So far, we’ve covered device compliance and Conditional Access. Today, we move into a powerful concept that enables security beyond device management:
Microsoft Intune App Protection Policies (MAM)
This is your go-to solution when:
- You can’t manage the device
- But still need to protect corporate data
What is App Protection Policy (MAM)?
App Protection Policies (MAM – Mobile Application Management) allow you to:
Secure corporate data inside apps
Control how data is accessed, shared, and stored
Protect data even on personal (BYOD) devices
Core Idea:
MAM protects the app and data, not the entire device.
MDM vs MAM (Quick Comparison)
Feature | MDM (Device Management) | MAM (App Protection) |
Scope | Entire device | Specific apps |
Device enrollment | Required | Not required |
Best for | Corporate-owned devices | BYOD & unmanaged devices |
Control | Full device | App-level only |
Why App Protection Matters
In today’s hybrid world:
- Employees use personal phones
- Contractors use unmanaged devices
- Organizations need secure access without intrusion
MAM solves this perfectly.
Real-World Scenario
An employee uses their personal Android/iPhone.
You want:
- Outlook access
- Prevent copy-paste to personal apps
- Wipe company data when they leave
Use App Protection Policies
Supported Apps
MAM works best with:
Microsoft Apps:
- Outlook
- Teams
- OneDrive
- Word, Excel, PowerPoint
Third-Party Apps:
Apps integrated with:
- Intune App SDK
- App Wrapping Tool
Key Capabilities of App Protection Policies
1. Data Protection
Control how data moves.
- Block copy/paste to personal apps
- Restrict “Save As”
- Encrypt app data
- Prevent data backup
Example:
Allow copy-paste only between managed apps
2. Access Requirements
Ensure only authorized users access apps.
- Require PIN
- Require biometric (Face ID / fingerprint)
- Re-authentication after timeout
Example:
App locks after 5 minutes of inactivity
3. Conditional Launch
Define conditions before app opens.
- Minimum OS version
- Device jailbroken/rooted check
- Require app version
Example:
Block jailbroken devices
4. Data Transfer Controls
Control sharing behavior:
- Restrict “Open In”
- Limit sharing to managed apps
- Disable screen capture
Example:
Block saving attachments to personal storage
5. Selective Wipe
One of the most powerful features:
Remove only corporate data, not personal data
Use cases:
- Employee leaves company
- Device lost
- Compliance failure
Creating an App Protection Policy
Step 1: Navigate
Intune Admin Center → Apps → App protection policies
Step 2: Choose Platform
- Android
- iOS/iPadOS
Step 3: Configure Policy
Example Configuration:
Data Protection:
- Block copy to unmanaged apps
- Encrypt app data
Access Requirements:
- Require PIN
- Timeout = 5 minutes
Conditional Launch:
- Block rooted devices
Step 4: Target Apps
Select:
- Microsoft apps (recommended baseline)
Step 5: Assign Users
Assign to:
- User groups (best practice)
MAM + Conditional Access
Powerful combo:
Policy Example:
- Allow access only if:
- App is protected by MAM
- User signs in
Flow:
- User opens Outlook
- Conditional Access checks
- MAM policy applied
- Secure session established
App Protection Without Enrollment (MAM-WE)
This is a game changer:
MAM works even if device is NOT enrolled in Intune
Perfect for:
- BYOD users
- External vendors
- Contractors
Advanced Scenarios
1. Work Profile (Android)
Separate:
- Personal apps
- Work apps
MAM enhances security inside work apps.
2. Integration with Microsoft Defender
- Detect risky apps
- Block compromised environments
3. App Protection Insights
Track:
- Policy usage
- Data transfer attempts
- Security violations
4. Multiple Policy Layers
Apply:
- Baseline policy (all users)
- Strict policy (VIP / sensitive roles)
Common Mistakes to Avoid
1. Not Using Conditional Access
Without CA, control is limited
2. Over-Restricting Users
Blocking too much can break productivity
Balance security + usability
3. Ignoring User Experience
Frequent PIN prompts = poor adoption
4. No Testing Phase
Always pilot before production rollout
Enterprise Strategy
Layered Approach
Level 1 (Baseline)
- Basic data protection
- Managed apps only
Level 2 (Standard Users)
- PIN enforcement
- Data transfer restrictions
Level 3 (High Security)
- No copy/paste
- No external sharing
- Strict Conditional Access
Example Use Case
Sales Team:
- Access Outlook, Teams
- Allow limited sharing
Finance Team:
- Block all external sharing
- Strict data controls
Best Practices
Use MAM for all BYOD scenarios
Combine with Conditional Access
Start with Microsoft recommended baseline
Monitor user feedback
Keep policies simple and scalable
What You Learned Today
What App Protection Policies are
MAM vs MDM differences
How to secure apps without device enrollment
Data protection and access controls
Real-world enterprise implementation
Final Thought:
"You don’t always need to control the device. But you must always protect the data."
.png)