Step 4: Block email access for unsupported devices

To help secure your organization’s information, you should block app access to Office 365 email for mobile devices that are not supported by MDM for Office 365. See Supported devices for a list of devices that are supported. To do this:

  1. Go to Security & Compliance Center > Data loss prevention> Device management. On the Device actions page, choose Device policies.
  2. Select Manage organization-wide device access settings.
  3. To block unsupported devices, choose Block under If a device isn't supported by MDM for Office 365, do you want to allow or block it from using an Exchange account to access your organization's email > Save.

Step 5: Choose security groups to be excluded from conditional access checks

If you want to exclude some people from conditional access checks on their mobile devices and you've created one or more security groups for those people, add the security groups here. The people in these groups will not have any policies enforced for their supported mobile devices.

  1. Go to Security & Compliance Center > Data loss prevention > Device management. On the Device actions page, choose Device policies.
  2. Select Manage organization-wide device access settings.
  3. Select Add to add the security group that has users that you’d like to exclude from being blocked access to Office 365. When a user has been added to this list, they’ll be able to access Office 365 email when using an unsupported device.
  4. Select the security group you want to use in the Select group panel.
  5. Select the name, and then Add > Save.
  6. On the Organization-wide device access settings panel, choose Save.

What is the impact of security policies on different device types?

When you apply a policy to user devices, the impact on each device varies somewhat between different device types. See the following table for examples of the impact of policies on different devices.

Security Policy
Windows Phone 8.1+
Android 4+
Samsung Knox
IOS 6+
Notes
Require encrypted backup
IOS encrypted backup required.
Block cloud backup
Block Google backup on Android (grayed out), cloud backup on iOS.
Block document synchronization
iOS: Block documents in the cloud.
Block photo synchronization
iOS (native): Block Photo Stream.
Block screen capture
X
Blocked when attempted.
Block video conference
FaceTime blocked on iOS, not Skype or others.
Block sending diagnostic data
X
Block sending Google crash report on Android.
Block access to app store
X
App store icon missing on Android home page, disabled on Windows, missing on iOS.
Require password for app store
iOS: Password required for iTunes purchases.
Block connection to removable storage
X
NA
Android: SD card will be grayed out in settings, Windows notifies user, apps installed there are not available
Block Bluetooth connection
***
***
***We can't disable BlueTooth as a setting on Android. Instead, we disable all the transactions that require BlueTooth: Advanced Audio Distribution, Audio/Video Remote Control, hands-free devices, headset, Phone Book Access, and Serial Port. A small toast message appears at the bottom of the page when any of these are used.
Install office admx templates

What happens when you delete a policy or remove a user from the policy?

When you delete a policy or remove a user from a group to which the policy was deployed to, the policy settings, Office 365 email profile and cached emails may be removed from the user's device. See the following table to see what is removed for the different device types:

What's removed
Windows Phone 8.1+
iOS 6+
Android 4+ (including Samsung Knox)
Managed email profiles*
Policy settings

Except for Block sending diagnostic data from device.
Note: *If the policy was deployed with the option Email profile is managed selected, then the managed email profile and cached emails in that profile will be deleted from the user's device.

Each user that the removed policy applied to will have the policy removed from their device the next time their mobile device checks in with MDM for Office 365 . If you deploy a new policy that applies to these users' devices, they'll be prompted to re-enroll in MDM for Office 365.

You can also wipe a device, either completely, or selectively wipe organizational information from the device.

Related Topics

Overview of Mobile Device Management for Office 365
Capabilities of Mobile Device Management for Office 365