Is there a way to not require an app pin for iOS devices that already have a device lock pin on them, but for UN-MANAGED/UN-ENROLLED devices?

Madison544 20 Reputation points
2024-10-02T17:51:52.5466667+00:00

If I am in the wrong sub, please let me know where else I should post - any help is appreciated!

We recently created an app protection policy to secure outlook and teams for users that wish to access those apps on their personal devices without fully enrolling their devices into our management. I do see that we can set access requirements to require app pin for access to the app, and we can then select to not require app pin when device pin is set. However, I am seeing that this only works for MDM enrolled devices as there is a note next to the setting that says this. Therefore, any iOS device that is MAM-WE and not in Intune, but has a phone lock passcode, is still prompted for an app pin.

My question is - Are there any other settings or policies we can set so that even unmanaged iOS devices don't need to put an app pin in if they have a device lock?

** Under conditional launch/device conditions for Android devices, we can set it to require device lock, so why can we not set the IOS policy to check an IOS for a device lock passcode before booting as well? **

Microsoft Intune iOS
Microsoft Intune iOS
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.iOS: An Apple mobile operating system.
223 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
941 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,048 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Xenia-MSFT 2,180 Reputation points Microsoft Vendor
    2024-10-03T03:06:02.2033333+00:00

    @Madison544 Thanks for posting in our Q&A.

    It is by design. Based on my understanding, iOS and Android are the same. In android article, it also describes that Select Not required to disable the app PIN when a device lock is detected on an enrolled device with Company Portal configured.

    User's image

    https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-android#access-requirements

    From your description, did you mean that you don't need to enter PIN to access protected app when this android device is not enrolled, and it has device lock PIN?

    If there is anything update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.