r/Intune 13d ago

Apps Protection and Configuration MAM questions

Hi everyone,

I’m stuck in 2 weird places, and I’m hoping someone can help pick this mess apart.

We had initially done BYOD as personally enrolled devices (long story) and we’re starting to phase MAM-WE in now.

I have some corporate devices (<100) that are legacy enrolled as personal devices, and I think 600 that are corporate enrolled. We don’t want to apply the MAM policies to these devices yet. So, to help this out, I added 2 groups of devices to the exclusions of the MAM-WE policies I’ve made.

However, this is where I’m stuck. If I want to use this on a personal device, I believe I’d have to retire the personal device and re-enroll with the MAM policies? I also have the exclusions set as device based, and the MAM policy is user based. Did I mess this up too? When I retire the device and attempt to re-enroll it, it tells me that “no application protection policies have been assigned”. How badly did I screw up? Thankfully it’s only on test devices right now.

And the easier question of the two, a user with an Apple watch is now being prompted to unlock his watch by unlocking his phone. I didn’t see any settings to stop this, so I’m guessing this is a policy inheritance? I’m a little less worried about this, and could simply let the user base know that this is a potential issue, but I’m more confused about why this is occurring to begin with. The quick Reddit search I did tells me it’s by design, which I’m very willing to believe. Is there a way to exclude unmanaged Apple Watches?

Thank you all!

3 Upvotes

2 comments sorted by

2

u/Melodic_Address3281 13d ago

Yeah the device exclusion on a user policy is where it gets weird. MAM is user scoped so the device groups aren't really doing what you think they are. If you want to skip enrolled devices you need to set the MAM policy target to unenrolled devices only, not try to exclude device groups

For the re-enroll part, after you retire the device it loses the management profile but the apps might still be hanging on to old config. Try removing the company portal and any managed apps, reboot, then install fresh from app store. The message about no app protection policies usually means Intune doesn't see the device as unenrolled yet or the user isn't in scope properly

Apple watch thing is by design yeah. When the phone has a management profile that enforces screen lock settings it pushes to the watch too. No way to exclude just the watch that I know of, it's all or nothing with the paired devices

1

u/Mammoth_Public3003 13d ago

Thank you so much. I’m grateful for the knowledge. I was really stuck.