Appearance
Runbook: Intune Mobile Application Management (MAM) for Personal Phones
Purpose
Staff access corporate email, Teams chat, and SharePoint from personal phones. Requiring full MDM enrollment on a personal device is an over-reach — it gives IT rights over personal apps and photos, and pushes users to find workarounds (IMAP, webmail on a browser) that are harder to govern than the M365 mobile apps. Intune MAM protects corporate data inside the Microsoft 365 mobile apps without enrolling the device itself. This runbook describes the policies to deploy, what they cover, and how users experience them.
Related story: FIDO2-015. Related:
runbooks/intune-usb-storage-block.mdrunbooks/twingate-compliance-enforcement.md
What MAM Covers (vs. MDM)
| Capability | MAM (this runbook) | MDM (full enrollment) |
|---|---|---|
| Manage the device (lock, locate, wipe entire phone) | No | Yes |
| Install corporate apps remotely | No | Yes |
| Enforce OS-level passcode | No (app-level PIN only) | Yes |
| Prevent copy/paste from corp apps to personal apps | Yes | Yes |
| Prevent Save As to personal storage | Yes | Yes |
| Require app-level PIN / biometric | Yes | — |
| Selectively wipe only corporate data | Yes | Yes (and whole device) |
| Require compliant device for access | App-protection policy + device check | Full compliance policy |
| Visibility into personal apps | None (privacy-preserving) | Full inventory |
| Appropriate for | BYOD / personal phones | Company-owned phones |
MAM is the right answer for BYOD. MDM is the right answer for company-provisioned phones, which we do not currently issue.
Target Apps (iOS and Android)
Policies apply to the Microsoft 365 mobile apps in their MAM-aware form:
- Outlook (iOS / Android)
- Teams (iOS / Android)
- OneDrive (iOS / Android)
- SharePoint (iOS / Android)
- Microsoft Word / Excel / PowerPoint (if used on mobile — optional)
- Edge mobile (optional; corporate browsing in Edge on mobile benefits from the same restrictions)
Users must sign into these apps with their corporate account. The apps detect the MAM policy at sign-in and apply protections automatically.
App Protection Policy — Settings
Path in Intune
Intune admin center → Apps → App protection policies → Create policy
Two policies total — one per platform (iOS, Android) — because the setting catalogs differ. Keep settings identical across platforms except where noted.
Policy name
- iOS:
cirius-mam-ios-m365 - Android:
cirius-mam-android-m365
Target apps
- Include the target apps list above
Data protection
| Setting | Value | Rationale |
|---|---|---|
| Backup org data to iTunes/iCloud/Google backup | Block | Prevent corporate data ending up in personal cloud backups |
| Send org data to other apps | Policy managed apps (or "Policy managed apps with OS sharing" on iOS for better UX) | Prevents sharing corp data to WhatsApp, personal email, etc. |
| Receive data from other apps | Policy managed apps | Prevents uncontrolled import of data into corp context |
| Restrict cut, copy, and paste between other apps | Policy managed apps with paste-in | Corp → personal paste blocked; personal → corp paste allowed (less friction) |
| Save copies of org data | Block | Prevents Save As to personal OneDrive Personal, local storage |
| Allow user to save copies to selected services | OneDrive for Business, SharePoint (corp) | Explicit permitted destinations |
| Encrypt org data | Require | Always-on encryption of data at rest inside the app |
| Sync policy-managed app data with native apps | Block | No bleed-over to native iOS Mail, Contacts, etc. |
| Printing org data | Block | Blanket prohibition avoids uncontrolled print trails |
| Third-party keyboards | Block (iOS), Warn (Android) | Third-party keyboards can exfiltrate what users type |
Access requirements
| Setting | Value |
|---|---|
| PIN for access | Require |
| PIN type | Passcode (numeric or alphanumeric user choice; minimum 4 digits) |
| PIN complexity | Require alphanumeric on iOS; Passcode minimum 6 digits on Android |
| Simple PIN | Block |
| Fingerprint / FaceID / biometric instead of PIN | Allow |
| Override biometric with PIN after timeout | 30 days |
| PIN attempts before reset | 5 |
| Work account credentials for access | Require |
| Recheck access requirements after inactivity | 30 minutes |
| Offline grace period (days) | 7 |
| Jailbroken / rooted devices | Block access |
Conditional launch (additional runtime checks)
| Check | Action |
|---|---|
| Min OS version (iOS) — current minus 2 majors | Block access |
| Min OS version (Android) — current minus 2 majors | Block access |
| Rooted / jailbroken | Block access |
| Device attestation (Google Play Protect on Android, DeviceCheck on iOS) | Require |
| Max PIN attempts exceeded | Wipe corporate data |
| Offline grace period exceeded | Block access |
| Min patch version (Android) | Block access (rolling 90-day target) |
Assignment
- Included groups:
AllStaff(Entra security group covering all licensed M365 users) - Excluded groups: None by default
MAM policies apply regardless of whether the device is Intune-enrolled.
User Experience — What Staff See
- First sign-in to Outlook / Teams / etc. after policy is deployed: User is prompted to set an app PIN or confirm biometric use
- During use: No visible difference for standard email / chat / file operations on corporate content
- Attempting to copy text from Outlook into WhatsApp: Paste is blocked and user sees a brief message explaining that corporate data cannot be pasted outside managed apps
- Attempting to Save As a Word document to the personal photos app: Blocked, with an explanatory message
- If the phone is lost and the user contacts IT to initiate corporate wipe: Rory issues a selective wipe from Intune — corporate data in the managed apps is deleted, personal apps and photos are untouched
- If user changes phones: Sign into the M365 apps on the new phone; policy re-applies; old phone's corporate data can be selectively wiped from the Intune console
Deployment Plan
Pre-flight (Day -7):
- Confirm AllStaff group membership is current
- Draft staff communication (below) — preview to Rory and Adriana
Pilot (Day 0):
- Assign the policy to a pilot group containing Rory + one volunteer
- Each pilot user signs out of all M365 apps on their phone, signs back in, confirms PIN setup and basic email/Teams operation
Broad rollout (Day 3):
- Switch assignment to AllStaff
- Send the staff communication
Watch window (Day 3–14):
- Respond to any "I can't do X" reports — most common is paste behavior
- Adjust settings only with documented justification; err on the side of keeping protections and providing the user an alternative path
Staff Communication (template)
Subject: Protecting corporate data on personal phones — app protection policies starting [date]
To help protect patient data and corporate information on the phones we use every day, we are deploying Intune App Protection policies to the Microsoft 365 mobile apps (Outlook, Teams, OneDrive, SharePoint).
What this means for you:
- You will be asked to set a PIN (or use Face ID / fingerprint) when you open Outlook or Teams on your phone for the first time after [date].
- You will still use your phone normally. These policies apply only to the M365 apps, not to your personal apps or photos.
- Copying or forwarding corporate data to personal apps (like WhatsApp, personal Gmail) will be blocked. If you have a workflow where you regularly needed to do this, please reply so we can find a compliant alternative together.
- If your phone is lost or stolen, IT can remove corporate data from the M365 apps without touching your personal apps or photos.
You do not need to do anything before [date]. If you have concerns or questions, reply to this email.
Rollback and Exceptions
- Rollback: Disable the policy assignment; policy unwinds within 30 minutes on next app launch. Historically protected data remains protected until removed by the user.
- Selective wipe (lost device): Intune admin center → Apps → App selective wipe. User-scoped, device-scoped, reversible within 48 hours if the device is recovered.
- Exceptions: File a SecOps story in COMP project. Exceptions should be per-setting (e.g. "allow save to personal OneDrive for user X for justified reason") not per-user-wholesale.
Compliance Mapping
- HIPAA 164.308(a)(5)(ii)(A) — security reminders and training (via policy prompts)
- HIPAA 164.310(d)(1) — device and media controls (selective wipe)
- HIPAA 164.312(a)(1) — access control on PHI
- HIPAA 164.312(e)(1) — transmission security (encrypted app container)
- SOC2 CC6.1 / CC6.7 — access and transmission controls
- SOC2 CC9.2 — vendor (employee-owned device) risk management
Auditor evidence:
- Policy configuration screenshots
- Intune app protection status report showing coverage across target populations
- Selective wipe log for any wipe events (demonstrates the process works)