A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
Also called APP, MAM policy.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains App protection policy in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- PIN
A brief secret code. The Windows Hello for Business kind is bound to a single machine and protected by its TPM, which means it stays put rather than travelling like a password does. App protection policies may additionally ask for a separate app-level code.
Related terms
- A record
Points a DNS name at an IPv4 address. A typical use is pointing a root (apex) domain at an app.
- Access restrictions
Allow and deny rules for inbound App Service traffic, matched on IP range, service tag or subnet. They can, for instance, restrict an app to a corporate NAT's public addresses.
- Access reviews
Microsoft Entra ID Governance capability that periodically asks reviewers or users themselves to confirm membership for guests, app users or groups, removing anyone who does not respond. PIM, by contrast, handles privileged roles.
- Admin consent
Approval of an app's permissions for the whole tenant, given by an administrator with the right authority. Application permissions always need it, and owning the app does not grant it.
- Admin consent workflow
Feature allowing users to ask an administrator to approve an app they cannot consent to themselves. Nominated reviewers handle the requests, yet the approver must hold a role able to grant admin consent.
- AI bill of materials
Catalogue compiled by AI security posture management in Defender CSPM listing what a generative AI app is built from, including its models, SDKs and data sources.
- Always ready instances
To avoid cold starts, a baseline of instances can be kept running and billed, either for chosen functions or function groups on Flex Consumption or for the whole app on Premium. Flex Consumption doesn't count them toward its maximum instance limit.
- Android Management API
The interface Google recommends for Android Enterprise; on devices, the Android Device Policy app enforces it. Intune runs corporate-owned devices on it already, and is migrating BYOD work profile devices too, replacing Company Portal there with the Microsoft Intune app.