Protect work devices from phishing, malware, and risky web content by using Microsoft Defender and Intune to block unsafe websites across your organization.

Imagine an employee loses their phone at an airport.
The device has Outlook, Teams, and OneDrive signed in with their work account. Company emails, files, and conversations could now be at risk.
The obvious solution might be to wipe the device. But because it's a personal phone, that would also delete personal photos, messages, and apps.
This is a common challenge in BYOD environments.
Organizations need a way to protect company data on personal devices without affecting employee privacy. That's exactly what Microsoft Intune is designed to do.
With the right Intune BYOD security policies in place, IT teams can remove corporate data from work apps while leaving personal data untouched.
Traditional mobile device management (MDM) works well for company-owned devices. Since the organization owns the hardware, IT teams can fully control how the device is configured and used.
Personal devices are different.
Employees expect privacy on their own phones and tablets. Most people are not comfortable giving their employer complete control over a device they use every day.
This creates a difficult choice:
Neither option is ideal.
Blocking access can hurt productivity and encourage employees to use unmanaged personal apps to get work done.
On the other hand, unrestricted access can leave corporate data on personal phones without encryption, copy-and-paste restrictions, or remote wipe capabilities.
A strong BYOD mobile security policy needs a middle ground.
That's where Intune stands out. Instead of managing the entire device, it can manage apps without managing the device itself. For organizations building out a modern workspace strategy, this is typically one of the first security layers to get right.
This approach helps organizations protect corporate data on personal phones while respecting employee privacy.

Microsoft 365 Licenses That Include Intune
Most Microsoft 365 plans already include Intune - you may not need to buy anything extra.
What You Need for BYOD App Protection

App Protection Policies - or APPs - are the heart of BYOD security in Intune. They protect company data inside specific apps, without touching anything personal on the device.
Microsoft organizes these policies into three levels.
Level 1 - Enterprise Basic The starting point. Covers app PIN, data encryption, and selective wipe. Good for low-risk users or a pilot rollout.
Level 2 - Enterprise Enhanced Adds copy/paste restrictions and blocks saving company files to personal storage. This is the right level for most employees.
Level 3 - Enterprise High Maximum protection - stricter PINs, shorter offline timeouts, screen capture blocking, and Mobile Threat Defense integration. Built for executives or anyone handling sensitive data.

Data Protection
Access Requirements
Conditional Launch These settings decide what happens when something looks wrong:
Intune app protection works out of the box with Microsoft 365 apps - Outlook, Teams, OneDrive, SharePoint, OneNote, Edge, and Power BI Mobile.
Third-party apps and internal company apps can also be supported if they're built with the Intune SDK or processed through the Intune App Wrapping Tool.
This section walks you through setting up app protection in Intune from start to finish - creating a policy, configuring Conditional Access, and what your users will see on their phones.









App protection policies assign to user groups, not devices.
Create a security group in Entra ID for your BYOD users and assign the policy to that group. For the first rollout, start with a small pilot group before expanding to everyone.
Once your iOS policy is done, go back and create the same policy for Android - and vice versa.
NOTE: On Android, make sure Android Enterprise work profile is configured. This separates work apps from personal apps on the device with a dedicated work container.
This step makes sure users can only access company data through protected apps.




On iOS:
On Android:
Go to Apps > Monitor > App protection status in the Intune admin center to see which users have the policy applied and when devices last checked in.
TIP: Policy deployment isn't always immediate. If users don't see protection settings applied, restart the application, sign out and back in, or allow additional time for policy synchronization. Use the App Protection Status report to verify policy delivery.
iOS and Android handle app protection differently. Knowing these differences helps you set policies correctly and avoid confusion when users reach out saying something isn't working.
When Intune deploys a work profile on an Android device, it creates a separate encrypted container just for work apps. Personal apps and work apps run completely independently.
Here's what that looks like in practice:
iOS doesn't use a work profile. Instead, protection lives inside each app itself.

If your users access Microsoft 365 on personal Windows laptops, Intune now covers that too.
Windows MAM without enrollment was introduced in 2023-2024 and protects Microsoft 365 apps on unmanaged Windows 10/11 devices - the same way it does on phones. It replaced Windows Information Protection (WIP), which Microsoft deprecated.
Requirements:
NOTE: Windows MAM is newer and still catching up to the mobile experience. Test it thoroughly before a broad rollout.
Good policies only work if people actually use them. Here's what makes the difference between a smooth rollout and a flood of IT support tickets.
The biggest resistance to BYOD policies comes from employees who think IT is watching their personal phone. Address that upfront.

Microsoft's App Protection framework has three levels. Level 1 is basic - PIN and encryption only. Level 2 adds copy/paste restrictions and blocks saving files to personal storage. Level 3 is the strictest - shorter offline timeouts, screen capture blocking, and Mobile Threat Defense integration.
For most organizations, this is how to apply them:
Set a recurring schedule so policies don't go stale:
A short monthly survey to users goes a long way too - small usability issues surface early before they become bigger problems.
Even a well-planned Intune deployment can run into problems. Most issues come from a few recurring mistakes - and they're all avoidable.
Policy not applying
Selective wipe not working
Users locked out after Conditional Access goes live
Android work profile not appearing

Protecting company data on personal devices requires more than creating a few policies in Intune. It takes the right expertise, a structured approach, and a clear understanding of how MAM, Conditional Access, and identity management work together.
Microsoft Solutions Partner Expertise: As a certified Microsoft Solutions Partner, we bring official Microsoft security guidance together with real-world deployment experience. We make sure your BYOD policies are configured correctly and integrated into your broader Microsoft 365 security strategy.
Intune and Microsoft 365 Security Specialists Our team specializes in:
We balance strong data protection with a smooth experience for your end users.
Compliance-Aligned BYOD Security We design BYOD strategies that support GDPR, HIPAA, PCI DSS, ISO 27001, and SOC 2 requirements by ensuring:
Practical, Real-World Experience We've helped organizations roll out BYOD programs across cloud-only and hybrid environments - covering everything from licensing and policy design to end-user communication and monitoring. Our approach ensures security without unnecessary friction for your team.
Ready to protect company data on personal devices the right way? Schedule a consultation to build the right BYOD security strategy for your organization.
Frequently Asked Questions
1. Can IT see my personal apps and data with Intune?
No. App protection policies only manage corporate apps like Outlook, Teams, and OneDrive. IT has no visibility into your personal photos, messages, apps, or browsing history.
2. What's the difference between MAM and MDM?
MDM (Mobile Device Management) enrolls your entire device, giving IT control over it. MAM (Mobile Application Management) only protects corporate apps without enrolling the device - which makes it the right fit for personal phones.
3. What happens if I try to copy work data to a personal app?
The action will be blocked or you'll see a warning, depending on your organization's policy settings. Data simply can't leave protected apps if the policy prevents it.
4. Can my company wipe my personal phone?
No. With MAM-only policies, only corporate data is removed through a selective wipe. Your personal apps, photos, and files stay untouched. A full device wipe is only possible if you've enrolled your device into MDM, which isn't typical for BYOD.
5. Which Microsoft 365 licenses include Intune for BYOD?
Microsoft 365 Business Premium, E3, E5, and EMS E3/E5 all include Intune Plan 1, which covers app protection policies. You'll also need Entra ID P1 if you want Conditional Access.
6. Do I need to install Company Portal on my iPhone?
No. iOS uses Microsoft Authenticator as the broker app. Company Portal is only required on Android devices.
7. How long does it take for policies to apply?
Up to 8 hours, since devices check in periodically. To speed it up, sign out of the managed app and sign back in to trigger a manual sync.
8. Can app protection policies work with third-party apps?
Yes, if the app uses the Intune SDK or has been processed through the Intune App Wrapping Tool. Many popular enterprise apps already support this.
9. What happens if my device is jailbroken or rooted?
Intune can detect compromised devices and either block access or trigger a selective wipe, depending on how the Conditional Launch settings are configured.
10. Is app protection available for Windows laptops?
Yes. Windows MAM for unmanaged Windows 10/11 devices was introduced in 2023-2024 and supports Microsoft 365 apps with similar controls to mobile.
11. What is MAM without enrollment?
MAM without enrollment (MAM-WE) means Intune protects corporate apps on a personal device without fully enrolling or managing the device itself. It's the standard approach for BYOD.
12. Can a user have both personal and work accounts on the same app?
Yes. Apps like Outlook and Teams support multiple accounts. Intune policies apply only to the work account - the personal account is unaffected.
13. What if an employee leaves the company?
IT can trigger a selective wipe remotely, which removes all corporate data from managed apps. The rest of the device stays exactly as it was.

CEO at Penthara Technologies
How to Block Unsafe Websites on Work Devices
Protect work devices from phishing, malware, and risky web content by using Microsoft Defender and Intune to block unsafe websites across your organization.
Your Microsoft 365 Tenant Has a Silent Data Leak. It Requires No Malware.
Your Microsoft 365 tenant can leak data silently - no malware, no alerts. Learn how simple misconfigurations enable ongoing email and data exfiltration.
Security Alerts That Nobody Investigates - And Why That’s More Dangerous Than Having None
Security alerts mean nothing if no one investigates them. Ignored alerts create false confidence - and give attackers the time they need to cause real damage.