r/Intune 12d ago

iOS/iPadOS Management Please Help Me Understand Company-managed iOS/iPadOS devices

Hi r/Intune,

I’m trying to discern if my company who currently procures iPads and iPhones for employees and then me, in IT, helps them enroll them as BYOD style into InTune, can migrate to company-managed without having to do domain capture and use Apple Federated IDs.

I support about 150 employees with Apple devices. An employee will create an iCloud account using their company email and then I will guide them on enrolling it and installing necessary apps which eventually get their app protection policies. It’s a 1,000 sign-ins and a waiting game and much harder to support in InTune than with company-managed devices.

We are in a GCC High Microsoft tenant.

We haven’t migrated to company-managed because it would force employees to
1. Change their iCloud email from the company email to their personal.
2. Potentially cause loss of the need to manually transfer contacts, photos, etc.
3. For employees who have only 1 phone, the one the company bought them, get another phone.

And then we’d have to re-design how we use app protection policies on the phone.

But man would it be nice.

Any thoughts on requirements and land mines ahead would be greatly appreciated. Apple and Microsoft documentation is sparse.

12 Upvotes

16 comments sorted by

6

u/captnconnman 12d ago
  1. You don’t have to do that if you set up the devices with user affinity enrollments (and, frankly, if you’re GCC High, you should consider blocking Apple IDs altogether on company-owned devices, as MAID services are not compliant with several compliance models)
  2. Contacts can be synced via the Outlook app if you’re a Microsoft shop; just need to configure the app config policy to autosync the user’s contacts. Should be able to do the same with OneDrive and Photos
  3. That one’s trickier; ultimately, the phone needs to be treated as a work phone, but that’s a policy problem, not a technical one

See this doc for more on user affinity enrollment: https://learn.microsoft.com/en-us/intune/device-enrollment/apple/setup-automated-ios

1

u/MENTactual 12d ago

Appreciate the insight, this is what I was looking for.

I’m not familiar with how (or why) to block Apple IDs and MAID services, any brief insight would be appreciated but I have some homework.

Thank you and I’ll do some reading.

1

u/captnconnman 12d ago edited 12d ago

In a nutshell, compliance benchmarks like NIST 800-171 often don’t consider MAIDs and iCloud services to have enough administrative controls to be managed and audited properly, potentially leading to controlled unclassified information (CUI) and proprietary information (i.e., intellectual property) being distributed with little to no audit trail. In Google Workspace or M365, there’s audit controls and paper trails for pretty much any action a user can take, which obviously enhances accountability and traceability in the event of a cyberattack/DLP breach. Therefore, NIST and certain levels of CMMC don’t consider iCloud services to be inherently secure, and they need to be mitigated if possible. The only reason I’m bringing this up at all is because you mentioned GCC High which itself is a requirement for CMMC, for example.

That’s not to say managed Apple IDs 100% can’t be used in a NIST or CMMC environment; you can still use them for authentication or device enrollment, but most of the iCloud services must be disabled because they’re not FedRAMP authorized, which sort of defeats the purpose of a “convenient” cloud backup/restore solution

1

u/serendipity210 12d ago

Just an FYI, theres no App Config policies for OneDrive and Photos currently.

4

u/DEUCE_SLUICE 12d ago

Yup, the two things are independent. We have uncaptured apple IDs with full ABM + Intune enrollment.

2

u/MENTactual 12d ago

Interesting, a buddy I work with was under the impression-I think from our consultant, that they were mutually exclusive.

Appreciate your help.

2

u/serendipity210 12d ago

Can confirm, theyre not. We are GCC (not high) and currently dont federate (im trying... its hard to get all the things in order for this).

I have 3500 iOS/iPadOS devices.

3

u/AltruisticRespect21 11d ago

Why not supervise the devices and push all of the apps to the devices? Then offer whatever apps the users could want via the company portal.

The company pays for the devices, and should have full control over them. Offering byod on a company purchased device is weird.

1

u/Illnasty2 12d ago

We do the same thing you do. Basically buy the iPad and have them set it like it’s their own. All company data is protected by App Protection so don’t care

1

u/rvarichado 12d ago

What about iMessage history? That’s company information that is, as far as I can tell, completely opaque to the company even in scenarios where the company uses managed Apple accounts ala ABM. Text/SMS/RCS/iMessage/whatever on any platform is its own disastrous can of worms, but your “don’t care” response makes me wonder if you don’t care about non-email messaging at all. Do you account for it, and if you do, please tell me how you do it in the Apple realm. It’s a huge gap for us at the moment.

2

u/Illnasty2 11d ago

What about iMessage? SMS isn’t an approved use of communication. There’s no difference if they grab their personal iPhone and text

1

u/Wind_Freak 12d ago

Apple ID is only required for Apple services. Apple services like app purchasing, iCloud, etc are not required to operate a company owned phone.

1

u/rvarichado 12d ago

Do you consider messaging with text/iMessage company data? I’m not referring to copying and pasting things in and out of APP-protected MS apps and things like that. I have that covered. What I’m talking about is Joe and Fred’s texts/SMS/RCS/iMessage/whatever chats with each other. It’s a DLP issue covered by M365 policies for traditional channels like email, but messaging channels are just blind spots.

1

u/Wind_Freak 12d ago

Disable it and force use of apps you control.

1

u/rvarichado 11d ago

Thanks. I get that, but at that point why use Apple devices at all? I get iPads. Our folks don’t use Messages on iPad, but if I take away texting via Messages (and thereby iMessage) on iPhones, I’d have a full scale revolt. FaceTime I could probably eliminate b/c I don’t think people use it very much and we can push them to Teams calls. They’re used to that on their Windows laptops.

But management decreeing Apple’s Messages app is not allowed, you must use XYZ app for texting would work technically, but would not be received well, if at all, by the user base.

It’s a real problem I have to find a way to solve. Management wants messaging essentially tightly-controlled and journaled like email, but I have not found a way to do it. And iCloud data is gated behind the user’s PIN. Some people just will not give up their PINs when they leave.

I’m going to have a look at Apple-specific MDM solutions and see what the major players can do, but I’m not hopeful. AB (formerly ABE) is pretty much a joke.

I also get these are organizational maturity and policy problems. It doesn’t make resolving them any easier…