Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Android»How to block mobile apps like TikTok with Microsoft Intune
    Android

    How to block mobile apps like TikTok with Microsoft Intune

    Peter KlapwijkBy Peter KlapwijkJuly 18, 2020Updated:July 18, 202035 Mins Read

    Every now and then there is bad about a (mobile) app in the news, because of all kinds of reasons. Encryption isn`t in place, the Chinese government might be using the app to spy on the whole world or whatever other reason.

    Whatever the reason is, it might be a reason for companies to block the app on the end-users device which has access to corporate access. With Microsoft Intune (Endpoint Manager) we have the possibility to block such apps on iOS and Android.

    For both operating systems we need to use another approach. On iOS we don`t have an option to block the installation of an app, we need to use a Compliance Policy, to block access to corporate data as soon as a restricted app is installed.
    On Android, we do have a way to block the installation of the app on a mobile device.

    To write this post, I used the popular mobile app TikTok.

    Block TikTok on Android devices

    On Android at the moment of writing we have two management solutions, Fully Managed and Work Profile (Corporate Owned, Personally Enabled (COPE) is coming in Preview very soon). If you only allow corporate work apps on a Fully Managed device, there is no need to use this configuration as the public Play Store cannot be accessed to download personal apps. Same for the Work Profile section on a personal device.
    This configuration is only applicable for Fully Managed devices where access to the public Play Store is allowed and probably will be applicable for Android COPE devices.

    An app like TikTok can be blocked on an Android device by assigning the app as Uninstall. This makes sure the app isn`t shown in the Play Store.

    • Sign-in to the Endpoint Manager admin center
    • Browse to Apps – Android app
    • Click + Add
    • Choose Managed Google Play app as App type
    • Click Select
    • Search for the app you want to block, in this case, TikTok
    • Click on the app to open it
    • Click Approve (Twice)
    • Click Done
    • Back in the Google Play Store search screen click Sync in the top left corner
    • Back in the Endpoint Manager admin center app view, open the app as soon as the sync is finished
    • Click Properties
    • Click Edit next to Assignments
    • Under Uninstall assign the app to a group or for example to All Devices
    • Click Review + save – Click Save

    That`s all for blocking TikTok on our Intune managed Android devices.

    End-user experience on Android

    To show the end-user experience on an Android device I only need one screenshot. As you can see I searched in the (public) Google Play store for TikTok, but the app isn`t available for installation.

    Now also let`s have a look what we need to configure to block TikTok on iOS devices.

    Block TikTok on iOS devices

    Unfortunately, we don`t have a solution to block the installation of apps on iOS. For iOS, we need to have a Compliance Policy in place, which blocks non-compliant devices to access corporate data. In a Compliance Policy we add the app Bundle ID of TikTok, so as soon as an user installs the app, the device is marked as not compliant and access to corporate data is blocked.

    I assume you have such a Compliance Policy already in place, if that`s not the case, you can get some information on that by reading this article.

    To find the Bundle ID of TikTok, use a browser to search for the app in the Apple App Store. In the URL, in the end, you`ll find the app ID. Note the number after ID.

    Still using a browser enter https://itunes.apple.com/lookup?id=835599320
    A small file txt file is downloaded. Open the file in a text editor and search for bundleid to find the Bundle ID, for TikTok that`s com.zhiliaoapp.musically
    This is an example for TikTok, if you want to block another app replace 835599320 with the number you found for that app.

    Now that we have found the Bundle ID, let`s configure the Compliance policy in Intune.

    • Switch back to the Endpoint Manager admin center
    • Browse to Devices – iOS/ iPadOS
    • Browse to Compliance policies
    • Click + Create Policy
    • Choose iOS/ iPadOS as Platform
    • Click Create
    • Give the policy a Name
    • Enter a Description (Optional)
    • Click Next
    • Open System Security
    • Under Restricted apps enter the app Name and Bundle ID
    • Click Next

    Assign the policy to a security group of choice or to All Users.

    End-user experience on iOS

    The user is still able to install the mobile app on iOS, but as soon as the restricted app is installed, the device is marked as not compliant.

    If you click on You need to update settings on this device, the reason is shown why the device is marked as not compliant and which app needs to be uninstalled to get compliant again.

    Side note

    For iOS, in the Device Restrictions profile, we also find a setting which mentions Restricted apps.
    Where the description states Device enrollment and automated device enrollment, this setting is only applicable to Apple Business Manager (formerly known as DEP) enrolled devices. And this only provides a reporting functionality, it does not block the installation of prohibited apps.

    I`d like to thank Jeroen Burgerhout for inspiring me to write this article 🙂

    Thank you for reading my post and happy testing!

    Android Intune iOS MEM Microsoft 365 Microsoft Endpoint Manager Security
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    MEM Monitoring: Get notified on Intune Configuration profile changes

    August 2, 2021

    Enable passwordless security key sign-in in Hybrid Azure Active Directory environments

    February 25, 2020

    Force Outlook on iOS and Android to access the Exchange Online mailbox

    March 29, 2019
    View 3 Comments

    3 Comments

    1. Mal on January 4, 2021 18:28

      For iOS you can also use the standard ABM/DEP MDM function to “Show or Hide” app to block prohibited apps. Setting apps as “Hidden” in Intune will effectively ‘removed’ from the user’s device. Yes, they can see the app in the App Store, but will not be able to run it.

      Reply
    2. DT on May 18, 2021 11:21

      I tried to do this, but when I blocking an app with Chinese URL, for example https://apps.apple.com/cn/app/%E7%99%BE%E5%BA%A6%E7%BD%91%E7%9B%98-%E9%87%8A%E6%94%BE%E6%89%8B%E6%9C%BA%E7%A9%BA%E9%97%B4/id547166701, it will display an error in Intune portal.

      Reply
    3. DavidS on August 29, 2023 01:06

      When I follow this, Once I get to where I can select TikTok, the select button never changes. There is no Approve button.

      Reply
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Create deployment ring groups for Microsoft Intune

    June 27, 2025

    Update Windows Defender during Windows Autopilot enrollments

    May 16, 2025

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    • Bluesky 1.5K
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Parth Savjadiya on Using Visual Studio with Microsoft Endpoint Privilege Management, some notes
    • Chris Johnson on Assign Deny Local Log On user right to an (Azure) AD group by using Microsoft Intune
    • Northernsky on Automatically wipe a Windows 10 device after a number of authentication failures
    • Henrik on Intune Driver update for Windows – Get applicable devices
    • Adam on Get notified on expiring Azure App Registration client secrets
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS Bluesky
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}