Skip to content
← Back to the guide

Intune app protection policies

8slides. Screenshot a slide, download it as a PNG, or use your browser's Print → Save as PDF for a LinkedIn-ready multi-page carousel — each slide becomes one page.

M
solvingmicrosoft365.com
1 / 8

Intune app protection policies

How MAM-WE protects corporate data inside specific apps on personal devices — without managing the device itself.

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 1Download PNG
M
solvingmicrosoft365.com
2 / 8
01

What does an app protection policy do on a personal phone?

It manages the Microsoft 365 apps (Outlook, Teams, OneDrive, Office) rather than the phone: requires a PIN or biometric for the apps, encrypts their data, blocks copying work content into personal apps, prevents saving…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 2Download PNG
M
solvingmicrosoft365.com
3 / 8
02

Do I need to enrol devices to use app protection policies?

No. App protection policies work on unenrolled devices, which is their main use — BYOD with no device management. They also apply to enrolled devices for extra app-level control. Conditional Access can require an app pr…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 3Download PNG
M
solvingmicrosoft365.com
4 / 8
03

Which apps support Intune app protection?

Microsoft 365 apps and a catalogue of third-party apps built with the Intune App SDK or wrapped with the App Wrapping Tool — Adobe Acrobat, Zoom, Salesforce, and others. Microsoft publishes the list; apps not on it cann…

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 4Download PNG
M
solvingmicrosoft365.com
5 / 8
04

BYOD, users won't tolerate enrolment

Posture: MAM only

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 5Download PNG
M
solvingmicrosoft365.com
6 / 8
05

Corporate device, wants full-device management

Posture: MDM + MAM (MAM policies still apply to the M365 apps on the enrolled device)

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 6Download PNG
M
solvingmicrosoft365.com
7 / 8
06

Frontline shared device

Posture: MDM in shared-device mode — MAM's per-user model doesn't fit

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 7Download PNG
M
solvingmicrosoft365.com
8 / 8
07

High-security role on corporate device

Posture: MDM + MAM + Defender for Endpoint mobile

Solving Microsoft 365 · www.solvingmicrosoft365.com/guides/intune-app-protection-policies

Slide 8Download PNG

Auto-generated from Intune app protection policies. This page is not indexed and isn't part of the guide itself.