Grant in Conditional Access that is met only when an Intune app protection policy applies to the client app. If the policy uses Require one of the selected controls, this grant can be satisfied in place of MFA.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Require app protection policy in context, with comparison tables and the common traps.
Terms in this definition
- Authorisation code
OAuth 2.0 grant used by native and web apps: the user signs in, and the app then acts on their behalf with delegated permissions.
- Conditional Access
Policy engine in Microsoft Entra ID P1 that, depending on signals such as risk or named locations, allows access subject to controls like MFA or a compliant device, or blocks it.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- App protection policy
A set of Intune rules on managed apps that safeguards organisational data, for example by demanding a PIN or preventing copy-paste and save-as into personal apps. It works whether or not the device is enrolled.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
- MFA
Multifactor authentication: asking for another factor on top of a password at sign-in, usually required by a Conditional Access grant control.
Related terms
- App-based Conditional Access
Restricts sign-in to apps that are protected by Intune, using the grant called Require app protection policy. From 30 June 2026, the approved-client-app grant became read-only, together with every policy that includes it.