FREE STUDY NOTES · MD-102

How Intune app protection policies work on managed and BYOD devices

How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.

From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)

An app protection policy is a set of rules that applies when a user works with organisational (“corporate”) data inside an app that integrates the Intune App SDK or has been wrapped with the Intune App Wrapping Tool. Policies target the user’s identity, so the same policy can follow a user to enrolled and unenrolled devices.

Scenario Device enrolled? What app protection adds
Corporate device enrolled in Intune Yes Data loss prevention inside apps on top of MDM controls such as Wi-Fi, VPN, certificates and app deployment
Device enrolled in a non-Microsoft MDM Yes (other vendor) App-level protection; MAM shouldn’t be combined with non-Microsoft MAM or container products
Personal device (BYOD) No App-level protection only: apps come from the public store, and no certificates, Wi-Fi or VPN profiles are delivered

What every user needs:

Policies apply only in the work context. A new document is personal until it is saved to a corporate location; in multi-identity apps such as Outlook, Word and Teams, personal accounts are unaffected. Figure 14.1 compares what app protection covers on enrolled and unenrolled devices.

One app protection policy, assigned to user groups, applies to two side-by-side devices. On both, inside the protected app, the policy covers only work account data and leaves personal data alone, with the same PIN, encryption and data transfer controls. Only the enrolled device also gets MDM settings and Retire, while the unenrolled personal device gets no device management and supports MAM selective wipe only.
Figure 14.1: App protection on an enrolled device and on an unenrolled personal device

Data protection framework

Microsoft groups recommended settings into three levels, each building on the previous one:

Level Name Adds
1 Enterprise basic data protection PIN, encryption, selective wipe, Android device attestation
2 Enterprise enhanced data protection Data leakage controls and minimum OS versions; recommended for most users
3 Enterprise high data protection Advanced data protection, stronger PIN, Mobile Threat Defense

Common trap: Using Windows Information Protection (WIP) to stop data being copied from work apps to personal apps on Windows - WIP was deprecated in July 2022 and removed from Windows 11 version 24H2; Intune app protection (MAM) covers Windows through Microsoft Edge, and Microsoft Purview handles wider data loss prevention.

Common trap: Assuming unenrolled Android users only need Outlook or Teams from the Play Store - the Company Portal app is required on Android to receive any app protection policy, even though the device isn’t enrolled.

Get the whole book

This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · MD-102 terms in the glossary · All MD-102 study notes

More MD-102 study notes