Windows app protection
With more users accessing corporate data from personal devices, application protection is more important than ever.
At the time of writing, Windows Mobile Application Management (MAM) is a new addition and only supports the Microsoft Edge browser. For that reason, we are going to configure MAM in this recipe and then also add conditional access policies to block anything that is not Microsoft Edge for personal devices.
Getting started
The first thing to watch here is that personal devices are not allowed to enroll in Microsoft Intune; otherwise, they will bypass the conditional access rules. This will be covered in Chapter 13, Tenant Administration.
How to do it…
Follow these steps to configure Windows application protection:
- The first step is to enable MAM across the tenant. This only has to be done once.
- In Tenant administration, click on Connectors and tokens and then Mobile Threat Defense.
- Add a connector for Windows...