Microsoft Intune App Protection for Windows (MAM for Windows)

แชร์
ฝัง
  • เผยแพร่เมื่อ 22 ก.ค. 2024
  • In this brief tutorial, I'll be keeping it light and breezy, discussing:
    The What: MAM for Windows in plain English.
    The Wow: Its slick features and how they’re a game-changer.
    The How: Quick guide to set it up without breaking a sweat.
    It's Windows security and data protection done right!
    0:00 What's the problem?
    1:24 What's the solution?
    2:15 Create a policy for Windows
    4:00 Create a CA policy to enforce MAM for Windows
    6:00 Test it out
    8:11 Conclusion?
  • วิทยาศาสตร์และเทคโนโลยี

ความคิดเห็น • 28

  • @patrick__007
    @patrick__007 ปีที่แล้ว +1

    Great feature. Thanks Dean!

  • @samv5876
    @samv5876 8 หลายเดือนก่อน

    nice one, what is the roadmap for this? Will this only support the browser based scenario or will it extend to the fat apps ?

  • @leklektv6154
    @leklektv6154 11 หลายเดือนก่อน

    Can we enforce a policy wherein end user could not install any software and prompt to have admin rights to install or block them when they try to install non compliance software. Thank you!

  • @sXRaider91
    @sXRaider91 3 หลายเดือนก่อน

    Hi Dean, very nice tutorial! Just a question: what are the dynamic rules for the 'Personal Device Users ' EntraID Group?

  • @joblearn1014
    @joblearn1014 10 หลายเดือนก่อน

    what licnses i need to enable to be able to use MAM>

  • @skoul27
    @skoul27 11 หลายเดือนก่อน

    I'm trying to add Edge app for windows MAM but it says "Can't find any apps". Do you know anything about it?

  • @lasolution365
    @lasolution365 4 หลายเดือนก่อน

    Do you need to enable WIP in Automatic Enrollment?

  • @QuintenMarais
    @QuintenMarais 3 หลายเดือนก่อน

    Hi Dean, A unique requirement I am facing, We have a CA policy applied to Windows devices, when accessing the Outlook app it will require BYOD devices to be enrolled and compliant to a compliance policy.. But, when the same user accesses OWA on a internet cafe machine, only a App protection policy needs to apply to that session .. the issue I am facing is that, both the App and OWA reports as a "Browser" to the CA policy.

  • @AutoNagri
    @AutoNagri 4 หลายเดือนก่อน

    Hi..
    After trying all the steps.. i am getting an error code of 53003.
    Test id not able to login chrome browser as per policy APP but getting an error in edge browser.

  • @i_m_veer_singh
    @i_m_veer_singh 11 หลายเดือนก่อน +1

    Hi Dean, I have more than 50 corporate iPad which are not under any vendor ABM or MDM and they all needs to be enrolled under our ABM. Is there any way to bulk enrol the devices under the ABM instead of manually doing it one by one using the Apple Configurator? I am using Intune as a MDM solution. Please suggest. Thanks

    • @DrKratzig
      @DrKratzig 9 หลายเดือนก่อน

      Hey, this could be done via your partner where you bought the devices. But your partner/vendor must be able to do so / allowed to do this. In Germany there are only a few official partners who can add devices to ABM.

  • @asdf87161
    @asdf87161 5 หลายเดือนก่อน +1

    The issue I am facing is that the work account gets registered under the local laptop work or school account after the MAM app protection policy for MS Edge is applied locally on the personal Windows laptop. Because of this, the user is able to login to local Teams, OneNote, Onedrive apps under the work account, but these applications cannot prevent copy and paste of information including files to other external applications. The app protection policy does work for the Office products within the Edge browser. How can I prevent the user from logging in to company O365 environment from the locally installed Teams, OneNote, Onedrive applications from the personal Windows laptop but allow all company O365 apps/data from MS Edge where the app protection policy works?

    • @agbnmr
      @agbnmr 4 หลายเดือนก่อน

      Conditional access - block the use of desktop apps

    • @TheMowgus
      @TheMowgus 10 วันที่ผ่านมา

      It would be nice if they had app protection policies for installed Office apps (just like they do on iOS and Android) but they don't. Seems like they want to push everyone to web based; even the new Outlook is just a web based app. They seem to forget that not everyone has constant or fast Internet access.

  • @lasolution365
    @lasolution365 ปีที่แล้ว +1

    Thank you, very interesting! Now, I am not sure why I would still use "App Enforced Restrction"...

    • @DeanEllerbyMVP
      @DeanEllerbyMVP  ปีที่แล้ว

      That's a good point! Perhaps this is the evolution of that?

  • @venezuelan15
    @venezuelan15 10 หลายเดือนก่อน

    screen shots?

  • @cyphernz
    @cyphernz ปีที่แล้ว +1

    What about preventing a user from using the Outlook App on a personal device?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP  ปีที่แล้ว

      You can achieve that with Conditional Access on it's own, but it's limited to allow or block (or require MFA i guess)

  • @Mkt6040
    @Mkt6040 9 หลายเดือนก่อน

    For the policy to take effect, does this require that the user be signed into the Edge browser with work profile/creds?

    • @DeanEllerbyMVP
      @DeanEllerbyMVP  9 หลายเดือนก่อน

      Yes, it does.

    • @nurbalqis9248
      @nurbalqis9248 9 หลายเดือนก่อน

      Hye dean,
      May i know is this features only works on window 11?
      because I can't log in even though I'm using a work account in the edge browser@@DeanEllerbyMVP

    • @TheMowgus
      @TheMowgus 10 วันที่ผ่านมา +1

      In testing I noticed that you have to be logged into Edge for this to work. That negates the point of this protection policy IMO. Staff have their corporate laptops but if they need to access their email from a friend's computer they will end up signing into Edge and the device gets registered in Entra. Might as well just block devices not joined in Entra rather than having staff signing into Edge with their tenant ID on non-corporate devices (which they won't sign out of or have the knowledge to delete their profile).

  • @danzirulez
    @danzirulez ปีที่แล้ว +2

    tried screenshotting? wonder if that works

    • @patrick__007
      @patrick__007 ปีที่แล้ว +1

      Guess that it will work. I believe this will also work on a protection policy in Android/iOS.

    • @DeanEllerbyMVP
      @DeanEllerbyMVP  ปีที่แล้ว +1

      Not tried! let me give it a go on a physical device, as I assume it will work fine on a virtual.

    • @danzirulez
      @danzirulez ปีที่แล้ว +2

      @@patrick__007 it does on iOS