Jump to content

Recommended Posts

Posted

My org is in the process of preparing for Cyber Essentials and are looking to roll out conditional access policies to lock down BYOD access and ensure that any devices accessing our cloud data are compliant.
The hurdle we've found as always is iPads. Co-managing windows devices and enrolling android devices in to Intune has been fine, however we use Jamf School for our iPads and are struggling to find any way that we can enroll them in to intune in order to assign a trusted device based conditional access policy for iOS devices. Without this we can't see any way that we can reliably monitor BYOD iOS devices and force enrollment for personal iPhones.

Has anyone else come across this issue and found any sort of solution that doesn't require moving every iPad to Jamf Pro or Intune? We've already moved MDM once a few years ago and it isn't an exercise any of our team are excited at the idea of doing again any time soon.

Posted

You can do it without an enrolling as devices in an MDM for Cyber Essentials using Conditional Access policies with MAM-WE (catchy name). It's primarily intended for BYOD, but for CE assessment it meets the requirements. 

 

MAM-WE is mobile apps management without enrollment. The policy essentially specifies that you can only access corporate/school data through an approved app. You then use App Protection Policies to ensure that the devices are compliant before the app installs or opens.

https://learn.microsoft.com/en-us/entra/identity/conditional-access/policy-all-users-windows-app-protection

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...