Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
Redmond desk6 min

How to Enable or Disable Edge’s MAMEnabled Policy in the Microsoft 365 Admin Center

Learn what Edge’s MAMEnabled policy does, how to configure it through the Microsoft Edge management service, and how to verify Intune MAM policy delivery on Windows.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Short answer: Microsoft Edge’s MAMEnabled policy controls whether the browser can contact Microsoft Intune to request and apply Mobile Application Management (MAM) policies. Set it to Enabled, or leave it unconfigured, when Edge should use Intune MAM. Set it explicitly to Disabled when Edge must not request those policies.

MAMEnabled is only the Edge-side switch. The actual data controls—such as copy-and-paste restrictions, protected downloads, screenshots, and watermarking—are configured in Intune App Protection Policies, with Microsoft Entra Conditional Access added when protected access must be enforced.

What the MAMEnabled policy does

Mobile Application Management protects organizational data inside a managed application or browser work profile rather than taking full control of a personal device. This makes it useful for Windows BYOD and other unmanaged-device scenarios.

In Edge, MAM controls apply to the organizational browsing context. They do not automatically govern a user’s personal browsing activity. Microsoft describes App Protection Policies as rules that contain or protect company data within managed apps; Edge is supported as a Windows app-protection browser.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft 365 Personal | 12-Month Subscription | 1 Person | Premium Office Apps: Word, Excel, PowerPoint and more | 1TB Cloud Storage | Windows Laptop or MacBook Instant Download | Activation Required
  • Designed for Your Windows and Apple Devices | Install premium Office apps on your Windows laptop, desktop, MacBook or iMac. Works seamlessly across your devices for home, school, or personal productivity.
  • Includes Word, Excel, PowerPoint & Outlook | Get premium versions of the essential Office apps that help you work, study, create, and stay organized.
  • 1 TB Secure Cloud Storage | Store and access your documents, photos, and files from your Windows, Mac or mobile devices.
  • Premium Tools Across Your Devices | Your subscription lets you work across all of your Windows, Mac, iPhone, iPad, and Android devices with apps that sync instantly through the cloud.
  • Easy Digital Download with Microsoft Account | Product delivered electronically for quick setup. Sign in with your Microsoft account, redeem your code, and download your apps instantly to your Windows, Mac, iPhone, iPad, and Android devices.

See Microsoft’s MAM FAQ and Windows App Protection settings.

Policy value Effect
Enabled Edge can communicate with Intune application-management services and request MAM policies.
Not configured MAM policies can still be applied. This is not the same as disabling MAM.
Disabled Edge does not communicate with Intune to request MAM policies.

The policy is named MAMEnabled, uses a Boolean value, and is not supported per profile according to Microsoft’s current policy reference.

Supported platforms and versions

  • Windows: Microsoft documents Edge version 89 or later.
  • macOS: Microsoft documents Edge version 89 or later.
  • Android and iOS: unsupported for this specific browser policy. Mobile Edge applications have a separate Intune App Protection configuration path.
  • Restart: dynamic refresh is not supported; restart Edge after the policy is delivered.

Do not confuse this browser policy with every Edge MAM scenario. Microsoft’s newer cross-tenant Edge for Business guidance specifies version 147 or later for that particular scenario only; it is not a universal minimum for MAMEnabled. See Edge cross-tenant MAM guidance.

Rank #2
Sale
The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • The Microsoft Office 365 Bible: The Most Updated and Complete Guide to Excel, Word, PowerPoint, Outlook, OneNote, OneDrive, Teams, Access, and Publisher from Beginners to Advanced
  • ABIS BOOK

Prerequisites

  • A Microsoft 365 tenant with access to the Microsoft Edge management service.
  • Administrative permissions to create Edge configuration policies and assign Microsoft Entra groups.
  • A Microsoft Entra user or security group for a controlled pilot.
  • Intune licensing for users who receive App Protection Policies.
  • An Intune App Protection Policy assigned to the intended Windows users and Microsoft Edge.
  • A Conditional Access design if users must access corporate resources only through a protected app or browser profile.
  • A supported Windows build and Edge version.

For the documented Windows Conditional Access scenario, Microsoft lists Windows 10 version 20H2 or later and Windows 11, with KB5031445 specified for the supported Edge scenario. That documentation does not support sovereign-cloud deployments. Check the current Windows app-protection Conditional Access requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Enable MAMEnabled in the Microsoft 365 admin center

The cloud service is called the Microsoft Edge management service. The labels can change, so search for the policy name if your tenant’s layout differs.

  1. Sign in to the Microsoft 365 admin center with an account that can manage Edge policies.
  2. Open Settings, then select Microsoft Edge.
  3. Open Configuration Policies and choose Create policy.
  4. Enter a descriptive name, such as Edge - Allow Intune MAM.
  5. Select the applicable platform. For a Windows deployment, choose the Windows 10 and 11 option offered by your tenant.
  6. Select the policy type presented by the tenant, such as an Intune or cloud policy channel.
  7. On Settings, select Add settings.
  8. Search for MAMEnabled or Mobile App Management Enabled, add it, and set the value to Enabled.
  9. Continue through the wizard and assign the policy to a narrowly scoped Microsoft Entra security group.
  10. Review the configuration and select Review + Create (or the equivalent final save command).
  11. Restart Edge on a targeted device after policy delivery.

The Microsoft Edge management service is documented at learn.microsoft.com/deployedge/microsoft-edge-management-service. A June 10, 2025 walkthrough also demonstrates the portal sequence and stresses completing the final review-and-create step: HTMD’s MAMEnabled walkthrough.

Assign the policy safely

  • Start with a small pilot group and a test user.
  • Use clear names that identify the platform, purpose, and owner.
  • Check group membership and exclusions before expanding the assignment.
  • Avoid overlapping assignments while testing; document which policy source owns MAMEnabled.
  • Protect emergency-access accounts from accidental Conditional Access lockout according to your organization’s access policy.

Applicable Edge management policies can merge, while conflicting settings are resolved through policy priority in the Edge management service. Intune configuration policies do not automatically receive the same priority handling. Review the service documentation before assigning competing policies.

Disable MAMEnabled

Explicitly disable it

  1. Edit or create an Edge configuration policy.
  2. Add MAMEnabled (or Mobile App Management Enabled).
  3. Set the value to Disabled.
  4. Assign it to the intended group, review the policy, save it, and restart Edge.

With an explicit Disabled value, Edge will not contact Intune to request MAM policies. This can undermine data-protection and Conditional Access objectives, so treat it as a security decision rather than a cosmetic browser setting.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Do not confuse removal with disablement

Deleting an assignment or leaving the setting unconfigured does not produce the Disabled behavior. Microsoft states that an unconfigured policy still allows MAM policies to be applied. Use an explicit Disabled value when the goal is to block Edge’s Intune MAM requests.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Verify that the policy reached the device

1. Check Edge management status

Confirm that the policy is assigned to the expected group and that the Edge management service reports deployment or processing for the target.

2. Check Intune or device-management status

On a managed test device, synchronize Company Portal or the applicable management client, then inspect the relevant configuration-policy status. A commonly documented route is Devices → Configuration → Policies, although portal locations vary by policy channel and tenant experience.

3. Inspect Windows Event Viewer

  1. Open Event Viewer.
  2. Browse to Applications and Services Logs → Microsoft → Windows → DeviceManagement-Enterprise-Diagnostics-Provider → Admin.
  3. Look for policy-processing events, including Event ID 814, and search the event data for MAMEnabled and its value.

Event 814 is evidence of MDM policy processing, not proof that the complete Intune MAM experience works. The event workflow is described in the HTMD article dated June 10, 2025: anoopcnair.com/mobile-app-management-policy-in-ms-edge-browser/.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. Validate identity and profile context

  • The correct user is signed in.
  • The intended organizational Edge profile is active.
  • The profile uses the expected organizational identity rather than a personal account.
  • The user is included in the Intune App Protection Policy assignment.
  • Edge has been fully closed and restarted after delivery.

5. Test an actual protection

Use a test operation that your Intune policy defines, such as copying organizational text to a personal destination, downloading corporate data, opening a link from a managed Microsoft app, taking a screenshot, or checking a watermark. Microsoft documents protected clipboard, protected downloads, watermarking, screenshot prevention, and Developer Tools protection as possible controls in Edge data-protection features.

Troubleshoot common failures

Symptom Likely cause Action
Policy never appears Wrong group, platform, or policy source Check assignment, group membership, platform selection, and precedence.
No Event Viewer entry Device has not checked in or is not receiving the policy channel Sync management, verify enrollment and identity, then restart Edge and Windows services as appropriate.
Policy appears but no data protection occurs No Intune App Protection Policy, wrong target, or wrong Edge profile Verify the App Protection assignment, user identity, profile, and configured controls.
User is blocked unexpectedly Conditional Access conditions do not match the MAM design Review Entra sign-in logs, Conditional Access results, licensing, and supported Windows requirements.
Change takes effect only after a delay Edge does not dynamically refresh this policy Close every Edge window and relaunch the browser.
Mobile device is unaffected Expected behavior for this policy Configure mobile Edge App Protection separately; Android and iOS are unsupported for MAMEnabled.

Also check for unsupported builds, sovereign-cloud limitations in the documented Windows Conditional Access scenario, conflicting policy sources, and users who are not included in the same groups as the App Protection Policy.

Where the actual protection is configured

Use Intune App Protection Policies for organizational-data transfer, copy-and-paste, storage, downloads, screenshots, watermarking, and related restrictions. Use Conditional Access when access to Microsoft 365 resources must require an app-protection state. Use Edge configuration policies for browser behavior and security settings; they complement, but do not replace, App Protection Policies.

For Edge-specific app configuration guidance, see Microsoft’s Edge app-configuration documentation. Full Intune MDM remains the better fit when you need device compliance, configuration profiles, application deployment, or wipe and retire operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Deployment checklist

  • MAMEnabled is intentionally Enabled, unconfigured, or Disabled.
  • The Edge policy targets the correct Microsoft Entra group.
  • An Intune App Protection Policy targets the same users and Microsoft Edge.
  • Conditional Access is scoped and licensed correctly where required.
  • Windows and Edge versions meet the applicable requirements.
  • Edge was restarted after delivery.
  • Edge management and Intune status were checked.
  • Event Viewer policy processing was reviewed.
  • A real data-protection operation was tested.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. Shenzhen desk3 min
    HONOR Expands Beyond Smartphones With Humanoid Robot RevealHONOR said it unveiled its first humanoid robot at MWC 2026 and named shopping assistance, workplace inspections, and supportive companionship as intended uses. Later Robotics D1 claims and a reported…
  2. Cupertino desk5 min
    Apple Unveils AirPods Max 2: The Upgrade That Should Have Happened Years AgoAirPods Max 2 adds H2-powered audio features and Apple claims up to 1.5× more effective ANC, but its design, Smart Case, and 20-hour battery rating are unchanged. Wired lossless audio…
  3. Cupertino desk4 min
    Apple’s OLED Touch MacBooks Are Coming—but the Dynamic Island Is the Real GambleApple has not announced an OLED touchscreen MacBook, but reports point to high-end models arriving in late 2026 or early 2027. The reported Mac Dynamic Island could be useful, but…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.