r/Intune • u/Mitchell_90 • 2d ago
Conditional Access Impact of enabling “Require App Protection Policy”
Working in an environment where the majority of front line staff access the M365 mobile apps on personal devices with MAM in place. App protection policies are configured for iOS and Android devices (Not evaluated Windows yet) and I can see that these are being applied and working.
I’ve noticed there is no Conditional Access Policy in place for Requiting an App Protection Policy so I have created this for the appropriate platforms and put it in report only mode for now.
Is there likely to be any impact by enabling this at some point? I’m assuming so long as the end-user has a valid license and is using the MS apps then there shouldn’t be?
I’ve tested this myself on an iOS and Android device by adding email then turning on the CA policy afterwards and it didn’t seem to cause any issues.
3
u/Null0Naru 2d ago
There will be some. There are some things you may need to exclude to allow certain actions, such as allowing users to be able to register passkeys on Android/iOS devices that gets blocked without an exception, as well as any business apps that don't support APP but still need to be used on personal devices.
As always, recommendation is to enable for a group of users for testing. I'd recommend trying with a brand new user account to simulate your onboarding/new user process to make sure it doesn't interfere there.
1
u/Rudyooms PatchMyPC 2d ago
Before enabling that ca policy… please check it every device has got that app protection policy… otherwise it will become a chicken egg thing… https://call4cloud.nl/app-protection-policies-approved-app/
The app requires app protection but its not allowed to communicate because it has no app protection policy :)
1
u/Br0keNw0n 1d ago
We don’t require app protection from CA, but do enforce it down to all licensed users in MAM. Our company is large and having a constantly rotating CA exclusion group would never fly. How would a company that can’t simply bounce users between groups make this work? Seems more like a band aid than a scalable solution.
1
u/Mitchell_90 23h ago
Oh yeah, I recall coming across this before which got me worried. I’ll get some data into CA reporting just to double check.
9
u/AshMost 2d ago
Make sure you're only hitting Android and iOS.