Deployment iOS MDM - Managed & Complaint Device

Implement SCA within Microsoft Endpoint Manager for you Compliant Device The moment a user connects with the AAD-account Access control via Azure AD Conditional Access enforces our App to require a complaint device.

Compliance Policy

  1. Login to Endpoint Manager with your Admin-Account

  2. Go to Devices → Compliance policies or follow this link: Compliance policies - Microsoft Endpoint Manager admin center

  3. Click on Create policy and select iOS/iPadOS as Plattform and click on Create

  4. Enter a Name for your Policy e.g. “Secure Contacts App Compliance Policy”

  5. Set necessary Compliance settings and Actions for noncompliance depending on environment

  6. Confirm each Next

  7. In Assignments pane, click Add group and search for SCA-Testgroup & confirm Select

  8. Click on Next

  9. Click on Create in Review + create pane

Conditional Access Policy

  1. Go to Endpoint security → Conditional access or follow this link: Conditional Access - Microsoft Endpoint Manager admin center

  2. Click on New policy to create a new Conditional Access policy

  3. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”

  4. Go to Users or workload identities in Assignments

  5. Go to Cloud apps or actions in Assignments

  6. Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value Mobile apps and desktop clients

  7. Go to Grant in the Access controls pane

  8. Set Enable Policy to On

  9. Click on Create

According to Microsoft, it is mandatory to target Office 365 and Secure Contacts as Cloud App in your Conditional Access Policy in order to correctly implement SCA. It is required to add Office 365 as Cloud App, because our Enterprise Application (Provectus - Secure Contacts) is using these data sources.

Last updated