Data encryption in App Protection Policy [iOS]

Pavels 66 Reputation points
2020-08-06T07:45:59.987+00:00

Hello,

In App Protection Policy there is an option to encrypt org data. Is this some additional encryption prior to normal iPad encryption?

16017-screenshot.jpg

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,781 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Jason Sandys 31,186 Reputation points Microsoft Employee
    2020-08-06T19:29:36.933+00:00

    Yes, this is an additional mechanism and layer to protect the data specific to the app itself. Device encryption doesn't preclude a malicious actor running on the device itself from potentially reading data from another app that it shouldn't have access to.

    0 comments No comments

  2. Crystal-MSFT 45,486 Reputation points Microsoft Vendor
    2020-08-07T03:10:28.583+00:00

    Hi,

    Agree with Jason, for the "Encrypt Org data" setting under app protection policy, it is an additional option and data marked as "corporate" is encrypted according to the IT administrator's app protection policy.

    For device encryption, based on my understanding, it is hareware level encryption. We can see more details in the following link:
    https://support.apple.com/en-sg/guide/security/sece3bee0835/web
    Note: Non-Microsoft link, just for the reference.

    Hope it can help.

    0 comments No comments