Ideas
What features would you like to see?
All of the feedback that you share in these forums will be monitored and reviewed by the Microsoft engineering teams responsible for building Microsoft Endpoint Manager Intune, though we can’t promise to reply to all posts.
Standard Disclaimer – our lawyers made us put this here ;-) We have partnered with UserVoice, a third-party service, so you can give us feedback. Please note that the Intune feedback site is moderated and is a voluntary participation-based project. Please send only feature suggestions and ideas to improve Intune. Do not send any novel or patentable ideas, copyrighted materials, samples or demos. Your use of the portal and your submission is subject to the UserVoice Terms of Service & Privacy Policy, including the license terms.
-
Ability to add apps to the list "require approved client app"
The "require approved client apps" feature in conditional access is a very good security feature, but sometimes a 3:rd party app must be supported, .e.g., a room booking system for mobile devices. If the feature "require approved client apps" is enabled, there is no way to support a 3:rd party app. Please make it possible to add apps (tenant wide) to the "require approved client apps" list.
330 votes -
Microsoft Whiteboard Client as Approved client app requirement for Conditional Access
Please add Microsoft Whiteboard Client as Approved client app requirement for Conditional Access so that this is not blocking productive on IOS/Android when trying to secure SharePoint/OneDrive.
https://docs.microsoft.com/en-us/azure/active-directory/conditional-access/technical-reference#approved-client-app-requirement304 votes -
Add Conditional Access support to Microsoft App Access Panel / MyApps
To allow us to create a blanket policy and then exclude the MyApps site from the Conditional Access Policy.
We can then allow customers to login and use the MyApps site as a launch pad to all their services whilst being very specific about what apps require additional compliance.
208 votes -
Conditional Access to Corporate Devices whilst allowing MAM-WE to Personal
Most users in companies have multiple devices, a mix of corporate and personal.
Most users don't mind enrolling Corporate devices but do not want to enrol personal devices but want access to email on those devices as well.
It should be possible to ensure the corporate devices must enroll, but the personal devices are only affected by MAM-WE policies so the personal devices for the same user do not need to enrol but only need to register.Maybe add an option to say if device in Corporate Identifiers it must enrol or make the conditional access policy able to read…
200 votes -
Custom text for block access option in Conditional Access
Please add the ability to customize the text that the end-user receive, when a sign in is being blocked due to corporate defined conditional access policies.
150 votes -
Device ownership a condition of conditional access
The potential to place a device into a quarantine before permission is granted to access any corporate resource. Many of my customers wish to use Intune and have a mobility strategy but wish to restrict access to corporate devices only.
Perhaps one way to achieve this is to make it a condition for conditional access scenarios that the device is 'corporate', which could be extended to Azure AD conditional access too. This may give the opportunity to have different access policies depending on the application or service being granted access to.
143 votes -
Support IPv6 in Conditional Access
Allow the use of IPv6 within Conditional Access.
127 votes -
Audit logs for Conditional Access
Add audit logs for Conditional Access, to log e.g. who created a policy, who modified what properties, who disabled / enabled a policy etc.
119 votes -
Conditional Access: Session Controls for Exchange Online (Outlook on the Web)
Expand the cloud app Session Controls area to be able to apply OWA policies on-the-fly.
Allow admins to do things like block download access unless the user is within a trusted location or on a compliant or domain joined device.
Effectively this, but without the need for ADFS: https://technet.microsoft.com/en-us/library/dn530630(v=exchg.150).aspx
Combining that with the SharePoint session controls will result in a more complete browser-only experience for unmanaged/untrusted devices.
116 votes -
Create a conditional access policy for Users not enrolled or on a compliant Device
Many of our users work from home and do not want their personal Windows computer to be either enrolled into our MDM suite or onto Azure AD. With our strict compliance regulations users are struggling to make their own Windows computer devices compliant.
Would it be possible to have a policy that is in the middle, where users can access emails, OneDrive for Business and SharePoint sites without the need to be on a domain joined computer or enrolled into our MDM suite. I would like to see this policy give the user access to all content but only from…
84 votes -
Extend conditional access to cover EWS for on-premise Exchange
Extend conditional access to cover EWS for on-premise Exchange. At present we are able to protect all entry methods other than Outlook on OSX connecting via EWS
72 votes -
Please fix the Conditional Access Policies on nested groups
We recently ran into the issue that our Conditional Access Policies were not applied to members of a nested Azure AD Security group that is a member of the Azure AD security group the policy is assigned to. Support confirmed this is currently "as designed". Can you please fix this so policies are applied to members of nested groups as well? Thank you!
67 votes -
MAC OS X Blocked from Sharepoint online and Exchange Online Access
We have many MAC OS X Computer on our network and would like our Users to be able to access Sharepoint online and Exchange online from their MAC OS X Machines.
We have a conditional access policy setup for all our User to protect our data around Sharepoint and Exchange online however MAC OS X users cant access these features online or even offline due to the policy being in place. This could be a supported device if a user for MAC OS X could complete the authentication process with the use of the digital certificate which is prompted to…
-
Screen_Shot_2016-11-02_at_11.07.58.png 75 KB -
Screen_Shot_2016-11-02_at_11.07.58_1_.png 75 KB -
Screen_Shot_2016-11-01_at_16.10.09.png 251 KB -
Screen_Shot_2016-11-02_at_10.51.43.png 199 KB -
Screen_Shot_2016-11-02_at_10.32.29.png 132 KB -
Screen_Shot_2016-11-01_at_12.18.07.png 296 KB -
Screen_Shot_2016-11-01_at_16.09.48.png 320 KB
59 votes -
-
Ability to block all cloud apps except the ones for Intune enrollment (Windows 10)
We have a Conditional Access policy which is configured to grant access to All cloud Apps only if you are Hybrid domain join or compliant.
We would like to setup exclusions within this CA for Intune enrollment apps, because selecting Microsoft Intune and Microsoft Intune Enrollment are not encompassing enough.
During the enrollment process (e.g. Windows10 device BYOD or during Autopilot Account setup) Microsoft Application Command Service app is used, unfortunately it can be excluded.
I have raised and identified this issue with MS support in the case number 119091321001371
54 votes -
Condition based on What version of Windows is installed (Home/Pro)
I've been looking at deploying Windows Information Protection (WIP) to BYO Win10 devices. Got the policy working and thought we were good to go. The issue now is Windows 10 Home doesn't support WIP. So these users have access to the corporate data by default.
I think it would be nice to be able to base a condition on the version (edition) of Windows. This would allow us to block windows 10 Home from using OneDrive sync/office apps natively and only allow access via the session based policy. We can then allow a better experience on Window 10 Pro users…
53 votes -
Add conditional access support for "Microsoft Dynamics 365 for Finance and Operations"
Allow Dynamics 365 to be blocked using conditional access, currently you cannot apply conditional access policies to Dynamics 365 ERP.
It would be great, if the product group would add this feature! Application is called "Microsoft Dynamics ERP" and have the following App ID "00000015-0000-0000-c000-000000000000" in Azure Active Directory.
Customers would like to add specific conditional access rules around the invoice approval.
49 votes -
Require device enrollment via Conditional access
At present we can only require a device to be marked as compliant. This may be too high of a bar for some organizations, specifically with Windows 10 devices. There should be an option to Require device enrollment, this would make implementing Conditional access easier for Windows 10 especially. That way, we can still force devices into our inventory and bring them under management control, without evaluating compliance as a bar to access. Compliance could be measured separately, and once the org has reached an acceptable compliance status across the entire inventory, only then move the lever up to Require…
45 votes -
Conditional Access feature support for PowerBI
Currently the PowerBI does not have feature support for Conditional Access with Intune or Azure AD Conditional Access.
This causes the PowerBI to be blocked when Conditional Access is configured and enabled for device targeting.
Requesting the feature support for Conditional Access to be implemented for PowerBI to allow this area of support for the product.
43 votes -
Yammer Support for Conditional Acces
Currently the Yammer Mobile App does not have feature support for Conditional Access with Intune or Azure AD Conditional Access to work with MAM WE.
This causes the Yammer App to be blocked when Conditional Access is configured and enabled for device targeting.
Requesting the feature support for Conditional Access to be implemented for Yammer to allow this area of support for the product.
Please also note the conversation in this thread: https://www.yammer.com/microsoft.com/#/Threads/show?threadId=800165359
Thank you.
42 votes -
Conditional Access for Windows - disable for RDS and Citrix
Conditional Access for Windows is working fine on client PC/devices. But if we enable Conditional Access for Windows with a customer that has RDS or Citrix (also a form of a client) then Enchange online and sharepoint online is block on RDS or Citrix.
Please change the policy settings for Conditional Access for Windows so that Contitional Access for Windows is not working on RDS and Citrix servers with Word/Outlook/Excel/OneDrive installed.40 votes
- Don't see your idea?