Microsoft

Microsoft Intune Feedback

Suggestion box powered by UserVoice

How can we improve Microsoft Intune

Add a policy to prevent device unenrollment from Company portal

Companies provide devices to their employees and generally wants to make sure that these devices will always remain managed through Intune. It could be interesting to have a policy that prevent users to unenroll a device identified as a company device from the Intune company portal.

641 votes
Vote
Sign in
(thinking…)
Password icon
Signed in as (Sign out)
You have left! (?) (thinking…)
Jean-Baptiste Frossard shared this idea  ·   ·  Flag idea as inappropriate…  ·  Admin →

The PMs involved have been talking about how best to give you a way to disable the “remove device” action. They think rather than focusing on platform enrollment types (iOS, Android, Windows), they could allow you to disable based on corporate vs personal ownership. I said I’d ask if that would work for you. :-)

Would that get you want you need?

68 comments

Sign in
(thinking…)
Password icon
Signed in as (Sign out)
Submitting...
  • Rob de Roos commented  ·   ·  Flag as inappropriate

    @Cathy, that would indeen be briliant! I can imagine however that in some cases (testing for example) you have to be able to exclude devices.

  • Alexander Kanakaris commented  ·   ·  Flag as inappropriate

    We are stalling the deployment of Intune for MDM of iOS and Android due to this huge security hole!

    This needs to be fixed ASAP as it poses a major security risk because the end users can even send a Refresh or Reset command via their mobile phone’s Company Portal app to their Corporate owned system in the office!

    I have an open case with Intune about this.

  • Jegan Devabalan commented  ·   ·  Flag as inappropriate

    We have 3000 devices about to get enrolled with Intune but its leaving a risk were user can un-enroll the device on their own. I would like microsoft to come with a solution as soon as they can . Also i want to be keep posted about this.

  • Darwis Fransida commented  ·   ·  Flag as inappropriate

    Yes, that will work for us to control/restrict the ability to remove device from InTune Comp Portal if the device ownership is set to Corporate.

  • Marco commented  ·   ·  Flag as inappropriate

    Actually it would be great if there would be an option to the user to remove his onmicrosoft.com account from the info. I personally broke the Intune enrollment when I removed the user and added a new one within the same session.
    Intune sees the device as unenrolled and even when I put back the original user the enrollment didn't recover.

    This is a known issue in the way intune manages shared devices that are used by different users as so far Intune has only one possible user assigned to the device

  • Dan goodwin commented  ·   ·  Flag as inappropriate

    Hi guys i have found a way round it if you have knox devices.

    Instead of enrolling android enterprise, enrol just android.

    The differences
    Android enterprise- if you uninstall the company portal, knox deployment will not force the enrolment again.

    Android- if you uninstall the company portal, knox deployment will force the user to go through the deployment again which involves installing and enrolling the company portal. During this time they are unable to use the back button, home button or split button.

    So I think rolling out the devices as personal will ensure the devices are still managed

  • Anonymous commented  ·   ·  Flag as inappropriate

    Disabling corporate vs personal would be an option. It may also be nice to have some sort of policy set that us as admins could deploy. As admins you could test with multiple devices and if it automatically did not allow removal of the portal app, that could hinder testing from our side. If you could deploy it as a policy set it could allow use to point this to specific groups or collections. A case for this would be that my company has some outward facing Android devices that we manage. We can not use DEP since thats iOS. There would be an administrative burden to always verify the Android devices are always imported via manual efforts to verify they are "company owned." We get in hundreds of these devices that a specific group of individuals use. The company wants these individual users to enroll vs an enrollment administrator. If you could target a policy to these people which would remove the ability in the app to be removed, it would be beneficial.

  • Stephen B commented  ·   ·  Flag as inappropriate

    This is a very basic MDM requirement for company owned devices.

    Please make this available ASAP!!

  • Dan commented  ·   ·  Flag as inappropriate

    What is the point of advertising Intune as MDM if this is not a feature. AirWatch ( a MDM solution ) provides this capability.

  • Anonymous commented  ·   ·  Flag as inappropriate

    "This policy setting is not applied if the computer is Azure Active Directory joined and auto-enrollment is enabled." As most people work this was please add Block Manual unenrollment

  • Carlos Conrado commented  ·   ·  Flag as inappropriate

    Hi Cathy having the disable remove device based on corp or personal device would be a good enough solution.

    Thanks

  • Rob de Roos commented  ·   ·  Flag as inappropriate

    Isn't this available allready? I believe it is. Disable manual unenrollment it is called if I am not mistaken.

← Previous 1 3 4

Feedback and Knowledge Base