-->
To help protect company data, restrict file transfers to only the apps that you manage. You can manage iOS apps in the following ways:
Protect Org data for work or school accounts by configuring an app protection policy for the apps. which we call policy managed apps. See Microsoft Intune protected apps.
Deploy and manage the apps through iOS device management, which requires devices to enroll in a Mobile Device Management (MDM) solution. The apps you deploy can be policy managed apps or other iOS managed apps.
The Open-in management feature for enrolled iOS devices can limit file transfers between iOS managed apps. Set Open-in management restrictions in configuration settings and then deploy them using your MDM solution. When a user installs the deployed app, the restrictions you set are applied.
Use app protection with iOS apps
The basic way to share files between Macs is to use File Sharing. To use this feature. Transfer Files with AirDrop. By far the easiest method is to use AirDrop, and so long as both Macs. Getting set up is simple. Choose what you want to share, invite your family members to join,. Turn on Wi-Fi and Bluetooth for both Macs. In order to use AirDrop, both Wi-Fi and Bluetooth must be enabled on both of your Macs: Wi-Fi — Click the 'Wi-Fi' icon in your Mac's menu bar, then click Turn Wi-Fi On in the drop-down menu.
Use App protection policies with the iOS Open-in management feature to protect company data in the following ways:
Devices not managed by any MDM solution: You can set the app protection policy settings to control sharing of data with other applications via Open-in or Share extensions. To do so, configure the Send Org data to other app setting to Policy managed apps with Open-In/Share filtering value. The Open-in/Share behavior in the policy managed app presents only other policy managed apps as options for sharing.
Devices managed by MDM solutions: For devices enrolled in Intune or third-party MDM solutions, data sharing between apps with app protection policies and other managed iOS apps deployed through MDM is controlled by Intune APP policies and the iOS Open in management feature. To make sure that apps you deploy using a MDM solution are also associated with your Intune app protection policies, configure the user UPN setting as described in the following section, Configure user UPN setting. To specify how you want to allow data transfer to other policy managed apps and iOS managed apps, configure Send Org data to other apps setting to Policy managed apps with OS sharing. To specify how you want to allow an app to receive data from other apps, enable Receive data from other apps and then choose your preferred level of receiving data. For more information about receiving and sharing app data, see Data relocation settings.
Configure user UPN setting for Microsoft Intune or third-party EMM
Configuring the user UPN setting is required for devices that are managed by Intune or a third-party EMM solution to identify the enrolled user account for the sending policy managed app when transferring data to an iOS managed app. The UPN configuration works with the app protection policies you deploy from Intune. The following procedure is a general flow on how to configure the UPN setting and the resulting user experience:
In the Microsoft Endpoint Manager admin center, create and assign an app protection policy for iOS/iPadOS. Configure policy settings per your company requirements and select the iOS apps that should have this policy.
Deploy the apps and the email profile that you want managed through Intune or your third-party MDM solution using the following generalized steps. This experience is also covered by Example 1.
Deploy the app with the following app configuration settings to the managed device:
key = IntuneMAMUPN, value = username@company.com
Example: ['IntuneMAMUPN', 'janellecraig@contoso.com']
Note
In Intune, the App Configuration policy enrollment type must be set to Managed Devices.Additionally, the app needs to be either installed from the Intune Company Portal (if set as available) or pushed as required to the device.
Note
Deploy IntuneMAMUPN app configuration settings to the target managed app which sends data, not the receiving app.
Note
Currently, there is no support for enrolling with a different user on an app if there is a MDM enrolled account on the same device.
Deploy the Open in management policy using Intune or your third-party MDM provider to enrolled devices.
Example 1: Admin experience in Intune or third-party MDM console
Go to the admin console of Intune or your third-party MDM provider. Go to the section of the console in which you deploy application configuration settings to enrolled iOS devices.
In the Application Configuration section, enter the following setting for each policy managed app that will transfer data to iOS managed apps:
key = IntuneMAMUPN, value = username@company.com
The exact syntax of the key/value pair may differ based on your third-party MDM provider. The following table shows examples of third-party MDM providers and the exact values you should enter for the key/value pair.
Third-party MDM provider Configuration Key Value Type Configuration Value Microsoft Intune IntuneMAMUPN String {{UserPrincipalName}} VMware AirWatch IntuneMAMUPN String {UserPrincipalName} MobileIron IntuneMAMUPN String ${userUPN} or ${userEmailAddress} Citrix Endpoint Management IntuneMAMUPN String ${user.userprincipalname} ManageEngine Mobile Device Manager IntuneMAMUPN String %upn%
Note
For Outlook for iOS/iPadOS, if you deploy a managed devices App Configuration Policy with the option 'Using configuration designer' and enable Allow only work or school accounts, the configuration key IntuneMAMUPN is configured automatically behind the scenes for the policy. More details can be found in the FAQ section in New Outlook for iOS and Android App Configuration Policy Experience – General App Configuration.
Example 2: End-user experience
Sharing from a policy managed app to other applications with OS sharing
A user opens the Microsoft OneDrive app on an enrolled iOS device and signs-in to their work account. The account the user enters must match the account UPN you specified in the app configuration settings for the Microsoft OneDrive app.
After sign-in, your Administrator configured APP settings apply to the user account in Microsoft OneDrive. This includes configuring the Send Org data to other apps setting to the Policy managed apps with OS sharing value.
The user previews a work file and attempts to share via Open-in to iOS managed app.
The data transfer succeeds and data is now protected by Open-in management in the iOS managed app. Intune APP does not apply to applications that are not policy managed apps.
Sharing from a iOS managed app to a policy managed app with incoming Org data
A user opens native Mail on an enrolled iOS device with a Managed email profile.
The user opens a work document attachment from native Mail to Microsoft Word.
When the Word app launches, one of two experiences occur:
- The data is protected by Intune APP when:
- The user is signed-in to their work account that matches the account UPN you specified in the app configuration settings for the Microsoft Word app.
- Your Administrator configured APP settings apply to the user account in Microsoft Word. This includes configuring the Receive data from other apps setting to the All apps with incoming Org data value.
- The data transfer succeeds and the document is tagged with the work identity in the app. Intune APP protects the user actions for the document.
- The data is not protected by Intune APP when:
- The user is not signed-in to their work account.
- Your Administrator configured settings are not applied to Microsoft Word because the user is not signed in.
- The data transfer succeeds and the document is not tagged with the work identity in the app. Intune APP does not protects the user actions for the document because it is not active.
Note
The user can add and use their personal accounts with Word. App protection policies don't apply when the user uses Word outside of a work-context.
- The data is protected by Intune APP when:
Validate user UPN setting for third-party EMM
After configuring the user UPN setting, validate the iOS app's ability to receive and comply to Intune app protection policy.
For example, the Require app PIN policy setting is easy to test. When the policy setting equals Require, the user should see a prompt to set or enter a PIN before they can access company data.
First, create and assign an app protection policy to the iOS app. For more information on how to test app protection policy, See Validate app protection policies.
See also
With purchase sharing, one adult in your Family Sharing group agrees to pay for any purchases from the App Store, iTunes Store, and Apple Books. You can then see and download your family members' purchases from your iPhone, iPad, iPod touch, Mac, Apple TV, and PC, and enjoy them too.* Follow the steps below to download family members' purchases to your device, and learn where to find those purchases if you don't see them.
How to download previous purchases from family members
When purchase sharing is turned on for your family, you can see and download items from each family member's purchase history. You can download music, movies, TV shows, and books on up to 10 of your devices, 5 of which can be computers. You can download apps to any devices that you own or control.
Download purchases on your iPhone, iPad, or iPod touch
Download purchases on your iPhone or iPod touch
- If you're not signed in, sign in with your Apple ID.
- Open the store app that you want to download content from, then go to the Purchased page.*
- App Store: Tap your profile picture in the upper-right corner, then tap Purchased.
- iTunes Store: Tap More , then tap Purchased.
- Apple Books: Tap your profile picture in the upper-right corner.
- Tap your family member's name to see their content. Learn what to do if you don't see any content or can't tap your family member.
- To download an item, tap Download next to it.
Download purchases on your iPad
- If you're not signed in, sign in with your Apple ID.
- Open the store app that you want to download content from.
- App Store: Tap your profile picture in the upper-right corner, then tap Purchased.*
- iTunes Store: Tap Purchased, then tap My Purchases.
- Apple Books: Tap your profile picture in the upper-right corner.
- Tap the family member's name to see their content. Learn what to do if you don't see any content or can't tap your family member.
- To download an item, tap Download next to it.
Download purchases on your Mac or PC
Download purchases on your Mac
- If you're not signed in, sign in with your Apple ID.
- Open the store app that you want to download content from, then go to the Purchased page.*
- App Store: Click your profile picture in the bottom-left corner.
- Apple Music app: From the menu bar, choose Account > Family Purchases.
- Apple TV app: From the menu bar, choose Account > Family Purchases.
- Apple Books: Click Book Store, then click Purchased under Quick Links on the right side of the Apple Books window.
- From the menu to the right of Purchased, choose a family member's name to view their content. For example, in the App Store:
- Download or play the items that you want.
Download purchases on your Windows PC
- If you're not signed in, sign in with your Apple ID.
- From the menu bar at the top of the iTunes window, choose Account > Family Purchases.*
- Select a family member's name to view their content.
- Download or play the items that you want.
Download purchases on your Apple Watch
- Open the App Store.
- Scroll to the bottom of the screen and tap Account.
- Tap Purchased.*
* In the store, items your family members have already purchased still show their full price. To avoid paying for the item again, download it from the Purchased page.
Download purchases on your Apple TV, smart TV, or streaming device
Download purchases on your Apple TV
Share Mac Folders
- On your Apple TV, select iTunes Movies, iTunes TV Shows, or App Store.
- Select Purchased, select Family Sharing, then select your family member to see their content.* You can access shared movies, TV shows, and apps on Apple TV, but not music.
Download purchases in the Apple TV app on your smart TV or streaming device
- Open the Apple TV app.
- Select Library > Family Sharing, then select your family member to see their content.* You can access shared movies and TV shows in the Apple TV app on smart TVs and streaming devices.
Share Mac Folder On Network
* In the store, items your family members have already purchased still show their full price. To avoid paying for the item again, access it from the Family Sharing page.
Where to find downloaded purchases
Once you've downloaded a family member's purchase to your device, you can look for it in these locations:
- Apps download to the Home screen on your iPhone, iPad, iPod touch, or Apple TV. Apps download to Launchpad on your Mac.
- Music downloads to the Apple Music app on your iPhone, iPad, iPod touch, Mac, or Apple Watch. Music downloads to iTunes for Windows on your PC.
- TV shows and movies download to the Apple TV app on your iPhone, iPad, iPod touch, Mac, Apple TV, or streaming device. TV shows and movies download to iTunes for Windows on your PC.
- Books download to the Apple Books app on your iPhone, iPad, iPod touch, Mac, or Apple Watch.
If you still don't see your family's shared content, learn what to do.
Learn more about Family Sharing
- Family Sharing requires a personal Apple ID signed in to iCloud.
- iOS 8 or later and OS X Yosemite or later are required to set up or join a Family Sharing group and are recommended for full functionality.
- Not all content is eligible to be shared. Content can be hidden by family members; hidden content is not available for download. Content downloaded from family members or acquired via redemption codes is not subject to Ask to Buy.
Mac Share Desktop
* Not all content and content types are available in all countries or regions. To share purchased content, all family members must use the same Apple ID country or region. Music, movies, TV shows, and books can be downloaded on up to 10 devices per account, five of which can be computers. Apps can be downloaded to any devices the family member owns or controls.