<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Force Windows Information Protection with Conditional Access	</title>
	<atom:link href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/feed/" rel="self" type="application/rss+xml" />
	<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/</link>
	<description>Intune, Windows, Office 365, Microsoft 365, Azure, Automation</description>
	<lastBuildDate>Sat, 04 Sep 2021 09:30:29 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
	<item>
		<title>
		By: Richard Johnston		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-172084</link>

		<dc:creator><![CDATA[Richard Johnston]]></dc:creator>
		<pubDate>Sat, 04 Sep 2021 09:30:29 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-172084</guid>

					<description><![CDATA[Great blog, thank you.

When registering a device, the BYOD end user gets a prompt asking &quot;Allow organization to manage this device&quot;. If unticked, it will register with Azure AD and allow terms of use to be accepted, but the WIP policy will not apply.

If the box is left ticked, it will work as intended.

I wonder if there is a way to force the tick box &quot;Allow organization to manage device&quot;?

Many thanks]]></description>
			<content:encoded><![CDATA[<p>Great blog, thank you.</p>
<p>When registering a device, the BYOD end user gets a prompt asking &#8220;Allow organization to manage this device&#8221;. If unticked, it will register with Azure AD and allow terms of use to be accepted, but the WIP policy will not apply.</p>
<p>If the box is left ticked, it will work as intended.</p>
<p>I wonder if there is a way to force the tick box &#8220;Allow organization to manage device&#8221;?</p>
<p>Many thanks</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-102913</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Wed, 06 May 2020 18:28:00 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-102913</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-102775&quot;&gt;Adriano&lt;/a&gt;.

Hi Adriano,

That`s a very good point. Used this in an environment where we didn`t use Autopilot.
But I assume when you exclude Microsoft Intune Enrollment in the CA policy as Cloud app, it should work.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-102775">Adriano</a>.</p>
<p>Hi Adriano,</p>
<p>That`s a very good point. Used this in an environment where we didn`t use Autopilot.<br />
But I assume when you exclude Microsoft Intune Enrollment in the CA policy as Cloud app, it should work.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Adriano		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-102775</link>

		<dc:creator><![CDATA[Adriano]]></dc:creator>
		<pubDate>Wed, 06 May 2020 07:48:34 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-102775</guid>

					<description><![CDATA[Hi Peter
I have the problem, when this Conditional Access Policy is active, I cannot enroll devices with autopilot. After autopilot detects my device correctly and sign in with my corporate credentials there comes the message &quot;Your sign-in was successful but your device must be registered with...&quot; and at this point I can not accept the Terms of use.. Is there something configured wrong?]]></description>
			<content:encoded><![CDATA[<p>Hi Peter<br />
I have the problem, when this Conditional Access Policy is active, I cannot enroll devices with autopilot. After autopilot detects my device correctly and sign in with my corporate credentials there comes the message &#8220;Your sign-in was successful but your device must be registered with&#8230;&#8221; and at this point I can not accept the Terms of use.. Is there something configured wrong?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-61309</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Fri, 13 Sep 2019 19:51:49 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-61309</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-61143&quot;&gt;Bryan&lt;/a&gt;.

Bryan,
Have not tested this with an AD joined device, but when the user tries to access Office 365 data the CA policy is applied and the Device is AAD Registered. So you end up in scenario 1 and 2 in a AD joined AAD registered device (like scenario 2). So you can consider it BYOD compared with my article :)]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-61143">Bryan</a>.</p>
<p>Bryan,<br />
Have not tested this with an AD joined device, but when the user tries to access Office 365 data the CA policy is applied and the Device is AAD Registered. So you end up in scenario 1 and 2 in a AD joined AAD registered device (like scenario 2). So you can consider it BYOD compared with my article 🙂</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Bryan		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-61143</link>

		<dc:creator><![CDATA[Bryan]]></dc:creator>
		<pubDate>Thu, 12 Sep 2019 09:33:51 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-61143</guid>

					<description><![CDATA[Really useful info, Peter. We have a mixture of corporate desktop state:
1)AD joined 
2)AD joined + AAD registered
3)AAD joined (MDM:Intune)
It will take us awhile to move all desktop to AAD joined. Am i right to say #1 and #2 will be considered as BYOD if we apply the method on this article?]]></description>
			<content:encoded><![CDATA[<p>Really useful info, Peter. We have a mixture of corporate desktop state:<br />
1)AD joined<br />
2)AD joined + AAD registered<br />
3)AAD joined (MDM:Intune)<br />
It will take us awhile to move all desktop to AAD joined. Am i right to say #1 and #2 will be considered as BYOD if we apply the method on this article?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52886</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Tue, 30 Apr 2019 14:47:09 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-52886</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52883&quot;&gt;Mario&lt;/a&gt;.

Thnx for the info Mario, but indeed the documentation describes it &quot;design to prevent personal files from being unintenionally encrypted by unenlighted apps. Unenlighted apps that need to access work using MAM need to be re-compiled as LOB apps or managed by using MDM with device enrollment.&quot; And MS Support confirms.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52883">Mario</a>.</p>
<p>Thnx for the info Mario, but indeed the documentation describes it &#8220;design to prevent personal files from being unintenionally encrypted by unenlighted apps. Unenlighted apps that need to access work using MAM need to be re-compiled as LOB apps or managed by using MDM with device enrollment.&#8221; And MS Support confirms.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Mario		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52883</link>

		<dc:creator><![CDATA[Mario]]></dc:creator>
		<pubDate>Tue, 30 Apr 2019 11:31:03 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-52883</guid>

					<description><![CDATA[Hi Peter,
this is the link:

https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/limitations-with-wip

This is also usefull link: https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure

That&#039;s correct, wordpad isn&#039;t listed as enlightened app.]]></description>
			<content:encoded><![CDATA[<p>Hi Peter,<br />
this is the link:</p>
<p><a href="https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/limitations-with-wip" rel="nofollow ugc">https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/limitations-with-wip</a></p>
<p>This is also usefull link: <a href="https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure" rel="nofollow ugc">https://docs.microsoft.com/en-us/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure</a></p>
<p>That&#8217;s correct, wordpad isn&#8217;t listed as enlightened app.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52882</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Tue, 30 Apr 2019 10:06:04 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-52882</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52880&quot;&gt;Mario&lt;/a&gt;.

Hi Mario,
Good to read. Could you share with me where you found this info: Only enlightened apps can be managed without device Enrollment.
I`m able to allow Wordpad to access corporate data (only since today, in the weekend got an access denied). As far as I know that is not an enlightened app even it is an Microsoft app.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52880">Mario</a>.</p>
<p>Hi Mario,<br />
Good to read. Could you share with me where you found this info: Only enlightened apps can be managed without device Enrollment.<br />
I`m able to allow Wordpad to access corporate data (only since today, in the weekend got an access denied). As far as I know that is not an enlightened app even it is an Microsoft app.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Mario		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52880</link>

		<dc:creator><![CDATA[Mario]]></dc:creator>
		<pubDate>Tue, 30 Apr 2019 09:17:48 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-52880</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52862&quot;&gt;Peter Klapwijk&lt;/a&gt;.

Hi Peter,
i have an update. On monday thinks started to work as expected. Chrome works in enterprise context and is protected app. I noticed that some icons on Intune portal are changed, so maybe Microsoft pushed updates during weekend. Also, i changed Publisher for Chrome app. It was O=GOOGLE INC... to O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US. Even, i tried with Google LLC before, but it didn&#039;t work. 

BUT, i overlooked fact that you are talking about devices without enrollment. Expirence i described was with enrolled device. 

On device without enrolmnet, still can&#039;t access corp dana with Chrome.
But looks like, it is expected:

- Only enlightened apps can be managed without device Enrollment.

Iz ]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52862">Peter Klapwijk</a>.</p>
<p>Hi Peter,<br />
i have an update. On monday thinks started to work as expected. Chrome works in enterprise context and is protected app. I noticed that some icons on Intune portal are changed, so maybe Microsoft pushed updates during weekend. Also, i changed Publisher for Chrome app. It was O=GOOGLE INC&#8230; to O=GOOGLE LLC, L=MOUNTAIN VIEW, S=CA, C=US. Even, i tried with Google LLC before, but it didn&#8217;t work. </p>
<p>BUT, i overlooked fact that you are talking about devices without enrollment. Expirence i described was with enrolled device. </p>
<p>On device without enrolmnet, still can&#8217;t access corp dana with Chrome.<br />
But looks like, it is expected:</p>
<p>&#8211; Only enlightened apps can be managed without device Enrollment.</p>
<p>Iz </p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Peter Klapwijk		</title>
		<link>https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52862</link>

		<dc:creator><![CDATA[Peter Klapwijk]]></dc:creator>
		<pubDate>Mon, 29 Apr 2019 19:05:17 +0000</pubDate>
		<guid isPermaLink="false">https://inthecloud247.com/?p=2235#comment-52862</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52794&quot;&gt;Mario&lt;/a&gt;.

Ok, that sounds as the opposite as expected.
Must say I just (re)created the WIP policy in my lab and I`m not able to access any corp data with Chrome. I do some further testing.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://inthecloud247.com/force-windows-information-protection-with-conditional-access/#comment-52794">Mario</a>.</p>
<p>Ok, that sounds as the opposite as expected.<br />
Must say I just (re)created the WIP policy in my lab and I`m not able to access any corp data with Chrome. I do some further testing.</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
