Deploy or validate your App Protection policies
As more organizations implement mobile device strategies for accessing work or school data, protecting against data leakage becomes paramount. App Protection policies are Intune's solution for protecting against data leakage. These policies, which are sometimes referred to as Mobile Application Management (MAM), are rules that ensure an organization's data remains safe or contained within a managed app. They allow you to control how apps on mobile devices access and share data. A policy can be a rule that's enforced when the user attempts to access or move corporate data, or a set of actions that are prohibited or monitored when the user is inside the app.
App Protection policies protect corporate data even if a device itself isn't managed. This feature allows you to enable bring-your-own-devices (BYOD) at work, where users may be reluctant to “enroll” their personal devices into management. App protection policies ensure corporate data in the apps you specify can't be copied and pasted to other apps on the device.
A managed app in Intune is a protected app that has Intune App Protection policies applied to it and is managed by Intune.
With App Protection policies, Intune creates a wall between your organization data and personal data.
- They ensure that users can't copy organization data from specified apps and paste it into other apps on the device, even if the device isn't managed.
- They define which apps are allowed to access your data.
- They can prevent the inadvertent or intentional copying of Copilot-generated content to apps on a device that aren't included in the list of permitted apps.
- They can also limit the blast radius of an attacker using a compromised device.
This configuration greatly increases your security posture with almost no impact to the user experience. Employees can use apps that they know and love, like Office and Microsoft Teams, while their organization can simultaneously protect the data contained within the apps and devices.
If you have custom Line of Business applications that need protection, you can currently use the app wrapping tool to enable App Protection policies with these applications. Or, you can also use the Intune App SDK. When your app has App Protection policies applied to it, Intune can manage the app. An app that Intune manages is referred to as a managed app. App Protection policies can also apply to apps running on devices that aren't managed by Intune. For a more detailed description of how App Protection policies work and the scenarios that Intune App Protection policies support, see App Protection policies overview.
Additional reading. For information about adding your organization's line-of-business (LOB) apps to Microsoft Intune to prepare for App Protection policies, see Add apps to Microsoft Intune. For a list of supported partner and Microsoft apps and are commonly used with Microsoft Intune, and for a list of apps that are integrated with the Intune SDK, see Microsoft Intune protected apps.
Data protection framework using App Protection policies
The choices available in App Protection policies enable organizations to tailor the protection to their specific needs. For some, it may not be obvious which policy settings are required to implement a complete scenario. To address this situation, Microsoft created a data protection framework for app protection policies. This framework is designed to safeguard organizational data by ensuring it remains secure within managed applications.
The data protection framework is organized into three distinct configuration levels. Each level builds on the previous one, providing increasing levels of security. This framework allows organizations to tailor their data protection strategies to their specific needs, ensuring that sensitive information remains secure while enabling productivity on mobile devices.
- Level 1 - Enterprise basic data protection. Microsoft recommends this configuration as the minimum data protection configuration for an enterprise device.
- Level 2 - Enterprise enhanced data protection. Microsoft recommends this configuration for devices where users access sensitive or confidential information. This configuration is applicable to most mobile users accessing work or school data. Some of the controls may impact the user experience.
- Level 3 - Enterprise high data protection. Microsoft recommends this configuration for devices run by an organization with a larger or more sophisticated security team, or for specific users or groups who are at uniquely high risk. For example, users who handle highly sensitive data where unauthorized disclosure causes considerable material loss to the organization. Any organization that's a likely target of well-funded and sophisticated adversaries should aspire to this configuration.
To see the specific recommendations for each configuration level and the minimum apps that must be protected, review Data protection framework using App Protection policies.
Core App Protection policy settings
A managed app in Intune is a protected app that Intune manages and has Intune App Protection policies applied to it. These apps support the core App Protection Policy settings, which are defined as:
- Protecting work or school account data while leaving personal data untouched in apps that support multiidentity.
- Restricting data transfer and copy-and-paste functions.
- Encrypting work or school account data.
- Configuring work or school account web links to open inside a managed browser, like Microsoft Edge.
- Enforcing access requirements to access work or school account data.
- Enforcing conditional launch behaviors to protect the work or school account data.
- Applying data loss prevention policies without managing the user's device.
- Enabling App Protection without requiring enrollment.
- Enabling App Protection on devices managed with non-Microsoft unified endpoint management solutions.
Benefits of using App Protection policies
There are several benefits of using Intune App Protection policies, including:
- Protecting your company data at the app level. Because mobile app management doesn't require device management, you can protect company data on both managed and unmanaged devices. The management is centered on the user identity, which removes the requirement for device management.
- End-user productivity isn't affected and policies don't apply when using the app in a personal context. The policies are applied only in a work context. This design enables you to protect company data without touching personal data.
- App protection policies ensure that the app-layer protections are in place. For example, you can:
- Require a PIN or fingerprint to open an app in a work context.
- Control the sharing of data between apps.
- Prevent the saving of company app data to a personal storage location.
- Intune Mobile Device Management (MDM) and Mobile Application Management (MAM) ensure that devices are protected. For example, you can require a PIN to access the device, or you can deploy managed apps to the device. You can also deploy apps to devices through your MDM solution. Doing so gives you greater control over app management.
There are other benefits to using MDM with App protection policies, and companies can use App protection policies with and without MDM at the same time. For example, consider an employee that uses both a phone issued by the company, and their own personal tablet. The company phone is enrolled in MDM and protected by App protection policies while the personal device is protected by App protection policies only.
If you apply a MAM policy to the user without setting the device state, the user gets the MAM policy on both their personal device and their company's Intune-managed device. You can also apply a MAM policy based on the managed state. So when you create an App Protection policy, next to Target to all app types, you would select No. Then do any of the following tasks:
- Apply a less strict MAM policy to Intune managed devices, and apply a more restrictive MAM policy to non MDM-enrolled devices.
- Apply a MAM policy to unenrolled devices only.
How App Protection policies protect app data
The following sections examine how App Protection policies protect both your corporate and personal data.
Apps without App Protection policies
When apps are used without restrictions, company and personal data can get intermingled. Company data can end up in locations like personal storage or transferred to apps beyond your purview and result in data loss. The arrows in the following diagram show unrestricted data movement between both corporate and personal apps, and to storage locations.
Data protection with App Protection policies
You can use App protection policies to prevent company data from saving to the local storage of the device (see the following image). You can also restrict data movement to other apps that aren't protected by App Protection policies. App Protection policy settings include:
- Data relocation policies like Save copies of org data, and Restrict cut, copy, and paste.
- Access policy settings like Require simple PIN for access, and Block managed apps from running on jailbroken or rooted devices.
Data protection with App Protection policies on devices managed by an MDM solution
The following illustration shows the layers of protection that MDM and App Protection policies offer together.
The MDM solution adds value by providing the following features:
- Enrolls the device
- Deploys the apps to the device
- Provides ongoing device compliance and management
The App Protection policies add value by providing the following security features:
- Help protect company data from leaking to consumer apps and services.
- Apply restrictions like save-as, clipboard, or PIN, to client apps.
- Wipe company data when needed from apps without removing those apps from the device.
Data protection with App Protection policies for devices without enrollment
The following diagram illustrates how the data protection policies work at the app level without MDM.
For personal devices that aren't enrolled in an MDM solution, App Protection policies can help protect company data at the app level. However, there are some limitations to be aware of, such as:
- You can't deploy apps to the device. The end user has to get the apps from the store.
- You can't provision certificate profiles on these devices.
- You can't provision company Wi-Fi and VPN settings on these devices.
Add Conditional Access protection to App protection
After an organization creates an App Protection policy in Intune, it should work with its identity team to configure Conditional Access policies in Microsoft Entra ID that enforce mobile app protection. So how do App Protection policies and Conditional Access policies work together in a Microsoft 365 Copilot deployment?
- App Protection policy. Ensures that an organization's data remains safe or contained within a managed app. These policies control how data is accessed and shared by apps on mobile devices. Essentially, App Protection policies help you manage and protect your organization's data by enforcing rules on how data can be used within specific applications.
- Conditional Access policy. Enforces data protection by controlling access to your organization's resources based on specific conditions. Conditional Access policies help ensure that only authorized users, using trusted devices and appropriate applications, can access sensitive resources within your Microsoft 365 environment. By implementing Conditional Access policies, you can strengthen your security posture, reduce the risk of unauthorized access, and meet regulatory compliance standards
In summary, App Protection policies focus on managing and protecting data within specific applications. At the same time, Conditional Access policies provide an extra layer of security by controlling access to your organization's resources based on predefined conditions. This combination ensures comprehensive data protection and aligns with the principles of Zero Trust security.