app protection policy
Intune App Protection Policy: What It Controls on Mobile Apps
In Microsoft Intune, an app protection policy applies to mobile apps: it governs data inside those apps, including on devices that are not enrolled. This guide covers MAM versus MDM, app targeting, PIN and biometrics as one campus configured them, managed iOS sharing, and a situation-to-decision table.
This article was researched with AI assistance and independently reviewed by multiple AI models before publication.
Key takeaways
- On mobile, an Intune app protection policy can keep corporate data under policy without enrolling the device, including both deliberate copies and accidental leaks.
- Intune splits MDM (whole-device control after enrollment) from MAM (app-level protection on personally owned phones); the two can run together.
- Target apps on the Apps page. `All Apps` covers Microsoft and partner titles that shipped the Intune SDK. *Editorial:* after you pick a targeting choice, re-check that newly introduced work apps still fall under it.
- Documented data controls include cut, copy, paste, save, and encryption. University of Idaho's campus policy uses PIN then biometrics after a 30-minute idle period or a device unlock, including Outlook — those values are that institution's choices, not a single figure presented as an Intune default.
- On managed iOS, set `Send org data to other apps` to `Policy managed apps with OS sharing` when staff need to hand data from a protected app into other iOS managed apps.
An Intune app protection policy is a mobile-app control: it governs how corporate data is reached inside apps on phones and tablets, and where that data can go next. On Microsoft Learn's overview, corporate data can stay under policy even when the phone or tablet is not enrolled, and those limits apply whether someone copies data on purpose or leaks it by accident.
This article covers that mobile-app scenario: MAM versus MDM, which titles get the policy, PIN and biometrics as one campus configured them, a managed iOS sharing option, and a situation-to-decision table.
What the policy is for
Microsoft Learn's create-policy documentation says the available choices let organizations tailor protection to their specific needs. There is also an entry-level configuration: it provides similar data protection control to Exchange Online mailbox policies, and it is a way for IT and staff to first meet app protection.
MAM versus MDM
Intune's two management models split between MDM, which governs the whole device after full enrollment, and MAM, which wraps protection around apps on personally owned phones. The two can run together on the same estate.
In that same explainer, MDM is a device-level approach that requires full Intune enrollment. NinjaOne lists data encryption, copy/paste and save controls, conditional app launch, and user authentication requirements for specific applications — primarily Microsoft 365 apps — as part of that MDM model, not as steps on the app-protection Data protection screen.
Data protection and encryption
A configuration walkthrough includes a Data protection step covering how users can interact with data in the apps, including cut, copy, paste, save, and encryption. Blocking backup to iTunes/iCloud appears in a separate deployment write-up among the same family of controls.
University of Idaho's support article treats encryption as applying to data on the mobile device whether or not the operating system is already encrypting it.
PIN, timeout, and biometrics
The 30-minute idle interval, the PIN-then-biometric sequence, and the Outlook detail below come from University of Idaho's help-desk article, which documents that campus's own configured policy. Microsoft Learn's create-policy documentation says the available choices let organizations tailor protection to their needs; Idaho's PIN, timeout, and biometric values are that campus's choices.
In Idaho's deployment, staff set a PIN when they first open a Microsoft app; later, a 30-minute idle interval or unlocking the phone triggers a biometric prompt. That campus write-up ties the biometric prompt to Outlook among the Microsoft apps on the device.
Which apps are covered
Policy scope starts on the Apps page: that is where you decide which applications receive the restrictions. Choosing All Apps covers the Microsoft catalog plus partner titles whose developers shipped the Intune SDK.
Editorial: after you choose targeting, re-check coverage when a new work app appears, so the apps you picked still match the catalog staff actually use.
Users following Idaho's path see a store link and tap Go to store to install.
A NinjaOne walkthrough lists Microsoft Intune and Azure AD Premium P1 licenses as general prerequisites, along with Intune SDK support in apps such as Outlook, Teams, and OneDrive. Treat those SKUs as one vendor's snapshot, and confirm current entitlements against Microsoft's own licensing documentation.
Managed iOS: sending org data to other apps
On managed iOS, set Send org data to other apps to Policy managed apps with OS sharing when staff need to hand data from a protected app into other iOS managed apps. In that July 2021 write-up, the setting is presented as giving staff room to move work content into the iOS apps they already prefer, and giving admins room to leave some titles outside protection on a device that is otherwise managed.
Policy design by situation
Use one table, not a second checklist. Rows marked Editorial are this article's judgement, not a sourced Intune default.
| Situation | Configuration decision |
|---|---|
| Personal phones; you cannot enroll the device | Apply MAM-style app protection now. Microsoft Learn includes protection of corporate data without enrollment. Do not wait for MDM. |
| Corporate devices that also need whole-device control | Enroll those devices in MDM. MAM can still run alongside. Hybrid is a split you can run, not an either/or. |
| First introduction of app protection | Use Microsoft's entry-level configuration on the create-policy path, which provides similar data protection control to Exchange Online mailbox policies, so IT and staff meet the controls in a familiar shape. |
| Work data in Microsoft and partner SDK apps | On the Apps page, choose which apps the policy targets. All Apps covers Microsoft plus partner titles with the Intune SDK. Editorial: when a new work app appears, verify it is covered under the targeting you chose. |
| Low tolerance for data leaving protected apps | Tighten Data protection: cut, copy, paste, save, and encrypt (NinjaOne walkthrough). Consider blocking backup to iTunes/iCloud, as in this deployment write-up. |
| Managed iPhones should share into other iOS managed apps | Set Send org data to other apps to Policy managed apps with OS sharing (July 2021 write-up). |
| You want a PIN or biometrics before a Microsoft app opens | Treat PIN, timeout, and biometrics as values you tailor. University of Idaho uses PIN then biometrics after a 30-minute idle period or a device unlock, including Outlook. Editorial: copy those values only if they match your friction tolerance — they are one campus's choices. |
| License check before assignment | NinjaOne's walkthrough lists Intune plus Azure AD Premium P1, and SDK-capable apps such as Outlook, Teams, and OneDrive. Confirm current SKUs with Microsoft. |
Sources
- App protection policies overview (Microsoft Learn)
- Create an app protection policy (Microsoft Learn)
- MAM vs MDM app protection policies in Intune (NinjaOne)
- What is Intune App Protection for mobile applications? (University of Idaho)
- Deploying App Protection Policies (Cracknells)
- App protection policies and managed iOS devices (Peter van der Woude)