Learn how Microsoft 365 app protection policies enable secure BYOD by controlling corporate data within apps without managing personal devices.
Ask about this video. Answers come from its transcript only — with the timestamp, so you can check them.
Generated from the transcript and can be wrong — check the timestamp.
Key Takeaways
- BYOD without proper controls is effectively a 'hope policy' risking data leaks.
- App protection policies secure corporate data inside apps without managing personal devices.
- Selective wiping removes only corporate data, preserving personal content on devices.
- Combining app protection policies with conditional access strengthens security posture.
- This method improves user acceptance by respecting privacy and device ownership.
What the video covers
- BYOD means using personal devices for work, offering flexibility but creating data protection challenges.
- Default settings allow copying corporate data from managed apps like Outlook to unmanaged apps like WhatsApp, posing security risks.
- Traditional options are full device enrollment with Intune or no control, both with drawbacks.
- App protection policies provide a third option by securing company data at the app level without enrolling or controlling the entire device.
- These policies create a 'walled garden' around corporate apps, protecting data while leaving personal apps and data untouched.
- Controls include restricting copy-paste, blocking saving to personal storage, requiring app-level PINs, and selective wiping of corporate data.
- App protection policies are configured under apps in Intune, not devices, and apply to Microsoft apps on iOS and Android.
- Conditional access can be combined with app protection policies to enforce access and enhance security.
- The approach balances user privacy with corporate data security, reducing HR conflicts and improving BYOD adoption.
- The video demonstrates step-by-step configuration of app protection policies and conditional access in Microsoft 365.
Chapters
- 00:00Introduction to BYOD and Data Protection Challenges
- 00:57Default Risks and Fixing Data Protection
- 01:55Real-World BYOD Issues and IT Challenges
- 02:58Common BYOD Options and Their Drawbacks
- 03:58App Protection Policies: Concept and Benefits
- 05:09Selective Wiping and Data Control Explained
- 05:57Configuring App Protection Policies in Intune
- 06:44Targeting Apps and Policy Settings Overview
- 07:30Data Movement Controls and Encryption
- 08:36PIN Requirements and Additional Security Settings
Full Transcript — Download SRT & Markdown
Speaker A
Jonathan? I've made a decision. We're going. Wait for Jonathan. BYOD. In case you didn't know, it means personal devices, you know, flexible working.
Speaker A
We're very progressive. Right, Charles? And can I ask, how are you protecting the data on those devices? Jonathan, we trust our team.
Speaker A
Charles, that wasn't the question. Well, they have passwords. Well, for example, can they copy a confidential client email from Outlook and paste it into, I don't know, WhatsApp?
Speaker A
No. Charles, that was kind of a question, not a statement. Well, presumably not. Presumably? Can they? Right now, on an unmanaged personal device, yes, absolutely can. Jonathan, that seems like a significant oversight.
Speaker A
It's not an oversight, Charles. It's the default, unless you configure it properly. Well, can it be fixed?
Speaker A
Yes. What we can do, Charles, is protect the data inside of the apps without enrolling the device or touching anything personal on their phones. Wait a moment.
Speaker A
You can control the data without controlling the phone? Yes. Well, when you say that. Charles, you didn't ask me. All you did was announce a new BYOD policy. Well, I'm asking you now. Okay, let me show you. Now, BYOD is one of
Speaker A
those policies that sounds great in a board meeting. But, when it reaches the IT department, it becomes a bit of a nightmare. Because here's what actually happens. Staff start using their personal devices. They access Outlook, Teams, and OneDrive. They download
Speaker A
client files. They collaborate. And it all works until it doesn't. And when something goes wrong, you know, like a leaver walking out with client data or a device getting lost or someone pasting a confidential email somewhere it shouldn't be pasted. And then IT get the
Speaker A
call. Even though IT never approved the setup in the first place. Now, here's the uncomfortable truth most businesses are sitting with right now.
Speaker A
If your staff can copy company data from Outlook and paste it into their WhatsApp, their personal Gmail, or even the notes on their iPhone, you've not got a BYOD policy. No, you've got a hope policy. Now, most people
Speaker A
think they've only got two options when it comes to smartphones. Option one, fully enroll every personal device into Intune and control the phone. But that doesn't work because people push back.
Speaker A
HR gets involved and no one ends up happy. Or option two, do nothing. Just trust people and hope for the best.
Speaker A
But there's a third option. And it's the option that most organizations aren't using. You can manage the data on the phone but not the phone. Now, Microsoft call this app protection policies.
Speaker A
And when you combine app protection policies with conditional access, your business gets genuine data control on personal devices without a single device getting enrolled. And that, ladies and gentlemen, is what we're looking at today. Now, let me explain the concept
Speaker A
before we dig into the portal because it's worth understanding why this works. When you enroll a device into Intune, you're managing the whole phone. It's great. It means you can push configuration. You can enforce compliance. You can even remotely wipe
Speaker A
it. Basically, you've got full control, which is great for corporately owned devices. But on people's personal devices, they just don't want that. And quite honestly, they shouldn't have to have it. So, app protection policies come to the rescue. They work differently.
Speaker A
Instead of wrapping a security policy around the actual device, you're wrapping your security policy around the apps that access company data. Now, think of this like a walled garden inside of the phone. Outlook, Teams, OneDrive, the Office apps. Everything
Speaker A
company related sits inside that walled garden. The rest of the phone, so personal photos, personal apps, personal messages, they're all completely untouched. Now, inside of your walled garden, you've got some control.
Speaker A
You can control whether, for example, a PIN is required to open company applications. You can control whether company data can be copied and pasted into unmanaged applications. You can also control things like whether files can be saved to personal storage, like, for example,
Speaker A
the camera roll. And what happens if someone leaves the business? Well, you can selectively wipe just the company data from the phone. You don't have to wipe the whole phone just the work content. So, the actual phone stays
Speaker A
personal. The data stays protected. And that is the difference. So, let's take a look at how this works in action. Okay.
Speaker A
App protection policies. So, I'm logged into the Microsoft 365 admin center. But I want to be in Intune. So, I'll launch that.
Speaker A
Okay. I'm then going to go into apps, okay? Notice where we're going. We're not going into devices. We're going to apps, okay?
Speaker A
And from there, we can go to protection. This is one of the key distinctions that maybe catches people out. So, app protection lives under applications, not devices. Because remember, we're not managing a device. What we're doing is managing an app experience.
Speaker A
So, we will create a policy, and I'm going to test on an iPhone, okay? So, I'll do that there. You can also create an app protection policy for Android as well. The same logic applies. So, I give this a name.
Speaker A
Something like this. You can give it a description. Click on next. Okay. We're going to target policy to where, okay?
Speaker A
We can look at all Microsoft apps, and I can click over there, and it'll tell you exactly what apps are going to be handled by this.
Speaker A
Or core Microsoft apps, okay? Again, I can look at that. So, I'm going to do it for these apps here, okay? These are the core apps that people want to use on their smartphones. Click on next.
Speaker A
Now, this is kind of where the real work happens, okay? All these settings. First of all, back up organizational data to iTunes and iCloud backups.
Speaker A
We don't want that doing. So, we can block that, okay? What about sending organizational data to other apps?
Speaker A
Okay? At the moment, it's set to all apps. I'm going to make this policy managed apps.
Speaker A
That means data can move between Outlook, Teams, Word, the managed apps, but it cannot leave and go to an unmanaged app, okay?
Speaker A
So, this is kind of the copy-paste control. So, things like copying Outlook data to a WhatsApp message, that will be blocked. But, if you try to copy something in Outlook to Word, that would be okay, okay? Because we can send
Speaker A
organizational data to other policy-managed apps, okay? What about saving copies of organizational data? Blocked, okay? That means staff can't save company files directly to their camera roll or their personal storage, okay?
Speaker A
Again, we can allow users to save copies to selected services, if we want to, okay?
Speaker A
I'm happy to leave this as any app, okay? We can scroll down to here.
Speaker A
What about receiving data from other apps, okay? I will set that to policy-managed app again, so it keeps the boundary clean both ways. So, I can't copy data from WhatsApp into Outlook, okay?
Speaker A
Again, restrict cut, copy, and paste between other apps, okay? Policy-managed apps with pasting, okay?
Speaker A
We can leave that as it is. We've got a character limit if you want to use that.
Speaker A
Scrolling down again, yes. So, we want all the organizational data on that device to be encrypted, okay?
Speaker A
Sync policy-managed app data with native apps or add-ins, we can block that. What about printing data, okay? That's a bit of a security problem, so I'll block that.
Speaker A
Okay, what about web content transfer, okay? Microsoft Edge, okay? Scroll down a little bit more.
Speaker A
Click on next. Now, PIN for access, okay? We're going to enable this, okay? We require it. So, even if the phone is unlocked, users would need a PIN to open Outlook or Teams. That's kind of an extra layer on top of the device lock.
Speaker A
So, it may be useful for shared households or nosy family members, that type of thing, okay?
Speaker A
PIN type, we can put numeric or passcode. Simple PIN, let's click on here. So, that would rule out things like 1 2 3 4, okay? So, you can block that if you want. Minimum PIN length, obviously, you might want to en...
Speaker A
something like that. Touch ID instead of PIN, yeah, we'll allow that. It's a few settings here you can work through.
Speaker A
Recheck the access requirements after so many minutes, okay? So, if someone puts the app in the background and comes back, they'll be prompted again. That's half an hour, you can lower that if you want to do that, okay?
Speaker A
Click on next. And then we've got some conditions here, okay? So, maximum PIN attempts, five. The action will be to reset the PIN, okay?
Speaker A
You can choose wipe data. Okay, if someone's entering it so many times, we can wipe that data from the device.
Speaker A
We've also got some offline grace periods, okay? Where we can block access, we can wipe data there.
Speaker A
Again, we've got some other bits here, so if if it's jailbroken, we can block access. We've also got things like if it's running a minimum iOS version, okay? We can also block access. So, a lot of different things we can do here,
Speaker A
okay? A lot of options. Click on next. Now, this would probably be all users, so I would add a group in here.
Speaker A
Select all users from here. You might have a specific BYOD group or something like that, but in most cases, it's going to be all users, okay? So, there's no device enrollment here, there's no MDM profile on the phone.
Speaker A
This is very kind of low-touch for users. Click on create. And we have our policy there.
Speaker A
Okay, bit of a demo. I've got an iPhone, so I go into Outlook. Look, your organization requires this account's data to be protected with a PIN. Okay, so I can put a PIN in.
Speaker A
Confirm it. Okay, so our test user has got an email. And it's confidential data. Okay.
Speaker A
So maybe our test user, who's called Colin, maybe he's a little bit naughty and he thinks, "Well, I'm going to copy this out of here." Okay, he copies.
Speaker A
Something like that. Copy. Okay, and he's going to put that into a notes on his iPhone.
Speaker A
Okay. So he types in here, "Confidential data." And he copies it in. And he gets this message here, look.
Speaker A
"Your organization's data cannot be pasted here." If you remember, we set that all up within our app protection policies. So all those settings now, we've got a PIN to enter the app. We can't copy out. All that was achieved with our app
Speaker A
protection policy. But, there's one more thing, okay? Something else I want to flag to make this a complete solution.
Speaker A
App protection policies protect the data inside supported apps, but they wouldn't stop someone from opening Safari on their iPhone and signing into Outlook on the web. That would bypass the managed app entirely.
Speaker A
Okay, so there's a bit of a gap. But, that gap is easy to close. Okay, and we close that with a beautiful conditional access policy.
Speaker A
So we're going to Intune. We go to conditional access. Okay, we'll create a new policy.
Speaker A
I will give this a name. Something like this. Okay. I will plumb that to all users. Or if you've got a BYOD group, you can do it to them. Okay, the target resources or cloud apps.
Speaker A
Okay, we're looking conditions. And we're going to target this at some device platforms. Okay?
Speaker A
Yes. Android, iOS. Okay? Click on done. We will then go to here. And we will grant access. Okay?
Speaker A
But we would require an app protection policy. So that closes that security gap a little bit more. We would then select it and we'd switch it on. Okay?
Speaker A
Well, I've actually got a security defaults on here. So I'm not going to create the policy. But together app protection has handled the data and now conditional access handles the the bypass. So together you've got a nice BYOD solution for
Speaker A
your smartphone. Now, I hope you've enjoyed today's video. Managing personal smartphones in a business is still a big problem. But Microsoft has the answer. I look forward to seeing you again soon.
Topics:BYODMicrosoft 365App Protection PoliciesIntuneConditional AccessData SecurityMobile Device ManagementPersonal DevicesCorporate Data ProtectionFlexible Working











