★ First page of Microsoft's 100,000-partner directory, sorted by responsiveness✓ Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation, Data & AI● Microsoft partner since 2006◆ 1,100+ organizations under management

BYOD Phones and Microsoft 365: Intune App Protection Without Enrolling the Device (What It Protects, What Users Notice, What It Needs)

2026-09-27·IT Partner·Security guidesNewIntuneBYODSecurityMicrosoft 365

Most staff read company email on a personal phone that is not enrolled in anything. Intune app protection policies were built for that: they protect the data inside Outlook, Teams, OneDrive and the Office apps on a phone the company does not manage, and remove that data when the person leaves. This article explains how mobile application management without enrollment works, the settings that matter, the Conditional Access rule that enforces it, what users see, iOS vs Android, licensing, and the privacy conversation with staff.

MAM without enrollment, explained

Microsoft's app protection policy overview (March 2026) describes policies that "ensure an organization's data remains safe or contained in a managed app," and lists three device states they apply to: enrolled in Intune, enrolled in a non-Microsoft MDM, or "not enrolled in any mobile device management solution." In Microsoft's words, "you can use Intune app protection policies independent of any mobile-device management (MDM) solution," and its guidance on MAM for unenrolled devices (April 2024) calls this "commonly used for personal or bring your own devices (BYOD)."

What is managed is the app, not the phone. Outlook, Teams, OneDrive, the Office apps, Edge and third-party apps built with the Intune SDK check the policy when a work account signs in. Personal apps, photos, texts and the phone's settings are untouched, because the policy never reaches them. Microsoft states it directly in its comparison with Android work profiles (June 2025): "IT admins are unable to read, access, or erase data that's owned or controlled by end users."

The platforms are iOS and iPadOS, Android and, in a narrower form, Windows, where Microsoft's MAM for Windows (October 2025) covers Microsoft Edge on personal, unmanaged devices.

The settings that matter

Microsoft's iOS (November 2025) and Android (March 2026) settings references list dozens of settings; a usable policy changes about a dozen. Microsoft's data protection framework (June 2025) sorts them into three levels; Level 1 is "the minimum data protection configuration for an enterprise device," and Level 2 is "for devices where users access sensitive or confidential information." We deploy Level 2 for any firm that handles client data.

Data protection: set "Send org data to other apps" to policy managed apps; "Receive data from other apps" the same way; "Save copies of org data" to block, with "Allow user to save copies to selected services" set to OneDrive and SharePoint; "Restrict cut, copy, and paste between other apps" to policy managed apps with paste in; "Backup org data to iTunes and iCloud backups" to block; "Encrypt org data" stays at its default of require; on Android, "Screen capture and Google Assistant" to block.

Access requirements: "PIN for access" stays required, with a minimum length of 6 rather than the default 4, and "Recheck the access requirements after (minutes of inactivity)" at its default of 30 minutes.

Conditional launch: "Max PIN attempts" at the default of 5, then wipe; "Offline grace period" to block after the default 1,440 minutes and wipe after 90 days offline; "Jailbroken/rooted devices" to block; "Min OS version" at the two most recent major releases; "Disabled account" to wipe, so a leaver's data is removed the next time the app opens.

Conditional Access: require app protection policy

The enforcement is a Conditional Access rule. Microsoft's grant control documentation (June 2026) says: "In Conditional Access policy, you can require that an Intune app protection policy is present on the client app before access is available to the selected applications." The mechanics matter: "Conditional Access requires that the device is registered in Microsoft Entra ID, which requires using a broker app. The broker app can be either Microsoft Authenticator for iOS or Microsoft Company Portal for Android devices."

Two consequences. The built-in Mail app on an iPhone and Gmail on Android cannot satisfy the grant, so they are blocked for work mail; Outlook is the only mail app that works. And the older "Require approved client app" grant is retiring; Microsoft's note says organizations must move to "Require app protection policy" and that new policies should use only that grant. The policy joins the baseline from Conditional Access policies every business should have: all users, the Office 365 cloud app, iOS and Android platforms, grant with "Require app protection policy," break-glass accounts excluded, report-only for a week.

What users notice: Outlook and Teams on day one

The user opens Outlook on their personal iPhone and signs in with the work account. Outlook tells them the organization is protecting data in the app and sends them to install Microsoft Authenticator (on Android, the Intune Company Portal), which registers the phone with Entra ID without enrolling it. Back in Outlook they set an app PIN or approve Face ID.

From then on: the app asks for the PIN after 30 minutes away; copying a paragraph from a work email into a personal notes app fails with a short message; attachments open only in Word, Excel or PowerPoint, not in a personal PDF app; saving to the phone's files or a personal cloud drive is blocked while OneDrive works; on Android, screenshots of work apps come out black. Teams behaves the same way.

A wipe is not instant: Microsoft's selective wipe documentation (June 2024) says "the user must open the app for the wipe to occur, and the wipe may take up to 30 minutes." Tell people this before rollout.

iOS vs Android differences

On iOS the broker is Microsoft Authenticator, which most users already have for MFA, and the only device-integrity check is the jailbreak block.

On Android, "the Intune Company Portal is required on the device to receive App Protection Policies for Android devices," installed but not enrolled. Android adds device-integrity settings iOS lacks: "Play integrity verdict," "Require device lock" and "Min patch version." The Android alternative is the personally owned work profile, which Microsoft compares with app protection on a dedicated page: the work profile is "a separate partition created at the Android OS level" with policies "enforced at the work profile level, not the app level," and it requires enrollment.

On personal Windows laptops, MAM protects Microsoft Edge only, and Microsoft's Conditional Access documentation still lists the Windows grant as in preview. A contractor who needs a full desktop on their own laptop is a Windows 365 Cloud PC case, and a company Mac is an Intune for macOS case.

Licensing: already in Business Premium and E3

App protection needs an Intune license on the user, not on the device. Microsoft's Intune licensing page (May 2026) says a device-only license does not support app protection policies. Microsoft 365 Business Premium ($264.00 per user per year, Microsoft list price, September 2026 price list) includes Intune Plan 1 and the Entra ID P1 that Conditional Access needs, as does Microsoft 365 E3 ($468.00 per user per year, same price list); Intune licensing explained lays out which plans include what.

A tenant on Business Standard or Office 365 E3 adds Microsoft Intune Plan 1 at $96.00 per user per year on an annual commitment, or $9.60 per user per month, plus Entra ID P1 at $84.00 per user per year (Microsoft list price, September 2026 price list).

The privacy conversation with staff

Rollouts fail on trust more than on technology. Write a one-page notice before the Conditional Access policy goes on, and put these facts in it. IT can see the work apps that carry the policy, the app version and the OS version. IT cannot see personal apps, photos, messages, browsing or location, and Microsoft's own documentation states that admins cannot read or erase data owned by the user. Leaving the firm removes the work data from the work apps and nothing else; the word "wipe" in the admin center means that, not a factory reset.

Then the trade: anyone who would rather not have work apps on a personal phone can use the web versions on a laptop, or the firm issues a phone. The one thing not to offer is an exception to the policy, because one unprotected Outlook is enough.

Frequently asked questions

Can Intune see my personal photos and texts on my phone?

No. App protection policies apply inside the work apps only. Microsoft's documentation states that IT admins cannot read, access or erase data owned or controlled by the user.

Do employees have to enroll their personal phone in Intune?

No. The policy works without enrollment. Users install Microsoft Authenticator (iOS) or the Company Portal app (Android) as a broker that registers the phone with Entra ID; no management profile is installed and IT cannot control the phone.

What happens to company data on a personal phone when an employee leaves?

A selective wipe removes work data from the work apps the next time they open, within about 30 minutes, and the "Disabled account" setting does it automatically once the account is disabled. Personal data is untouched.

Can I block the built-in Mail app on personal phones?

Yes. A Conditional Access policy that requires an app protection policy cannot be satisfied by the iOS Mail app or Gmail.

Sources

  • Microsoft Learn source files on GitHub (MicrosoftDocs/memdocs), opened 2026-09-27: "App protection policies overview", ms.date 03/04/2026; "MAM for unenrolled devices", 04/22/2024; "iOS/iPadOS app protection policy settings", 11/18/2025; "Android app protection policy settings", 03/02/2026; "Data protection framework", 06/12/2025; "App protection policies vs Android Enterprise work profiles", 06/12/2025; "How to wipe only corporate data from Intune-managed apps", 06/12/2024; "Data protection for Windows MAM", 10/02/2025; "Microsoft Intune licensing", 05/13/2026
  • Microsoft Learn source file on GitHub (MicrosoftDocs/entra-docs), opened 2026-09-27: "Grant controls in Conditional Access policy", ms.date 06/02/2026
  • Microsoft, "Microsoft Entra plans and pricing" (microsoft.com), opened 2026-09-27
  • IT Partner price sheet, Commercial segment, September 2026 US price list (Microsoft 365 Business Premium, Microsoft 365 E3, Microsoft Intune Plan 1, Microsoft Entra ID P1)
  • IT Partner pages linked above; IT Partner engineering notes from BYOD rollouts, September 2026
Setting (Microsoft's name) Our Level 2 value What the user notices
PIN for access; minimum PIN length; biometrics Require; 6; allowed PIN or Face ID after 30 minutes away
Send org data to other apps; Receive data from other apps Policy managed apps, dialer and maps excepted Attachments open only in Office apps
Save copies of org data; allowed services Block; OneDrive and SharePoint Saving to the phone or a personal cloud fails
Restrict cut, copy, and paste between other apps Policy managed apps with paste in Cannot paste work text into personal apps
Screen capture and Google Assistant (Android) Block Black screenshots in work apps
Max PIN attempts; Offline grace period 5, then wipe; block after 1,440 minutes, wipe after 90 days offline Data removed if the phone is lost
Jailbroken/rooted devices; Min OS version Block; two most recent major versions Old or modified phones refused
Conditional Access grant Require app protection policy (iOS and Android, Office 365 app) Native Mail and Gmail stop working for work mail

Key takeaways

  • App protection policies manage the app, not the phone: PIN, encryption, copy and paste limits and a wipe of work data only, with no enrollment.
  • The Conditional Access grant "Require app protection policy" makes it mandatory and sends users to the broker app (Authenticator on iOS, Company Portal on Android); the older approved-app grant is retiring.
  • About a dozen settings at Microsoft's Level 2 do the work; everything else stays at its default.
  • Licensing is the Intune Plan 1 and Entra ID P1 already in Business Premium and E3; standalone Intune Plan 1 is $96.00 per user per year (Microsoft list price, September 2026 price list).
  • Tell staff in writing what IT can and cannot see before the policy goes on, and do not grant exceptions.

Intune App Protection for BYOD Without Device Enrollment is $5 per user plus a $1,950 tenant fee over 1 week, fixed price and paid after approval: the iOS and Android policies at Level 2, the Conditional Access grant in report-only and then on, the staff notice, and the offboarding wipe procedure. Firms that want company-owned phones fully managed pair it with Microsoft Intune Initial Setup for iPhone and iPad Management ($4,500 per project, 2 weeks); for the Windows fleet, Microsoft Intune Initial Setup for Windows Device Management is $6,500 per project over 8 weeks. Licenses are on our Microsoft Intune Plan 1 and Microsoft 365 Business Premium pages at Microsoft's list price. Book a call with your phone count.

Questions this article didn’t answer?

Thirty minutes with Mike — our CEO, not a sales rep. Bring the hard version of the question.