How does the Managed Browser Service protect against social engineering attacks?
Social engineering attacks work when the user is conned into doing something illadvised. The Managed Browser Service protects against such attacks primarily by means of the device ID feature. The device ID is unknown to the user so cannot be consciously disclosed. Even if the user does disclose their user name and password these will be useless to the confidence trickster without the device ID.