How to apply an Intune app protection policy for specific devices

Nick Stewart 0 Reputation points
2024-02-16T11:10:46.3666667+00:00

We have a large number of shared desk phones running Android version 9 (latest version from the vendor). Any of our users can login into the shared devices, to complicate matters we also have a BYO Intune app protection policy applied to all users that prohibits devices from running such a low version of Android. I have been looking at creating a 2nd policy App protection policy for the desk phones and then look to exclude them from the main policy, to do this I have created a Dynamic AAD group that is auto populated when these devices register in AAD. however the documentation for Intune states that App protection policies apply only to user accounts and not dynamic resource groups. so I'm a bit stuck. Other than having a group that we populate manually when a user wants to use shared desk phone or not running app protection, does any one have an automated approach to resolve this issue ? Thanks in advance!

Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
984 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 10,776 Reputation points MVP
    2024-02-16T15:30:16.5533333+00:00

    Have you considered using Device filters for the assignments instead? You can create a filter for desk phones and exclude it from your APP assignment. Maybe this can help - https://rahuljindalmyit.blogspot.com/2021/06/a-pinch-of-settings-catalog-dash-of.html

    0 comments No comments

  2. Crystal-MSFT 52,216 Reputation points Microsoft Vendor
    2024-02-19T01:47:48.8366667+00:00

    @Nick Stewart, Thanks for posting in Q&A. Just as you know, App protection policy can only assign to user group. To prevent the Intune app protection policy which prohibits devices from running a low version on these shared devices. You can check if the filter in Intune can filter these devices. For app protection policy, it uses managed app type.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/filters#restrictions

    For managed app properties, I find one named deviceManagementType with a value "Corporate-owned dedicated devices with Azure AD Shared mode". If these shared devices are enrolled with this. We can choose this as a filter to avoid your app protection policy to apply to these devices.

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/filters-device-properties#managed-app-properties

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


  3. Kudi Dzambazi 0 Reputation points
    2025-02-18T22:09:25.2966667+00:00

    Hello, did you find a solution? i'm facing the same problem.

    Would be great to know.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.