074: Entra Shared Device Mode
Overview
-
Overview:
- Shared device mode is a feature of Microsoft Entra ID that enables you to build and deploy applications for scenarios involving frontline workers and educational settings where Android and iOS devices are shared among users¹.
- It addresses the challenge of supporting multiple users on devices originally designed for single users.
-
Benefits:
- Frontline Worker Support: Shared device mode allows you to create applications tailored for frontline workers, such as those in retail, healthcare, or field services.
- Single Sign-On (SSO): Employees can sign in once across all supported applications on a shared device.
- Global Sign-Out: At the end of their shift, employees can sign out globally, removing personal and company information from the device.
- Automatic Sign-Out: If an employee forgets to sign out, the device can automatically sign them out after a period of inactivity.
-
Drawbacks:
- Limited Personalization: Shared devices prioritize functionality over personalization, so individual user preferences may not be fully accommodated.
- Security Considerations: While shared device mode enhances convenience, it requires careful management to prevent unauthorized access to sensitive data.
-
Impact on End Users:
- Positive Impact: Simplified sign-in and sign-out experiences improve efficiency for frontline workers.
- Potential Challenges: Users may need to adapt to a shared device model, especially if they were accustomed to personalized settings on their own devices.
In summary, shared device mode streamlines access for frontline workers while maintaining security and control. It's a valuable feature for organizations managing shared Android and iOS devices in various contexts.
Reference
- Shared device mode overview - Microsoft identity platform. https://learn.microsoft.com/en-us/entra/identity-platform/msal-shared-devices
- Set up automated device enrollment for shared device mode. https://learn.microsoft.com/en-us/mem/intune/enrollment/automated-device-enrollment-shared-device-mode