Instiq
Chapter 4 · Manage and secure applications·v1.0.0·Updated 6/30/2026·~13 min

What's changed: Created MD-102 Chapter 4 (domain: Manage and secure applications). Deploy/update apps (Win32 app .intunewin/LOB app/Microsoft Store app, Microsoft 365 Apps, Office Deployment Tool, Microsoft 365 Apps admin center, Apple VPP/Google Play, Quiet Time policies, deployment status monitoring and installation failures) and app protection/configuration policies (app protection policies MAM in-app data protection for managed/unmanaged BYOD, require app protection via Conditional Access, app configuration policies).

4.2App protection and app configuration policies

Key points

Understand app protection policies (MAM) for in-app data protection on managed/unmanaged BYOD, requiring app protection via Conditional Access, and app configuration policies.

You can protect only the data inside apps without managing the whole device. Different in purpose from pre-configuring settings.

4.2.1App protection policies (MAM)

App protection policies are MAM (Mobile Application Management) that protect org data inside apps (restrict copy/paste, encryption, restrict "save as", require PIN). Because device enrollment (MDM) is not required, they protect unmanaged BYOD per app, and apply to managed devices too. Combine with Microsoft Entra Conditional Access to require an approved client app + an app protection policy for access. Remember: "in-app data protection (no enrollment)" = app protection policy.

4.2.2App configuration policies

App configuration policies pre-configure app settings for managed apps or managed devices and distribute them (connection URLs, defaults, sign-on info). This "pre-populates app settings," a different role from app protection policies (which protect data). It is also a different layer from device compliance (whole-device compliance).

Exam point

Cues: "protect org data inside apps (copy restriction/encryption/PIN), BYOD without enrollment" = app protection policy (MAM). "require an approved app + protection policy" = Conditional Access. "pre-configure app settings for managed apps/devices" = app configuration policy. Whole-device compliance = device compliance (different).

Warning

Watch the mix-ups: (1) App protection policy (MAM in-app data protection, no enrollment) vs app configuration policy (pre-configure app settings). (2) App protection policies work on BYOD without enrollment. (3) Device compliance/configuration profile (whole device) vs per-app MAM are different layers.

Diagram: an app protection policy is MAM (Mobile Application Management) protecting org data inside apps (copy restriction/encryption/PIN), works on unenrolled BYOD since enrollment is not required; an app configuration policy pre-configures managed app settings (connection URLs/defaults) (distinct roles); Microsoft Entra Conditional Access requires an approved client app + an app protection policy to control access.
Protect vs configure

4.2.3Section summary

  • App protection policies (MAM) protect in-app data and work on BYOD without enrollment
  • Conditional Access requires an approved app + an app protection policy
  • App configuration policies pre-configure app settings for managed apps/devices

Sign in to track progress — Log in.

Quick check

(just a quick review)

Q1. On employees’ personal phones (BYOD, unenrolled), you want to protect org data inside work apps by restricting copy/save. Best?

Q2. You want to pre-configure settings (connection URLs, defaults) for managed apps and distribute them. Best?

Q3. You want to allow access to org data only from an approved client app with an app protection policy applied. Best?

Q4. Which correctly describes app protection policies (MAM)?

Q5. What correctly distinguishes an app protection policy from an app configuration policy?

Check your understandingPractice questions for Chapter 4: Manage and secure applications

Keep track of your progress

The full study guide is free to read. Sign up free to practice with the question bank, track what you have read, review your mistakes, and highlight passages.