iOS/iPadOS Managing Apple Native Mail with Intune

I keep running into the same old thing, Apple Mail is impossible to be managed by Intune and to give up and force users to use Outlook. I’ve posted instructions with details on reddit (gets deleted) so decided to just post it here for my reference. Settings below are managing the data but allowing it to be a little open. Feel free to change for your environment to make more restrictive as needed.

Before all the keyboard warriors get all uppity that “Intune can’t truly manage manage Apple native mail, it’s not on the MAM list and isn’t truly implementing DLP.” MDMs by themselves aren't a DLP solution, they're one tool in the broader part of a solution. Avantis, WorkSpace One, and alike for MDMs can all manage Apple Native mail. Are they saying Intune magically is the only MDM service that can’t prevent Apple Native mail from saving files and data outside of work managed applications? Well, it totally can and they can’t delete my webpage in response. Can’t stop the signal.

Goals for Management of Native Mail App and Data on a BYOD iOS / iPadOS device

We’re going to achieve the goals in several steps.

First step is to push the email profile to Apple mobile devices. This will make the account managed by the company in native mail and remove the account once unenrolled or removed from Intune.

Next we need to prevent the Apple Native Mail app from saving files to iCloud and the phone storage device

Now that we have iOS Apple Native Mail restricted from saving, time to allow Native Mail to save to approved locations.

We can stop there, but for added protection, we can now create a Conditional Access policy to block any MAM access if a device had Intune removed or deleted from it. This still allows Native Mail, calendar, and contact syncs. We’re only targeting O365 apps that I have deployed using MAM protection policies already. You can add other apps deployed with MAM policy as needed.

That’s it, you now have Apple Native Mail for iOS managed by Intune.

To address the critiques of keyboard warriors that are upset because they just take everything at face value to just use Outlook: