as well.

This is incorrect, you can push Device Assigned Managed Apps to both Supervised and Unsupervised devices without a user being prompted for their Personal Apple ID, apps are not associated with their Personal Apple ID.

Posted
So in the case of the Gmail app, is there any scenario where it makes sense for that to be a managed app, given that it could quite easily be being used in a personal capactiy, too (and pulling the app off, rather than just wiping the work account data, would be unhelpful)?
Posted
So in the case of the Gmail app, is there any scenario where it makes sense for that to be a managed app, given that it could quite easily be being used in a personal capactiy, too (and pulling the app off, rather than just wiping the work account data, would be unhelpful)?

Bear in mind I am referring to using Jamf Pro MDM here, others may do this but not to my knowledge...

 

If both the institution and the user are using the same app, GMail then it's very likely you can restrict the institution account for copying and pasting, you can also restrict the domains this account can send email to. I would assume rather than pulling the app you would just remove the work email account?

Posted (edited)

I've been able to do a bit of testing and this is what I've worked out so far:

 

The setting I've been testing is Devices > Mobile and endpoints > Settings > iOS > Data sharing > Data actions, set to its most restrictive setting. The user I tested with therefore only needed Basic iOS MDM.

 

Allow users to copy Google Workspace items to personal apps:

I couldn't get this to do anything under Basic MDM, even though it's apparently supported. With the option unticked, I was still able to copy text from a work email in the Gmail app and paste it into the iOS Notes app.

 

The only way I could prevent work account content from being pasted into a third-party app was to up the MDM to Advanced and to set Gmail as a managed app. That then involved a few steps of onboarding to get the Google Device Policy app installed, an administrative profile downloaded, installed and trusted, and then the Gmail app updated. After that, content copied via the balloon menu when a chunk of text is highlighted was not available to paste outside of the app.

 

Allow users to share Google Workspace items to personal accounts with iOS share sheet:

Similarly not seeing this working under Basic MDM. I was able to select a chunk of text from a work email in the Gmail app and use the 'share' option in the balloon menu to attach it to a new note in iOS Notes.

 

Allow users to share Google Workspace items to AirDrop with iOS share sheet:

This option works under Basic MDM. Highlighting a chunk of text in a Gmail email or a Drive item and then selecting share form the iOS balloon menu, the AirDrop option is not shown.

 

Allow users to print Google Workspace files:

I wasn't testing on a device that had any printing option available anyway, but it might be that it does work, similar to the AirDrop and Files options do.

 

Allow users to save Google Workspace items to Files with iOS share sheet:

This option works under Basic MDM. Highlighting a chunk of text in a Gmail email or a Drive item and then selecting share form the iOS balloon menu, the "Save to Files" option is still shown but results in a pop-up stating that file sharing has been restricted by admin.

 

Allow users to save Google Workspace images and videos to iOS photos:

Haven't been able to test this properly, as I haven't been able to see what saving to iOS Photos looks like anyway, even with a non-work file.

 

Allow users to assign items to Contacts with iOS share sheet:

This option works under Basic MDM. When selecting an image in a work email or in Drive, the iOS share sheet hides the option to assign it to a contact (i.e. for adding a mugshot).

Edited by jthompson
Posted

So under Basic iOS MDM, there's still useful restriction available in preventing saving stuff to the Files app and preventing AirDrop.

 

Those only apply when using the Google apps though (and not even all of them, just Gmail, Drive, Docs, Sheets, Slides, Chat and Meet), so it may need to be used in conjuction with not allowing the Apple Mail app to be used with Workspace accounts.

Posted
So under Basic iOS MDM, there's still useful restriction available in preventing saving stuff to the Files app and preventing AirDrop.

 

Those only apply when using the Google apps though (and not even all of them, just Gmail, Drive, Docs, Sheets, Slides, Chat and Meet), so it may need to be used in conjuction with not allowing the Apple Mail app to be used with Workspace accounts.

With Jamf Pro it makes no difference which apps are being used to put these restrictions in place for BYOD users, there are at least 3 very large hospital trusts I know who use Jamf Pro for iOS and User Enrolment who use these restrictions for email and data content.

  • Thanks 1
Posted
With Jamf Pro it makes no difference which apps are being used to put these restrictions in place for BYOD users, there are at least 3 very large hospital trusts I know who use Jamf Pro for iOS and User Enrolment who use these restrictions for email and data content.

 

It does feel like Google's MDM offering is basically a case of mandating use of Google apps in order to completely ringfence Workspace data on iOS. To ringfence Workspace data whilst allowing use of third-party/Apple apps, then go use some other MDM.

 

Fair enough for a free option, I suppose.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...