Listed below are the details of the Intune updates for April 2016, and as per usual there are likely a few that are particularly applicable to your environment.

 

All of the April 2016 features are also supported for hybrid customers (Configuration Manager integrated with Intune).

App management

  • MAM user compliance.
    You can now view the status of your application management policies for any user in your Azure Active Directory (AAD) tenant. This includes:

    • Devices
    • Apps on the device

    Status values:
    Checked in: Indicates the policy was deployed to the user, and app was used in work context, and successfully received the policy.
    Not checked in: Indicates the policy was deployed to the user, but app has not been used in the work context since then.

  • MAM controls to prevent Outlook contacts sync (Android).
    A new setting is available for mobile application management without device enrollment. This setting allows you to prevent an application from syncing contacts to the native address book on Android devices. When this setting is enabled, targeted applications will no longer be able to save contacts to the native address book. When this setting is disabled, targeted applications will be able to save contacts to the native address book. When you remotely wipe a device or app, contacts that have already been saved to the native address book will be removed. This new setting is supported initially by the Outlook application on Android devices.

Device management

  • Phone number identification for corporate-owned devices. Phones that are categorized as “Corporate” are now identified with their full phone number when, for example, you run a mobile device inventory report. BYOD phone numbers continue to be masked with ****, with only the last 4 digits displayed.

Company portal updates

Android Company portal app
Users who have not enrolled their device in Intune and who do not have the correct certificate installed will not be able to sign in to the Android Company Portal app and will see the message, “You cannot sign in because your device is missing a required certificate.” The message includes a “How to resolve this” link that users can tap to see instructions for installing the certificate. To see the steps that end users follow to resolve the issue, see Your device is missing a required certificate.

Windows 10 Mobile and Windows Phone 8.1 Company Portal app
When end users are installing line-of-business apps, they will now see an improved app installation experience. If the app installation is taking a long time, users can manually sync their device to force the sync process to resume. To review the end-user instructions, see Sync your device manually to speed up app installations.

Company Portal website
When Windows 10 Mobile and Windows Phone 8.1 users are installing line-of-business apps, they will now see the following new statuses, which provide them with more detail about the status of their installation:

  • Waiting for device to sync – the user has tapped “Install” and the device now tries to sync with the Intune infrastructure. The sync is required before the installation can complete. The “Waiting for device to sync” message is also a link that users can tap to see instructions on how to manually sync their device with Intune if the sync process is taking a long time or gets stalled.
  • Downloading – the user’s download request is being processed and the device is downloading and installing the app.

Before these statuses were added, users got confused if an app installation took a long time, because they saw only an “Installing” status, which might remain on the screen for hours. Adding the new statuses means that, instead of calling support, users can now tap the “Waiting for device to sync” link and follow the instructions to force the sync process to resume.

What’s coming

Changes to Device Enrollment Managers accounts. To improve performance and scale, Intune will no longer show all Device Enrollment Managers (DEM) devices in the My Devices pane of the Company Portal app. Only the local device running the app is displayed, and only if it is enrolled via the Company Portal app. The DEM user may perform actions on the local device, but remote management of other enrolled devices can only be performed from the Intune admin console. Additionally, Intune will deprecate using DEM accounts with either the Apple Device Enrollment Program or the Apple Configurator tool. Both these enrollment methods already support user-less enrollment for shared iOS devices. Only use DEM accounts when user-less enrollment for shared devices is unavailable.

Keep informed about upcoming developments for Intune with the Cloud Platform roadmap.