App protection policies Flashcards

(23 cards)

1
Q

What do Intune app protection policies (APP) ensure?

A

They ensure an organization’s data remains safe or contained in a managed app.

APP rules control how data is accessed and shared by apps on mobile devices.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What can an Intune app protection policy enforce?

A

A rule enforced when the user attempts to access or move ‘corporate’ data.

It can also include a set of actions that are prohibited or monitored inside the app.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What are some benefits of using Intune app protection policies?

A
  • Protecting corporate data on mobile devices without requiring device enrollment
  • Controlling how data is accessed and shared by apps on mobile devices
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Can Intune app protection policies be used independently of MDM solutions?

A

Yes, they can be used independent of any mobile-device management (MDM) solution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What types of devices can have app protection policies configured?

A
  • Devices enrolled in Microsoft Intune
  • Devices enrolled in a third-party MDM solution
  • Devices not enrolled in any MDM solution
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is required for an app to be managed using Intune app protection policies?

A

The app must be integrated with the Intune SDK or wrapped by the Intune App Wrapping Tool.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What are the end-user requirements to use app protection policies on an Intune-managed app?

A
  • The end user must have a Microsoft Entra account
  • The end user must have a license for Microsoft Intune assigned to their Microsoft Entra account
  • The end user must belong to a security group targeted by an app protection policy
  • The end user must sign into the app using their Microsoft Entra account
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What are the 9 high level steps to create App protection policies for iOS/iPadOS and Android apps?

A
  1. Apps > Protection. This selection opens the Protection details, where you create new policies and edit existing policies.
  2. Select Create policy and select either iOS/iPadOS or Android
  3. Basics : Name + Descr
  4. Apps page You must add at least one app.
  5. Data protection :
  6. Access requirements
  7. Conditional launch
  8. Assignments: to groups of users
  9. Review+create
How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What is required on the Apps page of the app protection policy?

A

You must add at least one app

The Apps page allows you to choose which apps should be targeted by this policy.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What controls can be configured on the Data protection page?

A

Data loss prevention (DLP) controls, including cut, copy, paste, and save-as restrictions

These settings determine how users interact with data in the apps that this app protection policy applies.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What settings does the Access requirements page provide?

A

Settings to configure the PIN and credential requirements that users must meet to access apps

This is specifically for accessing apps in a work context.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What does the Conditional launch page allow you to configure?

A

Sign-in security requirements for your app protection policy

You can select a Setting, enter the Value that users must meet, and select the Action for non-compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

What is the purpose of the Assignments page?

A

To assign the app protection policy to groups of users

The policy must be applied to a group of users to take effect.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Fill in the blank: The Data protection page includes _______ controls.

A

[DLP]

DLP stands for Data Loss Prevention, which includes various data interaction restrictions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

True or False: Multiple actions can be configured for a single setting on the Conditional launch page.

A

True

This allows flexibility in handling sign-in security requirements.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What must be done for the app protection policy to take effect?

A

Apply the policy to a group of users

This is done through the Assignments page.

17
Q

What is the relationship between Intune app protection policies and data loss prevention (DLP) controls?

A

Policies can have strict DLP controls for unmanaged devices and more relaxed controls for MDM managed devices

18
Q

How can you create or edit an Intune app protection policy?

A

Browse to Apps > Protection in the Intune admin center, then select Create policy or edit an existing policy

19
Q

What is the first step to use filters when assigning Intune app protection policies?

A

Navigate to the Assignments page and select Edit filter

20
Q

What is the data protection policy for unmanaged devices?

A

Strict data loss prevention (DLP) controls are in place

This policy ensures high security for devices that are not managed by a Mobile Device Management (MDM) system.

21
Q

How does the data protection policy for MDM managed devices differ from that for unmanaged devices?

A

The DLP controls may be a little more relaxed

MDM managed devices typically have more oversight and management, allowing for less stringent DLP measures.

22
Q

Fill in the blank: You can have one data protection policy for unmanaged devices in which _______ controls are in place.

A

strict data loss prevention (DLP)

23
Q

True or False: Both unmanaged and MDM managed devices have strict DLP controls.

A

False

Unmanaged devices have strict DLP controls, while MDM managed devices have more relaxed controls.