Step-by-Step Guide: Setting Up MAM (Mobile Application Management) in Intune
Setting up Mobile Application Management (MAM) in Microsoft Intune involves several steps. MAM allows you to protect and manage the apps that your employees use to access corporate data, without requiring device enrollment. Here's a guide to help you set it up:
Step 1: Sign in to the Microsoft Intune Portal
Sign in to the Microsoft Endpoint Manager admin center: Visit endpoint.microsoft.com and log in with your administrator credentials.
Step 2: Configure MAM Policies
MAM policies are used to protect corporate data in mobile apps.
Navigate to "Apps":
In the left-hand pane, select Apps.
Create an App Protection Policy:
Under Policies, select App protection policies.
Click Create policy.
Choose the platform (iOS/iPadOS or Android).
Configure App Policy Settings:
Basics: Provide a name for your policy and an optional description.
Targeted apps: Select the apps you want to apply this policy to. You can choose from the Microsoft recommended apps or manually add custom apps by entering the app package name or URL.
Data protection: Configure settings related to data protection, such as preventing data backup, restricting copy/paste between apps, encrypting app data, etc.
Access requirements: Set up access requirements such as requiring a PIN, setting a minimum OS version, or requiring a managed device.
Conditional launch: Define what actions should be taken if certain conditions are met, such as a maximum PIN attempts before data is wiped.
Assignments: Assign the policy to user groups.
Review and Create:
Review the policy configuration and click Create.
Step 3: Assign MAM Policies to Users
Assign Policy:
After creating the policy, you need to assign it to a user group.
Go to the Assignments section in the policy you just created.
Click Select groups to include and choose the user groups to which you want the policy to apply.
Step 4: Enable Conditional Access (Optional)
Conditional Access ensures that only compliant devices or approved apps can access your company’s data.
Go to Conditional Access:
In the Microsoft Endpoint Manager admin center, go to Devices > Conditional Access.
Create a New Policy:
Click New policy.
Define the users, apps, and conditions you want to apply.
Set Grant to require an app protection policy.
Assign the Policy:
Assign the policy to the appropriate groups and applications.
Step 5: Monitor and Manage MAM Policies
Monitor Compliance:
Go to Apps > App protection status to monitor the compliance and status of your app protection policies.
Review Logs:
Check for any issues or alerts related to MAM policies and troubleshoot as necessary.
Step 6: End-User Experience
Once the MAM policies are deployed, users will experience the following:
When accessing protected apps, they might be prompted to enter a PIN or meet other access requirements.
Data sharing will be restricted according to the policy settings.
The apps will enforce encryption and other data protection measures.
This setup provides a secure way to manage and protect corporate data within mobile applications, even on devices that are not enrolled in Intune.






Comments