{"id":325,"date":"2018-12-14T13:16:39","date_gmt":"2018-12-14T12:16:39","guid":{"rendered":"http:\/\/test.bleuanus.nl\/?p=325"},"modified":"2018-12-14T13:17:49","modified_gmt":"2018-12-14T12:17:49","slug":"migrate-users-from-ios-mail-native-to-microsoft-outlook-with-intune","status":"publish","type":"post","link":"https:\/\/www.bleuanus.nl\/index.php\/2018\/12\/14\/migrate-users-from-ios-mail-native-to-microsoft-outlook-with-intune\/","title":{"rendered":"Migrate users from ios mail native to Microsoft Outlook with Intune"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Nowadays, the smartphone takes up a lot of room in our personal and professional lives. Being able to receive your work emails directly on a mobile device is becoming popular.&nbsp;Based on&nbsp;<a href=\"https:\/\/blogs.technet.microsoft.com\/enterprisemobility\/2017\/03\/16\/this-is-a-cant-miss-episode-of-the-endpoint-zone\/\">latest numbers provided by Brad Anderson<\/a>&nbsp;from Microsoft, companies are more willing to use mobile device management solution like&nbsp;<a href=\"https:\/\/channel9.msdn.com\/Series\/Endpoint-Zone\/The-Endpoint-Zone-with-Brad-Anderson-1801\">Microsoft Intune<\/a>&nbsp;and let users access company data from outside the corporate network.&nbsp;Some companies shared beautiful stories of using Microsoft\u2019s EMS solution, like&nbsp;<a href=\"http:\/\/www.zdnet.com\/article\/cloud-strategies-mobility-collaboration-at-g-j-pepsi-cola-bottlers\/\">Pepsi Cola<\/a>&nbsp;and&nbsp;<a href=\"https:\/\/customers.microsoft.com\/en-us\/search?sq=&amp;ff=story_product_categories%26%3EEnterprise%20Mobility%20%2B%20Security&amp;p=2&amp;so=story_publish_date%20desc\">much more<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Companies gain a lot of benefits in letting their employees access corporate data from everywhere, especially emails.&nbsp;There are several mail applications available in the App Store or Google Play Store for Android, but iOS native mail app and Outlook app are by far the most popular for iOS platform. Which one do you prefer?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Some users will gain more productivity with iOS native mail app while some users will choose Outlook app for preference and security. The good thing about Outlook app with Intune is that it supports MAM policy that protects data in the application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Using non-Microsoft mail app expose you the risk of getting minimum of support. For example, a few months ago, Apple modified the way iOS mail native works, some users were affected by the new one and they can\u2019t synchronize with Office 365.&nbsp;If you MDM is Microsoft Intune and you want to secure your mobile devices, we highly recommend that you enforce the use of Outlook App without exception.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It\u2019s not something hard to do as long as you follow a guideline if your goal is to do it smoothly. This blog post will explain how to move all users from Native Mail app to Outlook app with Intune.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li><em>Deploying Microsoft Outlook App<\/em><\/li><li><em>Assign App Protection Policy<\/em><\/li><li><em>Blocking Mail Native App using Conditional Access<\/em><\/li><\/ol>\n\n\n\n<h2 class=\"wp-block-heading\">INTUNE IOS MAIL OUTLOOK APP \u2013 BETTER TOGETHER<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The learning curve with a new application may seem obvious and easy to you, but for some, it\u2019s not. Each person manages emails differently and uses different options. Migrating to Outlook means, they need to change the way they work and learning the new app. There are good chances that you create a shock wave in your company if you coordinate to block&nbsp;<a href=\"https:\/\/support.apple.com\/en-ca\/mail\">iOS mail native app<\/a>&nbsp;and the installation of Microsoft Outlook App at the same time.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What about using both apps during a grace period? Users will be able to test the Outlook App, report any technical issues or request features. A kind of inside technical preview! Doing it this way won\u2019t affect productivity.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">DEPLOYING MICROSOFT OUTLOOK APP<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">With Intune, you can configure a required deployment of&nbsp;<a href=\"https:\/\/itunes.apple.com\/ca\/app\/microsoft-outlook\/id951937596?mt=8\">Microsoft Outlook app for iOS<\/a>&nbsp;and targets a group or all users. This way ensure that all enrolled devices in Intune receive the Microsoft Outlook app.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>To deploy an application with Microsoft Intune, open your browser and navigate to&nbsp;<a href=\"https:\/\/portal.azure.com\/#blade\/Microsoft_Intune_Apps\/MainMenu\/1\/selectedMenuItem\/Overview\">https:\/\/portal.azure.com\/#blade\/Microsoft_Intune_Apps\/MainMenu\/1\/selectedMenuItem\/Overview<\/a><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp02.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61196\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Add&nbsp;<\/strong>and select&nbsp;<strong>App Type&nbsp;<\/strong><strong>iOS<\/strong><\/li><li>Click on&nbsp;<strong>Search the App Store&nbsp;<\/strong>and type&nbsp;<strong>Outlook&nbsp;<\/strong>in the search field<\/li><li>Once you find&nbsp;<strong>Microsoft Outlook<\/strong>, select the app and click&nbsp;<strong>Select<\/strong>&nbsp;at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp03.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61197\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Review the information provided automatically by clicking on<strong>&nbsp;App information<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp04.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61198\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Once you\u2019re ready, click on&nbsp;<strong>Add&nbsp;<\/strong>at the bottom<\/li><li>The application is created but not assigned yet, to assign the application to a group, click on&nbsp;<strong>Assignments&nbsp;<\/strong>blade and&nbsp;<strong>Add group<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp05.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61199\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Select&nbsp;<strong>Required&nbsp;<\/strong>at&nbsp;<strong>Assignment type&nbsp;<\/strong>to enforce the app on mobile devices<\/li><li>Select&nbsp;<strong>Included Groups&nbsp;<\/strong>and choose which group you want to target or use both switch to deploy to all users or all devices. Once you configure the included assignment, click on&nbsp;<strong>Ok&nbsp;<\/strong>at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp08.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61202\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>If you want to exclude a specific group that doesn\u2019t want to receive the app automatically, click on&nbsp;<strong>Excluded Groups&nbsp;<\/strong>and selects the group<\/li><li>To save the assignment, don\u2019t forget to click on&nbsp;<strong>Save&nbsp;<\/strong>at the top of the assignments blade.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp09.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61203\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">APP PROTECTION POLICY<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Now that the application is currently being deployed to all your devices, it\u2019s important that you secure your app data in&nbsp;<a href=\"https:\/\/itunes.apple.com\/ca\/app\/microsoft-outlook\/id951937596?mt=8\">Microsoft Outlook App for iOS<\/a>. This will make sure to containerize the content of your company data in the app and block copy paste or save-in.&nbsp;MAM protects corporate data from managed apps to a personal app.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>To create an&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/intune\/app-protection-policies\">app protection policy<\/a>, open your browser and navigate to&nbsp;https:\/\/portal.azure.com\/#blade\/Microsoft_Intune_Apps\/MainMenu\/14\/selectedMenuItem\/Overview<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp11.jpg\" alt=\"Intune iOS Mail Outlook app\" class=\"wp-image-61222\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Add a policy<\/strong>&nbsp;and type a policy name<\/li><li>Make sure the platform is&nbsp;<strong>iOS&nbsp;<\/strong>and click on&nbsp;<strong>Select required apps<\/strong><\/li><li>For a better user experience, check all apps and click&nbsp;<strong>Select&nbsp;<\/strong>at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp12.jpg\" alt=\"Intune Block iOS Mail App\" class=\"wp-image-61223\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Configure required settings&nbsp;<\/strong>and change these settings<ul><li>Allow the app to transfer data to others apps<ul><li><strong>Policy managed apps<\/strong><\/li><\/ul><\/li><li>Prevent \u201cSave As\u201d<ul><li><strong>Yes<\/strong><\/li><\/ul><\/li><li>Select which storage services corporate data can be saved to<ul><li><strong>OneDrive for Business<\/strong><\/li><li><strong>Sharepoint<\/strong><\/li><\/ul><\/li><li>Restrict cut, copy and paste with other apps<ul><li><strong>Policy managed apps with paste in<\/strong><\/li><\/ul><\/li><\/ul><\/li><li>Click on&nbsp;<strong>Ok&nbsp;<\/strong>at the bottom once you\u2019re finish<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp13.jpg\" alt=\"Intune Block iOS Mail App\" class=\"wp-image-61224\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click&nbsp;<strong>Create&nbsp;<\/strong>at the bottom&nbsp;to save the new policy<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Now that the policy is created, we will assign the policy to the same group we used to deploy Outlook app.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on your new policy and then click&nbsp;<strong>Assignments<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp14.jpg\" alt=\"Intune Block iOS Mail App\" class=\"wp-image-61225\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Select groups to include<\/strong>,&nbsp;choose the same group previously selected for Outlook app assignment and click&nbsp;<strong>Select<\/strong><\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">From now, users that have already installed the outlook app will start to get this popup on their iPhone<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp10.jpg\" alt=\"\" class=\"wp-image-61219\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">BLOCKING MAIL NATIVE APP WITH CONDITIONAL ACCESS<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The Outlook app is now deployed and users can use it securely. Users will start to use the application side by side with the iOS mail app. Consequently, users will use this time to learn functionalities and become familiar with the new app.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">By experience, try to educate your users with videos or step by step guide. Explain to them the use of Microsoft support directly in the Outlook app.&nbsp;<a href=\"https:\/\/outlook.uservoice.com\/forums\/293349-outlook-for-ios\">User Voice<\/a>&nbsp;is also available to see which features is coming soon.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If some users&nbsp;don\u2019t want to use anymore the iOS mail app and you are deploying an email profile with Intune, you can disable the mail synchronization&nbsp;on the mobile device itself by going to&nbsp;<strong>Settings \u2013 Accounts &amp; Passwords<\/strong>.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>your account<\/strong>&nbsp;and&nbsp;<strong>deactivate Mail<\/strong><\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp15.jpg\" alt=\"Email profile iOS\" class=\"wp-image-61266\"\/><\/figure>\n\n\n\n<h6 class=\"wp-block-heading\">Important Info<\/h6>\n\n\n\n<p class=\"wp-block-paragraph\">If you deploy an email profile with your MDM, the email profile won\u2019t be removed once you remove the profile deployment. Only a new enrollment will remove the email profile on your iOS devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Before going to the next step, wait from 2 weeks to 2 months based on users expectation or CSO requirement. It\u2019s a balance between productivity and security. Try to educate the most you can your users before going further.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Are you now ready to block mail native app? Follow this step by step guide by using the conditional access.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Open your browser and navigate to conditional access blade&nbsp;<a href=\"https:\/\/portal.azure.com\/#blade\/Microsoft_AAD_IAM\/ConditionalAccessBlade\/Policies\">https:\/\/portal.azure.com\/#blade\/Microsoft_AAD_IAM\/ConditionalAccessBlade\/Policies<\/a><\/li><li>Click on&nbsp;<strong>New&nbsp;<\/strong>and type a policy name like&nbsp;<strong>Mail Native Block<\/strong><\/li><li>In the Assignments section, click on&nbsp;<strong>Users and groups&nbsp;<\/strong>and within&nbsp;<strong>Include&nbsp;<\/strong>section, choose&nbsp;<strong>Select users and groups<\/strong>, which is the same group you are using till the beginning.<\/li><li>Once you\u2019re finished, click&nbsp;<strong>Done<\/strong>&nbsp;at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp17.jpg\" alt=\"Conditional access blocking Basic Authentication\" class=\"wp-image-61328\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Cloud apps,&nbsp;<\/strong>select&nbsp;<strong>Office 365 Exchange Online&nbsp;<\/strong>to target email service and select&nbsp;<strong>Done&nbsp;<\/strong>at the bottom.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp18.jpg\" alt=\"Conditional access blocking Basic Authentication\" class=\"wp-image-61329\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Click on&nbsp;<strong>Conditions&nbsp;<\/strong>blade, and select&nbsp;<strong>Device Platforms<\/strong><\/li><li>Configure the conditions by clicking&nbsp;<strong>Yes<\/strong>, click on&nbsp;<strong>Include<\/strong>,&nbsp;select&nbsp;<strong>iOS&nbsp;<\/strong>platform and click&nbsp;<strong>Done&nbsp;<\/strong>at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp19.jpg\" alt=\"Conditional access blocking Exchange ActiveSync\" class=\"wp-image-61330\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>Select&nbsp;<strong>Client apps (preview)&nbsp;<\/strong>and enable by selecting&nbsp;<strong>Yes<\/strong><\/li><li>Enable these checkboxes<ul><li><strong>Mobile apps and desktop clients<\/strong><\/li><li><strong>Exchange ActiveSync clients<\/strong><\/li><li><strong>Other clients<\/strong><\/li><\/ul><\/li><li>Once you\u2019re finished, click on&nbsp;<strong>Done twice&nbsp;<\/strong>at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp20.jpg\" alt=\"Conditional access blocking Exchange ActiveSync\" class=\"wp-image-61331\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>In the&nbsp;<strong>Access controls&nbsp;<\/strong>section, click on&nbsp;<strong>Grant&nbsp;<\/strong>blade<\/li><li>Select&nbsp;<strong>Block access&nbsp;<\/strong>in the Grant section then click&nbsp;<strong>Select&nbsp;<\/strong>at the bottom<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp21.jpg\" alt=\"Conditional access blocking Exchange ActiveSync\" class=\"wp-image-61332\"\/><\/figure>\n\n\n\n<ul class=\"wp-block-list\"><li>The conditional access rule is now ready and configure, enable the policy by choosing&nbsp;<strong>Enable Policy&nbsp;<\/strong>at&nbsp;<strong>Yes<\/strong>.<\/li><\/ul>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp22.jpg\" alt=\"Conditional access blocking Exchange ActiveSync\" class=\"wp-image-61333\"\/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">USER BEHAVIOR<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Ask your users to open the mail native app and if your rule works, you will see this warning email telling the user that the access has been blocked.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><img decoding=\"async\" src=\"https:\/\/scd-systemcenterdude.netdna-ssl.com\/wp-content\/uploads\/2018\/06\/Outlookapp24.png\" alt=\"Conditional access blocking Exchange ActiveSync\" class=\"wp-image-61335\"\/><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">For now, users will need to use Microsoft Outlook app.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Nowadays, the smartphone takes up a lot of room in our personal and professional lives. Being able to receive your work emails directly on a mobile device is becoming popular.&nbsp;Based on&nbsp;latest numbers provided by Brad Anderson&nbsp;from Microsoft, companies are more willing to use mobile device management solution like&nbsp;Microsoft Intune&nbsp;and let users access company data from [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-325","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/325","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/comments?post=325"}],"version-history":[{"count":2,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/325\/revisions"}],"predecessor-version":[{"id":328,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/posts\/325\/revisions\/328"}],"wp:attachment":[{"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/media?parent=325"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/categories?post=325"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.bleuanus.nl\/index.php\/wp-json\/wp\/v2\/tags?post=325"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}