Skip to content
How to Block Viewing of Corporate Documents in Unmanaged Apps on iOS or iPadOS using Intune Policy

How to Block Viewing of Corporate Documents in Unmanaged Apps on iOS or iPadOS using Intune Policy

Written By Anoop C Nair
Last Updated November 14, 2025
Posted In Intune
SHARE

How to Block Viewing of Corporate Documents in Unmanaged Apps Using Intune Policy! The Intune policy “Block viewing corporate documents in unmanaged apps” for iOS/iPadOS is a data protection setting. When this policy is turned on, employees cannot open or share company files using apps that are not managed or approved by your organization.

When this setting is enabled, only the apps that are deployed and managed through Intune will appear in the iOS Share menu. This ensures that unmanaged or personal apps cannot open or access corporate files. For example, if the Teams app is not managed by Intune, it will not show up as a sharing option for corporate documents, thereby minimizing the risk of sensitive data being shared outside the organization.

This policy empowers IT administrators with stronger control over how corporate data is accessed and used across devices. It reduces the risk of data leakage through insecure or personal apps. Additionally, it simplifies compliance management by aligning data access practices with the organization’s security policies and regulatory requirements, ensuring sensitive information remains protected at all times.

This policy helps organizations strengthen their overall data security. It keeps corporate documents safe by blocking access from personal or unmanaged devices. It also ensures that all users and devices follow the same data access rules, making it easier to maintain consistency and control.

Patch My PC
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.1
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.1

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy

The “Block viewing corporate documents in unmanaged apps” policy is helps you to prevent sensitive organizational data from being accessed through apps that are not managed or protected by your company’s Intune or MAM (Mobile Application Management) policies.

  • First, sign in to the Microsoft Intune admin center.
  • Go to Devices and choose iOS/iPadOS.
  • Next, select Configuration Settings, and under the Create tab, click New Policy to begin creating your configuration.
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.2
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.2

Create a Profile for iOS/iPadOS Devices

On the Create a Profile page, the platform iOS/iPadOS will appear automatically. From there, choose the Profile Type as Templates to proceed with configuring the required policy settings for Apple devices.

  • Profile Type > Templates
  • Choose Device Restriction from Template
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.3
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.3

Provide the Name and Description for your Policy

In the Basics settings page, provide the Name and Description for your policy. For example:Name: Block viewing corporate documents in unmanaged apps and Description: Block viewing corporate documents in unmanaged apps using Intune policy. These details help identify the purpose of the policy and make it easier to manage within the Intune portal.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.4
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.4

Configuration Settings – App Store, Doc Viewing, and Gaming

In the Configuration Settings section, select App Store, Doc Viewing, and Gaming. Then, verify that the option Block viewing corporate documents in unmanaged apps is available. By default, this setting appears as Not configured, allowing you to modify it as per your organization’s security requirements.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.5
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.5

Corporate Documents cannot be Viewed or Accessed through Unmanaged or Personal App

In this step, confirm that the Block viewing corporate documents in unmanaged apps option is available under the selected category and is set to Yes. This ensures that corporate documents cannot be viewed or accessed through unmanaged or personal apps, helping to protect sensitive organizational data.

Policy nameSettings
Block viewing corporate documents in unmanaged apps Yes
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Table 1
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.6
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.6

Scope Tags of the Policy Settings

Scope tags are especially useful in larger organizations, where different admin groups manage specific sets of devices or users. By applying appropriate scope tags, you can ensure that only authorized administrators have visibility and control over this policy.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.7
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.7

Assignments – Add Device Groups

Under the Assignments tab, click Add Groups under the Included Groups section. From the list, select the group HTMD Supervised Device – iOS or iPadOS. This step ensures that the policy is applied only to the targeted supervised Apple devices managed through Intune.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.8
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.8

Carefully Verify all the Configured Settings

In the Review + Create section, carefully verify all the configured settings, including the policy name, description, configuration options, scope tags, and assigned groups. Once you’ve confirmed that everything is accurate, click Create to finalize and deploy the policy.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.9
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.9

Policy Notification

After the policy is created, a notification will appear in the Intune admin center confirming that the policy has been successfully deployed. The below screenshot helps you to show more details.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.10
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.10

Device and User Check in Status

After deploying the policy, you can monitor the Device and User Check-In Status in the Intune admin center. This section helps you verify whether the targeted iOS or iPadOS devices and users have successfully received and applied the policy.

How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy - Fig.11
How to Block Viewing of Corporate Documents in Unmanaged Apps using Intune Policy – Fig.11

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP from 2015 onwards for 10 consecutive years! He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is also a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read