App protection policies Flashcards
(23 cards)
What do Intune app protection policies (APP) ensure?
They ensure an organization’s data remains safe or contained in a managed app.
APP rules control how data is accessed and shared by apps on mobile devices.
What can an Intune app protection policy enforce?
A rule enforced when the user attempts to access or move ‘corporate’ data.
It can also include a set of actions that are prohibited or monitored inside the app.
What are some benefits of using Intune app protection policies?
- Protecting corporate data on mobile devices without requiring device enrollment
- Controlling how data is accessed and shared by apps on mobile devices
Can Intune app protection policies be used independently of MDM solutions?
Yes, they can be used independent of any mobile-device management (MDM) solution.
What types of devices can have app protection policies configured?
- Devices enrolled in Microsoft Intune
- Devices enrolled in a third-party MDM solution
- Devices not enrolled in any MDM solution
What is required for an app to be managed using Intune app protection policies?
The app must be integrated with the Intune SDK or wrapped by the Intune App Wrapping Tool.
What are the end-user requirements to use app protection policies on an Intune-managed app?
- The end user must have a Microsoft Entra account
- The end user must have a license for Microsoft Intune assigned to their Microsoft Entra account
- The end user must belong to a security group targeted by an app protection policy
- The end user must sign into the app using their Microsoft Entra account
What are the 9 high level steps to create App protection policies for iOS/iPadOS and Android apps?
- Apps > Protection. This selection opens the Protection details, where you create new policies and edit existing policies.
- Select Create policy and select either iOS/iPadOS or Android
- Basics : Name + Descr
- Apps page You must add at least one app.
- Data protection :
- Access requirements
- Conditional launch
- Assignments: to groups of users
- Review+create
What is required on the Apps page of the app protection policy?
You must add at least one app
The Apps page allows you to choose which apps should be targeted by this policy.
What controls can be configured on the Data protection page?
Data loss prevention (DLP) controls, including cut, copy, paste, and save-as restrictions
These settings determine how users interact with data in the apps that this app protection policy applies.
What settings does the Access requirements page provide?
Settings to configure the PIN and credential requirements that users must meet to access apps
This is specifically for accessing apps in a work context.
What does the Conditional launch page allow you to configure?
Sign-in security requirements for your app protection policy
You can select a Setting, enter the Value that users must meet, and select the Action for non-compliance.
What is the purpose of the Assignments page?
To assign the app protection policy to groups of users
The policy must be applied to a group of users to take effect.
Fill in the blank: The Data protection page includes _______ controls.
[DLP]
DLP stands for Data Loss Prevention, which includes various data interaction restrictions.
True or False: Multiple actions can be configured for a single setting on the Conditional launch page.
True
This allows flexibility in handling sign-in security requirements.
What must be done for the app protection policy to take effect?
Apply the policy to a group of users
This is done through the Assignments page.
What is the relationship between Intune app protection policies and data loss prevention (DLP) controls?
Policies can have strict DLP controls for unmanaged devices and more relaxed controls for MDM managed devices
How can you create or edit an Intune app protection policy?
Browse to Apps > Protection in the Intune admin center, then select Create policy or edit an existing policy
What is the first step to use filters when assigning Intune app protection policies?
Navigate to the Assignments page and select Edit filter
What is the data protection policy for unmanaged devices?
Strict data loss prevention (DLP) controls are in place
This policy ensures high security for devices that are not managed by a Mobile Device Management (MDM) system.
How does the data protection policy for MDM managed devices differ from that for unmanaged devices?
The DLP controls may be a little more relaxed
MDM managed devices typically have more oversight and management, allowing for less stringent DLP measures.
Fill in the blank: You can have one data protection policy for unmanaged devices in which _______ controls are in place.
strict data loss prevention (DLP)
True or False: Both unmanaged and MDM managed devices have strict DLP controls.
False
Unmanaged devices have strict DLP controls, while MDM managed devices have more relaxed controls.