Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Intune App Protection Policies (APP), also called mobile application management (MAM), protect work data inside supported Android and iOS/iPadOS applications without requiring full device enrollment in supported scenarios. They can restrict copy and paste, saving, sharing, screenshots, app access, and offline use while leaving a personal device under the user’s control.
That makes APP useful for BYOD, contractors, and devices managed by another MDM. It is not a replacement for device management: APP does not provide device-wide inventory, compliance, certificates, Wi-Fi, VPN, OS controls, or application deployment.
This guide updates the concepts covered in the HTMD Blog article “Intune App Protection Policies for Android iOS Devices”, published on July 31, 2024, using the current Microsoft Intune configuration model.
What Intune App Protection Policies protect
APP policies apply to a user’s organizational identity and the work context inside an Intune-enabled application. Depending on the platform and application, they can:
#1 Best Overall
- Perfect Fit for Samsung Galaxy S22: Precision-engineered exclusively for the Samsung Galaxy S22, this OtterBox case offers a flawless fit. It not only preserves your phone's sleek design but also ensures unparalleled protection against everyday hazards.
- Rugged Multi-Layer Defense: Featuring dual-layer construction with a rigid shell and internal rubber layer, our case exceeds 3X military drop standards (MIL-STD-810G 516.6), crafted from over 35% recycled plastic for eco-conscious resilience.
- Secure Grip, Streamlined Protection: Rely on the OtterBox legacy with Commuter Series—total protection with rubber-gripped edges for a secure hold. It's a slim, easy-to-install case providing durable quality and a precise fit for hassle-free defense
- Wireless Charging Compatible: Its slim profile is pocket-friendly, offering protection and ease for your on-the-go lifestyle
- Trusted OtterBox Quality: With OtterBox, you're not just buying a case; you're investing in peace of mind.
- Restrict copying and pasting between managed and unmanaged apps.
- Control whether managed data can be received from personal apps.
- Prevent users from saving corporate copies to local storage or personal applications.
- Allow saving only to approved destinations such as OneDrive for Business or SharePoint.
- Encrypt organizational data inside the managed app.
- Require an app PIN, biometrics, or reauthentication.
- Block or limit screenshots and screen recording where supported.
- Control keyboards, web links, sharing, and offline access.
- Detect rooted or jailbroken devices and apply warning, blocking, or selective-wipe actions.
- Remove managed corporate data from the app context through a selective wipe.
These controls protect organizational data within supported managed applications. They do not guarantee control over every copy a user may have made outside that context, and a selective wipe is not a factory reset.
See Microsoft’s App Protection overview and data-protection framework for platform-specific behavior.
APP versus full MDM
| Requirement | APP/MAM | Full MDM enrollment |
|---|---|---|
| Protect work data inside supported apps | Yes | Yes, with APP added when needed |
| BYOD without full enrollment | Yes, in supported scenarios | No |
| Device inventory and compliance | Limited or unavailable | Yes |
| Certificates, Wi-Fi, VPN, and device restrictions | No | Yes |
| OS updates and device-wide passcode enforcement | No | Yes |
| Copy, paste, save, and app-level data controls | Yes | Only when APP is configured |
Choose APP for privacy-sensitive BYOD, contractors, or devices already enrolled in another MDM. Choose full MDM when the organization needs device-wide controls. Corporate-owned devices often benefit from both MDM and APP.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Supported deployment scenarios
- Intune-enrolled device: APP complements device compliance and management.
- Third-party MDM device: APP can protect Microsoft 365 data without replacing the existing MDM, although conflicting policies must be avoided.
- Unenrolled personal device: MAM without enrollment protects supported apps and work data, not the entire phone or tablet.
“Without enrollment” does not mean “without setup.” Microsoft currently states that the Company Portal app is required for Intune App Protection, including MAM scenarios where the device itself is not enrolled. Broker and Conditional Access behavior can vary by platform and scenario, so validate the final experience in a pilot.
Prerequisites
Before creating a policy, verify:
- The user has a Microsoft Entra ID account.
- The user has an appropriate Intune entitlement assigned. Microsoft’s current plan and licensing details are available on the Intune pricing page.
- The user belongs to the security group targeted by the policy.
- The tested application is included in the policy.
- The user signs in to the application with the organizational Entra account, not only a personal account.
- The application supports Intune App Protection.
- Company Portal is installed and signed in as required by the scenario.
- Microsoft Entra Conditional Access is planned where access must be limited to approved, protected applications.
Supported applications
Supported Microsoft apps include products such as Outlook, Word, Excel, Teams, OneDrive, SharePoint, Edge, OneNote, and To Do, subject to Microsoft’s current support matrix. Third-party apps must integrate the Intune App SDK or be prepared with the Intune App Wrapping Tool. An administrator cannot apply complete APP controls to an arbitrary Android or iOS/iPadOS app.
Use Microsoft’s protected-app list. For custom applications, the Intune App SDK generally provides the fuller feature set. The App Wrapping Tool can protect some apps without the same code-level integration, but capabilities and support are more limited.
Rank #2
- Compatibility: Engineered exclusively for Samsung Galaxy A17 / A16 5g with precision cutouts that give full access to ports, speakers, and buttons without interfering with wireless charging. Our 24/7 dedicated support team resolves any model or quality concerns instantly.
- Military-Grade Dual-Layer Protection: A shock-absorbing TPU interior with reinforced corner airbags and a heat-dissipating honeycomb core is wrapped in a hard polycarbonate outer shell. Certified 14ft drop protection guards your phone against high-impact falls onto concrete warehouse floors and rocky hiking terrain.
- 360 Screen Defense with Tempered Glass: Each case includes a separate HD tempered glass protector that delivers full edge-to-edge coverage while preserving original touch sensitivity and clarity. It shields against pocket-key scratches and face-down drops on gym tiles or concrete floors.
- Practical Design for Secure Grip: Textured side panels and a non-slip matte back provide a confident hold during sweaty gym workouts, one-handed texting, and fast-paced daily commutes. The fingerprint-resistant finish stays clean, and soft-touch buttons deliver crisp, responsive feedback.
- All-Scenario Versatility: The minimalist, low-profile matte design blends effortlessly into any environment, from business commutes to weekend hikes. It pairs rugged durability with everyday pocketability for heavy-duty protection without the bulk.
Create an Android or iOS/iPadOS APP policy
- Sign in to the Microsoft Intune admin center.
- Go to Apps > App protection policies.
- Select Create policy.
- Choose Android or iOS/iPadOS. Create separate policies because the available controls differ.
- Enter a policy name and description.
- Select the device-management targeting option.
- Select the protected applications.
- Configure Data protection, Access requirements, and Conditional launch.
- Assign the policy to a pilot user security group.
- Review the configuration and select Create.
Microsoft’s current procedure is documented in Create an app protection policy.
Choose device-management targeting carefully
- All device types: Applies to managed and unmanaged device contexts.
- Managed devices: Limits the policy to recognized managed devices.
- Unmanaged devices: Targets MAM-without-enrollment scenarios.
Assignment filters can further distinguish enrolled and unenrolled Android or iOS/iPadOS devices. APP is primarily user- and application-oriented. Assign MAM-without-enrollment policies to user groups; do not assume a device-group assignment will activate a policy on an unenrolled device.
Recommended data-protection baseline
Use the following as a conservative starting point, then adjust it for business workflows:
- Send organizational data to other apps: Policy-managed apps only.
- Receive data from other apps: Policy-managed apps only.
- Save copies: Block, or permit only OneDrive for Business and SharePoint.
- Cut, copy, and paste: Policy-managed apps only, or no destinations for highly sensitive data.
- Encryption: Require encryption of organizational data.
- Screen capture: Block where the platform and application support it and where the business case justifies the usability impact.
- Web links: Require links from managed apps to open in Microsoft Edge when appropriate.
- Keyboards: Restrict third-party keyboards on iOS/iPadOS and configure approved keyboards on Android where available.
These are recommendations, not universal Microsoft requirements. Test document editing, collaboration, sharing, and accessibility before applying restrictive settings broadly.
Access requirements
Configure whether the managed app requires an app PIN, whether the PIN is numeric or alphanumeric, its minimum length, biometric authentication, inactivity timeout, and reset frequency. A practical baseline is to require a PIN, block simple PINs, use a minimum length of six characters where supported, and require reauthentication after inactivity.
Recommended Free Tools
An app PIN is not the same as the device lock. APP protects access to the managed app context; MDM device-password policy protects the device more broadly. Configure both when device-wide security is required.
Rank #3
- Compatibility: This case Fit for Samsung Galaxy A17 5G (6.7 inch, 2025) and Samsung Galaxy A16 5G (6.7 inch, 2024). Please confirm your phone moderl before purchasing
- Strong Magnetic Attraction: This Galaxy A17 5G / A16 5G Phone Case has built-in 38 super N52 magnets. Its magnetic attraction reaches 2400 gf, which is almost 7X stronger than ordinary. Provide a strong connection to all magnetic accessories—wallets, car mounts, ring holders. Enjoy a safer and more convenient experience
- Tempered Glass Screen Protector: This Samsung Galaxy A17 5G / A16 5G Phone Case includes 1× premium tempered glass screen protector that preserves original touch sensitivity and HD clarity. Offers reliable scratch and drop defense for your phone's Screen, without compromising responsiveness or display quality
- Translucent Matte Back: This Samsung A17 5G / A16 5G Case crafted from high-quality matte TPU and translucent PC, this case reveals the phone logo with an elegant, refined finish. The frosted texture delivers a comfortable, non-slip grip, while the nano antioxidant layer effectively resists stains, sweat, and minor scratches—keeping your case clean and clear longer
- 14FT Military Grade Drop Protection: A17 5G / A16 5G Phone Case has rigid polycarbonate backplate paired with flexible, shock-absorbing TPU bumpers around the edges, plus 4 built-in corner airbags. Provides comprehensive protection against accidental drops, bumps, and impacts
Conditional launch controls
Conditional launch evaluates conditions before allowing access or while the app is running. Relevant controls include:
- Minimum operating-system version.
- Minimum app version and Intune SDK version.
- Rooted or jailbroken device detection.
- Device threat level from a mobile threat-defense integration.
- Android Google Play device-integrity and Play Protect results.
- Maximum failed PIN attempts.
- Offline grace period.
- Actions such as warn, block access, or wipe corporate data.
Set a defined offline period rather than allowing indefinite offline access. Android Play Integrity results may be cached, and Microsoft—not the administrator—determines service-check frequency. A delayed result does not necessarily indicate a policy failure.
Android-specific considerations
Install and sign in to Company Portal, verify Google Play Services and Play Protect, and test rooted or modified devices. Android work-profile and fully managed deployments may also receive MDM restrictions, so document which control comes from MDM and which comes from APP.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsFor Microsoft 365 app scenarios, Microsoft notes that Android MAM may require Microsoft Entra device registration before the user can continue. Distinguish this registration requirement from full Intune device enrollment. Also verify the current supported Android versions and app requirements rather than hard-coding an old minimum version into documentation.
iOS/iPadOS-specific considerations
iOS/iPadOS exposes similar controls but is not identical to Android. Face ID and Touch ID behavior depends on the device and operating-system version. Keyboard restrictions are important, and share extensions require special attention.
APP cannot fully control the iOS/iPadOS share extension without device management. Corporate data is encrypted before it is shared outside the managed app, but the share sheet can create behavior different from ordinary copy-and-paste restrictions.
Rank #4
- 【Compatible with Samsung A16 5G】Specially designed for Samsung Galaxy A16 5G.Package includes Soft HD Screen Protector and install them according to the instructions..【Note that】wireless charging is not supported!
- 【Camera Lens Protection】 This phone case use lens slide design, it easy to slide and not to loose, and enhance protective of your phone camera from scratches, collision, scuffs and impact, not only improve safety, protect your privacy but also has a sense of fashion.
- 【360° Rotable Magnetic Kickstand】 Advanced Ring Metal kickstand can rotate 360°, easy to rotate and sturdy on thephone case. Built in kickstand gives you the convenience to watch videos and movies hands-free with desired comfort and stability.
- 【Full Body Protection】The phone case is made of anti-scratch hard rigid PC bumper and shock resistance soft TPU, with Air-Cushion Technology for all corners and the raised TPU bezel design, provide all around double protection of your phone from drops, scratches and bumps.
- 【High Quality after Sales Service】We are committed to producing high-quality products, If you come across any issues while using the product, please feel free to reach out to us.we will provide you with the most reasonable solution.
For Intune-enrolled iOS/iPadOS applications, validate managed-app configuration values where applicable:
IntuneMAMUPN
IntuneMAMOID
IntuneMAMDeviceID
Incorrect values can cause the wrong policy to be delivered or prevent delivery. Some Microsoft applications began receiving values automatically from the Intune 2409 service release, but that does not mean every third-party or line-of-business app is automatically configured.
Integrate Microsoft Entra Conditional Access
APP alone should not be treated as complete access control. Without Conditional Access, users may be able to reach a workload through an unsupported or unprotected client, depending on the service and tenant configuration.
- In the Microsoft Entra admin center, create a pilot Conditional Access policy.
- Target the appropriate users and groups.
- Select the relevant cloud apps, such as Exchange Online, SharePoint Online, or Microsoft 365 services.
- Include the required mobile platforms.
- Use grant controls such as Require approved client app and/or Require app protection policy.
- Block legacy authentication.
- Exclude emergency break-glass accounts from broad policies, then protect and monitor those accounts separately.
Deploy the APP policy before enforcing the matching Conditional Access requirement. Existing devices may need time to receive and process the policy. Enforcing Conditional Access first can cause avoidable lockouts.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Test with a representative pilot
Use a pilot group containing an enrolled and unenrolled Android device, an enrolled and unenrolled iPhone or iPad, a device managed by another MDM, a user with multiple protected apps, and a user excluded from the policy.
- Sign in to Outlook, Teams, OneDrive, Word, and Edge.
- Copy from a managed app to a personal app and in the reverse direction.
- Save a work document locally, to OneDrive, and to SharePoint.
- Test screenshots and screen recording.
- Test the iOS/iPadOS share sheet and a third-party keyboard.
- Disable the device PIN and test the app response.
- Test an outdated app and operating system.
- Take the device offline beyond the configured grace period.
- Trigger incorrect app-PIN attempts.
- Test a native mail client or unsupported app under Conditional Access.
- Disable or remove the user account and perform a selective wipe.
Record expected results separately for Android and iOS/iPadOS. A successful sign-in proves only that authentication worked; it does not prove that transfer restrictions, integrity checks, selective wipe, or Conditional Access are functioning.
Best Value
- Compatibility: Samsung Galaxy 𝗔𝟭𝟲/𝗔𝟭𝟳 Case cares for every detail with precise cutouts allow easy access to all ports, speakers, cameras, buttons, and other functions. Won't compatible with any other phone models. Notice: Due to the metal ring on the back, the case will 𝗡𝗢𝗧 𝘄𝗼𝗿𝗸 𝘄𝗶𝘁𝗵 𝗪𝗶𝗿𝗲𝗹𝗲𝘀𝘀 𝗖𝗵𝗮𝗿𝗴𝗶𝗻𝗴 𝗳𝘂𝗻𝗰𝘁𝗶𝗼𝗻
- 𝗜𝗻𝘀𝘁𝗮𝗹𝗹𝗮𝘁𝗶𝗼𝗻 𝗧𝗶𝗽𝘀: This case has a 2-in-1 polycarbonate front cover, frame, and back cover. 𝗖𝗿𝘂𝗰𝗶𝗮𝗹𝗹𝘆, 𝗱𝗲𝘁𝗮𝗰𝗵 𝘁𝗵𝗲 𝗳𝗿𝗼𝗻𝘁 𝗰𝗼𝘃𝗲𝗿 𝗳𝗶𝗿𝘀𝘁. After applying the film, install the front cover onto your phone. 𝗜𝗳 𝘆𝗼𝘂 𝗲𝗻𝗰𝗼𝘂𝗻𝘁𝗲𝗿 𝗱𝗶𝗳𝗳𝗶𝗰𝘂𝗹𝘁𝗶𝗲𝘀 𝗶𝗻𝘀𝘁𝗮𝗹𝗹𝗶𝗻𝗴 𝗶𝘁, 𝗰𝗼𝗻𝘁𝗮𝗰𝘁 𝗰𝘂𝘀𝘁𝗼𝗺𝗲𝗿 𝘀𝗲𝗿𝘃𝗶𝗰𝗲
- Tempered Glass Screen Protector : The Samsung Galaxy 𝗔𝟭𝟲/𝗔𝟭𝟳 phone case presents [2 Packs] advanced HD clarity 9H hardness ultra resistant tempered glass screen protector. The front cover provides 360-degree all-round protection for your phone, effectively prevents screen scratches, supports fingerprint recognition, and improved touch-smooth surface for better handheld experience
- Premium Material Construction: Our phone cases are made of high - quality, impact - resistant polycarbonate. This combo offers great durability, withstanding daily bumps, drops, and scratches to protect your phone long - term. The materials are robust, rarely cracking or deforming
- Weather and Chemical Resistance: Our phone cases are built to withstand physical impacts, elements, and common chemicals. They resist sunlight, humidity, and spills of water, coffee, or hand - sanitizer. This protection against environmental factors and chemicals enhances durability and longevity, ensuring optimal performance and year - round phone safety
Troubleshoot common failures
The policy does not apply
Check the user’s group membership, app targeting, organizational sign-in, Company Portal state, application support, policy processing time, and conflicting assignments. APP settings apply to the work context; personal use of the same app is not normally affected.
Conditional Access blocks access
Confirm whether the user is receiving both a device-compliance requirement and an APP requirement. Check the cloud-app scope, approved-client-app setting, MAM registration, licensing, legacy authentication, and whether Conditional Access was enabled before the APP policy arrived.
The wrong iOS/iPadOS policy arrives
For enrolled applications, verify IntuneMAMUPN, IntuneMAMOID, and, where required, IntuneMAMDeviceID. Incorrect managed-app configuration can cause incorrect policy targeting.
PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteAndroid integrity results seem inconsistent
Capture the device model, Android version, Google Play Services state, Play Protect state, root or modification status, last integrity result, and configured action. Account for service-side throttling and cached results before treating a delayed result as a policy defect.
Selective wipe removes less than expected
APP selective wipe removes organizational data from the managed app context. It is not a full-device wipe and cannot guarantee removal of every user-created copy that has already left that context.
When APP is not enough
- Android Enterprise work profile: Provides stronger work/personal separation with device-management capabilities.
- Apple User Enrollment: Offers privacy-conscious management for iOS/iPadOS.
- Full Intune MDM: Adds device compliance, inventory, certificates, VPN, Wi-Fi, and device restrictions.
- Microsoft Defender for Endpoint: Supplies mobile threat signals that APP conditional launch can evaluate; use it when the operational value justifies the additional deployment.
- Microsoft Purview: Adds information-protection and governance controls that can follow documents beyond a managed app boundary.
These technologies are complementary, not interchangeable: APP controls application data flow, MDM manages devices, Defender contributes threat signals, and Purview protects information and governance context.
Bottom line
Intune APP is the least intrusive Microsoft control for protecting work data on supported Android and iOS/iPadOS applications, especially on BYOD and third-party-MDM devices. Create separate platform policies, assign them to users, install Company Portal, target only supported applications, and pair APP with Conditional Access. Use full MDM when the organization needs guarantees about the entire device rather than only the managed app context.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

