Set up security and access from mobile devices

To secure the access to the WorkZone Mobile (New) app app's web services that are used by WorkZone Mobile (New) app, it is recommended to configure conditional access, which will only allow access from compliant mobile devices.

Prerequisite: Mobile devices must be managed by Intune and compliance policies must be configured and enabled on the devices.

Log in to the Microsoft Azure portal.

Create a new policy

  1. Click Azure Active Directory on the menu.
  2. Under Security, click Protect > Conditional Access > Create new policy.
  3. Type name of the policy into the Name field. For example, Check_for_device_Compliance.

  4. Under Assignments, click Users and groups.
  5. On the Include tab, click All users > Done. This ensures that all users will be checked.
  6. Click Target resources and select Resources from the dropdown.
  7. On the Include tab, click Select resources.
  8. Click Select to expand the list of applications. Select the WorkZone Mobile (New) app app that you have created earlier.
  9. Click Select.
  10. Click Conditions > Device platforms > Yes to enable Configure.
  11. Select Any device > Done. This ensures that all platforms will be checked.
  12. Click Locations > Yes to enable Configure.
  13. On the Include tab, click Any location > Done. This ensures that all locations will be checked.
  14. Click Client apps > Yes to enable Configure.
  15. Select the Browser, Mobile apps and desktop clients, Exchange ActiveSync clients and Other clients checkboxes.
  16. Click Done.
  17. Under Access controls, click Grant > Grant access.
  18. Select the Require multi-factor authentication and Require device to be marked as compliant options.
  19. In the For multiple controls section, select Require one of the selected controls.
  20. Click Select.
  21. Click On to enable the policy, and then Create. The created policy now appears as Enabled.

For more information about configuring conditional access policy, see Learn about Conditional Access and Intune Microsoft article.