Skip to content

Runbook: Intune Mobile Application Management (MAM) for Personal Phones

Purpose

Staff access corporate email, Teams chat, and SharePoint from personal phones. Requiring full MDM enrollment on a personal device is an over-reach — it gives IT rights over personal apps and photos, and pushes users to find workarounds (IMAP, webmail on a browser) that are harder to govern than the M365 mobile apps. Intune MAM protects corporate data inside the Microsoft 365 mobile apps without enrolling the device itself. This runbook describes the policies to deploy, what they cover, and how users experience them.

Related story: FIDO2-015. Related:

  • runbooks/intune-usb-storage-block.md
  • runbooks/twingate-compliance-enforcement.md

What MAM Covers (vs. MDM)

CapabilityMAM (this runbook)MDM (full enrollment)
Manage the device (lock, locate, wipe entire phone)NoYes
Install corporate apps remotelyNoYes
Enforce OS-level passcodeNo (app-level PIN only)Yes
Prevent copy/paste from corp apps to personal appsYesYes
Prevent Save As to personal storageYesYes
Require app-level PIN / biometricYes
Selectively wipe only corporate dataYesYes (and whole device)
Require compliant device for accessApp-protection policy + device checkFull compliance policy
Visibility into personal appsNone (privacy-preserving)Full inventory
Appropriate forBYOD / personal phonesCompany-owned phones

MAM is the right answer for BYOD. MDM is the right answer for company-provisioned phones, which we do not currently issue.


Target Apps (iOS and Android)

Policies apply to the Microsoft 365 mobile apps in their MAM-aware form:

  • Outlook (iOS / Android)
  • Teams (iOS / Android)
  • OneDrive (iOS / Android)
  • SharePoint (iOS / Android)
  • Microsoft Word / Excel / PowerPoint (if used on mobile — optional)
  • Edge mobile (optional; corporate browsing in Edge on mobile benefits from the same restrictions)

Users must sign into these apps with their corporate account. The apps detect the MAM policy at sign-in and apply protections automatically.


App Protection Policy — Settings

Path in Intune

Intune admin center → Apps → App protection policies → Create policy

Two policies total — one per platform (iOS, Android) — because the setting catalogs differ. Keep settings identical across platforms except where noted.

Policy name

  • iOS: cirius-mam-ios-m365
  • Android: cirius-mam-android-m365

Target apps

  • Include the target apps list above

Data protection

SettingValueRationale
Backup org data to iTunes/iCloud/Google backupBlockPrevent corporate data ending up in personal cloud backups
Send org data to other appsPolicy managed apps (or "Policy managed apps with OS sharing" on iOS for better UX)Prevents sharing corp data to WhatsApp, personal email, etc.
Receive data from other appsPolicy managed appsPrevents uncontrolled import of data into corp context
Restrict cut, copy, and paste between other appsPolicy managed apps with paste-inCorp → personal paste blocked; personal → corp paste allowed (less friction)
Save copies of org dataBlockPrevents Save As to personal OneDrive Personal, local storage
Allow user to save copies to selected servicesOneDrive for Business, SharePoint (corp)Explicit permitted destinations
Encrypt org dataRequireAlways-on encryption of data at rest inside the app
Sync policy-managed app data with native appsBlockNo bleed-over to native iOS Mail, Contacts, etc.
Printing org dataBlockBlanket prohibition avoids uncontrolled print trails
Third-party keyboardsBlock (iOS), Warn (Android)Third-party keyboards can exfiltrate what users type

Access requirements

SettingValue
PIN for accessRequire
PIN typePasscode (numeric or alphanumeric user choice; minimum 4 digits)
PIN complexityRequire alphanumeric on iOS; Passcode minimum 6 digits on Android
Simple PINBlock
Fingerprint / FaceID / biometric instead of PINAllow
Override biometric with PIN after timeout30 days
PIN attempts before reset5
Work account credentials for accessRequire
Recheck access requirements after inactivity30 minutes
Offline grace period (days)7
Jailbroken / rooted devicesBlock access

Conditional launch (additional runtime checks)

CheckAction
Min OS version (iOS) — current minus 2 majorsBlock access
Min OS version (Android) — current minus 2 majorsBlock access
Rooted / jailbrokenBlock access
Device attestation (Google Play Protect on Android, DeviceCheck on iOS)Require
Max PIN attempts exceededWipe corporate data
Offline grace period exceededBlock access
Min patch version (Android)Block access (rolling 90-day target)

Assignment

  • Included groups: AllStaff (Entra security group covering all licensed M365 users)
  • Excluded groups: None by default

MAM policies apply regardless of whether the device is Intune-enrolled.


User Experience — What Staff See

  1. First sign-in to Outlook / Teams / etc. after policy is deployed: User is prompted to set an app PIN or confirm biometric use
  2. During use: No visible difference for standard email / chat / file operations on corporate content
  3. Attempting to copy text from Outlook into WhatsApp: Paste is blocked and user sees a brief message explaining that corporate data cannot be pasted outside managed apps
  4. Attempting to Save As a Word document to the personal photos app: Blocked, with an explanatory message
  5. If the phone is lost and the user contacts IT to initiate corporate wipe: Rory issues a selective wipe from Intune — corporate data in the managed apps is deleted, personal apps and photos are untouched
  6. If user changes phones: Sign into the M365 apps on the new phone; policy re-applies; old phone's corporate data can be selectively wiped from the Intune console

Deployment Plan

  1. Pre-flight (Day -7):

    • Confirm AllStaff group membership is current
    • Draft staff communication (below) — preview to Rory and Adriana
  2. Pilot (Day 0):

    • Assign the policy to a pilot group containing Rory + one volunteer
    • Each pilot user signs out of all M365 apps on their phone, signs back in, confirms PIN setup and basic email/Teams operation
  3. Broad rollout (Day 3):

    • Switch assignment to AllStaff
    • Send the staff communication
  4. Watch window (Day 3–14):

    • Respond to any "I can't do X" reports — most common is paste behavior
    • Adjust settings only with documented justification; err on the side of keeping protections and providing the user an alternative path

Staff Communication (template)

Subject: Protecting corporate data on personal phones — app protection policies starting [date]

To help protect patient data and corporate information on the phones we use every day, we are deploying Intune App Protection policies to the Microsoft 365 mobile apps (Outlook, Teams, OneDrive, SharePoint).

What this means for you:

  • You will be asked to set a PIN (or use Face ID / fingerprint) when you open Outlook or Teams on your phone for the first time after [date].
  • You will still use your phone normally. These policies apply only to the M365 apps, not to your personal apps or photos.
  • Copying or forwarding corporate data to personal apps (like WhatsApp, personal Gmail) will be blocked. If you have a workflow where you regularly needed to do this, please reply so we can find a compliant alternative together.
  • If your phone is lost or stolen, IT can remove corporate data from the M365 apps without touching your personal apps or photos.

You do not need to do anything before [date]. If you have concerns or questions, reply to this email.


Rollback and Exceptions

  • Rollback: Disable the policy assignment; policy unwinds within 30 minutes on next app launch. Historically protected data remains protected until removed by the user.
  • Selective wipe (lost device): Intune admin center → Apps → App selective wipe. User-scoped, device-scoped, reversible within 48 hours if the device is recovered.
  • Exceptions: File a SecOps story in COMP project. Exceptions should be per-setting (e.g. "allow save to personal OneDrive for user X for justified reason") not per-user-wholesale.

Compliance Mapping

  • HIPAA 164.308(a)(5)(ii)(A) — security reminders and training (via policy prompts)
  • HIPAA 164.310(d)(1) — device and media controls (selective wipe)
  • HIPAA 164.312(a)(1) — access control on PHI
  • HIPAA 164.312(e)(1) — transmission security (encrypted app container)
  • SOC2 CC6.1 / CC6.7 — access and transmission controls
  • SOC2 CC9.2 — vendor (employee-owned device) risk management

Auditor evidence:

  • Policy configuration screenshots
  • Intune app protection status report showing coverage across target populations
  • Selective wipe log for any wipe events (demonstrates the process works)

Internal use only — Cirius Group