INTUNE-011: Application protection policies (MAM)

Platform
Entra ID / M365
Category
Intune / Endpoint Management
Severity
High
Zero Trust pillar
Devices (weight 3)
Golden fixtures
3
Branch coverage
Observed: fixtures prove the verdicts they exercise
Provenance
baseline

What it checks

Application protection policies (Mobile Application Management) control how corporate data is handled within managed applications on both enrolled and unenrolled devices. Without these policies, users can copy corporate data to personal applications, share files through unmanaged channels, or back up corporate data to personal cloud storage. MAM policies are essential for preventing data leakage on mobile devices.

Recommended value

App protection policies applied to all managed apps on iOS and Android; cut/copy/paste restricted to managed apps; backup to unmanaged services blocked

Remediation

Create application protection policies for both iOS and Android platforms targeting all Microsoft 365 and line-of-business applications that handle corporate data. Configure data protection settings to prevent cut/copy/paste to unmanaged applications, block backup to personal cloud services, and require app-level PIN or biometric authentication. Assign the policies to all users who access corporate data on mobile devices and monitor the app protection status report for non-compliant applications.

Fixture-proven verdicts

Every verdict below is proven by a golden fixture in the module's gating test suite. This table derives from the last green run; it cannot be edited by hand.

Verdict scenarios for INTUNE-011
ScenarioExpected verdict
cleanPASS
known-badWARN
throttledNot Assessed

Framework mappings

NIST SP 800-53
AC-19