Skip to content

Commit a64632d

Browse files
committed
Merging changes synced from https://github.com/MicrosoftDocs/memdocs-pr (branch live)
2 parents 3e7d6c6 + 4a42fe9 commit a64632d

4 files changed

Lines changed: 43 additions & 35 deletions

File tree

memdocs/intune/apps/app-configuration-policies-use-ios.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -225,7 +225,7 @@ Apple's Automated Device Enrollments are not compatible with the app store versi
225225
- **Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity**:
226226

227227
> [!NOTE]
228-
> This process is not needed for iOS/iPadOS devices enrolling with ADE through Setup Assistant with modern authentication. Also, this is not needed for devices enrolling with ADE with user affinity if a VPP token is being used to send the Company Portal app to the device.
228+
> When the enrollment profile has **"Install Company Portal"** set to yes, Intune pushes the application configuration policy below automatically as part of the initial enrollment process. This configuration should not be deployed manually to users or devices as this will cause a conflict with the payload already sent during enrollment, resulting on end-users being asked to download a new management profile after signing in to Company Portal (when they shouldn't, because there is a management profile already installed on these devices).
229229
230230
``` xml
231231
<dict>

memdocs/intune/apps/manage-microsoft-edge.md

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -273,6 +273,18 @@ You can disable the extension framework, like Coupons, within Edge for iOS and A
273273
> [!NOTE]
274274
> Edge for iOS does not support disabling extensions.
275275
276+
#### Control Cookie Mode
277+
278+
You can control whether sites can store cookies for your users within Edge for Android. To do this, configure the following setting:
279+
280+
|Key |Value |
281+
|:-----------|:-------------|
282+
|com.microsoft.intune.mam.managedbrowser.cookieControlsMode |**0** (default) allow cookies <br>**1** block non-Microsoft cookies <br>**2** block non-Microsoft cookies in InPrivate mode <br>**3** block all cookies |
283+
284+
> [!NOTE]
285+
> Edge for iOS does not support controling cookies.
286+
287+
276288
### Kiosk mode experiences on Android devices
277289

278290
Edge for Android can be enabled as a kiosk app with the following settings:

memdocs/intune/configuration/telecom-expenses-monitor.md

Lines changed: 15 additions & 22 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ keywords: Saaswedo
66
author: MandiOhlinger
77
ms.author: mandia
88
manager: dougeby
9-
ms.date: 06/08/2020
9+
ms.date: 09/06/2022
1010
ms.topic: how-to
1111
ms.service: microsoft-intune
1212
ms.subservice: configuration
@@ -34,10 +34,12 @@ Using Intune, you can manage telecom expenses from data usage on organization-ow
3434

3535
The integration with Datalert can set, monitor, and enforce roaming and domestic data usage limits. When the limits exceed your thresholds, alerts are automatically triggered. You can also configure the service to apply different actions to users or groups, such as disable roaming or exceed the threshold. The Datalert management console includes reports that show data usage and monitoring information.
3636

37+
> [!IMPORTANT]
38+
> When you enable integration with Datalert, Intune is allowed to send the Subscriber Number, such as the device's phone number, and Azure AD `DeviceID` to an external third party.
39+
3740
The following image shows how Intune integrates with Datalert:
3841

39-
> [!div class="mx-imgBorder"]
40-
> ![Diagram of Intune and Datalert integration](./media/telecom-expenses-monitor/tem-datalert-intune-solution-diagram.png)
42+
:::image type="content" source="./media/telecom-expenses-monitor/tem-datalert-intune-solution-diagram.png" alt-text="A screenshot that shows the Microsoft Intune and Datalert integration, including blocking and unnblocking data." lightbox="./media/telecom-expenses-monitor/tem-datalert-intune-solution-diagram.png":::
4143

4244
To use the Datalert service with Intune, there are some configuration settings in Datalert and Intune. This article shows you how to:
4345

@@ -85,17 +87,15 @@ Intune integrates with the following telecom expense management provider:
8587

8688
The following image shows the green check marks when the connection succeeds:
8789

88-
> [!div class="mx-imgBorder"]
89-
> ![Datalert page showing Intune / Datalert on successful connection.](./media/telecom-expenses-monitor/tem-datalert-connection.png)
90+
:::image type="content" source="./media/telecom-expenses-monitor/tem-datalert-connection.png" alt-text="[A screenshot that shows the Datalert page with the Microsoft Intune / Datalert Connection with a successfull status.":::
9091

9192
7. In **Datalert App / ADAL Consent**, set the switch to **On**. On the Microsoft authentication page, select **Accept**.
9293

9394
You're redirected to a Datalert **thank you** page that closes after a few moments. Datalert validates the connection, and shows green check marks next to the items that validated. If validation fails, you see a message in red. Contact Datalert support for help.
9495

9596
The following image shows the green check marks when the connection succeeds:
9697

97-
> [!div class="mx-imgBorder"]
98-
> ![Datalert page showing Datalert App / ADAL Consent on successful connection.](./media/telecom-expenses-monitor/tem-datalert-adal-consent.png)
98+
:::image type="content" source="./media/telecom-expenses-monitor/tem-datalert-adal-consent.png" alt-text="[A screenshot that shows the Datalert page with the Datalert App / ADAL Consent status that's successfull." lightbox="./media/telecom-expenses-monitor/tem-datalert-adal-consent.png":::
9999

100100
8. In **MDM Profiles management (optional)**, set the switch to **On**. This setting allows Datalert to read the available profiles in Intune to help you set up policies.
101101

@@ -105,8 +105,7 @@ Intune integrates with the following telecom expense management provider:
105105

106106
The following image shows the green check marks when the connection succeeds:
107107

108-
> [!div class="mx-imgBorder"]
109-
> ![Datalert page showing M D M Profiles management on successful connection.](./media/telecom-expenses-monitor/tem-datalert-mdm-profiles.png)
108+
:::image type="content" source="./media/telecom-expenses-monitor/tem-datalert-mdm-profiles.png" alt-text="[A screenshot that shows the Datalert page with the MDM Profiles management status with a successfull connection." lightbox="./media/telecom-expenses-monitor/tem-datalert-mdm-profiles.png":::
110109

111110
### Step 2: Confirm telecom expense management is active in Intune
112111

@@ -116,8 +115,7 @@ After you complete Step 1, your connection is automatically enabled. In Intune,
116115

117116
2. Select **Tenant administration** > **Connectors and tokens** > **Telecom Expense Management**. Look for the **Active** connection status:
118117

119-
> [!div class="mx-imgBorder"]
120-
> ![Intune page showing datalert connection status Active](./media/telecom-expenses-monitor/tem-azure-portal-enable-service.png)
118+
:::image type="content" source="./media/telecom-expenses-monitor/tem-azure-portal-enable-service.png" alt-text="[A screenshot that shows Microsoft Intune with a successful and active connection status with Datalert in the Endpoint Manager admin center." lightbox="./media/telecom-expenses-monitor/tem-azure-portal-enable-service.png":::
121119

122120
### Step 3: Deploy the Datalert app to devices
123121

@@ -136,8 +134,7 @@ To create device categories in Intune, see [map devices to groups](../enrollment
136134

137135
These categories are shown to users during enrollment ([enroll Android devices](../enrollment/android-enroll.md)). Depending on the category users choose, the enrolled device is moved to the corresponding device group.
138136

139-
> [!div class="mx-imgBorder"]
140-
> ![Screenshot of the Corporate device group Dynamic membership rules page.](./media/telecom-expenses-monitor/tem-dynamic-membership-rules.png)
137+
:::image type="content" source="./media/telecom-expenses-monitor/tem-dynamic-membership-rules.png" alt-text="[A screenshot that shows the Corporate device group Dynamic membership rules page in Microsoft Intune." lightbox="./media/telecom-expenses-monitor/tem-dynamic-membership-rules.png":::
141138

142139
#### Add the Datalert app to Intune
143140

@@ -151,13 +148,11 @@ The following steps add the Datalert app. As an example, iOS/iPadOS is used. [Ad
151148

152149
4. Choose the **Datalert** app > **Select**:
153150

154-
> [!div class="mx-imgBorder"]
155-
> ![Add the datalert app from the app store to Intune client apps](./media/telecom-expenses-monitor/tem-select-app-from-apple-app-store.png)
151+
:::image type="content" source="./media/telecom-expenses-monitor/tem-select-app-from-apple-app-store.png" alt-text="[A screenshot that shows how to add the Datalert app in Microsoft Intune.":::
156152

157153
5. Enter any additional properties, such as app information and scope tags:
158154

159-
> [!div class="mx-imgBorder"]
160-
> ![Enter the app properties, including the name, description, choose the OS, and more settings to the app in Intune](./media/telecom-expenses-monitor/tem-steps-to-create-the-app.png)
155+
:::image type="content" source="./media/telecom-expenses-monitor/tem-steps-to-create-the-app.png" alt-text="[A screenshot that shows how to enter the app properties, including the name, description, choose the OS, and more settings to the app in Microsoft Intune." lightbox="./media/telecom-expenses-monitor/tem-steps-to-create-the-app.png":::
161156

162157
6. Select **OK** > **Add** to save your changes. The Datalert app is shown in the list.
163158

@@ -169,17 +164,15 @@ The following steps add the Datalert app. As an example, iOS/iPadOS is used. [Ad
169164

170165
In these steps, you'll choose to make the app installation required or optional for the group. The following example shows the installation as required. When required, users must install the Datalert app after enrolling their device.
171166

172-
> [!div class="mx-imgBorder"]
173-
> ![Screenshot of the Add a policy pane](./media/telecom-expenses-monitor/tem-assign-datalert-app-to-device-group.png)
167+
:::image type="content" source="./media/telecom-expenses-monitor/tem-assign-datalert-app-to-device-group.png" alt-text="[A screenshot that shows how to add an app policy in Microsoft Intune." lightbox="./media/telecom-expenses-monitor/tem-assign-datalert-app-to-device-group.png":::
174168

175169
### Step 4: Add organization phone lines to the Datalert console
176170

177171
Intune and Datalert services are now configured to communicate with each other. Next, add your organization paid phone lines to the Datalert console. Enter thresholds and actions for any cellular or roaming usage violations. You can manually add corporate paid phone lines to the Datalert console, or automatically add them after the device is enrolled in Intune.
178172

179173
To set these items, go to the [Datalert setup for Microsoft Intune](http://www.datalert.fr/microsoft-intune/intune-setup) (opens Datalert's web site). Under the **Settings** tab, follow the steps in the setup wizard.
180174

181-
> [!div class="mx-imgBorder"]
182-
> ![Screenshot of the wizard for Datalert setup.](./media/telecom-expenses-monitor/tem-add-phone-lines-to-datalert-console.png)
175+
:::image type="content" source="./media/telecom-expenses-monitor/tem-add-phone-lines-to-datalert-console.png" alt-text="[A screenshot that shows the Datalert website when the Microsoft Intune setup completes." lightbox="./media/telecom-expenses-monitor/tem-add-phone-lines-to-datalert-console.png":::
183176

184177
The Datalert service is now active. It starts monitoring data usage, and disabling cellular and roaming data on devices that exceed the configured usage limits.
185178

@@ -205,4 +198,4 @@ For the end-user experience, the following articles may help:
205198
206199
## Next steps
207200

208-
Data usage reporting is available in Saaswedo's Datalert management console.
201+
Data usage reporting is available in Saaswedo's Datalert management console.

memdocs/intune/enrollment/device-enrollment-program-enroll-ios.md

Lines changed: 15 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: Lenewsad
99
ms.author: lanewsad
1010
manager: dougeby
11-
ms.date: 04/15/2022
11+
ms.date: 08/24/2022
1212
ms.topic: how-to
1313
ms.service: microsoft-intune
1414
ms.subservice: enrollment
@@ -33,9 +33,6 @@ ms.collection:
3333

3434
# Automatically enroll iOS/iPadOS devices by using Apple's Automated Device Enrollment
3535

36-
> [!IMPORTANT]
37-
> Apple recently changed from using the Apple Device Enrollment Program (DEP) to using Apple Automated Device Enrollment (ADE). The Microsoft Intune user interface doesn't currently reflect that change. Currently, you'll still see *Device Enrollment Program* in the Intune portal. Wherever you see references to DEP, Intune now uses Automated Device Enrollment.
38-
3936
You can set up Intune to enroll iOS/iPadOS devices purchased through Apple's [Automated Device Enrollment (ADE)](https://deploy.apple.com). Automated Device Enrollment lets you enroll large numbers of devices without ever touching them. Devices like iPhones, iPads, and MacBooks can be shipped directly to users. When a user turns on the device, Setup Assistant, which includes the typical out-of-box-experience for Apple products, runs with preconfigured settings and the device enrolls into management.
4037

4138
To enable ADE, you use the Intune portal and either the [Apple Business Manager (ABM)](https://business.apple.com/) portal or the [Apple School Manager (ASM)](https://school.apple.com/) portal. In either Apple portal, you need a list of serial numbers or a purchase order so you can assign devices to Intune for management. You create ADE enrollment profiles in Intune. These profiles contain settings that are applied to devices during enrollment. ADE can't be used with a [Device Enrollment Manager](device-enrollment-manager-enroll.md) account.
@@ -45,18 +42,24 @@ To enable ADE, you use the Intune portal and either the [Apple Business Manager
4542
4643
If you experience sync problems during the enrollment process, you can look for solutions at [Troubleshoot iOS/iPadOS device enrollment problems](/troubleshoot/mem/intune/troubleshoot-ios-enrollment-errors#error-messages).
4744

48-
## Automated Device Enrollment and Company Portal
45+
## Deploy Company Portal app
46+
47+
> [!IMPORTANT]
48+
> We don't recommend using the App Store version of the Company Portal app because it isn't compatible with automated device enrollment and doesn't provide the automatic updates and availability like deployment does.
4949
50-
ADE enrollments aren't compatible with the App Store version of the Company Portal app. You can give users access to the Company Portal app on an ADE device. You might want to provide this access for one of the following reasons:
51-
- To let users choose which corporate apps they want to use on their devices
52-
- To use modern authentication to complete the enrollment process
53-
- To provide a staged enrollment in which the device is enrolled and receives device policies before users authenticate in Company Portal
50+
Deploying the Intune Company Portal app through Intune is the best way to provide the app to users and the only way to:
5451

55-
To enable modern authentication during enrollment, push the app to the device by using **Install Company Portal with VPP** (Volume Purchase Program) in the ADE profile. For more information, see [Automatically enroll iOS/iPadOS devices with Apple's ADE](device-enrollment-program-enroll-ios.md#create-an-apple-enrollment-profile).
52+
* Enable automatic app updates for Company Portal on ADE devices
53+
* Ensure all ADE devices, including already-enrolled ones, receive the app
5654

57-
To enable the Company Portal to update automatically and provide the Company Portal app on devices already enrolled with ADE, deploy the Company Portal app through Intune as a required VPP app with an [application configuration policy](../apps/app-configuration-policies-use-ios.md#configure-the-company-portal-app-to-support-ios-and-ipados-devices-enrolled-with-automated-device-enrollment) applied. Deploy the Company Portal app in this way to enable Device Staging for devices only without user affinity. With Device Staging, a device is fully enrolled and receives device policies before the addition of a user affinity. Device Staging can also be used to transition a device without user affinity, to a device with user affinity.
55+
Deploy the app as a required, VPP app [with device licensing](../apps/vpp-apps-ios.md#how-are-purchased-apps-licensed). For information about how to sync, assign, and manage a VPP app, see [assign a volume-purchased app](../apps/vpp-apps-ios.md#assign-a-volume-purchased-app).
5856

59-
Specifically for the authentication method Setup Assistant with modern authentication, do not separately deploy the Company Portal app as a client app, with or without an app config targeted to it. ADE devices enrolling with Setup Assistant with modern authentication should be excluded from any separate Company Portal targeting in the tenant. The Company Portal is sent as a required app automatically when Setup Assistant with modern authentication is chosen as the authentication method in the assigned enrollment profile.
57+
To enable automatic app updates for Company Portal, go to your app token settings in the admin center and change **Automatic app updates** to **Yes**. See [Upload an Apple VPP or Apple Business Manager location token](../apps/vpp-apps-ios.md#upload-an-apple-vpp-or-apple-business-manager-location-token) for the steps to access your token settings. If you don't enable automatic updates, the device user will need to manually check for them on their own.
58+
59+
*Device staging* is used to transition a device without user affinity, to a device with user affinity. To stage a device, set up VPP deployment as described earlier in this section. Then configure and deploy an [app configuration policy](../apps/app-configuration-policies-use-ios.md#configure-the-company-portal-app-to-support-ios-and-ipados-devices-enrolled-with-automated-device-enrollment). Make sure the policy only targets those ADE devices without user affinity.
60+
61+
> [!IMPORTANT]
62+
> During initial enrollment, Intune automatically pushes the app configuration policy settings under [Use the Company Portal on an Automated Device Enrollment (ADE) device enrolled with user affinity](../apps/app-configuration-policies-use-ios.md#configure-the-company-portal-app-to-support-ios-and-ipados-devices-enrolled-with-automated-device-enrollment) when the enrollment profile setting **"Install Company Portal"** is set to yes. This configuration should not be deployed manually to users because it will cause a conflict with the configuration sent during the initial enrollment. If both are deployed, Intune will incorrectly prompt device users to sign in to Company Portal and download a management profile they've already installed.
6063
6164
## What is supervised mode?
6265

0 commit comments

Comments
 (0)