First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Intune App Protection for BYOD Without Device Enrollment
ImplementationSecurity and Protection

Intune App Protection for BYOD Without Device Enrollment

Intune App Protection for BYOD Without Device Enrollment is a one-week, fixed-fee implementation that protects Microsoft 365 data inside the Microsoft apps on employees' personal iPhones, iPads and Android phones — without enrolling the device, and without IT seeing or controlling anything outside those apps. IT Partner designs and builds Intune app protection policies for Outlook, Teams, the Office apps, OneDrive and Edge (PIN or biometric, encryption, cut/copy/paste and save-as restrictions, managed-browser links, offline grace period, jailbroken and rooted-device block), enforces them with a Microsoft Entra Conditional Access policy that uses 'Require app protection policy' — the control that replaces 'Require approved client app', which Microsoft retired on June 30, 2026 — adds Windows MAM for Microsoft Edge where it fits, writes the selective-wipe runbook and the per-platform registration guide, and proves it on a pilot before the rollout wave. The fee is a tenant fee plus a per-user fee for the users you roll out to. Every user in scope needs an Intune licence (Intune Plan 1 is included in Microsoft 365 Business Premium, E3, E5 and F3); licences are yours and are not part of the fee. Corporate-owned devices that need device-level control are covered by the Intune enrollment services for iPhone and iPad, Android, Windows and macOS.

Timeline 1 weekService owner Roman SotnikMicrosoft IntuneMicrosoft Entra IDMicrosoft 365

What this engagement is

There are two ways to protect company data on a phone an employee owns, and choosing between them is the first decision. Mobile device management (MDM) enrolls the device: IT gains device-level control — compliance checks, OS-update rules, Wi-Fi and certificate profiles, full or selective wipe — and the employee accepts that the organization can see the device in Intune. Mobile application management (MAM) never enrolls the device. An Intune app protection policy lives inside each Microsoft app the employee signs into with a work account — Outlook, Teams, Word, Excel, PowerPoint, OneNote, OneDrive, SharePoint, Edge and the other apps built on the Intune App SDK. Inside that boundary IT can require a PIN or biometric, encrypt work data, stop it being copied, saved or shared into personal apps, and wipe it when someone leaves; outside that boundary the phone stays the employee's. For personal devices Microsoft's own guidance recommends MAM; for organization-owned devices it recommends enrollment, with MAM layered on top where specific apps need extra protection. This service is the MAM half. The enrollment half is Microsoft Intune Initial Setup for iPhone & iPad Management and Microsoft Intune Initial Setup for Android Device Management. IT Partner runs the readiness check (licences, existing Conditional Access, current MDM state, the apps people actually use on their phones, iOS/iPadOS and Android version spread), writes a one-page decision record for which users get MAM, which get enrollment and which get both, then builds the policies: one app protection policy for iOS/iPadOS and one for Android, targeted to unmanaged devices and to the Microsoft core apps, assigned to a security group; a Microsoft Edge app-configuration policy so links from Outlook and Teams open in the managed browser; and the Conditional Access policy that makes the whole thing enforceable — 'Require app protection policy' for iOS/iPadOS and Android, started in report-only, switched on for the pilot group, then for production. Where the organization has personal Windows PCs reaching Microsoft 365 through a browser, we add the optional Windows MAM policy for Microsoft Edge. We validate on a pilot of up to ten users, support the rollout wave, and hand over the selective-wipe runbook, the registration guides and the app-protection status report your administrators will use from then on. Why now: on June 30, 2026 Microsoft retired the Conditional Access grant 'Require approved client app'. Policies that still contain it are read-only — they can be disabled or deleted but not edited — and Microsoft's guidance is that every new policy use 'Require app protection policy' instead. Microsoft's current documentation says the old policies keep enforcing while they stay enabled; its earlier retirement notice said the grant would simply stop applying. Either way they can no longer follow your app mix or your user population, so treat them as a liability rather than a control. And the replacement grant only does anything if an Intune app protection policy is actually assigned to the user and the app — which is why this engagement builds both halves together and migrates any policy that still names the retired grant. The broader design of your Conditional Access estate is its own service: Microsoft Entra ID Conditional Access Policy Implementation; our article Microsoft Entra ID Conditional Access: Real-World Design Patterns shows where the app-protection grant sits in a full policy set and why policies should not be left in report-only. Who this is for: organizations of roughly 25–1,000 users on Microsoft 365 whose employees read mail and Teams on their own phones and tablets, and tenants whose Conditional Access still references the retired grant. Who it is not for: corporate-owned fleets that need device-level control (use the enrollment services), kiosk and shared devices, and organizations whose main exposure is a line-of-business app not built with the Intune App SDK — each of those is separately scoped. The fee has two parts. The tenant fee covers the design, the policies, the Conditional Access work, the pilot and the documentation. The per-user fee, counted for every user in the target group agreed at kickoff, covers the rollout support that scales with headcount — the registration guides, the wave communications, help-desk escalation for registration failures during the rollout window, and the app-protection status review before sign-off.

Success criteria

01Every user in the approved target group holds an Intune licence (Intune Plan 1 or a suite that includes it) and a Microsoft Entra ID P1 or P2 licence, confirmed from the tenant licence report before any policy is assigned.
02One iOS/iPadOS and one Android app protection policy exist, targeted to unmanaged devices and to the approved Microsoft app set, carrying the approved data-transfer, save-as, cut/copy/paste, encryption, PIN or biometric, offline-grace-period, jailbroken/rooted-device and minimum-OS settings, and assigned to the target security group.
03A Conditional Access policy requiring an app protection policy on iOS/iPadOS and Android for the approved resources is enabled for the target group, with break-glass accounts excluded and the report-only sign-in evidence reviewed before enforcement.
04Every existing Conditional Access policy that still references the retired 'Require approved client app' grant has a validated replacement and is disabled, with the before-and-after state recorded.
05On the pilot devices, work data behaves as designed on each platform: PIN or biometric prompt, blocked copy/paste and save-as into personal apps, links opening in Microsoft Edge, and native mail clients denied access — recorded in the pilot report.
06A selective wipe issued from the Intune admin center removes work data from the pilot user's apps and leaves personal data untouched, and the runbook reproduces the steps your administrators will follow.
07Where the optional Windows MAM policy is in scope, a personal Windows device that is not Microsoft Entra-joined or MDM-enrolled receives the Microsoft Edge policy and passes the matching Conditional Access check.
08Your administrators can read the app-protection status report, find users whose apps are not checked in, issue a selective wipe and walk a user through registration — demonstrated in the handover session.

What you receive

BYOD readiness assessment: licence coverage (Intune Plan 1, Microsoft Entra ID P1), every Conditional Access policy that references the retired 'Require approved client app' grant, current MDM state, the apps in use on personal devices (including native mail clients), iOS/iPadOS and Android version spread, existing app protection or app configuration policies, and any Mobile Threat Defense connector.
Decision record — MAM versus MDM per user population, the protected app set, the protection level measured against Microsoft's app protection data-protection framework (basic, enhanced or high), PIN and biometric rules, the data-transfer, save-as and cut/copy/paste positions, offline grace period, minimum OS and app versions, and whether Windows MAM is in scope — approved before anything is configured.
One iOS/iPadOS app protection policy and one Android app protection policy, targeted to unmanaged devices and assigned to the target security group, covering Outlook, Teams, Word, Excel, PowerPoint, OneNote, OneDrive, SharePoint, Microsoft Edge and the other Microsoft core apps you approve.
App configuration policies for managed apps where the design requires them — Microsoft Edge as the managed browser for links opened from Outlook and Teams, plus any approved Outlook or Teams settings.
Conditional Access: a new policy with 'Require app protection policy' for iOS/iPadOS and Android on the approved resources, staged report-only, then pilot, then production; a validated replacement and controlled disablement of every policy still using the retired grant; and a companion control so Exchange ActiveSync and other clients that cannot carry an app protection policy do not bypass it.
Optional Windows MAM policy for Microsoft Edge on personal Windows devices, with the Windows Security Center threat-defense connector and the matching Conditional Access policy, where the readiness check confirms the devices and tenant qualify.
Pilot validation report for up to ten users across iOS/iPadOS and Android (and Windows where in scope): registration, policy delivery, PIN, data-transfer blocks, managed-browser behaviour, native-mail denial and selective wipe, with unresolved items outside scope listed.
Rollout wave support for every user in the target group: a user communication template, per-platform registration guides (Microsoft Authenticator on iOS/iPadOS, Company Portal on Android, the Edge work profile on Windows), help-desk escalation for registration failures during the rollout window, and an app-protection status review before sign-off.
Selective-wipe and offboarding runbook: how to issue a MAM selective wipe from the Intune admin center, what it removes and what it leaves, the check-in timing users should expect, and the disabled-account conditional-launch action that blocks or wipes work data automatically when an account is disabled in Microsoft Entra ID.
As-built configuration, administrator operations and troubleshooting runbook (app-protection status report, 'not checked in' triage, policy-conflict checks), and a recorded administrator handover session.

How the work unfolds

Day 1 — Kickoff, readiness and decision record

Confirm licences and administrative access, inventory Conditional Access (flagging every policy that names the retired grant), current MDM state and the apps people use on their phones. Decide the populations (MAM, enrollment or both), the protected app set, the protection level, whether Windows MAM is in scope, the pilot users, success measures and client responsibilities. Count the target group for the per-user fee.

Day 2 — Policy build in report-only

Create the iOS/iPadOS and Android app protection policies targeted to unmanaged devices, the Microsoft Edge app configuration policy, the optional Windows MAM policy, and the Conditional Access policy with 'Require app protection policy' in report-only mode with break-glass exclusions. Build the companion control for clients that cannot carry a policy. Review the report-only sign-in evidence.

Day 3 — Pilot

Pilot users install the broker app (Microsoft Authenticator on iOS/iPadOS, Company Portal on Android) and sign in; verify PIN or biometric, encryption, data-transfer and save-as blocks, managed-browser links, native-mail denial and selective wipe on each platform. Switch the Conditional Access policy on for the pilot group. Correct in-scope issues and record results.

Day 4 — Rollout wave

Send the approved communications and registration guides, enable the Conditional Access policy for the target group in the agreed order, run help-desk escalation for registration failures, watch the app-protection status report, and disable each policy that still used the retired grant once its replacement is proven.

Day 5 — Status review, documentation and handover

Review who is checked in and who is not, close remaining registration issues, finalize the decision record, as-built, selective-wipe runbook and administrator runbook, run the recorded handover session, and confirm acceptance against the success criteria.

Prerequisites

An active Microsoft Intune tenant. No device-enrollment foundation is required — this service works whether or not you have ever enrolled a device — but an Intune licence must be assigned to every user in the target group. Intune Plan 1 is included in Microsoft 365 Business Premium, Microsoft 365 E3, E5 and F3 and in Enterprise Mobility + Security E3 and E5; other users need Microsoft Intune Plan 1 on its own.
Microsoft Entra ID P1 or P2 for every user covered by the Conditional Access policy (included in the same suites), and at least one break-glass account that will be excluded from the policy.
The Microsoft 365 licences the apps themselves need to accept a policy — an Exchange Online mailbox for Outlook, and Microsoft 365 Apps for Word, Excel and PowerPoint — as Microsoft's app protection requirements state.
Personal devices on iOS/iPadOS and Android versions supported by Intune and by the current Microsoft app releases; Android devices must have Google Play services. Devices without Google Play services (some regional models and AOSP builds) cannot be protected this way.
Willingness of users to install the broker app and the Microsoft apps from the public app stores: Microsoft Authenticator on iOS/iPadOS, Company Portal on Android. Company Portal is required on Android even though the device is never enrolled.
A client-controlled security group for the target population (or the criteria to build one) and a pilot group of up to ten users with at least one iOS/iPadOS and one Android device between them.
Approved administrative access to Microsoft Intune and Microsoft Entra Conditional Access, either through a delegated (GDAP) relationship or a client-provided account, for the duration of the engagement.
Disclosure of existing Conditional Access policies, Terms of Use, MFA design, any other MDM or UEM in use, existing app protection or app configuration policies, Mobile Threat Defense vendors, and Exchange Online mobile device access rules.
For the optional Windows MAM scope: personal Windows 11 (or Windows 10 version 20H2 or later with the update Microsoft requires) devices that are not Microsoft Entra-joined or MDM-enrolled to any tenant, running Microsoft Edge Stable; Microsoft's documentation excludes sovereign clouds for the Conditional Access grant, so government tenants should ask first.
A client project owner and technical decision-maker who can approve the decision record on Day 1, make pilot users available, approve the communications, and validate results within the one-week schedule; a help desk aware of the rollout timing.

Who does what

IT Partner

  • Lead the readiness assessment, the MAM-versus-MDM decision record, the protected-app and settings design, the pilot, the rollout wave and the acceptance review.
  • Build and assign the iOS/iPadOS and Android app protection policies, the Microsoft Edge app configuration policy and, where in scope, the Windows MAM policy and its threat-defense connector.
  • Create the Conditional Access policy with 'Require app protection policy', stage it report-only, pilot and production, build the companion control, and migrate and disable every policy that still uses the retired grant.
  • Write the per-platform registration guides and the user communication template, and validate registration and protection on the pilot devices.
  • Provide help-desk escalation for registration failures during the rollout window and review the app-protection status report before sign-off.
  • Test and document the selective-wipe procedure and the disabled-account action, and deliver the offboarding runbook.
  • Deliver the as-built configuration, the administrator operations and troubleshooting runbook, and a recorded handover session.
  • Document dependencies outside scope — unsupported apps, devices without Google Play services, Conditional Access redesign needs — for separate remediation.

Your team

  • Provide and maintain the Intune, Microsoft Entra ID and Microsoft 365 licences for every user in scope; licences are not part of the fee.
  • Provide the administrative access, the target security group (or its criteria), the pilot users and devices, and the disclosures listed under prerequisites.
  • Approve the decision record on Day 1: populations, protected apps, settings, offline grace, minimum versions, Windows MAM scope and the rollout order.
  • Own the BYOD statement to employees — what the policy does and does not touch on a personal phone — and approve and send the communications from the template we provide.
  • Ensure users install the broker app and the Microsoft apps, and provide first-line help desk during the rollout with escalation to IT Partner for registration failures.
  • Review the pilot report and the status review, give decisions within the one-week schedule, and approve acceptance against the success criteria.
  • Own ongoing operation after handover — new joiners' registration, selective wipes for leavers, policy changes as apps and OS versions move — unless separately contracted.
  • Provide change approvals and any required security or privacy review of the design before enforcement.

What's not included

Device enrollment and MDM — compliance policies, device configuration profiles, Wi-Fi, VPN and certificate profiles, OS-update rules and full device wipe all require enrollment and belong to Microsoft Intune Initial Setup for iPhone & iPad Management, Microsoft Intune Initial Setup for Android Device Management, Microsoft Intune Initial Setup for Windows Device Management and Microsoft Intune Initial Setup for macOS Device Management.
Conditional Access baseline design — MFA design, location and risk policies, tenant-wide policy redesign and trusted-device architecture. This engagement adds the app-protection policy and migrates the retired-grant policies only; the estate design is Microsoft Entra ID Conditional Access Policy Implementation.
Microsoft Defender for Endpoint and Mobile Threat Defense on personal devices. The threat-level conditional-launch settings are configured only where a Mobile Threat Defense connector already exists in the tenant; Defender for Endpoint on enrolled devices is Microsoft Defender for Endpoint Deployment for Intune-Managed Devices.
Corporate-owned device programs — Apple Business Manager and Automated Device Enrollment, Android Enterprise enrollment models, Windows Autopilot, Samsung Knox, Microsoft Entra shared device mode, kiosk and dedicated devices, and iOS User Enrollment or account-driven enrollment, which is a different management model.
Licences — Microsoft Intune Plan 1, Microsoft Entra ID P1 or P2, Microsoft 365 Apps and any Mobile Threat Defense subscription are purchased separately and are the customer's; no Microsoft charge is included in the fee.
Line-of-business and third-party apps — apps not built with the Intune App SDK cannot receive a policy; SDK integration, app wrapping and vendor troubleshooting are separately scoped. Third-party apps on Microsoft's protected-apps list can be added to the policy, but their vendor's behaviour is not warranted by this service.
Data classification and content controls — Microsoft Purview sensitivity labels, data loss prevention and retention. App protection governs where app data can move, not what the content is.
Identity and messaging work beyond the companion control — MFA and passwordless rollout, identity federation, Exchange Online mobile device access rule redesign, and remediation of applications that do not support modern authentication.
Ongoing operation after acceptance — new-joiner registration, leaver wipes, policy tuning as apps and OS versions move, and help desk beyond the rollout window — available through the Managed Microsoft Intune Service. Escalation to Microsoft under our Premier Support agreement is a paid add-on where a case needs it.
Commercial and logistics items — devices, carrier services, formal end-user training beyond the registration guides, travel, and taxes.

Limitations & technical notes

!What partners most often get wrong on BYOD app protection — three warnings worth reading first: (1) a policy nobody enforces — without the Conditional Access grant, users keep reading mail in the native mail app and the policy protects nothing, and Microsoft's own validation guidance notes users will not report it because they simply have unrestricted access; (2) the grant without the policy — 'Require app protection policy' blocks any app that cannot present a policy, so switching it on before the policy is assigned locks out your own users, which is why this engagement stages report-only, pilot, production; (3) forgetting the Android broker — the Company Portal app must be installed on Android even though the device is never enrolled, and communications that do not say so generate a help-desk queue.
!App protection governs data inside policy-managed apps only. It cannot see or control the device: no OS-update enforcement, no device-passcode enforcement beyond Android's 'require device lock' check, no control over personal apps, no full wipe. Organizations that need those controls should enroll the device instead of, or as well as, applying app protection.
!Boundary caveats Microsoft documents: on iOS/iPadOS the share extension can still open work data in unmanaged apps because app protection cannot control the share sheet without managing the device; screen-capture blocking for work data is a policy setting on both platforms, but nothing prevents a photograph of the screen. App protection reduces data leakage; it does not eliminate it.
!Broker apps and registration: the Conditional Access grant requires the device to be registered in Microsoft Entra ID through Microsoft Authenticator on iOS/iPadOS or Company Portal on Android. Registration is not enrollment — the device appears as registered, not managed — but the words used in user communications matter, and ours say exactly that.
!Windows MAM covers Microsoft Edge only, on personal Windows devices that are not Microsoft Entra-joined or MDM-enrolled to any tenant. Microsoft's Intune documentation describes it as available for supported Windows versions, while its Conditional Access documentation still labelled the Windows app-protection grant as preview at the time of writing; the Windows Security Center threat-defense connector requires Windows 11 version 23H2 or later. We treat Windows MAM as optional and confirm eligibility in the readiness check.
!Android devices need Google Play services; the Play integrity verdict needs the device online at check time. Devices without Google Play services, Microsoft Teams Android devices, and Android Enterprise dedicated devices without shared device mode cannot be protected this way.
!The retired grant: Microsoft's documentation states that since June 30, 2026 Conditional Access policies containing 'Require approved client app' are read-only — they can be disabled or deleted, not edited — and continue to be enforced while enabled; Microsoft's earlier retirement notice said the grant would stop applying. We rely on it either way for nothing: the replacement is built, proven on the pilot, and the old policy disabled in a controlled step.
!Policy delivery and wipe are not instant. Apps pick up policy at sign-in and at check-in; a selective wipe takes effect at the next app launch or at the Intune SDK's periodic check, which Microsoft documents as every 30 minutes while the app is in use. Users offline beyond the grace period are blocked, not wiped, unless the decision record says otherwise.
!Apps that do not support the grant are blocked by design — that includes native mail and calendar clients, which is the point — and Microsoft lists a few apps (Kaizala, Skype for Business, Visio) that never supported it. The readiness check surfaces any app your users depend on that falls outside the protected-apps list before enforcement.
!If a device later enrolls in Intune MDM, the policy targeted to unmanaged devices stops applying to it; estates that run both models need a policy set for each management state. The unmanaged set is built here; the managed set is configured by the enrollment services.
!The one-week schedule assumes licences assigned before kickoff, pilot users available on Day 3, the decision record approved on Day 1, and no dependency on a Conditional Access redesign. Client-side delays move the completion date rather than the scope.
!The fee covers one tenant, one iOS/iPadOS and one Android app protection policy plus the optional Windows Edge policy, the Microsoft core apps, one new Conditional Access policy and the migration of retired-grant policies, a pilot of up to ten users, and rollout support for the target group counted at kickoff. Additional policy sets (for example, different settings for contractors), third-party apps or additional populations are a written, approved change in scope; organizations above roughly 1,000 users are quoted as a scoped project.
!App protection improves control over where company data can go, but no management platform can guarantee prevention of every data-loss event, security incident, service outage, registration failure or compliance issue. Technical content reviewed September 2026.

Frequently asked questions

MAM or MDM — which one do we need for personal phones?

Start from who owns the device and what you need to control. If the phone is the employee's and you need to protect the company data in Outlook, Teams, the Office apps, OneDrive and Edge, app protection (MAM) does that without enrolling the device and without IT seeing the rest of the phone — Microsoft's guidance recommends it for personal devices. If the device is organization-owned, or you need device-level controls — OS-update rules, Wi-Fi and certificate profiles, a compliance check before access, a full wipe — you need enrollment (MDM), and Microsoft recommends enrolling organization-owned devices and layering app protection on top where specific apps need it. Most organizations end up with both: MAM for personal phones, MDM for corporate ones. This engagement writes that split down in a decision record on Day 1 and builds the MAM half; the MDM half is the Intune enrollment service for each platform.

What can IT see and do on my personal phone with app protection?

Inside the Microsoft apps you sign into with your work account: IT can require a PIN or biometric, encrypt the work data, stop it being copied, saved or shared into personal apps, require links to open in Microsoft Edge, block the apps on a jailbroken or rooted phone, and remove the work data — only the work data — when you leave. Outside those apps: nothing. The device is not enrolled, so IT cannot see your personal apps, photos, messages or location, cannot push settings to the phone and cannot wipe it. The phone does get registered with Microsoft Entra ID through Microsoft Authenticator (iOS) or Company Portal (Android) so Conditional Access can recognise it; registration is not enrollment, and the registration guide we hand over explains the difference in plain words.

Microsoft retired 'Require approved client app' on June 30, 2026 — what does that mean for us?

Any Conditional Access policy that still uses that grant became read-only on that date: you can disable or delete it, but not edit it, and new policies can only use 'Require app protection policy'. Microsoft's current documentation says the old policies keep enforcing while enabled; its earlier retirement notice said the grant would stop applying. Either way you cannot adapt them to a new app or a new group of users, so they no longer function as a control you can manage. The replacement grant only works when an Intune app protection policy is actually assigned to the user and the app — so the fix is not a one-line policy edit; it is building the app protection policies, adding the new grant, proving it on a pilot and then disabling the old policy. That is exactly the sequence in this engagement.

Which apps are protected?

Any app built with the Intune App SDK that a user signs into with a work account: Outlook, Teams, Word, Excel, PowerPoint, OneNote, OneDrive, SharePoint, Microsoft Edge, To Do, Planner, Loop, Viva Engage, Power BI, Power Apps and the rest of Microsoft's protected-apps list, plus third-party apps their vendors have integrated with the SDK. Native mail, calendar and browser apps cannot receive a policy, so the Conditional Access grant denies them access to work data — which is the intended outcome. Line-of-business apps your developers built need the SDK or app wrapping first; that is separately scoped.

What does the user actually experience?

On iOS or iPadOS they install Microsoft Authenticator if they do not already have it, sign into Outlook or Teams with their work account, accept a short registration prompt, and set an app PIN or use Face ID or Touch ID. On Android they install Company Portal and the Microsoft apps, sign in, and Company Portal registers the device — it does not enroll it — then they set the PIN. From then on the work apps ask for the PIN or biometric after the inactivity period you chose, copy and paste into personal apps is blocked or limited as designed, save-as offers only approved locations such as OneDrive, and links open in Edge. Personal apps are untouched. Users may need to restart an app once for the policy to apply; the registration guides cover that.

Can people keep using the built-in Mail app on their iPhone?

No — and that is deliberate. The native Mail app cannot carry an Intune app protection policy, so once 'Require app protection policy' is enforced it is denied access to the mailbox. Users move to Outlook, where the policy applies. The readiness check finds who is on native mail today, the communications tell them what to install and when, and the rollout is ordered so nobody is cut off before they have Outlook working. The companion control we build makes sure Exchange ActiveSync clients cannot slip around the policy either.

What happens when an employee leaves?

Two things, and both are in the runbook. First, disabling the account in Microsoft Entra ID triggers the 'disabled account' conditional-launch action, which blocks or wipes the work data in the protected apps automatically at the next check-in. Second, an administrator can issue a selective wipe from the Intune admin center for any user at any time — it removes the work data from the Microsoft apps on that device and leaves personal data alone. The wipe takes effect at the next app launch or the SDK's periodic check, which Microsoft documents as every 30 minutes while the app is running. Nothing about this requires the device to be enrolled or the employee to hand the phone over.

Which licences do we need?

Every user in scope needs an Intune licence and Microsoft Entra ID P1 or P2 for the Conditional Access policy. Both are included in Microsoft 365 Business Premium, E3, E5 and F3 and in Enterprise Mobility + Security E3 and E5; if you are on Business Basic or Standard, Intune Plan 1 and Entra ID P1 can be added per user. Outlook also needs an Exchange Online mailbox and the Office apps need Microsoft 365 Apps — Microsoft's stated requirements for the apps to accept a policy. We confirm all of this from your licence report on Day 1, before any policy is assigned. Licences are yours and are not part of our fee; the subscription pages linked from this page show current pricing.

Does this cover employees' personal Windows laptops?

Partly, and we are careful about it. Windows MAM applies an app protection policy to Microsoft Edge on a personal Windows device that is not joined or enrolled to any tenant — so work sites opened in Edge get the protections, and Conditional Access can require it. It covers Edge only: not Outlook desktop, not Office desktop apps, not the file system. Microsoft's Intune documentation describes it as available, while its Conditional Access documentation still labelled the Windows grant as preview at the time of writing, so we treat it as optional and confirm your devices qualify in the readiness check. If people need full Office on a personal PC, the answer is usually a managed device, Windows 365 or Azure Virtual Desktop — a different conversation we will have with you honestly.

How much does it cost, and what does 'per user' mean?

The fee is a tenant fee plus a per-user fee — see the price on this page. The tenant fee covers the design, the policies, the Conditional Access work, the pilot and the documentation. The per-user fee is counted once for every user in the target group agreed at kickoff and covers the rollout support that scales with headcount: registration guides, communications, help-desk escalation during the rollout window and the status review before sign-off. Worked example on the listed rates: 100 users is $500 plus the $1,950 tenant fee, $2,450 in total; 250 users is $3,200. Organizations above roughly 1,000 users are quoted as a scoped project. Licences are separate. The price is fixed in writing before work begins, and you pay after you approve delivery.

How long does it take?

One week: readiness and the decision record on Day 1, policies built in report-only on Day 2, pilot on Day 3, rollout wave on Day 4, status review and handover on Day 5. That assumes licences are assigned before kickoff, the decision record is approved on Day 1, pilot users are available on Day 3 and no Conditional Access redesign is needed first. Very large or multi-region rollouts can be staged in waves after the pilot; that changes the calendar, not the scope.

We already manage corporate phones with Intune. Does this conflict?

No — it completes the picture. App protection policies are targeted by management state, so the policies built here apply to unmanaged devices and leave your enrolled fleet alone; if you also want app-level protection on enrolled devices, that is a second policy set targeted to managed devices, which the decision record covers and the enrollment services configure. The Conditional Access policy is written so an enrolled, compliant device or an app carrying a protection policy both satisfy it — one policy, both populations.

We already have some app protection policies. Is this still the right service?

Usually yes. Existing policies are often unassigned, assigned to the wrong group, targeted to all device types instead of unmanaged ones, or never enforced by Conditional Access — which the June 2026 retirement made visible for many tenants. The readiness check reviews what is there, the decision record says what to keep, merge or replace, and the fee is the same fixed price. We do not rebuild what already works.

Does app protection stop screenshots or someone photographing the screen?

Screenshots of work data can be blocked as a policy setting on iOS/iPadOS and Android, and we can enable it where the decision record calls for it. A photograph of the screen with another device cannot be prevented by any software, and on iOS the share sheet can still hand work content to an unmanaged app because Microsoft's app protection does not control the share extension without managing the device. App protection makes accidental and casual leakage hard; it is not a defence against a determined insider, and we say so rather than oversell it.

What happens after handover?

You receive the decision record, the as-built configuration, the selective-wipe and offboarding runbook, the administrator runbook, the registration guides and the recorded handover session, and your administrators run it: new joiners register, leavers are wiped, and policies are adjusted as apps and OS versions move. If you would rather we ran it, the Managed Microsoft Intune Service covers ongoing operation. Organizations that buy their Microsoft licensing through IT Partner also get break-fix support during business hours at no extra charge, so a registration problem after handover is a ticket, not a quote.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$5 per user + $1,950 tenant fee
1 week
Book a BYOD scoping call