Microsoft 365 Endpoint AdministratorManage identity and compliance (10-15%)Easy
A company policy dictates that all unmanaged devices accessing Microsoft 365 services must use a compliant app for email and document viewing. You need to implement this policy to ensure that devices not enrolled in Intune still adhere to security standards. Which Microsoft Intune feature should you configure?
- AConditional Access policies
- BDevice configuration profiles
- CApp protection policies
- DDevice compliance policies
Show answer & explanationAnswer & explanation
Correct answer: C. App protection policies
App protection policies (APP) are designed to protect organizational data within applications, even on unmanaged devices. They define what actions users can take with corporate data within compliant apps.
Why the other options are wrong
- A. Conditional Access policies control access to resources based on conditions, but APP ensures data protection *within* apps after access is granted.
- B. Device configuration profiles manage settings and features on managed devices, not unmanaged devices.
- D. Device compliance policies assess the health and compliance of managed devices, not unmanaged ones.
App protection policies (APP)
Rules that ensure an organization's data remains safe or contained in a managed app, even on unmanaged devices. They prevent data leakage and enforce security requirements within the app itself.
- Protect organizational data at the app level.
- Can be applied to both managed and unmanaged devices.
- Control actions like copy/paste, save-as, and access to corporate data.
Memory trick: Apps Protect Data Everywhere, securing your digital sphere.