Close Menu
    Facebook X (Twitter) Instagram
    Saturday, October 11
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»Intune»App protection policies»Configure bookmarks ,allow and block URLs for the Managed Browser using intune

    Configure bookmarks ,allow and block URLs for the Managed Browser using intune

    Eswar KonetiBy Eswar KonetiDecember 27, 7:28 am3 Mins Read App protection policies 16,858 Views
    Share
    Facebook Twitter LinkedIn Reddit

    If you are using Microsoft intune as MDM solution to manage mobile devices ,you will certainly hit the requirement of managing Internet access using Managed Browser policies with Microsoft Intune to allow or block,bookmark and set home page with certain URL’s.

    Intune Managed Browser is a web browsing application that you can download from public app stores (apple store or Google play store) for use in your organization. Since this app has integration with the Intune SDK, you can also apply app protection policies like controlling cut ,copy,paste that comes with intune app protection policies.

    If you are allowing end users to use managed browser for corporate use ,you must apply app protection policies and restrict managed apps to open the URL’s in intune browser .

    If you are controlling the data on the managed apps using application protection policies ,you have the option of opening the URL within the managed apps using intune browser hence it is good advice to configure URL’s what is allowed and what is blocked for security reasons.

    In this blog post ,we will see how to bookmark ,set homepage ,allow and block certain URLs for the Managed Browser .

    1. Login to www.portal.azure.com

    2.Click on Intune node ,browse through Mobile apps ,App Configuration Policies (https://portal.azure.com/#blade/Microsoft_Intune_Apps/MainMenu/14/selectedMenuItem/Overview)

    image

    Or you can also click on Intune app Protection node (soon this node will be removed and you are required to use above option) ,under App management ,click on App Configuration (https://portal.azure.com/#blade/Microsoft_Intune/SummaryBlade/2)

    image

    3. Click on Add Config ,supply name and description

    image

    4. Under select required app ,choose Managed Browser (ManBro) for both iOS and Andriod,click Ok

    image

    image

    5.Under Configuration ,first identify the URL’s that you want to allow .If you have requirement to block certain URL’s ,follow the steps above ,change the name to block.

    image

    You need to supply 2 values in the configuration 1.Name and 2.Value

    image

    Key Name to Allow URL’s:

    com.microsoft.intune.mam.managedbrowser.AllowListURLs

    Key Name to block URL’s:

    com.microsoft.intune.mam.managedbrowser.BlockListURLs

    I want to allow couple of URL’s that intune users access via browser are separated by (|)

    http://eskonr.com/*|https://*.microsoft.com/*|https://expenses.contoso.com|http://www.eskonr.com:8080

    http://eskonr.com/* –>Match all URL’s that begin with eskonr.com

    https://*.microsoft.com/* –>Match all subdomains under

    http://www.eskonr.com:8080 –>match single webpage that contains port number

    To allow authentication, and access to Intune documentation, *.microsoft.com is exempt from the allow or block list settings. It is always allowed.

    If you want to block any specific URL’s,add the above values in block list key value.

    How to bookmarks specific URL’s ?

    Key Name to bookmark:

    microsoft.intune.mam.managedbrowser.homepage

    Values:

    Cyberark|https://cybr.intranet.asia/PasswordVault/default.aspx||Eswar Koneti Blog|http://www.eskonr.com

    Each bookmark consists of the bookmark title, and the bookmark URL. Separate the title, and URL with the | character.

    To configure multiple bookmarks, separate each pair with the double character, ||

    SNAGHTML9d8d461f

    6.Click Save,go to assignments and add group who should receive these settings.

    End User Experience:

    After you create the configuration and assign to group (list of users), on mobile device that was enrolled or MAM-WE(without enrolled) ,open intune browser ,you will see the changes that we configured in homepage ,bookmarks.

    If you try to access any URL in the browser which is not allowed ,you will see message saying the URL is blocked. Unless you go back to the setting and allow ,user cannot open the URL using intune browser.

    References:

    https://docs.microsoft.com/en-us/intune/app-configuration-managed-browser

    https://docs.microsoft.com/en-us/azure/active-directory/active-directory-application-proxy-get-started#how-to-get-started

    allowed and blocked URLs app logs block list URL bookmarks managed browser intune managed browser set homepage in managed browser whitelist URL
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    Export Microsoft Entra ID User Authentication Methods to CSV using PowerShell & Microsoft Graph API

    August 13, 2:08 pm

    SCCM SQL Report – Compare Installed Apps on TWO Different Computers

    July 13, 10:35 am

    Automating Intune Deployment Rings Using Entra ID Dynamic Groups and Regex

    July 01, 10:31 pm

    4 Comments

    1. Ian on November 23, 2018 4:19 PM

      Hi Eswar,
      Great article!
      I wonder if you know if this method can also be used to always clear cached user data on sign out of O365 apps on Android?
      I have a Samsung tablets which are shared by a few people. Once you have logged on once it retains your details and therefore can select your username from the login drop-down. If you select the wrong name it will auto sign you in to the other persons account. If I could even set it to force re-entry of the password every time, That would be a super successful result.

      Kind Regards

      Ian M

      Reply
      • Eswar Koneti on November 24, 2018 11:22 PM

        Hi Ian,
        Intune do not support shared mobile devices . It must be managed by single user account for now .If the mobile device is MAM-we or enrolled,it cannot be operated by different account.
        But upon wipeout or reset of mobile device,all the user data will be gone.

        Thanks,
        Eswar

        Reply
    2. Michael on November 14, 2018 5:36 AM

      Im having Android devices work place joined... Do I need anything else?
      I have created the same configuration as stated in this guide - but no bookmarks are showed in the Managed browser??

      Reply
      • Eswar Koneti on November 14, 2018 9:24 PM

        Hi,
        Please do check if you have selected managed browser in the app protection policy and that is being applied to users/groups correctly.

        Reply

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.