An employee wants Outlook and Teams on a personal phone. The company needs to protect work data without managing the entire device. Intune MAM without MDM enrollment can do this, provided the licences, supported apps, policy targeting and Conditional Access are aligned.
Public inquiries about Intune often look similar: an administrator sets up an app protection policy, then turns on Conditional Access, and a message appears on the phone that the policy cannot be found. One specific case describes exactly this sequence of steps in the Microsoft 365 Business Premium environment. The comments offer several possibilities, but without looking into the specific tenant, a single cause cannot be determined. Therefore, an approach that separates application protection, access evaluation, and device management makes more sense.
MAM, MDM and identity registration are different
MDM manages the device as a whole: its configuration, status and, depending on the type of registration, actions on the device. MAM protects work data in a supported application. For example, a policy may restrict the transfer of company data to a personal application, require a PIN for work context, or remove work data from the application when an employee leaves. Microsoft describes MAM without enrollment for Android, iOS/iPadOS and Windows.
Pay attention to the word "registration". Mobile Conditional Access may require device registration in Microsoft Entra ID via an intermediary application for evaluation. This is not the same as fully enrolling the phone in Intune MDM management. Microsoft in the "Require app protection policy" describes the need for a broker application: on iOS Microsoft Authenticator, on Android Microsoft Authenticator or Company Portal. Explain to the user in advance what will happen when they log in, as confusing these two steps is a reason to distrust BYOD.
| Requirement | MAM without MDM | Device management via MDM |
|---|---|---|
| Protect work data in supported Outlook or Teams | Yes, according to app support and policy | Yes, often combined with MAM |
| Set operating-system and device-compliance rules | No | Yes, within platform and enrollment limits |
| Remove only work data from a protected app | Yes, with selective MAM wipe | Also possible in managed-device scenarios |
| Factory-reset a personal phone | Not through MAM alone | Only where the managed-device scenario permits it |
| Manage a userless company kiosk | Not as the only management method | Usually, depending on the device type |
The table does not mean that MAM will guarantee the protection of every application and every way of opening the file. The support of the specific client, platform and access path is decisive. Microsoft also explicitly says that a selective MAM wipe removes corporate data from the app, while a full device wipe belongs to MDM.
Which licences do you need?
For a user who benefits from Intune app protection policies, verify entitlement to Microsoft Intune Plan 1 or the corresponding package. Intune Licensing Documentation states that a license is needed by a user or device that directly or indirectly benefits from the service; the device license itself without user assignment does not cover the app protection policy. If you want to enforce access via Conditional Access, also check the Microsoft Entra ID P1 or P2 permissions for the affected users. App-based Conditional Access documentation lists P1/P2 as a prerequisite.
Microsoft 365 Business Premium includes both Intune Plan 1 and Entra ID P1. However, this does not mean that the policy automatically works for everyone in the tenant. Mixed licenses are common: verify assignment to specific people affected by the policy, including outsiders using company data. Conversely, don't buy Intune Suite just because you need basic MAM; this is an extension to Plan 1 for other advanced abilities.
Protect the app before enforcing access

This rollout order reduces the risk of locking pilot users out of email:
- Choose scenarios and platforms. For example, Outlook and Teams on personal iPhones and Android phones. Include web access and other email clients in the inventory.
- Check licences and groups. A test user needs the relevant entitlements and membership of both the MAM and Conditional Access target groups. Test work and personal accounts on the same phone.
- Create an app protection policy for each platform. Configure protected apps, data transfer, saving copies, access conditions and loss-of-access behaviour. Microsoft documents the setup separately for iOS/iPadOS and Android.
- Test the app first. Sign in to a supported Outlook or Teams version and confirm that protection applies before using blocking Conditional Access as the only test.
- Add Conditional Access in report-only mode. Target the right platforms, apps and client types; exclude emergency accounts and review sign-in logs. Enable the policy for the pilot group only after testing.
- Test an employee departure. Confirm access revocation and selective removal of work data. Tell users in advance what is removed and what remains theirs.
For a mix of managed and private phones, app protection policies can be targeted by device management status. One group of users does not automatically mean the same restrictions for both corporate and personal devices.
What changed in Conditional Access in 2026?
Older guides recommend the “Require approved client app” grant. Microsoft made it read-only on 30 June 2026. Existing policies can still apply, but administrators can no longer create or edit them. New policies should use “Require app protection policy”. Check each client before migration: an app that met the old approved-client requirement may not support the new grant.
This is not just changing the name of the option in the portal. The new grant verifies the presence of the corresponding app protection policy on the supported application. Therefore, when migrating, it is not enough to override the condition and hope that the old application list will work the same. Keep a list of clients that people actually use, test them before turning off the old rule. If you are setting up a new policy, do not create a process dependent on a historical grant.
Windows BYOD has narrower limits
The statement "MAM also works on Windows" is true, but it can be misleading. Microsoft Guide for Windows describes Microsoft Edge protection on supported versions of Windows. It is not a general protection for all desktop applications and all browsers. The grant for app protection policy on Windows is still in preview according to Conditional Access overview.
Additionally, on Windows, MAM for Edge applies to unmanaged devices. If the device is already managed via MDM, MAM enrollment for this scenario will be blocked; when switching to MDM, MAM rules no longer apply. Microsoft therefore combines the option "Require app protection policy" or "Require device to be marked as compliant" in the model policy. If both are requested at the same time, some users could be blocked. Before deployment, also verify the desktop applications you want to enable or disable on your private PC, separately from Edge access.
When Intune cannot find the policy
Do not assume the licence is the cause. Check, in order: the user’s Intune and Entra entitlements; membership of the MAM and Conditional Access groups; the policy’s platform and app targets; app support for protection policies; identity registration and the required broker app; and any other policy that may block sign-in first. In Intune troubleshooting, check policy applicability and status. In the Entra sign-in logs, inspect the evaluated Conditional Access policies and the grant result. “Policy did not apply” and “policy applied but its grant failed” are different problems.
Save model situations in the pilot: company data can be opened in protected Outlook, cannot be moved to an unprotected application, work data disappears after access is revoked, and personal content remains. Such a test is more important than the green icon for the policy in the portal.
Frequently asked questions
Must an employee enrol a personal phone in Intune MDM to use MAM?
No. MAM without MDM enrolment is supported. Mobile Conditional Access may still require device identity registration in Entra through a broker app; that is not full device management.
Can IT erase my personal photos through MAM?
A selective MAM wipe removes work data from protected apps; it does not factory-reset the phone. Employers should explain their exact BYOD policy and the type of registration requested.
Is Microsoft 365 Business Premium enough?
It includes Intune Plan 1 and Entra ID P1, relevant to basic MAM with Conditional Access. Check assignment to each affected user, app support and configuration. A licence alone does not prove the rollout works.
Can one policy cover mobile Outlook and Outlook Desktop?
Do not assume that from the name MAM. iOS and Android have their own supported apps and policies. The documented Windows Conditional Access scenario centres on Edge; assess desktop Outlook separately.
Should we delete the old approved-client-app policy?
Not without a pilot. It is read-only but may still apply. Inventory the clients, prepare the app-protection-policy grant, test it with a pilot group and then retire the old rule.
What should the pilot deliver?
The result should be more than a configured policy. Record the permitted apps and platforms, each target role’s licence, work-data rules, Conditional Access test results and selective-wipe procedure. Tell users plainly that the company protects the work account and data inside the app; it does not automatically control the entire personal phone.
Related article: Intune: license for user or device








