Skip to main content

πŸš¦πŸŸ’πŸ“±CA - Require MAM AppProPol or Compliant Device πŸ€–

The BYOD-friendly cousin of full device compliance. Office 365 on Android only through a managed app, or from a phone the tenant fully controls. The user's personal photos stay theirs.

🚦Type Conditional Access🟒Action Grant, require MAM or compliantπŸ“±Target Android devices
reference-build Β· ca-mam-or-compliant-androidGolden Master reference
License tier
Business Premium (Entra ID P1)
Control plane
Entra Conditional Access + Intune
Scope
Android, Office 365, app clients
Reversibility
report-only first, clean-revert

What this policy is about πŸ€–β€‹

Requiring a fully compliant device works beautifully on a corporate laptop and terribly on the phone in someone's pocket. Nobody wants their private Android enrolled to the day job, and you do not want the wipe button for their holiday photos. So this policy offers a choice: reach Office 365 from Android either through an approved client app carrying an app protection policy (MAM), or from a fully compliant device. Either satisfies it. Anything else gets a polite no.

That is the whole trick. Corporate control lands on the company data inside the app, not on the whole handset, and BYOD stops being a security hole.

πŸ€” The catch

App protection guards the app, not the phone. It keeps corporate mail and files inside Outlook and Teams, encrypted and un-copyable into WhatsApp, but it does nothing about a jailbroken OS or a dodgy keyboard. It is a container around your data, not a health check on the device. That is the trade you are making for BYOD, and it is usually the right one.

Why this matters πŸ•΅οΈβ€‹

Say no to personal Android entirely and users route around you: they forward mail to a private account, screenshot the roster, paste the customer list into a chat app, and now your data is somewhere you have zero controls at all. Shadow IT is what happens when the sanctioned path is too painful, and "enrol your personal phone or go without" is exactly that kind of pain.

MAM gives you a sanctioned path that people will actually take. Corporate data lives inside managed Outlook and Teams, protected by a PIN, encrypted at rest, and blocked from leaking into unmanaged apps, while the rest of the phone stays the user's own business. Like Data reciting Starfleet protocol, the app follows the rules precisely without anyone having to seize the whole machine to make it happen. And for the users who do carry a fully managed corporate phone, compliance still counts, so nobody with a locked-down device gets stopped for lacking the MAM path.

πŸ› οΈ Configuration​

Where: Entra admin center β†’ Protection β†’ Conditional Access β†’ Policies.

CA policy diagram: Android platform, Office 365, require app protection policy or compliant device

SettingValue
Users, includeAll users
Users, excludeπŸ›‘οΈπŸ§‘β€πŸ’Όβ›“οΈπŸ”“πŸš¦Group - Break the Glass solution
πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“πŸš¦Group - No compliant device required for πŸ’»πŸͺŸ users
πŸ›‘οΈπŸ§‘β€πŸ’ΌπŸ‘ˆπŸ”“πŸš¦Group - No compliant device required for πŸ“±πŸ€– users
Conditions, device platformsAndroid
Conditions, client appsMobile app and desktop clients
Target resourcesOffice 365
GrantRequire one of: App protection policy, or compliant device
SessionNone

The two grant controls are an OR, not an AND, which is the point: a fully managed corporate phone passes on compliance, a personal phone passes by using a managed app. Every other grant control in the screenshot is greyed out, so MFA and the rest are handled by their own policies and not stacked in here.

Report-only first, always. Enforce this cold and any user whose Android is neither compliant nor running an app protection policy is locked out of mobile Office 365 on the spot. Run it in Report-only, confirm the app protection policies are deployed and phones are actually landing in a managed app, then flip to On.

Caveats βš οΈβ€‹

App protection needs the policy behind it. This CA rule checks for a MAM verdict; the Android app protection policies are what create that verdict and set the PIN, encryption and copy-paste rules. Without them assigned, "requires app protection" is a gate guarding nothing.

Only managed apps make it through. The path only exists for apps that support app protection: Outlook, Teams, the Office apps, Edge. The stock Gmail app or a native mail client cannot carry the policy, so they get blocked, and that surprises users who never opened Outlook on their phone. Communicate it before you enforce.

MAM is a container, not a compliance check. A rooted device or a malicious keyboard is outside its remit. Where the risk profile demands the whole phone be trustworthy, require compliance instead of accepting MAM, and accept that BYOD gets harder.

License and reversibility. Conditional Access is Entra ID P1 and Intune app protection is core, both included in Business Premium. Clean-revert: set it to Off and unmanaged Android reaches Office 365 again, which is why a disabled mobile-gate belongs in drift detection as a door that reopened with nobody watching.


Corporate data in a managed app, personal phone left alone: BYOD that neither side has to lie about. πŸ€–