Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
Standardmäßig ist der Prompt ausgewählt, der zuerst die Quelle prüft. Sie können zu einem direkten Befehl wechseln oder eine lokale Kopie herunterladen.
Quelldateien prüfen
Lesen Sie SKILL.md und alle von SkillsMP angezeigten Begleitdateien, bevor Sie sich für eine Installation entscheiden.
Mit Codex oder Claude installieren Kopieren Sie diesen Prompt, fügen Sie ihn in Codex, Claude oder einen anderen Assistant ein und lassen Sie die Skill-Seite prüfen und installieren.
Ein direkter Befehl überspringt den Prüf-Prompt. Prüfen Sie die Quelle, bevor Sie ihn ausführen.
Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
Deploying enterprise mobile app protection without full device management (MDM)
Implementing BYOD policies that protect corporate data while respecting personal privacy
Configuring Microsoft Intune App Protection Policies for iOS and Android
Enforcing data loss prevention controls on managed mobile applications
Do not use when full device management (MDM) is already deployed and sufficient -- MAM adds complexity when MDM already provides the needed controls.
Common Misconfigurations & Verification
Policy assigned but not enforced (no Conditional Access) — without a CA grant requiring app protection, users bypass MAM via unmanaged apps. Verify by attempting corporate sign-in from a non-policy app and confirming it is blocked.
Outdated Intune App SDK — newer policy controls silently no-op on old SDK builds. Verify the wrapped/SDK version matches the policy version and re-test the affected control.
Cut/copy/paste DLP gaps — paste from a managed app (Outlook) into an unmanaged app (Notes) must be blocked, while managed-to-managed (Teams) works. Verify both paths.
Selective wipe untested — trigger a wipe from the portal and confirm corporate data is removed while personal data remains.
Offline grace period too long — disconnect the device and confirm access is blocked after the configured interval, not indefinitely.
Jailbreak/root conditional launch off — verify a rooted test device is blocked from launching managed apps.
Over-restrictive tier creep — verify the policy tier matches data sensitivity so users don't route around it via shadow IT.
Prerequisites
Microsoft Intune or equivalent MAM platform (VMware Workspace ONE, MobileIron)
Azure AD for identity and conditional access policies
Azure AD > Conditional Access > New Policy:
- Users: All users with corporate apps
- Cloud apps: Office 365, custom LOB apps
- Conditions: All platforms
- Grant: Require app protection policy
- Session: App enforced restrictions
Step 5: Test and Validate MAM Controls
Test each policy control on both platforms:
# Verify data transfer restrictions
1. Open managed app (Outlook)
2. Copy text from email body
3. Attempt pastein unmanaged app (Notes) -- should be blocked
4. Attempt pastein managed app (Teams) -- should work
# Verify selective wipe
1. Enroll test device with MAM
2. Access corporate data in managed apps
3. Trigger selective wipe from Intune portal
4. Verify corporate data removed, personal data intact
# Verify offline grace period
1. Access managed app while connected
2. Disconnect from network
3. After grace period expires, verify app access blocked
Step 6: Monitor and Respond
Configure MAM monitoring dashboards:
App protection policy assignment status
Non-compliant device/user reports
Selective wipe execution logs
Jailbreak/root detection alerts
Failed PIN attempt tracking
Key Concepts
Term
Definition
MAM
Mobile Application Management - app-level policies without requiring full device enrollment
App Protection Policy
Set of rules enforcing data protection at the app level (encryption, DLP, access controls)
Selective Wipe
Removing only corporate data from managed apps while preserving personal data
App Wrapping
Post-build process applying MAM SDK policies to apps without source code modification
Containerization
Isolating corporate app data in an encrypted container separate from personal apps
Tools & Systems
Microsoft Intune: Cloud-based MAM/MDM platform with app protection policies
Intune App SDK: SDK for integrating MAM controls into custom iOS/Android apps
Intune App Wrapping Tool: Post-compilation tool for applying MAM policies without code changes
VMware Workspace ONE: Alternative MAM platform with app containerization
Azure AD Conditional Access: Policy engine for enforcing MAM enrollment as access condition
Common Pitfalls
SDK version mismatch: Intune App SDK version must match the policy version. Outdated SDK versions may silently fail to enforce newer policies.
iOS managed pasteboard: iOS enforces paste restrictions through managed pasteboard, which requires the app to opt-in via Intune SDK integration.
App wrapping limitations: Wrapped apps cannot use certain features (push notifications on some platforms). SDK integration is preferred for full functionality.
User experience friction: Overly restrictive policies cause user frustration and shadow IT. Start with Tier 1 and escalate based on data sensitivity.