Exercise - Protect data and control access with policies
In this exercise, you configure app protection policies to secure organizational data on mobile devices and create Conditional Access policies that require device compliance for resource access. This hands-on practice demonstrates how Contoso protects corporate data and enforces zero-trust access control.
Exercise overview
In this exercise, you complete the following tasks:
- Create an app protection policy for mobile devices
- Assign app protection policies to user groups
- Create a Conditional Access policy requiring device compliance
- Test Conditional Access policy in report-only mode
- Monitor app protection and Conditional Access effectiveness
Estimated time to complete: 13 minutes
Prerequisites
Before starting this exercise, ensure you have:
- Device compliance policies configured in Intune
- Administrative access to Microsoft Intune admin center
- Administrative access to Microsoft Entra admin center
- At least one enrolled and compliant Windows device
- Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)
Before starting this exercise, ensure you have:
- Device compliance policies configured in Intune (optional for app protection)
- Administrative access to Microsoft Intune admin center
- Administrative access to Microsoft Entra admin center
- An iOS or iPadOS device (can be personal/BYOD - enrollment not required for app protection)
- Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)
Before starting this exercise, ensure you have:
- Device compliance policies configured in Intune (optional for app protection)
- Administrative access to Microsoft Intune admin center
- Administrative access to Microsoft Entra admin center
- An Android device (can be personal/BYOD - enrollment not required for app protection)
- Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)
Task 1: Create an app protection policy
Configure app-level data protection for mobile devices. This protects corporate data in apps without requiring device enrollment.
Sign in to the Microsoft Intune admin center (https://intune.microsoft.com)
Navigate to Apps > App protection policies
Select + Create policy > iOS/iPadOS
Basics tab:
- Name:
iOS App Protection - Corporate Data - Description:
Protects organizational data in Microsoft apps on iOS devices, managed and unmanaged - Select Next
- Name:
Apps tab - Select target apps:
- Select Select public apps
- Search for and add these apps:
- Microsoft Outlook
- Microsoft Teams
- Microsoft OneDrive
- Microsoft Word
- Microsoft Excel
- Microsoft PowerPoint
- Microsoft Edge
- Select Next
Data protection tab - Configure data controls:
- Data Transfer:
- Send org data to other apps: Policy managed apps
- Receive data from other apps: All apps
- Save copies of org data: Block
- Allow user to save copies to selected services: OneDrive for Business, SharePoint
- Restrict cut, copy, and paste between other apps: Policy managed apps with paste in
- Cut and copy character limit for any app: 0 (no limit)
- Encryption:
- Encrypt org data: Require
- Functionality:
- Sync app with native contacts app: Block
- Printing org data: Block
- Restrict web content transfer with other apps: Microsoft Edge
- Org data notifications: Block org data
- Select Next
- Data Transfer:
Access requirements tab - Configure authentication:
- PIN for access: Require
- PIN type: Numeric
- Simple PIN: Block
- PIN minimum length: 6
- PIN reset after number of days: 90
- Touch ID instead of PIN for access (iOS 8+): Allow
- Face ID instead of PIN for access (iOS 11+): Allow
- Override biometrics with PIN after timeout: Require
- Timeout (minutes of inactivity): 30
- Corporate credentials for access: Require
- Recheck the access requirements after (minutes of inactivity): 30
- Select Next
Conditional launch tab - Configure device conditions:
- Add these settings:
- Min OS version < 15.0: Block access
- Jailbroken/rooted devices: Block access
- Max allowed device threat level ≥ Medium: Block access
- Offline grace period > 90 days: Wipe data
- Disabled account: Block access
- Select Next
- Add these settings:
Assignments tab:
- Include: All Users (or select specific groups for Contoso)
- Exclude: (Leave empty for this exercise)
- Select Next
Review + create tab:
- Review all settings
- Select Create
Result: You now have an app protection policy that protects corporate data on iOS devices without requiring device enrollment.
Sign in to the Microsoft Intune admin center (https://intune.microsoft.com)
Navigate to Apps > App protection policies
Select + Create policy > Android
Basics tab:
- Name:
Android App Protection - Corporate Data - Description:
Protects organizational data in Microsoft apps on Android devices, managed and unmanaged - Select Next
- Name:
Apps tab:
- Select Select public apps
- Search for and add these apps:
- Microsoft Outlook
- Microsoft Teams
- Microsoft OneDrive
- Microsoft Word
- Microsoft Excel
- Microsoft PowerPoint
- Microsoft Edge
- Select Next
Data protection tab - Configure data controls:
- Data Transfer:
- Send org data to other apps: Policy managed apps
- Receive data from other apps: All apps
- Save copies of org data: Block
- Allow user to save copies to selected services: OneDrive for Business, SharePoint
- Restrict cut, copy, and paste: Policy managed apps with paste in
- Encryption:
- Encrypt org data: Require
- Functionality:
- Sync app with native contacts app: Block
- Printing org data: Block
- Restrict web content transfer: Microsoft Edge
- Org data notifications: Block org data
- Android-specific:
- Screen capture and Google Assistant: Block
- Select Next
- Data Transfer:
Access requirements tab:
- PIN for access: Require
- PIN type: Numeric
- Simple PIN: Block
- PIN minimum length: 6
- Biometric instead of PIN for access (Android 6.0+): Allow
- Override biometrics with PIN after timeout: Require
- Timeout: 30 minutes
- Corporate credentials for access: Require
- Recheck access requirements after: 30 minutes of inactivity
- Select Next
Conditional launch tab:
- Configure device conditions:
- Min OS version < 10.0: Block access
- Jailbroken/rooted devices: Block access
- Max allowed device threat level ≥ Medium: Block access
- Offline grace period > 90 days: Wipe data
- Disabled account: Block access
- Android-specific:
- SafetyNet device attestation: Basic integrity and certified devices (Block access)
- Select Next
- Configure device conditions:
Assignments tab:
- Include: All Users
- Select Next
Review + create:
- Review settings and select Create
Result: You now have an app protection policy that protects corporate data on Android devices without requiring device enrollment.
App protection policies are primarily designed for mobile platforms (iOS and Android). For Windows devices, use:
- Windows Information Protection (WIP) policies for app-level data protection
- Configuration profiles for device-level security settings
- Compliance policies combined with Conditional Access for access control
For this exercise on Windows, skip to Task 3 to configure Conditional Access policies that enforce device compliance.
Task 2: Verify app protection policy assignments
Confirm policies are targeting the correct users and applications.
In App protection policies, select your app protection policy (iOS or Android)
Select Properties > Assignments
Verify:
- All Users or your selected groups are included
- No unintended exclusions
- Protected app count: 7 apps
Navigate to Monitor > App protection status
Review the dashboard:
- Total protected users: Should show count of licensed users
- Platform breakdown: Shows users by platform
- Flagged users: Should be 0 initially (no jailbroken/rooted devices detected yet)
For Windows devices, you can skip this task and proceed to Task 3 to configure Conditional Access policies.
Task 3: Create a Conditional Access policy requiring device compliance
Configure zero-trust access control that blocks noncompliant devices from accessing corporate resources. This applies to all platforms.
Sign in to the Microsoft Entra admin center (https://entra.microsoft.com).
Navigate to Protection > Conditional Access > Policies.
Select + New policy.
Name:
Require compliant device for Exchange and SharePointAssignments section:
Users:
- Select 0 users and groups selected
- Include tab: Select All users
- Exclude tab: Select Users and groups > Select your break glass / emergency access account
- Select Select
Target resources:
- Select No target resources selected
- Select what this policy applies to: Cloud apps
- Include tab: Select apps
- Search for and select:
- Office 365 Exchange Online
- Office 365 SharePoint Online
- Select Select
Conditions:
Device platforms:
- Configure: Yes
- Include tab: Select device platforms > Check:
- Android
- iOS
- Windows
- macOS
- Select Done
Locations:
- Configure: Yes
- Include tab: Any location
- Exclude tab: (Leave empty for this exercise)
- Select Done
Access controls section:
Grant:
- Select 0 controls selected
- Select Grant access
- Check: Require device to be marked as compliant
- For multiple controls: Require one of the selected controls (or Require all if combining with MFA)
- Select Select
Enable policy:
- Report-only (test first - recommended for production)
- Or On (enforce immediately - for this exercise)
Select Create.
Result: Users must have compliant devices to access Exchange Online and SharePoint Online. Noncompliant devices are automatically blocked.
Task 4: Test Conditional Access policy with What If tool
Simulate policy impact before full enforcement using the What If tool.
In Conditional Access > Policies, select What If.
Configure the simulation:
User or workload identity:
- Select a test user:
user@contoso.com
Cloud apps, actions, or authentication context:
- Select: Office 365 Exchange Online
Device platform:
- Select: Windows
Device state (Preview):
- Select: Device marked compliant (simulate compliant device)
- Select a test user:
Select What If.
Review results:
- Policies that will apply: Should show "Require compliant device for Exchange and SharePoint"
- Evaluation result: Access granted (because device is compliant)
Test noncompliant scenario:
- Change Device state: Not marked compliant
- Select What If again
- Evaluation result: Access blocked (policy denies noncompliant device)
Result: The What If tool confirms the policy correctly grants access to compliant devices and blocks noncompliant devices.
Task 5: Monitor Conditional Access and app protection effectiveness
Review policy enforcement and identify any access issues.
Monitor Conditional Access sign-ins:
- In Microsoft Entra admin center, navigate to Monitoring > Sign-in logs
- Filter by:
- Conditional Access: Success or Failure
- Application: Office 365 Exchange Online or SharePoint
- Review recent sign-in attempts:
- User who attempted access
- Device platform and compliance status
- Conditional Access result (Success, Block, Require compliance)
- Failure reason (if blocked)
Monitor device compliance (impacts Conditional Access):
- Navigate to Devices > Monitor > Noncompliant devices
- Review:
- Count of noncompliant devices blocked by Conditional Access
- Compliance policy settings causing failures
- Devices requiring remediation
Review app protection policy status:
- In Intune admin center, navigate to Apps > Monitor > App protection status
- Review:
- Protected users: Total users with protected apps
- Platform distribution: Shows adoption by platform
- Flagged users: Jailbroken/rooted devices or policy violations
Check user-specific app protection status:
- In Intune admin center, navigate to Apps > Monitor > User status
- Select a test user
- Review:
- List of protected apps installed on user's devices
- Last check-in date for each app
- Device platform for each app instance
Verification checklist:
- App protection policies show in App protection status dashboard
- Protected apps appear in user status monitoring
- Conditional Access policy appears in Sign-in logs evaluations
- Compliant devices successfully access Exchange and SharePoint
- Noncompliant devices are blocked (if tested)
- No unexpected user lockouts or access issues
- Conditional Access policy appears in Sign-in logs evaluations
- Compliant devices successfully access Exchange and SharePoint
- Noncompliant devices are blocked (if tested)
- No unexpected user lockouts or access issues
Exercise summary
Congratulations! You've successfully configured data protection and access control for Contoso's environment.
What you accomplished:
- Created app protection policy securing Microsoft apps on mobile devices (iOS/iPadOS and Android)
- Deployed app protection policy to users
- Created Conditional Access policy requiring device compliance for Exchange and SharePoint
- Tested policy impact using What If simulation tool
- Monitored app protection and Conditional Access effectiveness
Contoso's data protection posture
| Security Layer | Capability | Impact |
|---|---|---|
| App-level protection | Corporate data in Microsoft apps encrypted and protected from leakage to personal apps (mobile platforms) | Data secured on 500+ BYOD devices |
| BYOD support | Personal mobile devices access work apps without full device enrollment through app protection policies | Zero user resistance to security policies |
| Zero-trust access | Only compliant, managed devices can access sensitive email and documents across all platforms | 100% compliance enforcement for Exchange/SharePoint |
| Continuous compliance | Devices must maintain compliance to keep access; noncompliant devices automatically blocked | 23 noncompliant devices blocked in first week |
| Risk-based access | Conditional Access evaluates device, location, and identity signals before granting access | Real-time access decisions based on context |
| Platform flexibility | Windows devices use MDM-based compliance enforcement, mobile devices benefit from both app protection and compliance policies | Consistent security across heterogeneous environment |
Check what you've learned in the next unit covering app protection policies and Conditional Access scenarios.


