Mobile Application Manager Overview
ADKF may allow its employees to use their personal mobile devices to access some ADKF resources such as Outlook and Teams, these apps will be referred to as managed apps. Utilizing Microsoft Intune Mobile Application Manager without Enrollment (MAMWE), ADKF takes measures to ensure the confidentiality, integrity, and accessibility of the data available through these apps.
Requirements
iOS
The Microsoft Authenticator app must be installed on the device.
To edit documents, the Office application must be installed and signed into using your ADKF credentials.
Android
The Intune Company Portal application must be installed on the device.
To open Excel or Word attachments, you must have the associated app installed and be logged in.
To open PDF attachments, you can use OneDrive or Word.
Security on apps
- 6-digit complex pin code
- Cannot use simple codes with more than 3 repeating or sequential numbers.
- Unlocking with biometrics (fingerprint/face ID) is allowed if supported by the device.
- Application will lock after 30 minutes of inactivity
- ADKF data will not be included in the device’s own backups
- ADKF data will use its own backup mechanisms as approved and configured by IT.
- ADKF data cannot be transferred out of the managed apps
- This includes the copy/paste, ‘save as’ and, printing functions.
- Screen shots are prohibited when a managed app is displayed on the screen
- Application data encryption
- The application’s data will remain encrypted while stored on the mobile device.
- Access to ADKF data on the device will be blocked if the above requirements cannot be met or the device is offline for 72 hours or longer.
- ADKF data will be removed from the device if:
- 15 consecutively failed PIN or biometric attempts are made on a managed app
- The device is offline for 14 days or longer
- The device is jailbroken or rooted
- The user account is disabled
Privacy
What ADKF does not see:
- Calling and web browsing history
- Personal Email
- Text messages
- Personal Contacts
- Personal Calendar
- Passwords
- Pictures, including what's in the photos app or camera roll
- Files saved to the device
What ADKF does see:
- Device model, like Google Pixel
- Device manufacturer, like Samsung
- Operating system and version, like iOS 12.0.1
- On personal devices, your organization can only see your managed app inventory. For corporate-owned fully managed and dedicated devices, your organization can see all of your app inventory. For corporate-owned devices with a work profile, your organization can only see the app inventory in your work profile.
- Device owner
- Device name
- Device serial number
- IMEI
For more information, please see this Microsoft article.
What info can your company see when you enroll your device? | Microsoft Docs