Strengthening Our Cybersecurity Posture
About the Program
If you use your personal smartphone or tablet to access UTMB resources, you'll need to enroll it in Microsoft Intune as part of UTMB's Bring Your Own Device (BYOD) program. Intune helps protect university data by confirming your device meets required security standards while keeping your personal information separate and private.
What You Need to Know
iOS & Android Operating Systems
- Your device cannot be modified to bypass Apple or Android restrictions, also known as being "jailbroken" or "rooted."
- Your device must be on an operating system currently receiving security updates.
- You will not be able to Airdrop to or from UTMB resources.
Passcodes & PINs
- Your device must have a passcode to unlock.
- Passcode Length of 6 for iOS and 4 for Android.
- No easy sequences (e.g., 1111 or 1234).
- No unlock patterns.
- Screen will lock after 15 minutes of inactivity.
- Passcode will be required 15 minutes after screen lock.
Privacy Information
- Intune checks for compliance (e.g., Operating System and PIN) and grants access to UTMB resources accordingly.
- Intune collects only limited device info (e.g., model, MAC, OS) and doesn’t access personal data.
- Intune cannot see your calling history, browsing history, photos, emails, text messages, calendar or passwords.
- Intune cannot track your location or call log data.
UTMB Apps
- Only the Outlook App via the UTMB Company Portal can be used to access email. Native Email Apps can no longer be used.
- You will not be able to use M365 Apps installed outside of the UTMB Company Portal.
- Microsoft Authenticator must be installed. This is a requirement from Microsoft.
- Only M365 Apps like Outlook and Teams will be affected; apps like Epic Haiku/Canto are currently out of scope.
Unenroll Your Device
You can use the Company Portal website to remotely unenroll and unregister a personal device from work or school. Once you remove a device, your organization no longer manages the device and it is removed from the Company Portal app and website.
Important: You may lose access to protected work data, such as files, apps, and email, on the device after you unenroll.
- Sign in to the Company Portal website using your work or school account. You can sign in from any device.
- Select the menu icon (three horizontal lines) in the upper-left corner, then select Devices.
- Select the device you want to remove.
- Select Remove (trash can icon).
- If you do not see Remove, select the More (...) menu to view additional options.
- When prompted, select Remove again to confirm.
- Your device has now been unenrolled from Company Portal.
- Select the menu icon (three horizontal lines) in the upper-left corner and choose Sign Out.
iOS Device Enrollment Instructions
Before You Begin
Enrolling your iOS device in Intune will change how you access UTMB apps and data. Please review the following information before continuing.
-
UTMB Apps and Accounts
- UTMB email will only be available through the Outlook app installed from the UTMB Company Portal.
- You will no longer be able to access UTMB email or other protected UTMB resources through apps installed outside of Intune, including your device's native mail app.
- Apps installed through the Company Portal can only be used with UTMB accounts. Personal accounts and non-UTMB work accounts are not supported. This restriction applies to Outlook, Teams, and any future apps made available through the Company Portal.
- Only one version of an app can be installed on your device. For example, if Outlook is installed through Intune, you cannot install a separate App Store version of Outlook for personal use.
-
iCloud and Data Sharing
- Apps installed through Intune cannot access personal iCloud backups.
- Data stored in Intune-managed apps is subject to UTMB security policies and may not be accessible outside of the UTMB-managed environment.
- You will not be able to use AirDrop to transfer UTMB-managed data.
-
Microsoft Authenticator
- Microsoft Authenticator is required and must be installed to complete enrollment.
- If you currently use Microsoft Authenticator for personal or non-UTMB accounts, you may need to reconfigure those accounts after enrollment.
- Reconfiguration steps vary by service. Contact the service provider for instructions if needed.
Video Tutorials
Enrolling Your iOS Device
Enrolling Your iOS Device
iOS BYOD enrollment transcript
[Background music]
Narrator:
Here at UTMB, we take information security seriously. Whether it's patient information, financial documents, or private employee information, it's an ongoing effort to keep that data safe. This video will be covering the Intune enrollment process for iPhones.
To get started, we need to make sure that a few Microsoft apps are not on your phone. We will be removing Authenticator, Teams, and Outlook. If these apps are not on your phone, feel free to skip ahead to the next part of the video. You may also uninstall any other Microsoft programs that you may need.
Here, we'll be demonstrating the process to remove an app, using Authenticator as an example.
- First, we're going to swipe from right to left until we reach the App Library. This library contains every app installed on your phone.
- Next, we're going to select and hold the Authenticator app, then select Delete App from the menu that appears and confirm by selecting Delete again.
- While you're here in the App Library, you can search for both the Teams and Outlook apps and delete them using the same method.
Next, be sure to turn off your Wi-Fi if you're physically located at a UTMB facility. If you're at home, you can continue without making any changes.
- Now we're going to open the Settings menu, represented by a gear icon.
- In the Settings, open the General section of the Settings menu.
- Next, select VPN & Device Management. Now we're in the correct menu to begin the enrollment.
- Select Sign in with Work or School Account. This will bring up a text box where you can enter in your UTMB email address, then select Continue.
- After submitting your password, a Duo screen will appear, followed by a Duo notification at the top of your screen.
- You can swipe down on the Duo notification to approve it.
- It is important that you do not leave this screen, as it can reset the enrollment process back to the beginning.
- Now that you've processed the Duo push, a new screen will appear asking, Is this your device?
- Select Yes, this is my device.
- A prompt will now appear where you will sign into iCloud by selecting the option at the bottom, labeled Sign into iCloud.
- Now the screen will say, Apple account for your organization.
- Select Continue to proceed.
- After submitting your password, a Duo screen will appear, followed by a Duo notification at the top of your screen.
- You can swipe down on the Duo notification to approve it. You will be given the option to stay signed in.
- Select No to avoid future lockouts when your password is changed.
- Select Allow Remote Management and then enter your six-digit iPhone PIN. If your PIN is still 4 digits, you'll be asked to change to a six-digit PIN when adding your Intune apps. The process of changing your PIN and adding Intune apps to your phone is shown in a separate video in the BYOD series.
- You will now get a prompt notifying you about the initial Intune app installation.
- Select Install, and your phone will install UTMB Company Portal, Microsoft Authenticator, Microsoft Outlook, and Microsoft Teams.
- This app installation can take up to 30 minutes, so you may not have access to the apps immediately.
Once your apps are installed, open the Microsoft Teams app.
- When the app opens, you will be prompted to select an account.
- Select your UTMB account to continue. You will then see a prompt indicating that the app will restart.
- Select OK. Teams will ask for location permissions.
- Select Allow while using app.
- Finally, Teams will ask for notification permissions.
- Select Allow to receive alerts for any messages or calls that you will be receiving from Teams.
That's it. You're officially enrolled in Intune!
If you experienced any errors or problems during this process, please check out the troubleshooting section of the BYOD instructional page at byod.utmb.edu.
Installing Apps on iOS
Installing Apps on iOS
iOS BYOD application installation video
Important: If you would like to receive UTMB email on your device follow these steps to To access UTMB email on your device, you must install Microsoft Outlook from the UTMB Company Portal. If Outlook is already installed on your device, delete it before installing the Company Portal version.
iOS BYOD app installation transcript
Narrator:
- To install an app for work, tap the UTMB company portal icon that was added to your device during BYOD enrollment.
- If prompted, choose your UTMB account.
- Choose the type of device you are currently using.
- Select the app you want to install. In this case we are installing the Outlook email app.
- You may need to select your device if this message is displayed, tap on the message to confirm your device, then select the device you are currently using.
- Once you've selected your device, tap the Install button.
- Tapping the Install button will send a request to Intune to push the app to your device.
- This may take a few minutes.
- When prompted, press the Install button.
- Wait for the app to complete installing, then tap on the app to open it.
- Depending on the app you install, you may be prompted to add an account.
- You may receive prompts indicating that UTMB is protecting data in the app.
- Please accept and follow the instructions in these prompts.
- After accepting these prompts, you may be asked about permissions for the app.
- Once permissions have been chosen, the app installation is complete.
Enrollment Instructions
- If installed, remove Microsoft Outlook, Microsoft Teams, and Microsoft Authenticator from your device.
- Note: After enrollment, Outlook can only be used with your UTMB email account.
- Ensure your device is not connected to UTMB Wi-Fi. The enrollment process will fail if your device is connected to the network.
- On your device, navigate to Settings > General > VPN & Device Management > Sign In to Work or School Account.
- Enter your full UTMB email address when prompted.
- Sign in using your UTMB password and complete DUO authentication.
- When prompted to sign in to iCloud, enter your UTMB password and complete DUO authentication.
- When prompted, allow remote management.
- If asked to restore your work apps and data, select Don't Restore.
- Your device will receive the following apps. Select Install when prompted:
- UTMB Company Portal
- Microsoft Authenticator
- Microsoft Teams
- Microsoft Outlook
- Note: These apps may take several minutes to appear.
- Open Microsoft Teams and Microsoft Outlook.
- Select your UTMB account and complete any remaining prompts.
Once sign-in is complete, your device is enrolled.
Android Device Enrollment Instructions
Before You Begin
Follow these steps to enroll your Android in the UTMB BYOD program using Microsoft Intune.
Enrollment Instructions
Installing Apps on Android
- Open the Play Store in your work profile.
- Select the app you want to install. For this example, choose Microsoft Outlook.
- Select Install.
- Wait for the app to finish downloading and installing, then select Open.
- If prompted, select Add account.
- Select your UTMB account and choose Continue.
- Note: Only UTMB accounts can be added to work apps.
- If prompted to set up notifications, choose whether to allow or disable notifications for the app.
- You may see a message indicating that UTMB is protecting the app. Select Continue to proceed.
- Installation Complete. The app is now installed and ready to use.
Frequently Asked Questions
If the FAQ does not address your questions about this change, please email the UTMB Office of Information Security at security@utmb.edu or call (409) 772-3838.
-
When does this take effect?
Now – Intune has been undergoing extensive configuration development and testing to ensure that the controls are effective and minimally invasive. Pilot group testing has been completed and practices for ongoing controls development have been generated and approved by UTMB leadership.
-
What is Intune?
Intune is a component of UTMB’s Microsoft licensed management and security tools. Intune adds a small application to enrolled systems to allow it to respond to configuration checks (and eventually to request applications from the UTMB Company Portal).
-
What is the UTMB policy?
These requirements are not new. UTMB has long required both UTMB-owned and personally owned devices to be securely configured before accessing UTMB networks and data. This requirement is outlined in UTMB Security Practice Standards 1.4, Portable Computing (effective Jan. 1, 2008), and 5.1, Platform & Application Hardening (effective Sept. 3, 2002).
The updated BYOD process does not create a new policy. It simply verifies that devices meet existing security requirements before access to UTMB resources is granted.
-
Can this change affect my Contacts even if I don't enroll in Intune?
Yes, anyone currently using their personal mobile device to access UTMB Exchange Email may need to save their contacts depending on their device settings. (Important: This is true for all users, not just those who will enroll in Intune.) For more information, see the Android instructions and iOS instructions pages for details related to your specific device.
-
What are Personal Device Features and UTMB Protections?
Allowed actions (will work):
- Taking photos with the camera while inside a UTMB managed app.
- Inserting existing photos or screenshots using Add/Attach | Photo Library while inside a UTMB managed app.
- Copy and Paste to and between UTMB managed apps (for example from Outlook to Teams).
- Copying text from an unmanaged app into a UTMB managed (for example from Safari or Chrome to Outlook).
Disallowed actions (won't work):
- Sharing from the Photos app into a UTMB managed app.
- Taking screenshots of UTMB managed apps.
- Copy and Paste from UTMB managed apps to external apps. (for example from Outlook to Safari or Chrome).
Important reminders:
- If Copy and Paste don't work, try to Attach or Upload instead.
- Keep work content inside managed apps to remain compliant.
- Avoid mixing personal and company data — managed apps keep company data secure.
- Selecting web links require the UTMB managed Edge browser.
- Selecting Zoom and Webex meeting links require the UTMB managed Zoom and Webex apps.
-
Can Intune WIPE (erase data and/or reset configuration) or PUSH apps/software/configuration changes to my personal device?
No, the Personal Device profile used by Intune does not allow wiping or “factory settings reset” on personal devices. If/when changes to device setting are required to establish or maintain access to UTMB resources or updates to apps loaded from the UTMB Store are required, enrolled devices/users will receive notices and guidance to make the changes, however the device/user MUST INITIATE the change/update.
-
What if I need help enrolling my device in Intune?
If you need assistance enrolling your device in Intune, please contact the UTMB Service Desk at (409) 772-5200. If possible, call from a landline or a different cellphone.
-
Are students required to enroll in Intune?
Personal device enrollment only applies to UTMB employees. Students, including those who are also employed by UTMB, are currently not required to enroll.
-
Will additional apps be supported?
Adding additional UTMB managed Apple or Android apps (including special keyboards) can be requested using the self-service portal.
Note: Integrating other calendars with the Outlook calendar is currently not supported.
-
Where can we learn more about Intune?
If you have additional questions regarding Intune or the changes to UTMB’s BYOD practices, email the Office of Information Security at security@utmb.edu or call and leave a voicemail at (409) 772-3838.
You can also check out Microsoft’s Intune knowledgebase page, What info can your organization see when you enroll your device?
-
Can “jailbroken” or “rooted” devices enroll in Intune and be confirmed as compliant for accessing UTMB networks, resources and data?
“Jailbroken” or “rooted” devices can enroll in Intune, however they are not compliant, and will not be able to access UTMB networks, resources, and data.
-
Are there "productivity" options for users or personal devices that are not enrolled in Intune?
Yes. Devices not enrolled in Intune (or determined to not be security controls compliant by Intune) will still have access to the Citrix virtual desktop (Storefront) environment. Please note: Access to UTMB email via Outlook, webmail, POP/SMTP will be restricted to Intune enrolled/confirmed compliant devices.
-
Is Intune required for Duo multifactor authentication for remote work/access?
No, Duo MFA device registration (to receive Duo push, passcode or phone call notifications for remote access via VPN/Citrix/etc.) is a completely separate process and does not require Intune enrollment.
Please note: iOS and Android devices used to access UTMB resources via VPN/remote access, will need to be enrolled in Intune to confirm compliance.
-
Does Intune track my location or activity?
No, location services, call logs, etc. are maintained as personal settings or are controlled via personal applications. Intune does not have access to personal device settings or personal app settings.
-
Does Intune have access to my personal files?
No, Intune will only monitor for compliant configuration settings and allow access to UTMB resources, as appropriate. No access to personal data/files is established and only limited device information (Model, OS version, etc.) is collected and maintained by Intune.
-
What classes of mobile devices are included?
In this phase of the roll-out, only iOS-based and Android devices (tablets, smartphones, etc.) are included, however additional development and configurations are progressing to include Windows-based laptops and other device classes. This does not apply to UTMB Owned devices as they are configured in Intune differently.
-
Where can we learn more about Outlook for iOS and Android?
Check out the Outlook for iOS and Android quick start instructions at Microsoft.