Bring Your Own Device (BYOD) Program

Office of Information Security

Strengthening Our Cybersecurity Posture

About the Program

If you use your personal smartphone or tablet to access UTMB resources, you'll need to enroll it in Microsoft Intune as part of UTMB's Bring Your Own Device (BYOD) program. Intune helps protect university data by confirming your device meets required security standards while keeping your personal information separate and private.

What You Need to Know

iOS Device Enrollment Instructions

Before You Begin

Enrolling your iOS device in Intune will change how you access UTMB apps and data. Please review the following information before continuing.

  • UTMB Apps and Accounts

    • UTMB email will only be available through the Outlook app installed from the UTMB Company Portal.
    • You will no longer be able to access UTMB email or other protected UTMB resources through apps installed outside of Intune, including your device's native mail app.
    • Apps installed through the Company Portal can only be used with UTMB accounts. Personal accounts and non-UTMB work accounts are not supported. This restriction applies to Outlook, Teams, and any future apps made available through the Company Portal.
    • Only one version of an app can be installed on your device. For example, if Outlook is installed through Intune, you cannot install a separate App Store version of Outlook for personal use.
  • iCloud and Data Sharing

    • Apps installed through Intune cannot access personal iCloud backups.
    • Data stored in Intune-managed apps is subject to UTMB security policies and may not be accessible outside of the UTMB-managed environment.
    • You will not be able to use AirDrop to transfer UTMB-managed data.
  • Microsoft Authenticator

    • Microsoft Authenticator is required and must be installed to complete enrollment.
    • If you currently use Microsoft Authenticator for personal or non-UTMB accounts, you may need to reconfigure those accounts after enrollment.
    • Reconfiguration steps vary by service. Contact the service provider for instructions if needed.

Video Tutorials

Enrollment Instructions

  1. If installed, remove Microsoft Outlook, Microsoft Teams, and Microsoft Authenticator from your device.
  2. Note: After enrollment, Outlook can only be used with your UTMB email account.
  3. Ensure your device is not connected to UTMB Wi-Fi. The enrollment process will fail if your device is connected to the network.
  4. On your device, navigate to Settings > General > VPN & Device Management > Sign In to Work or School Account.
  5. Enter your full UTMB email address when prompted.
  6. Sign in using your UTMB password and complete DUO authentication.
  7. When prompted to sign in to iCloud, enter your UTMB password and complete DUO authentication.
  8. When prompted, allow remote management.
  9. If asked to restore your work apps and data, select Don't Restore.
  10. Your device will receive the following apps. Select Install when prompted:
    • UTMB Company Portal
    • Microsoft Authenticator
    • Microsoft Teams
    • Microsoft Outlook
    • Note: These apps may take several minutes to appear.
  11. Open Microsoft Teams and Microsoft Outlook.
  12. Select your UTMB account and complete any remaining prompts.

Once sign-in is complete, your device is enrolled.

Android Device Enrollment Instructions

Installing Apps on Android

  1. Open the Play Store in your work profile.
  2. Select the app you want to install. For this example, choose Microsoft Outlook.
  3. Select Install.
  4. Wait for the app to finish downloading and installing, then select Open.
  5. If prompted, select Add account.
    • Select your UTMB account and choose Continue.
    • Note: Only UTMB accounts can be added to work apps.
  6. If prompted to set up notifications, choose whether to allow or disable notifications for the app.
  7. You may see a message indicating that UTMB is protecting the app. Select Continue to proceed.
  8. Installation Complete. The app is now installed and ready to use.

Frequently Asked Questions

If the FAQ does not address your questions about this change, please email the UTMB Office of Information Security at security@utmb.edu or call (409) 772-3838.

  • When does this take effect?

    Now – Intune has been undergoing extensive configuration development and testing to ensure that the controls are effective and minimally invasive. Pilot group testing has been completed and practices for ongoing controls development have been generated and approved by UTMB leadership.

  • What is Intune?

    Intune is a component of UTMB’s Microsoft licensed management and security tools.  Intune adds a small application to enrolled systems to allow it to respond to configuration checks (and eventually to request applications from the UTMB Company Portal).

  • What is the UTMB policy?

    These requirements are not new. UTMB has long required both UTMB-owned and personally owned devices to be securely configured before accessing UTMB networks and data. This requirement is outlined in UTMB Security Practice Standards 1.4, Portable Computing (effective Jan. 1, 2008), and 5.1, Platform & Application Hardening (effective Sept. 3, 2002).

    The updated BYOD process does not create a new policy. It simply verifies that devices meet existing security requirements before access to UTMB resources is granted.

  • Can this change affect my Contacts even if I don't enroll in Intune?

    Yes, anyone currently using their personal mobile device to access UTMB Exchange Email may need to save their contacts depending on their device settings. (Important: This is true for all users, not just those who will enroll in Intune.) For more information, see the Android instructions and iOS instructions pages for details related to your specific device.

  • What are Personal Device Features and UTMB Protections?

    Allowed actions (will work):

    • Taking photos with the camera while inside a UTMB managed app.
    • Inserting existing photos or screenshots using Add/Attach | Photo Library while inside a UTMB managed app.
    • Copy and Paste to and between UTMB managed apps (for example from Outlook to Teams).
    • Copying text from an unmanaged app into a UTMB managed (for example from Safari or Chrome to Outlook).

    Disallowed actions (won't work):

    • Sharing from the Photos app into a UTMB managed app.
    • Taking screenshots of UTMB managed apps.
    • Copy and Paste from UTMB managed apps to external apps. (for example from Outlook to Safari or Chrome).

    Important reminders:

    • If Copy and Paste don't work, try to Attach or Upload instead.
    • Keep work content inside managed apps to remain compliant.
    • Avoid mixing personal and company data — managed apps keep company data secure.
    • Selecting web links require the UTMB managed Edge browser.
    • Selecting Zoom and Webex meeting links require the UTMB managed Zoom and Webex apps.
  • Can Intune WIPE (erase data and/or reset configuration) or PUSH apps/software/configuration changes to my personal device?

    No, the Personal Device profile used by Intune does not allow wiping or “factory settings reset” on personal devices. If/when changes to device setting are required to establish or maintain access to UTMB resources or updates to apps loaded from the UTMB Store are required, enrolled devices/users will receive notices and guidance to make the changes, however the device/user MUST INITIATE the change/update.

  • What if I need help enrolling my device in Intune?

    If you need assistance enrolling your device in Intune, please contact the UTMB Service Desk at (409) 772-5200. If possible, call from a landline or a different cellphone.

  • Are students required to enroll in Intune?

    Personal device enrollment only applies to UTMB employees. Students, including those who are also employed by UTMB, are currently not required to enroll.

  • Will additional apps be supported?

    Adding additional UTMB managed Apple or Android apps (including special keyboards) can be requested using the self-service portal.

    Note: Integrating other calendars with the Outlook calendar is currently not supported.