Protect Mobile Data with MAM, No MDM Needed
App Protection Policies (MAM) protect your work apps on mobile without enrolling the personal phone. Here's how and why it works for BYOD.
Your staff read their work email on personal phones, whether they declare it or not. Fully enrolling them in device management (MDM) raises real concerns about privacy, consent and sometimes outright rejection: few people accept that their employer manages their private phone. App Protection Policies, or MAM (Mobile Application Management), offer an elegant alternative: protect only the data inside work applications, without ever touching the rest of the device or seeing personal data. It is a pragmatic answer to a very common problem, and one that regulators and works councils tend to welcome because it draws a clear, defensible line between what the employer governs and what remains strictly private.
MAM vs MDM: what's the difference?
The distinction is fundamental and shapes your whole mobile architecture choice. MDM manages the entire device; MAM focuses on the app and its data. Understanding where the boundary lies helps you address users' legitimate concerns.
The scope of each
MDM enrolls the device, applies global restrictions and can wipe it entirely. MAM, by contrast, acts as a bubble around work data inside compatible apps, with no grip on the system or personal apps.
- MDM enrolls and manages the whole device; MAM protects the app alone.
- MAM requires no enrollment of the personal phone.
- It applies to compatible apps like Outlook, Teams, Word or Edge.
- A wipe in MAM affects only the work data.
Why MAM reassures in BYOD
In BYOD, the user keeps full control of their device. The company sees neither their photos, nor their messages, nor their personal apps. This clean separation removes the main barrier to adoption and eases GDPR compliance, since the employer never processes private data.
What App Protection Policies protect
An app protection policy governs data behavior inside Microsoft 365 apps. You control data exchange, authentication and saving, without ever accessing the user's personal content.
- 1Require a PIN or biometrics to open the work application.
- 2Block copy-paste from managed apps to unmanaged apps.
- 3Prevent saving work files outside approved locations (OneDrive, SharePoint).
- 4Encrypt work data at rest inside the application.
- 5Remotely wipe only the work data when someone leaves or loses the phone.
When to choose MAM (and when not to)
MAM suits personal devices (BYOD), contractors and temporary use perfectly. For company-provided and company-owned devices, MDM remains more comprehensive because it also manages system configuration, certificates and hardware restrictions. The two approaches are not opposed: they can coexist depending on user profiles.
Common mistakes to avoid
MAM is powerful, but a few pitfalls recur during first deployments.
- Believing MAM encrypts the whole phone: it only protects data inside managed apps.
- Forgetting to pair MAM with Conditional Access to allow only protected apps.
- Configuring overly strict restrictions that break legitimate business use.
- Ignoring that some incompatible apps cannot be governed by MAM.
- Not explaining to users why an app PIN is being requested.
With MAM, the company protects its data without ever intruding on the private phone.
A concrete example
A consulting firm employs many contractors who read their engagement email and documents on their own phones. Enrolling all these devices in MDM would be unthinkable: neither the contractors nor the legal team would accept full management of personal devices owned by third parties. The answer is MAM: an App Protection Policy requires a PIN to open Outlook and Teams, blocks copy-paste to unmanaged apps and prevents saving attachments outside OneDrive. The day an engagement ends, a selective wipe removes the company's data without ever touching the contractor's personal data.
This example shows MAM's real strength: it protects data where it lives, inside the application, without imposing the weight and intrusion of MDM. For every situation where the company does not own the device, it is often the only approach that is at once effective, acceptable to users and GDPR-compliant. It lets you extend the same protection to seasonal staff, partners and personal phones without a single enrollment.
Calibrating with Microsoft's data protection framework
Rather than inventing your settings from scratch, lean on the data protection framework Microsoft documents for App Protection Policies. It structures the settings into three progressive levels, from the most flexible to the strictest, sparing you both under-provisioning and the excess zeal that breaks usage. Each level adds further requirements around the PIN, data transfer and access conditions, so you climb in security through controlled steps rather than all at once.
- 1Basic level: app PIN, encryption of work data and remote selective wipe.
- 2Enhanced level: blocking copy-paste to unmanaged apps and restricting saving to approved locations.
- 3High level: stricter PIN requirements and additional conditional access controls for sensitive data.
- 4Assign each level to the matching user profile, from the general population to high-risk groups.
- 5Periodically review the applied level as usage and threats evolve.
Adopting this framework has a double benefit: you save time by starting from a proven baseline, and you gain a common language to justify your choices to an auditor. Rather than defending each ticked box in isolation, you demonstrate that your configuration matches a recognized level of protection, tailored to the real sensitivity of the data being handled.
Combining MAM with Conditional Access
MAM protects data inside applications, but it reaches its full strength when paired with Conditional Access. You can then require that access to work email or files be possible only from a managed application protected by an App Protection Policy. A user who tries to open their work mailbox in an unmanaged mail app would be denied access, without the company having to manage their phone at all.
- Require an approved, protected app to access work data.
- Block access from unmanaged applications.
- Enforce a PIN or biometrics before the app opens.
- Condition access on compliance with the protection policy.
- All without enrolling or managing the personal device.
This combination delivers a level of security close to MDM for work data, while fully preserving the user's privacy. It is the key to a BYOD program that is at once secure, GDPR-compliant and accepted by teams rather than resented by them.
How AuPoint helps
AuPoint lets you deploy App Protection Policies in a few clicks, in plain language, with an impact preview before application and reversible policies. You secure your mobile data in BYOD while respecting GDPR and your teams' privacy, and you naturally connect these policies to Conditional Access to allow only protected applications.
Frequently asked questions
Does MAM work on iOS and Android?
Yes. App Protection Policies apply to compatible Microsoft 365 applications on both iOS and Android, with equivalent settings for PIN, copy-paste blocking and restricted saving.
What does the company see on a MAM phone?
Nothing of the personal sphere. IT manages the policy applied to work apps and can wipe only the work data, but has no visibility into the user's photos, messages or private apps.
Can you wipe only the work data?
Yes, that is a major strength of MAM. When someone leaves or loses the device, a selective wipe removes work data from managed apps while leaving all personal data intact.
Do you need a license to use MAM?
Yes. MAM without enrollment relies on an Intune license assigned to the users concerned. That license is what allows App Protection Policies to be applied to their work applications, regardless of the device used.
Want to secure BYOD mobility without enrolling personal phones? With AuPoint, deploy your App Protection Policies in a few clicks, in full respect of GDPR and privacy.