Video summary
Episode 51 - Protecting BYOD devices with MAM for Windows
Main summary
Key takeaways
Overview (Episode topic)
- The episode discusses protecting BYOD / unmanaged Windows devices using MAM for Windows (Mobile Application Management) in Microsoft Intune.
- Enforcement and data protection focus on Microsoft Edge (Edge for Business).
Key technological concepts and features
1) What “MAM for Windows” is
- MAM (Mobile Application Management) is an Intune capability for controlling access to corporate apps and corporate data on unmanaged devices.
- For Windows, it targets similar goals to older Windows-focused approaches, but is positioned as a more complete approach to:
- Apply DLP-style controls to prevent data exfiltration
- Enforce authentication requirements
- Run device compliance/security checks before allowing access
2) Integration: Mobile Threat Defense (MTD) connector
- In Intune, the process begins by setting up the Mobile Threat Defense connector:
- Configured via Intune Tenant Administration → Connectors
- Integrates into Windows Security Center
- Purpose:
- On MAM enrollment, collect device security signals and compute a device threat level
- Use those signals in compliance checks to determine whether the device can access corporate apps/data
3) App protection policy (DLP + compliance checks)
- Created under Intune → Apps → Protection → App protection policy
- Platform selection includes Windows (the older “Windows Information Protection” is mentioned, but not used in the demo).
App selection limitation noted
- During the demo, the only available protected app for Windows was Microsoft Edge (other apps like Office/OneDrive/etc. not available yet).
- Mitigation: protecting Edge can still protect many cloud apps because Edge is used to access them.
DLP controls configured for Edge
- Data entering Edge: configured to allow sources (speaker prefers allowing inbound data)
- Data leaving Edge: set to block destinations to prevent corporate data exfiltration
- Copy/paste controls:
- Uses an “ORC” style model (described in terms of “data sources/destinations” rather than simple allow/block)
- Goal: allow copy/paste within corporate contexts, but block copy/paste outside protected locations
- Printing: configured to block printing from the protected context
Health / compliance checks
- Includes:
- App conditions (example mentioned: offline grace period)
- Device conditions, including:
- Minimum OS version (mentioned)
- Most important demo setting: maximum allowed device threat level
- Example outcome in the demo:
- Allow access for medium threat level devices
- Block access for devices with higher risk
4) Conditional Access policy enforcement (cloud sign-in moment)
- A Conditional Access policy is created to enforce MAM requirements:
- Applies when users sign into targeted cloud apps (Office 365) from Windows, specifically in the browser/client context
- Grants access only if the app protection policy is satisfied (i.e., the user completes MAM enrollment)
- Critical requirement emphasized by the speaker:
- The same users/groups must be assigned to both:
- the Conditional Access policy
- the Intune app protection policy
- Otherwise, users may be blocked because they won’t have the required app protection policy condition satisfied
- The same users/groups must be assigned to both:
5) Microsoft Edge for Business unified portal (Microsoft 365 Admin Center)
- Mentions Microsoft’s unified Edge for Business portal inside the Microsoft 365 admin center.
- Purpose:
- Push Edge configurations across platforms for both managed and unmanaged devices during MAM enrollment
- Preview/customization features highlighted:
- Watermarking protection: adds watermarks when sensitive content is displayed in protected Edge sessions
- Screen capture protection: restricts screenshots/recordings to add extra DLP controls
- Protected downloads: downloaded files are stored in OneDrive rather than exfiltrating to the unmanaged device
Demo walkthrough (BYOD UX + enforcement results)
Enrollment and user experience issue (and fix)
- Demo begins on an unmanaged/personal device:
- User disables antivirus / makes the device “unsafe” to trigger compliance failure.
- When signing into corporate Edge, the user is prompted:
- “Allow your organization to manage your device”
- Speaker critique:
- The prompt behavior could cause enrollment to fail if the system attempts full management of personally owned devices.
- Fix recommended:
- Configure Intune enrollment restrictions:
- Disable MDM enrollment when adding work/school accounts on Windows
- Configure Intune enrollment restrictions:
- Result:
- Avoids the device-management prompt
- MAM enrollment succeeds (goal is MAM, not full device management)
Compliance enforcement flow
- After enrollment, device fails compliance due to disabled protections (high threat level):
- Access to corporate cloud applications is blocked.
- User can fix the issue (restore AV / update state), then:
- Re-check/retry takes about ~10 seconds on average
- Device becomes compliant and access is granted after successful checks
DLP behavior demonstrated after access is allowed
- Using SharePoint documents in protected Edge:
Blocked actions
- Download blocked
- Message indicates the organization prevents downloading
- Print blocked
Copy/paste behavior
- Copy/paste from protected app to Notepad is blocked
- Copy/paste within protected cloud content/apps works (within the allowed corporate context)
Session-context protection
- Protection applies to the protected Edge session context:
- Even when visiting an unprotected website, data copy/paste out of protected Edge can still be blocked (because the app/session context remains protected)
Troubleshooting / operational capability
- Mentions selective wipe via Intune app protection features:
- Can issue a wipe request targeting an enrolled user/device instance
- In the demo, wipe effectively deletes the Edge browser profile data:
- cookies, favorites, etc.
- Mentions remote wipe as possible and demonstrates the wipe workflow.
Roadmap note
- Speaker notes they haven’t personally seen specific public roadmap items for near-term changes of interest, but expects ongoing improvements.
Main speakers / sources
- Dion Pico — Cloud Security Architect, IT Impressive (host/interviewer)
- Myron Hgry — Technology Lead, Pink Elephant (Microsoft partner/MSSP); Microsoft MVP on security/CXDR/identity; focuses on Microsoft security products and implementations