How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.
From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)
An app protection policy is a set of rules that applies when a user works with organisational (“corporate”) data inside an app that integrates the Intune App SDK or has been wrapped with the Intune App Wrapping Tool. Policies target the user’s identity, so the same policy can follow a user to enrolled and unenrolled devices.
| Scenario | Device enrolled? | What app protection adds |
|---|---|---|
| Corporate device enrolled in Intune | Yes | Data loss prevention inside apps on top of MDM controls such as Wi-Fi, VPN, certificates and app deployment |
| Device enrolled in a non-Microsoft MDM | Yes (other vendor) | App-level protection; MAM shouldn’t be combined with non-Microsoft MAM or container products |
| Personal device (BYOD) | No | App-level protection only: apps come from the public store, and no certificates, Wi-Fi or VPN profiles are delivered |
What every user needs:
Policies apply only in the work context. A new document is personal until it is saved to a corporate location; in multi-identity apps such as Outlook, Word and Teams, personal accounts are unaffected. Figure 14.1 compares what app protection covers on enrolled and unenrolled devices.
Microsoft groups recommended settings into three levels, each building on the previous one:
| Level | Name | Adds |
|---|---|---|
| 1 | Enterprise basic data protection | PIN, encryption, selective wipe, Android device attestation |
| 2 | Enterprise enhanced data protection | Data leakage controls and minimum OS versions; recommended for most users |
| 3 | Enterprise high data protection | Advanced data protection, stronger PIN, Mobile Threat Defense |
Common trap: Using Windows Information Protection (WIP) to stop data being copied from work apps to personal apps on Windows - WIP was deprecated in July 2022 and removed from Windows 11 version 24H2; Intune app protection (MAM) covers Windows through Microsoft Edge, and Microsoft Purview handles wider data loss prevention.
Common trap: Assuming unenrolled Android users only need Outlook or Teams from the Play Store - the Company Portal app is required on Android to receive any app protection policy, even though the device isn’t enrolled.
This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · MD-102 terms in the glossary · All MD-102 study notes
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.