Exercise - Protect data and control access with policies

Completed

In this exercise, you configure app protection policies to secure organizational data on mobile devices and create Conditional Access policies that require device compliance for resource access. This hands-on practice demonstrates how Contoso protects corporate data and enforces zero-trust access control.

Exercise overview

In this exercise, you complete the following tasks:

  1. Create an app protection policy for mobile devices
  2. Assign app protection policies to user groups
  3. Create a Conditional Access policy requiring device compliance
  4. Test Conditional Access policy in report-only mode
  5. Monitor app protection and Conditional Access effectiveness

Estimated time to complete: 13 minutes

Prerequisites

Before starting this exercise, ensure you have:

  • Device compliance policies configured in Intune
  • Administrative access to Microsoft Intune admin center
  • Administrative access to Microsoft Entra admin center
  • At least one enrolled and compliant Windows device
  • Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)

Before starting this exercise, ensure you have:

  • Device compliance policies configured in Intune (optional for app protection)
  • Administrative access to Microsoft Intune admin center
  • Administrative access to Microsoft Entra admin center
  • An iOS or iPadOS device (can be personal/BYOD - enrollment not required for app protection)
  • Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)

Before starting this exercise, ensure you have:

  • Device compliance policies configured in Intune (optional for app protection)
  • Administrative access to Microsoft Intune admin center
  • Administrative access to Microsoft Entra admin center
  • An Android device (can be personal/BYOD - enrollment not required for app protection)
  • Test user account with appropriate licenses (Microsoft 365 E5 or equivalent)

Task 1: Create an app protection policy

Configure app-level data protection for mobile devices. This protects corporate data in apps without requiring device enrollment.

  1. Sign in to the Microsoft Intune admin center (https://intune.microsoft.com)

  2. Navigate to Apps > App protection policies

  3. Select + Create policy > iOS/iPadOS

  4. Basics tab:

    • Name: iOS App Protection - Corporate Data
    • Description: Protects organizational data in Microsoft apps on iOS devices, managed and unmanaged
    • Select Next
  5. Apps tab - Select target apps:

    • Select Select public apps
    • Search for and add these apps:
      • Microsoft Outlook
      • Microsoft Teams
      • Microsoft OneDrive
      • Microsoft Word
      • Microsoft Excel
      • Microsoft PowerPoint
      • Microsoft Edge
    • Select Next
  6. Data protection tab - Configure data controls:

    • Data Transfer:
      • Send org data to other apps: Policy managed apps
      • Receive data from other apps: All apps
      • Save copies of org data: Block
      • Allow user to save copies to selected services: OneDrive for Business, SharePoint
      • Restrict cut, copy, and paste between other apps: Policy managed apps with paste in
      • Cut and copy character limit for any app: 0 (no limit)
    • Encryption:
      • Encrypt org data: Require
    • Functionality:
      • Sync app with native contacts app: Block
      • Printing org data: Block
      • Restrict web content transfer with other apps: Microsoft Edge
      • Org data notifications: Block org data
    • Select Next
  7. Access requirements tab - Configure authentication:

    • PIN for access: Require
    • PIN type: Numeric
    • Simple PIN: Block
    • PIN minimum length: 6
    • PIN reset after number of days: 90
    • Touch ID instead of PIN for access (iOS 8+): Allow
    • Face ID instead of PIN for access (iOS 11+): Allow
    • Override biometrics with PIN after timeout: Require
    • Timeout (minutes of inactivity): 30
    • Corporate credentials for access: Require
    • Recheck the access requirements after (minutes of inactivity): 30
    • Select Next
  8. Conditional launch tab - Configure device conditions:

    • Add these settings:
      • Min OS version < 15.0: Block access
      • Jailbroken/rooted devices: Block access
      • Max allowed device threat level ≥ Medium: Block access
      • Offline grace period > 90 days: Wipe data
      • Disabled account: Block access
    • Select Next
  9. Assignments tab:

    • Include: All Users (or select specific groups for Contoso)
    • Exclude: (Leave empty for this exercise)
    • Select Next
  10. Review + create tab:

    • Review all settings
    • Select Create

Result: You now have an app protection policy that protects corporate data on iOS devices without requiring device enrollment.

  1. Sign in to the Microsoft Intune admin center (https://intune.microsoft.com)

  2. Navigate to Apps > App protection policies

  3. Select + Create policy > Android

  4. Basics tab:

    • Name: Android App Protection - Corporate Data
    • Description: Protects organizational data in Microsoft apps on Android devices, managed and unmanaged
    • Select Next
  5. Apps tab:

    • Select Select public apps
    • Search for and add these apps:
      • Microsoft Outlook
      • Microsoft Teams
      • Microsoft OneDrive
      • Microsoft Word
      • Microsoft Excel
      • Microsoft PowerPoint
      • Microsoft Edge
    • Select Next
  6. Data protection tab - Configure data controls:

    • Data Transfer:
      • Send org data to other apps: Policy managed apps
      • Receive data from other apps: All apps
      • Save copies of org data: Block
      • Allow user to save copies to selected services: OneDrive for Business, SharePoint
      • Restrict cut, copy, and paste: Policy managed apps with paste in
    • Encryption:
      • Encrypt org data: Require
    • Functionality:
      • Sync app with native contacts app: Block
      • Printing org data: Block
      • Restrict web content transfer: Microsoft Edge
      • Org data notifications: Block org data
    • Android-specific:
      • Screen capture and Google Assistant: Block
    • Select Next
  7. Access requirements tab:

    • PIN for access: Require
    • PIN type: Numeric
    • Simple PIN: Block
    • PIN minimum length: 6
    • Biometric instead of PIN for access (Android 6.0+): Allow
    • Override biometrics with PIN after timeout: Require
    • Timeout: 30 minutes
    • Corporate credentials for access: Require
    • Recheck access requirements after: 30 minutes of inactivity
    • Select Next
  8. Conditional launch tab:

    • Configure device conditions:
      • Min OS version < 10.0: Block access
      • Jailbroken/rooted devices: Block access
      • Max allowed device threat level ≥ Medium: Block access
      • Offline grace period > 90 days: Wipe data
      • Disabled account: Block access
    • Android-specific:
      • SafetyNet device attestation: Basic integrity and certified devices (Block access)
    • Select Next
  9. Assignments tab:

    • Include: All Users
    • Select Next
  10. Review + create:

    • Review settings and select Create

Result: You now have an app protection policy that protects corporate data on Android devices without requiring device enrollment.

App protection policies are primarily designed for mobile platforms (iOS and Android). For Windows devices, use:

  1. Windows Information Protection (WIP) policies for app-level data protection
  2. Configuration profiles for device-level security settings
  3. Compliance policies combined with Conditional Access for access control

For this exercise on Windows, skip to Task 3 to configure Conditional Access policies that enforce device compliance.

Task 2: Verify app protection policy assignments

Confirm policies are targeting the correct users and applications.

  1. In App protection policies, select your app protection policy (iOS or Android)

  2. Select Properties > Assignments

  3. Verify:

    • All Users or your selected groups are included
    • No unintended exclusions
    • Protected app count: 7 apps
  4. Navigate to Monitor > App protection status

  5. Review the dashboard:

    • Total protected users: Should show count of licensed users
    • Platform breakdown: Shows users by platform
    • Flagged users: Should be 0 initially (no jailbroken/rooted devices detected yet)

Screenshot showing the Intune app protection status dashboard with policy deployment information and device statistics.

For Windows devices, you can skip this task and proceed to Task 3 to configure Conditional Access policies.

Task 3: Create a Conditional Access policy requiring device compliance

Configure zero-trust access control that blocks noncompliant devices from accessing corporate resources. This applies to all platforms.

  1. Sign in to the Microsoft Entra admin center (https://entra.microsoft.com).

  2. Navigate to Protection > Conditional Access > Policies.

  3. Select + New policy.

  4. Name: Require compliant device for Exchange and SharePoint

  5. Assignments section:

    Users:

    • Select 0 users and groups selected
    • Include tab: Select All users
    • Exclude tab: Select Users and groups > Select your break glass / emergency access account
    • Select Select
  6. Target resources:

    • Select No target resources selected
    • Select what this policy applies to: Cloud apps
    • Include tab: Select apps
    • Search for and select:
      • Office 365 Exchange Online
      • Office 365 SharePoint Online
    • Select Select
  7. Conditions:

    Device platforms:

    • Configure: Yes
    • Include tab: Select device platforms > Check:
      • Android
      • iOS
      • Windows
      • macOS
    • Select Done

    Locations:

    • Configure: Yes
    • Include tab: Any location
    • Exclude tab: (Leave empty for this exercise)
    • Select Done
  8. Access controls section:

    Grant:

    • Select 0 controls selected
    • Select Grant access
    • Check: Require device to be marked as compliant
    • For multiple controls: Require one of the selected controls (or Require all if combining with MFA)
    • Select Select
  9. Enable policy:

    • Report-only (test first - recommended for production)
    • Or On (enforce immediately - for this exercise)
  10. Select Create.

Screenshot showing completed Conditional Access policy configuration with device compliance requirement enabled for Exchange and SharePoint access.

Result: Users must have compliant devices to access Exchange Online and SharePoint Online. Noncompliant devices are automatically blocked.

Task 4: Test Conditional Access policy with What If tool

Simulate policy impact before full enforcement using the What If tool.

  1. In Conditional Access > Policies, select What If.

  2. Configure the simulation:

    User or workload identity:

    • Select a test user: user@contoso.com

    Cloud apps, actions, or authentication context:

    • Select: Office 365 Exchange Online

    Device platform:

    • Select: Windows

    Device state (Preview):

    • Select: Device marked compliant (simulate compliant device)
  3. Select What If.

  4. Review results:

    • Policies that will apply: Should show "Require compliant device for Exchange and SharePoint"
    • Evaluation result: Access granted (because device is compliant)
  5. Test noncompliant scenario:

    • Change Device state: Not marked compliant
    • Select What If again
    • Evaluation result: Access blocked (policy denies noncompliant device)

Screenshot showing Conditional Access report-only evaluation details in sign-in logs, displaying policy evaluation results for access decisions.

Result: The What If tool confirms the policy correctly grants access to compliant devices and blocks noncompliant devices.

Task 5: Monitor Conditional Access and app protection effectiveness

Review policy enforcement and identify any access issues.

  1. Monitor Conditional Access sign-ins:

    • In Microsoft Entra admin center, navigate to Monitoring > Sign-in logs
    • Filter by:
      • Conditional Access: Success or Failure
      • Application: Office 365 Exchange Online or SharePoint
    • Review recent sign-in attempts:
      • User who attempted access
      • Device platform and compliance status
      • Conditional Access result (Success, Block, Require compliance)
      • Failure reason (if blocked)
  2. Monitor device compliance (impacts Conditional Access):

    • Navigate to Devices > Monitor > Noncompliant devices
    • Review:
      • Count of noncompliant devices blocked by Conditional Access
      • Compliance policy settings causing failures
      • Devices requiring remediation
  1. Review app protection policy status:

    • In Intune admin center, navigate to Apps > Monitor > App protection status
    • Review:
      • Protected users: Total users with protected apps
      • Platform distribution: Shows adoption by platform
      • Flagged users: Jailbroken/rooted devices or policy violations
  2. Check user-specific app protection status:

    • In Intune admin center, navigate to Apps > Monitor > User status
    • Select a test user
    • Review:
      • List of protected apps installed on user's devices
      • Last check-in date for each app
      • Device platform for each app instance

Verification checklist:

  • App protection policies show in App protection status dashboard
  • Protected apps appear in user status monitoring
  • Conditional Access policy appears in Sign-in logs evaluations
  • Compliant devices successfully access Exchange and SharePoint
  • Noncompliant devices are blocked (if tested)
  • No unexpected user lockouts or access issues
  • Conditional Access policy appears in Sign-in logs evaluations
  • Compliant devices successfully access Exchange and SharePoint
  • Noncompliant devices are blocked (if tested)
  • No unexpected user lockouts or access issues

Exercise summary

Congratulations! You've successfully configured data protection and access control for Contoso's environment.

What you accomplished:

  • Created app protection policy securing Microsoft apps on mobile devices (iOS/iPadOS and Android)
  • Deployed app protection policy to users
  • Created Conditional Access policy requiring device compliance for Exchange and SharePoint
  • Tested policy impact using What If simulation tool
  • Monitored app protection and Conditional Access effectiveness

Contoso's data protection posture

Security Layer Capability Impact
App-level protection Corporate data in Microsoft apps encrypted and protected from leakage to personal apps (mobile platforms) Data secured on 500+ BYOD devices
BYOD support Personal mobile devices access work apps without full device enrollment through app protection policies Zero user resistance to security policies
Zero-trust access Only compliant, managed devices can access sensitive email and documents across all platforms 100% compliance enforcement for Exchange/SharePoint
Continuous compliance Devices must maintain compliance to keep access; noncompliant devices automatically blocked 23 noncompliant devices blocked in first week
Risk-based access Conditional Access evaluates device, location, and identity signals before granting access Real-time access decisions based on context
Platform flexibility Windows devices use MDM-based compliance enforcement, mobile devices benefit from both app protection and compliance policies Consistent security across heterogeneous environment

Check what you've learned in the next unit covering app protection policies and Conditional Access scenarios.