1. Home
  2. iOS and Android

Mobile Device Setup

This article will help you complete the setup on your personal or company-provided mobile device.

Note: You cannot have both GCC High and commercial email accounts in the Outlook app at once. 
 

Atomus only manages official Microsoft 365 applications for compliance on personal devices. As a result, please keep company data within these managed apps.

Android

  1. Open Google Play Store on your Android phone.
  2. Install and open the Intune Company Portal app.
  3. Sign in using the Atomus provided M365 username.
  4. The app will guide you through the Work Profile setup process.
  5. Once completed, you will then be able to download any pre-approved apps directly from the Google Play Store app (with the briefcase icon) in the Work Profile of your device.
    1. Note: if any additional apps are needed, please contact your company administrator.
    2. Admins: please refer to this Atomus Help Guide for instructions on how to add apps as available for download in the Intune Company Portal app (for iOS and Android devices)

 

 

iOS Devices

iOS Note for users on company provided Apple devices: Please make sure that you have been provided an organizational Apple ID and Apple ID Password by Atomus before you proceed with this.

  1. If you are coming from an existing Microsoft environment, you will need to remove the existing accounts from the Microsoft Authenticator app and add it again to the new environment. Please follow these steps:
    1. On the computer: Go to one of the following links, depending on whether your environment is GCC or GCC High (your company Point of Contact should know which you are, or feel free to reach out to success@atomuscyber.com to ask):
      1. GCC
      2. GCC High
    2. On the computer: Authenticate on the web browser as requested using the email that your organization has just migrated (hint: up until the migration, it was likely a .onmicrosoft email, and after the migration, is likely your old email with new credentials that you've updated). Once you can see the following screen, you can continue on to step C:
    3. On the computer: If it is there (as seen in the image above), delete the authenticator app.
    4. In the iPhone Microsoft Authenticator App: tap on the email you've signed into on the computer (see step B for assistance on which email this may be, as you may see several work emails in the app). If in doubt, reach out to your company Point of Contact.
    5. In the iPhone Authenticator App: tap on the gear on the top right, then remove the account. Select All apps on this device, if it provides the option.
    6. On the computer: click Add sign-in method, then:
      1. Authenticator app
      2. Add
      3. Next
      4. Next
      5. You should see a QR code, stop at this screen and continue to step G
In the iPhone Authenticator App: tap the + on the top right of the screen, Work or school account, then tap 
    1. Scan QR code
    2. Scan the QR code on your computer and click Next, it will then ask you to authenticate on the app to test the connection. 

 

Please continue on the next steps depending on whether you are using your own personal iPhone or a company provided iPhone

If using a personal iOS device:

  • You can download any needed Microsoft apps and sign into them as expected.
    • If you're setting up a new phone or recently switched to GCC/GCC High, you may have to re-setup your Microsoft Authenticator App by signing into one of the below sites:
  • Once signed in, manage existing authentication methods or add a new one in your Microsoft Authenticator App

If on a company provided iOS device:

Due to configuration restrictions with Microsoft and Apple, these steps will require that you sign in with a personal AppleID in order to download the required/allowed apps.

  1. Sign into a Personal Apple ID on the work device
  2. Download the Intune Company Portal app from the iOS App Store
  3. Sign out of your personal Apple ID on the work device

  4. Sign back in using your work Apple ID

  5. Sign into the Intune Company Portal app using the Atomus provided M365 username. You will be guided through the setup, as shown in the reference video below.
  6. Once you have installed the profile in Settings, you will then be able to download any pre-approved apps directly from the Intune Company Portal app.
    1. Note: if any additional apps are needed, please contact your company administrator.
    2. Company admins: please refer to this Atomus Help Guide for instructions on how to add apps as available for download in the Intune Company Portal app (for iOS and Android devices)

 

What if I want other email addresses on my device in addition to my new Microsoft email address?

We recommend that you use your Apple "Mail" application for all personal and non-Atomus email addresses you would like to access on your mobile device.

This is my personal mobile device, I don't want Atomus to have access to my personal information.

Our access is limited to the Microsoft Office365 Applications logged in with your work credentials to maintain security and compliance configurations. We do not have access or control to your mobile device.

Is there anything I can't have on my mobile device to stay compliant?

There is a requirement from NIST 800-171 that does not allow downloads of any Bytedance applications including TikTok. Any device used for work in any capacity is restricted from this.