IBM MaaS360

IBM MaaS360

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Android PO - Dependency on MS Azure and inTune for Conditional access

    Posted Wed April 06, 2022 09:17 AM
    Hello,

    We have a client that had a particular (but reasonable) Requirement ,
    Background: they already have Mas360 enrolled devices with on prem implementation of exchange (via CE) and they are planning to move to the cloud shortly (O365).
    Expectation: They want to make sure that the users can only access their MS applications from their enrolled devices (PO mode) and should be blocked from any non enrolled device. 
    In short the logic is If the application is opened from within the Maas360 container it should work, but if it is outside the container they should not be able to log on.
    Issue
    We followed the steps for Conditional Access and SSO and couldn't really get further as we kept getting errors. Authentication kept failing when setting policy to anything other than "allow all devices".

    We got the following response for Support (over multiple interactions):

    The device seems not a Maas360 managed device, its deviceCompliance attribute has value [UNKNOWN], due to the access policy configured for this application, its access to the app is denied.

    Can we confirm with the user if the device involved in the flow captured in the video is a Maas360 managed device ? if it's not a managed device, it's expected the access is denied. To allow the unmanaged device access, the access policy will need to update to allow it. We confirmed that is is a BYOD device on PO

    it is an expected behaviour on the PO device if user chooses "Maas360" app based authentication. We have again checked with our team and have been informed that currently there is no other available method for "MaaS360" based auth on PO devices. If customer still wishes for the same, we would request them to raise a RFE (Request for Enhancement) for our Product team to look at a possibility of having this feature in our Solution. Upon putting in a RFE, our Product team will directly communicate with you/customer via the RFE tool. If there is a scope to cater to this requirement, our Product team will convey that information to you via the RFE ticket.

    MaaS360 SSO inside PO is restricted by default due to security concerns. It uses the clipboard, so it cannot tell the difference between PO and non-PO apps. All apps even outside the PO profile can authenticate using the MaaS360 app on the device. If the customer is fine with this limitation, then we can enable the back end setting for them."

    This basically means that this option will also allow apps such as MS Outlook and Teams to be configured by users outside the work profile, escaping the work container. So this will allow all webview apps even outside the PO container to use Maas SSO. If this is not acceptable to the customer, then they can leverage Azure CA This defeats the purpose of containerization

    (conditional access) which doesn't have this limitation. More detailed information for the same can be checked from this below link:  

    Link: https://www.ibm.com/docs/en/maas360?topic=iaam-integrating-maas360-microsoft-enforce-device-compliance-through-azure-ad-conditional-access

    "
    I want to know if there is any changes to this, needing to depend on MS intunes specifically is awkward.


    ------------------------------
    Deep Mantri
    ------------------------------


  • 2.  RE: Android PO - Dependency on MS Azure and inTune for Conditional access

    Posted Wed April 06, 2022 01:07 PM
    Hi..

    This does work and has been tested. There are a few things to check.

    1. The Device must be registered in Azure using the MaaS Application Settings/Corporate Settings/Configure Microsft Authenticator. NOTE: this must be done with the MaaS360 app.
    2. The MaaS360 App and the MS Authenticator must be in the Managed Profile when this is done.
    3. If this is successful and the other onboarding steps have been done correctly the device compliance state will be synched over tor AzureAD Device list. (NOTE: This is not the same as the Endpoint Manager device list).
    4. If you create a conditional access rule with a Grant Rule that requires a compliant device, and include ActiveSync and mobile apps in the list, only compliant devices will be able to connect to Exchange Online from apps in the Managed Profile only.

    Have a look at the following to make sure you have completed all the steps required.

    https://community.ibm.com/community/user/security/blogs/clinton-adams1/2021/08/09/maas360-now-integrates-with-azure-ad-conditional-a

    Thanks...

    ------------------------------
    Clinton Adams
    ------------------------------



  • 3.  RE: Android PO - Dependency on MS Azure and inTune for Conditional access

    Posted Wed April 06, 2022 10:07 PM
    Edited by Deep Mantri Thu April 07, 2022 01:38 AM
    Hi Clinton ,
    Thanks for the reply ,  the issue is that this still requires intune license as a pre requisite ( as per the link you have shared.)
    This is a major hindrance as the client feels it is redundant to have both intune license and maas360 licenses.

    Also just to add , doesn't the "is managed and is compliant" condition need the device to be managed fully , i.e. it needs to be in DO mode? At least that is what support had informed us.
    Has this changed ?
    ------------------------------
    Deep Mantri
    ------------------------------



  • 4.  RE: Android PO - Dependency on MS Azure and inTune for Conditional access

    Posted Thu April 07, 2022 12:24 PM
    Hi..

    Microsoft gets paid either way. An Intune license is required for the user of a device being managed by MaaS60 being synched over to Azure AD for Conditional Access.

    No, a PO device will reflect as Enrolled and Compliant in Azure AD. If the user activates Outlook, for example, in the Managed Profile, it will work. If they try and do the same on the personal side of the device, it will fail the Conditional Access check. User Sign-In logs will show you what happens if you test this.

    Thanks...


    ------------------------------
    Clinton Adams
    ------------------------------



  • 5.  RE: Android PO - Dependency on MS Azure and inTune for Conditional access

    Posted Thu April 07, 2022 11:45 PM
    Hello ,
    Thanks for clarifying , customer was hoping they could manage without needing additional license purchases for azure conditional access or intunes by leveraging everything from security verify itself, but seems they will have to make those additional purchases for this particular use case.

    ------------------------------
    Deep Mantri
    ------------------------------