Short for mobile application management. Rather than enrolling a phone or laptop, Intune applies app protection policies to the work apps and their data, which suits personally owned BYOD devices.
Also called mobile application management.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains MAM in context, with comparison tables and the common traps.
Terms in this definition
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- BYOD
Bring your own device: staff working on their own phones, tablets or laptops. Microsoft Entra ID normally registers these devices instead of joining them.
Related terms
- Microsoft Intune
Microsoft's endpoint management service, run from the cloud, covering both MDM and MAM. Conditional Access grant controls can depend on its compliance policies for devices and protection policies for apps.
- Microsoft Intune Plan 2
Adds advanced features on top of Plan 1, for instance Advanced Analytics, Remote Help, Tunnel for MAM, FOTA and management of specialty devices. Microsoft 365 E3 has included them since July 2026.