In this post we will see how to setup Intune Compliance Policy for iOS. Intune Compliance Policy for iOS devices are to help to protect company data, the organization needs to make sure that the devices used to access company apps and data comply with certain rules. These rules might include using a password/PIN to access devices and encrypting data stored on devices. These set of such rules is called a compliance policy. Best option is to use compliance policy with Azure AD Conditional Access.
Video Tutorial to setup Intune Compliance Policy for iOS here
- Intune Compliance policy setup for Windows 10 Devices here
- Intune Compliance policy setup for Android Devices here
- Sign in to the Azure portal with an account that has Intune admin access.
- Select More services, enter Intune in the text box, and then select Enter.
- Select Intune – Device Compliance – Compliance – Policies – and Click on +Create policy button to create new compliance policy and select platform as “iOS”.
- Settings confgurations are really important for compliance policy. There are some improvements in Azure portal iOS compliance policies in terms of password settings.
- There are 4 categories in iOS compliance policies and those are Email, Device Health, Device Properties and System Security.
- Email setting requires mobile devices to have a managed email profile to get access to corperate resources.
- Device Health setting will check whether the device is jail brocken or not. If the iOS device is Jailbrocken it won’t provide access mail access to that device.
- Device Properties setting will check the OS version of the device and if the minimum version of the iOS OS.
- System Security setting is basally for password settings. There are some improvements over Intune silverlight portal here. We can have option not to configure some of the settings like “Number of non-alphanumeric characters in password”. This was not possible with Intune silverlight portal.
Require a password to unlock mobile devices.
Minimum password length
Number of non-alphanumeric characters in password
Maximum minutes of inactivity before password is required
Password expiration (days)
Number of previous passwords to prevent reuse
10. Deploy Intune Compliance Policy for iOS to All iOS devices dynamic device group. Click on Assignment and select the dynamic device group. I would use AAD dynamic device groups to deploy compliance policies rather than AAD user groups.
(Update Device Groups are not supported for Compliance policies – hence use user groups for Intune compliance policies)
What is device compliance in Intune Azure preview – here