Hello, good morning.
Is it possible to restrict Office Applications like Teams & Outlook to use only Work or School Accounts?
Best Regards,
Rui
Rui,
Yes this is possible and like most challenges there are several ways to accomplish this depending on the environment and tools available. 1) Are you AAD, Hybrid, AD on-prem?
2) Do you want to stay in the Microsoft ecosystem or do you want to leverage functionality within Workspace ONE UEM, Access, or another thirty-party authentication platform?
There are options like GPO, CSP, etc depending on your environment and applications.
I've used this before: https://learn.microsoft.com/en-us/sharepoint/use-group-policy#allow-syncing-onedrive-accounts-for-on...
More info on tenant restrictions: https://learn.microsoft.com/en-us/azure/active-directory/external-identities/tenant-restrictions-v2
Hi, good morning.
I just want to know if it's possible to do this trough config keys, like they say here:
https://kb.vmware.com/s/article/50120818
Best Regards,
Rui
Hi,
You can allow only work account using config key described following MS docs.
https://learn.microsoft.com/ja-jp/mem/intune/apps/app-configuration-policies-use-ios#allow-only-conf...
The settings are as follows.
Hello, good afternoon.
Unfortunately we are using a generic account to enroll the phones...this only works if every device is configured with a specific account.
Best Regards,
Rui
And also this is for iOS only, not Android.
@rmcpdias, sorry I had Windows on my brain, what endpoints are you using? Windows, Mac, iOS, Android?
Hi, in this case we are using Android.
Hi,
I see your situation..
For Android, it seems that allowed accounts can be specified using following config.
https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-use-android#allow-only-...
>Key com.microsoft.intune.mam.AllowedAccountUPNs
>Values
>One or more ; delimited UPNs.
>Only account(s) allowed are the managed user account(s) defined by this key.
If you are not using a specific account when enrolling devices, I think you will have to manually specify all accounts in the Application Configuration.(I have never tried with Android device.)
Thank you very much. I'm going to test it to see if it works!