Instiq
Chapter 4 · Manage and secure applications·v1.0.0·Updated 6/29/2026·~13 min

What's changed: Created MD-102 Chapter 4 (domain: Manage and secure applications). Deploy/update apps (Win32 app .intunewin/LOB app/Microsoft Store app, Microsoft 365 Apps, Office Deployment Tool, Microsoft 365 Apps admin center, Apple VPP/Google Play, Quiet Time policies, deployment status monitoring and installation failures) and app protection/configuration policies (app protection policies MAM in-app data protection for managed/unmanaged BYOD, require app protection via Conditional Access, app configuration policies).

4.2App protection and app configuration policies

Key points

Understand app protection policies (MAM) for in-app data protection on managed/unmanaged BYOD, requiring app protection via Conditional Access, and app configuration policies.

You can protect only the data inside apps without managing the whole device. Different in purpose from pre-configuring settings.

4.2.1App protection policies (MAM)

App protection policies are MAM (Mobile Application Management) that protect org data inside apps (restrict copy/paste, encryption, restrict "save as", require PIN). Because device enrollment (MDM) is not required, they protect unmanaged BYOD per app, and apply to managed devices too. Combine with Microsoft Entra Conditional Access to require an approved client app + an app protection policy for access. Remember: "in-app data protection (no enrollment)" = app protection policy.

4.2.2App configuration policies

App configuration policies pre-configure app settings for managed apps or managed devices and distribute them (connection URLs, defaults, sign-on info). This "pre-populates app settings," a different role from app protection policies (which protect data). It is also a different layer from device compliance (whole-device compliance).

Continue reading — free sign-up

You're reading the free preview. Sign up free to read this section in full, plus every chapter (including 4+) and all questions.