Your organization uses Azure AD, Microsoft 365, Intune, and Azure Information Protection. The security requirements state: personal devices do not need Intune enrollment; users must enter a PIN before accessing corporate email; personal iOS and Android devices may access corporate cloud services; and users must be prevented from copying corporate email content to cloud storage services other than OneDrive for Business. Which configuration should you create to enforce these rules?
Choose an answer
Tap an option to check your answer.
Correct answer: an app protection policy from the Microsoft Intune admin center.
Why this is the answer
An app protection policy (APP) from the Microsoft Intune admin center is the correct solution. APPs protect organizational data within applications, even on personal devices not enrolled in Intune. This directly addresses the requirement for personal devices not needing Intune enrollment while still enforcing security. APPs can enforce a PIN for app access (corporate email), allow access to corporate cloud services on personal iOS and Android devices, and prevent data leakage by restricting copy-pasting corporate content to unauthorized cloud storage services. Device configuration profiles manage device-level settings, not app-level data protection on unenrolled devices. DLP policies in Purview focus on data classification and preventing data exfiltration across various services, but APPs are specifically designed for in-app data protection on mobile devices. Insider risk management policies detect and act on risky user activities, which is a different security domain.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed