Skip to main content
Systems Engineering

Mobile Application Management for BYOD: MAM Without Enrolment

Use Microsoft Intune mobile application management and app protection policies to protect work data on BYOD devices without requiring full device enrolment.

Mobile Application Management for BYOD: MAM Without Enrolment
Eleanor HayesEleanor Hayes8 min read

In this guide

Share

Mobile application management (MAM) gives organisations a practical way to protect work data on personally owned phones and tablets without taking full administrative control of the device. In Microsoft Intune

, app protection policies apply controls to supported applications and to the work identity inside those applications. This makes MAM without enrolment useful for bring-your-own-device (BYOD) populations where the business needs data-loss controls but cannot justify device-wide management.

The boundary matters. MAM does not turn an unmanaged phone into a compliant managed device. It cannot deploy device certificates, configure corporate Wi-Fi or VPN profiles, enforce every operating-system setting or perform a factory reset. Its purpose is narrower: control how organisational data is accessed, stored and transferred inside supported apps.

#Mobile Application Management, MDM and BYOD

Mobile device management (MDM) manages the device. Mobile application management manages supported applications and their organisational data. Microsoft Intune supports both approaches, and the same organisation can use them for different populations.

DecisionMAM without enrolmentMDM with app protection
Primary boundaryWork identity and organisational data inside supported appsThe device plus organisational data inside apps
Typical ownershipPersonally owned BYODCorporate-owned or fully managed BYOD
Device configurationNo device-wide configuration profilesCan deploy compliance, certificates, Wi-Fi, VPN and configuration profiles
Data removalSelective removal of organisational app dataSelective removal and, where authorised, device wipe or retire actions
Application requirementApp must support Intune app protectionBroader application and device controls are available

Use MAM without enrolment when the required outcome is to contain corporate data in approved apps, separate work and personal contexts, and remove organisational data when access should end. Use MDM when the risk decision depends on device compliance, certificate deployment, operating-system configuration, inventory or full lifecycle management.

#How Intune MAM Without Enrolment Works

Intune app protection policies are assigned to users and targeted at supported applications. Microsoft describes a managed app as an application in which Intune can apply app protection policy. Supported Microsoft applications and participating third-party apps integrate the Intune App SDK or use the Intune App Wrapping Tool.

The policy can control three broad areas:

  • Data protection: restrict saving copies of organisational data, control cut, copy and paste, determine which apps may send or receive work data, and require managed web links to open in an approved browser.
  • Access requirements: require a PIN or supported biometric check before organisational data is opened in the app and require periodic access rechecks.
  • Conditional launch: warn or block when defined conditions are not met, such as minimum operating-system versions or rooted and jailbroken device signals supported by the platform.

Policy applies to the work context. Personal accounts and personal data in the same supported application are not automatically brought under corporate ownership. This identity-centred boundary is the main privacy advantage for BYOD, but it also means administrators must test multi-identity behaviour in every important application.

#Conditional Access Is the Admission Gate

App protection policy controls what happens after a supported app receives organisational data. Microsoft Entra Conditional Access controls whether the session is admitted. Microsoft recommends using Conditional Access with Intune app protection policies so that unsupported clients cannot simply bypass the application-level restrictions.

A mobile Conditional Access policy can require an app protection policy for selected cloud applications on iOS/iPadOS and Android. Stage this with a dedicated pilot group and report-only evaluation before enforcement. Keep emergency-access accounts outside the pilot according to the organisation’s documented Conditional Access standard, and review sign-in logs before expanding scope.

The grant control has a broker dependency. Microsoft currently documents Microsoft Authenticator as the broker on iOS and Microsoft Company Portal as the broker on Android for this flow. The device is registered with Microsoft Entra ID

as part of satisfying the app-protection grant, but that registration is not the same as Intune MDM enrolment.

#A Bounded BYOD MAM Rollout

  1. Define the data boundary. List the Microsoft 365 and line-of-business services that BYOD users need, the supported apps that will carry the data, and any workflow that still depends on an unsupported client.
  2. Choose a pilot population. Use a named security group with representatives from iOS and Android, common device versions, multi-account users and the support team.
  3. Confirm application support. Check Microsoft’s current protected-app list and verify that each required client integrates Intune app protection. Do not assume that every mobile client or browser can enforce the same controls.
  4. Create platform-specific app protection policies. Configure separate iOS/iPadOS and Android policies. Start from Microsoft’s data-protection framework, then document every deviation.
  5. Configure data-transfer controls. Decide which managed apps may exchange organisational data, whether saving to personal storage is blocked, how web links open and what exceptions are necessary for real workflows.
  6. Configure access and launch controls. Set work-context PIN or biometric requirements, offline grace periods, minimum OS requirements and responses to rooted or jailbroken devices. Avoid aggressive values that have not been tested against travel and connectivity scenarios.
  7. Add Conditional Access in report-only mode. Target the same pilot population and relevant cloud apps. Evaluate successful and failed sign-ins before switching the policy on.
  8. Test positive and negative paths. Confirm supported apps receive policy; unsupported clients are denied as designed; work data cannot be pasted into an unmanaged app; approved transfers still work; personal data remains unaffected; and broker installation guidance is understandable.
  9. Exercise selective wipe. Use a dedicated test identity and non-production data. Confirm the wipe request is received when the protected app checks in and that organisational data is removed without deleting personal data.
  10. Expand in batches. Monitor app-protection status, Conditional Access sign-ins, support contacts and exceptions between each expansion.

#Scoping and Policy Design

Do not assign the first policy to all users. Separate populations by device-management state and data sensitivity. Microsoft allows app protection targeting to distinguish managed from unmanaged devices, which supports a more restrictive policy for unenrolled BYOD while retaining a different baseline for Intune-enrolled corporate devices.

A useful design starts with three questions:

  • Which identities are allowed to use BYOD for organisational data?
  • Which applications form the managed data boundary?
  • What device or application condition causes a warning, a block or selective removal?

Keep exceptions explicit. If a business process requires export to an unmanaged app, document the data class, owner, review date and compensating control. A broad transfer exception added to make one workflow function weakens every other protected workflow in the same assignment.

#Troubleshooting MAM Without Enrolment

SymptomCheck firstEvidence
Policy does not appear in the appUser assignment, application support, licence, platform policy and work-account sign-inIntune app-protection status and the app’s diagnostic information
User is repeatedly prompted to authenticateRequired broker app, account registration, Conditional Access result and overlapping policiesMicrosoft Entra sign-in logs and Conditional Access details
Unsupported app still reaches dataConditional Access scope, excluded users or apps, client-app condition and modern-auth pathSign-in event showing which policy and grant controls were evaluated
Copy or save restriction behaves unexpectedlyReceiving-app classification, transfer exceptions and multi-identity contextPolicy assignment plus a repeatable test using non-sensitive data
Selective wipe remains pendingWhether the app has launched and checked in since the requestIntune app selective-wipe status
Corporate device receives the BYOD policyDevice-management-state targetingPolicy assignment report for the user and device

Diagnose from evidence rather than weakening controls. A failed sign-in should be correlated with its Conditional Access evaluation. A data-transfer issue should be reproduced with a known source app, destination app, identity and content type. A pending wipe should be interpreted in light of Microsoft’s requirement that the application runs and checks in before the organisational data is removed.

#Selective Wipe and Offboarding

Intune app selective wipe removes organisational data from Intune-managed apps without performing a factory reset of a personally owned device. Microsoft supports device-based and user-level requests. User-level wipe is deliberately broad: it issues wipe commands to protected apps across the user’s devices and continues at check-in until the user is removed from the list.

Use device-based wipe when a known personal device is lost or retired. Reserve user-level wipe for cases where organisational access must be removed across every protected device, such as a confirmed leaver. Record the requester, scope and time, then monitor the request to completion. Microsoft notes that the user must open the app for the wipe to occur and that completion can take up to 30 minutes after the request reaches the running app.

#Limitations and the Next Safe Decision

MAM without enrolment does not deploy applications to the device, issue certificate profiles or configure corporate Wi-Fi and VPN settings. It also cannot protect organisational data inside an application that does not support the Intune policy framework. Those are design constraints, not faults to work around by assuming device compliance.

The next safe decision is therefore population-specific. If supported apps cover the required workflow and the security objective is containment of organisational data, pilot MAM without enrolment. If access depends on device certificates, device compliance, network configuration or full endpoint lifecycle control, require MDM instead. Many organisations should run both models: MDM plus MAM for corporate devices and MAM-only for an approved BYOD population.

For the identity side of the control, see the Microsoft Entra ID technology profile. For endpoint policy context, see Microsoft Intune.

Evidence trail

Sources and verification

Primary documentation and external technical references used in this article.

  1. 01Microsoft — App Protection Policies Overviewlearn.microsoft.com
  2. 02Microsoft — Mobile Application Management for unenrolled deviceslearn.microsoft.com
  3. 03Microsoft — Conditional Access grant controlslearn.microsoft.com
  4. 04Microsoft — Require approved client apps or app protection policylearn.microsoft.com
  5. 05Microsoft — Wipe only corporate data from Intune-managed appslearn.microsoft.com
Eleanor Hayes

Eleanor Hayes

Systems Engineering Editor

Dr Eleanor Hayes is a veteran cryptography researcher and enterprise security architect specialising in zero-trust network implementations.

Published Last changed
View Profile
Reader Interaction

Comments

Add a thoughtful note on Mobile Application Management for BYOD: MAM Without Enrolment. Comments are checked for spam and held for moderation before appearing.

Loading comments...

Discover more

Learn More About KBY

Was this useful?

Engineering insights, direct to you.

Receive the latest Systems Engineering tutorials, production guides, Engineering Labs and operational best practices.