Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 2)
Introduction
This is the second article in this series. In the first part, we discussed the need to properly configure your Intune settings and policies for Teams Android devices. Here we will go over a few more items related to settings in Intune. We will also go over configuring Conditional Access Policies for these devices. Finally, we will talk about Teams Configuration profiles and testing your devices.
Detailed Configuration Steps (Continued)###### Check the Intune and Azure Active Directory Device Limits
Click on “Device settings.”
Note the number of devices in the “Maximum number of devices per user.
Switch back to the “Microsoft Endpoint Manager” and click on “Devices.”
Click on “Enroll devices.”
Click “Enrollment device limit restrictions.”
Click on the name of the Device Limit Restriction Policy.
If the device limit is less than that of the Azure Active Directory devices, click on “Properties.”
Click the “Edit” button.
Change the value of the “Device limit” to something that matches or exceeds the Azure Active Directory device limit or the maximum, 15, whichever is greater.
Click the “Review + save” button.
Click the “Save” button.
Click the “Edit” button for the “Apps” section.
Set the “Target to apps on all device types” switch to “No.”
Click the “Review + save” button.
Click the “Save” button. Repeat for the rest of the policies written for the Android platform.
Click on the first policy in the list. (The policies used in the examples were created from the templates provided by Microsoft and are in “Report only” mode. The “Terms of Use” Policy was manually created.)
In the “Cloud apps or actions” section, if the value is “All cloud apps,” this section of the policy is not compatible with Teams Phones. The example policy, therefore, is not compatible with Teams Phones. You do not need to perform the additional checks for this policy.
If the value is “1 app included” check to see if it is “Office 365.” If not, the policy is not compatible.
The “Conditions” section of the sample policy indicates that there are “0 conditions selected.” The settings in this section are compatible with Teams Phones. Continue checking the other sections of the policy:
If “Client apps” are configured, the Conditional Access Policy is not compatible.
The “Require multi-factor authentication” control in the “Grant” section of the policy is selected. The settings in this section are compatible. Continue checking the other sections of the policy.
If one of the documented unsupported controls or a “Terms
The “Session” section of the sample policy indicates that there are “0 controls selected.” The settings in this section are compatible with Teams Phones.
If “Use Conditional Access Apps Control” had been selected, the “Session” section would not be compatible.
This policy has one section that is incompatible. Select and copy the query you used to create the “Teams Phone” filter in step 1 above from the open “Notepad” session. (I told you we would need this later!).
Click the “0 conditions selected” button in the “Conditions” section.
Click the “Not configured” button in the “Filter for devices” condition
Set the “Configure” option to “Yes.”
Click “Exclude filtered devices from policy” in the “Devices matching the rule” section.
Click the “Edit” button above the “Rule syntax” box.
Paste the query into the “Rule syntax” box.
Click the “Apply” button above the “Rule Syntax” box.
Click the “Done” button.
Click the policy’s “Save” button. Continue checking the rest of the Conditional Access Policies.
Click “All user” beneath the “Include” tab.
Click the “Exclude” tab.
Click “No cloud apps, actions, or authentication contexts selected” in the “Cloud apps or actions” section.
Click “Select apps” beneath the “Include” tab.
Click the checkbox next to “Office 365.” You could instead choose these applications:
Microsoft Teams
Office 365 SharePoint Online
Click the “Select” button.
Click “0 conditions selected” in the “Conditions” section.
Click the “Not configured” button in the “Device platforms” section.
Click the “Not configured” button in the “Locations”
Set the “Configure” option to “Yes.”
Click the “Not configured” button under the “Filter for devices” section
Set the “Configure” option to “Yes.”
Click the “Edit” button to the right above the “Rule syntax” box.
Paste the query from before into the “Rule Syntax” box.
Click the “Done” button.
Click the “Grant access” option.
Click the checkbox for “Require device to be marked as compliant.” Select these options as required by your implementation. Make sure to avoid the unsupported options and Terms of Use requirements.
Click the “Select” button.
Verify that the settings in the profile are working as configured on the phone. Summary
Integrating your Teams Phones with the Microsoft Security and Compliance suite of products is possible. Special handling is required for several of the components:
eGroup | Enabling Technologies is available and ready to help you with the integration of your Teams devices into your organizational security and compliance plan. Excluding them from your security and compliance deployment is not advisable. If you need help with your Teams devices or in implementing your overall security infrastructure, please contact us today!
References
The post Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 2) appeared first on eGroup.