Endpoint management

MAM

Mobile Application Management

Mobile Application Management is the discipline of securing corporate data at the application layer rather than the device layer. It applies policy to individual apps such as Outlook, Teams, and OneDrive so that corporate information stays encrypted, access-controlled, and separable from personal data, even on a device the organisation does not own or fully manage.

Why MAM matters in a Microsoft estate

MAM matters for endpoint teams because device, app, compliance, update, and troubleshooting signals often sit across several Microsoft admin areas. Linking these terms back to Intune and device-reporting routes helps readers move from definition to action.

How MAM shows up in practice

In Microsoft Intune, MAM is delivered through app protection policies, which wrap supported apps with controls covering PIN or biometric authentication before the app opens, encryption of app data at rest, restrictions on cut, copy, and paste between managed and unmanaged apps, and blocking of backup to unmanaged cloud storage. They also provide a selective wipe capability that removes corporate data and access from the managed app without touching personal photos, messages, or other apps on the device. This is what makes MAM the practical answer to Bring Your Own Device programmes.

It protects the organisation's data without requiring the user to hand over the level of control that full Mobile Device Management enrolment implies, and it avoids the legal and trust problems that come from an organisation being able to remotely wipe a personally owned phone in its entirety. MAM operates in two distinct modes that get confused often. MAM for enrolled devices layers app protection on top of an already MDM-managed device for defence in depth. MAM without enrolment, sometimes called MAM-WE, applies app protection entirely independently of device enrolment. This is the mode used for unmanaged personal devices, and increasingly for external users and guest accounts accessing Teams or SharePoint through app protection policies rather than full membership.

A frequent misconception is that MAM alone is sufficient security policy. Without Conditional Access requiring an approved client app or app protection policy as a condition of sign-in, users can often route around MAM entirely by accessing mail or files through a browser or a non-managed mail client not subject to the wrapped-app controls. App protection policy targeting is also more fragile in practice than it looks on paper, since policies are assigned per platform and per app.

Gaps commonly appear when a newly adopted app, such as a third-party PDF viewer with Intune SDK integration or a new Microsoft app like Loop, isn't included in the existing policy set. That gap then ends up as an unprotected path for corporate data. Because MAM policies apply per user and per app rather than per device, licence and coverage auditing has to be done at that same granularity. It's common in mature estates to find users covered for Outlook and Teams but with gaps in newer or less obvious managed apps, and those gaps quietly become the weak point in an otherwise well-designed BYOD data protection strategy.

Related terms

Glossary