Deployment iOS MDM - Managed & Complaint Device
Last updated
Last updated
Implement SCA within Microsoft Endpoint Manager for you Compliant Device The moment a user connects with the AAD-account Access control via Azure AD Conditional Access enforces our App to require a complaint device.
Login to Endpoint Manager with your Admin-Account
Go to Devices → Compliance policies or follow this link: Compliance policies - Microsoft Endpoint Manager admin center
Click on Create policy and select iOS/iPadOS as Plattform and click on Create
Enter a Name for your Policy e.g. “Secure Contacts App Compliance Policy”
Set necessary Compliance settings and Actions for noncompliance depending on environment
Confirm each Next
In Assignments pane, click Add group and search for SCA-Testgroup & confirm Select
Click on Next
Click on Create in Review + create pane
Go to Endpoint security → Conditional access or follow this link: Conditional Access - Microsoft Endpoint Manager admin center
Click on New policy to create a new Conditional Access policy
Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
Go to Users or workload identities in Assignments
Go to Cloud apps or actions in Assignments
Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value Mobile apps and desktop clients
Go to Grant in the Access controls pane
Set Enable Policy to On
Click on Create
According to Microsoft, it is mandatory to target Office 365 and Secure Contacts as Cloud App in your Conditional Access Policy in order to correctly implement SCA. It is required to add Office 365 as Cloud App, because our Enterprise Application (Provectus - Secure Contacts) is using these data sources.
Include your SCA-Testgroup to Users and Groups
Include as Cloud Apps the apps Office 365 and Provectus - Secure Contacts
Set Require compliant device