Video summary

Episode 51 - Protecting BYOD devices with MAM for Windows

Main summary

Key takeaways

Technology

Overview (Episode topic)

  • The episode discusses protecting BYOD / unmanaged Windows devices using MAM for Windows (Mobile Application Management) in Microsoft Intune.
  • Enforcement and data protection focus on Microsoft Edge (Edge for Business).

Key technological concepts and features

1) What “MAM for Windows” is

  • MAM (Mobile Application Management) is an Intune capability for controlling access to corporate apps and corporate data on unmanaged devices.
  • For Windows, it targets similar goals to older Windows-focused approaches, but is positioned as a more complete approach to:
    • Apply DLP-style controls to prevent data exfiltration
    • Enforce authentication requirements
    • Run device compliance/security checks before allowing access

2) Integration: Mobile Threat Defense (MTD) connector

  • In Intune, the process begins by setting up the Mobile Threat Defense connector:
    • Configured via Intune Tenant Administration → Connectors
    • Integrates into Windows Security Center
  • Purpose:
    • On MAM enrollment, collect device security signals and compute a device threat level
    • Use those signals in compliance checks to determine whether the device can access corporate apps/data

3) App protection policy (DLP + compliance checks)

  • Created under Intune → Apps → Protection → App protection policy
  • Platform selection includes Windows (the older “Windows Information Protection” is mentioned, but not used in the demo).

App selection limitation noted

  • During the demo, the only available protected app for Windows was Microsoft Edge (other apps like Office/OneDrive/etc. not available yet).
  • Mitigation: protecting Edge can still protect many cloud apps because Edge is used to access them.

DLP controls configured for Edge

  • Data entering Edge: configured to allow sources (speaker prefers allowing inbound data)
  • Data leaving Edge: set to block destinations to prevent corporate data exfiltration
  • Copy/paste controls:
    • Uses an “ORC” style model (described in terms of “data sources/destinations” rather than simple allow/block)
    • Goal: allow copy/paste within corporate contexts, but block copy/paste outside protected locations
  • Printing: configured to block printing from the protected context

Health / compliance checks

  • Includes:
    • App conditions (example mentioned: offline grace period)
    • Device conditions, including:
      • Minimum OS version (mentioned)
      • Most important demo setting: maximum allowed device threat level
  • Example outcome in the demo:
    • Allow access for medium threat level devices
    • Block access for devices with higher risk

4) Conditional Access policy enforcement (cloud sign-in moment)

  • A Conditional Access policy is created to enforce MAM requirements:
    • Applies when users sign into targeted cloud apps (Office 365) from Windows, specifically in the browser/client context
    • Grants access only if the app protection policy is satisfied (i.e., the user completes MAM enrollment)
  • Critical requirement emphasized by the speaker:
    • The same users/groups must be assigned to both:
      • the Conditional Access policy
      • the Intune app protection policy
    • Otherwise, users may be blocked because they won’t have the required app protection policy condition satisfied

5) Microsoft Edge for Business unified portal (Microsoft 365 Admin Center)

  • Mentions Microsoft’s unified Edge for Business portal inside the Microsoft 365 admin center.
  • Purpose:
    • Push Edge configurations across platforms for both managed and unmanaged devices during MAM enrollment
  • Preview/customization features highlighted:
    • Watermarking protection: adds watermarks when sensitive content is displayed in protected Edge sessions
    • Screen capture protection: restricts screenshots/recordings to add extra DLP controls
    • Protected downloads: downloaded files are stored in OneDrive rather than exfiltrating to the unmanaged device

Demo walkthrough (BYOD UX + enforcement results)

Enrollment and user experience issue (and fix)

  • Demo begins on an unmanaged/personal device:
    • User disables antivirus / makes the device “unsafe” to trigger compliance failure.
  • When signing into corporate Edge, the user is prompted:
    • “Allow your organization to manage your device”
  • Speaker critique:
    • The prompt behavior could cause enrollment to fail if the system attempts full management of personally owned devices.
  • Fix recommended:
    • Configure Intune enrollment restrictions:
      • Disable MDM enrollment when adding work/school accounts on Windows
  • Result:
    • Avoids the device-management prompt
    • MAM enrollment succeeds (goal is MAM, not full device management)

Compliance enforcement flow

  • After enrollment, device fails compliance due to disabled protections (high threat level):
    • Access to corporate cloud applications is blocked.
  • User can fix the issue (restore AV / update state), then:
    • Re-check/retry takes about ~10 seconds on average
    • Device becomes compliant and access is granted after successful checks

DLP behavior demonstrated after access is allowed

  • Using SharePoint documents in protected Edge:

Blocked actions

  • Download blocked
    • Message indicates the organization prevents downloading
  • Print blocked

Copy/paste behavior

  • Copy/paste from protected app to Notepad is blocked
  • Copy/paste within protected cloud content/apps works (within the allowed corporate context)

Session-context protection

  • Protection applies to the protected Edge session context:
    • Even when visiting an unprotected website, data copy/paste out of protected Edge can still be blocked (because the app/session context remains protected)

Troubleshooting / operational capability

  • Mentions selective wipe via Intune app protection features:
    • Can issue a wipe request targeting an enrolled user/device instance
    • In the demo, wipe effectively deletes the Edge browser profile data:
      • cookies, favorites, etc.
  • Mentions remote wipe as possible and demonstrates the wipe workflow.

Roadmap note

  • Speaker notes they haven’t personally seen specific public roadmap items for near-term changes of interest, but expects ongoing improvements.

Main speakers / sources

  • Dion Pico — Cloud Security Architect, IT Impressive (host/interviewer)
  • Myron Hgry — Technology Lead, Pink Elephant (Microsoft partner/MSSP); Microsoft MVP on security/CXDR/identity; focuses on Microsoft security products and implementations

Original video