Skip to Content

App Protection Policies: Data Security on Mobile

App Protection Policies (MAM)

App Protection Policies (also called Mobile Application Management, or MAM) are rules that protect company data within specific apps — without managing the entire device. This is especially important on mobile devices where you might use the same phone for both work and personal activities.

How App Protection Policies Work

Instead of managing your whole device, app protection policies create a protective "wrapper" around work apps. Here's what they can do:

  • Require a PIN to open work apps — You might need to enter a separate PIN (or use Face ID/fingerprint) when opening Outlook, even if your device is already unlocked
  • Prevent data sharing — Block "Copy/Paste" from work apps to personal apps
  • Block "Save As" to personal locations — Can't save a work document to personal Dropbox or personal OneDrive
  • Restrict "Open In" — Can't open a work email attachment in a personal app
  • Require approved apps — Only Outlook can access work email, not the native Mail app
  • Encrypt app data — Data stored by work apps is encrypted at rest
  • Block screen capture — (Android only) Prevents screenshots within work apps

What You'll Notice

App PIN

When you open Outlook (or another work app) for the first time after a period of inactivity, you might be asked for a PIN or biometric authentication. This is separate from your device unlock PIN. IT sets how often you need to re-authenticate (typically every 15-30 minutes).

"Open In" Restrictions

If you try to open a work document in a non-approved app, you'll see a message like "This action is not allowed" or "Your organization doesn't allow opening files in this app." You can only open work files in approved apps like:

  • Microsoft Outlook (email attachments)
  • Microsoft OneDrive (cloud files)
  • Microsoft Teams (shared files)
  • Microsoft Office apps (Word, Excel, PowerPoint)
  • Microsoft Edge (for work browsing)

Copy/Paste Restrictions

If IT has configured copy/paste restrictions:

  • Work → Personal: You copy text from a work email and try to paste it into a personal messaging app — it won't paste (or pastes blank)
  • Personal → Work: You can usually paste personal content into work apps (less restricted)

Why App Protection Policies Matter

Consider this scenario: You're at a conference and someone asks to borrow your phone to make a call. Without app protection policies, they could open your Outlook and read company emails. With app protection policies, they'd need to enter your work app PIN — which they don't have.

Or this: You forward a confidential email to your personal Gmail "to save it." App protection policies prevent this, keeping company data within the managed app ecosystem.

App Protection Without Enrollment (MAM-WE)

In some cases, IT might apply app protection policies without enrolling your device at all. This is called "MAM Without Enrollment" (MAM-WE) and is common for BYOD scenarios where employees don't want their personal device managed.

In this case:

  • Your device is NOT enrolled in Intune
  • IT can NOT wipe your device or see device details
  • IT CAN require a PIN, restrict data sharing, and selectively wipe company data from work apps
  • You sign into Outlook with your work account, and the policies apply automatically

How to Tell if App Protection Is Active

Signs that app protection policies are in effect:

  • Work apps show "Your organization manages this app" banner
  • You're asked for a PIN or Face ID when opening Outlook
  • You can't copy text from Outlook into a personal app
  • Work app icons have a briefcase badge (Android work profile)
  • Screen capture is blocked within work apps (Android)

What to Do If an App Asks for a PIN

If Outlook (or another work app) asks you to set up a PIN:

  1. Tap "Set up PIN"
  2. Enter a numeric PIN (typically 4-6 digits, as required by IT)
  3. Confirm the PIN
  4. The PIN will be required when opening the app after inactivity

On iOS, this PIN may be shared across all managed work apps — so you only enter it once, and it applies to Outlook, Teams, OneDrive, etc.

Beawit Consulting configures Intune app protection policies to secure company data on mobile devices. Contact us for MAM policy design and deployment.

Next, we'll cover software updates and how Intune handles patching.

Learn how app protection policies keep company data secure within individual apps.
Rating
0 0

There are no comments for now.

to be the first to leave a comment.