Employees often access corporate data using smartphones and tablets — many of which are personal, unmanaged devices. While mobile access increases flexibility and productivity, it also introduces security risks if data is downloaded, copied, or shared outside of approved apps or environments. This lesson focuses on how to use Conditional Access to enforce App Protection Policies . These policies allow organizations to protect company data at the app level, rather than the device level, by controlling how data is accessed, used, and stored within mobile apps like Outlook, OneDrive, and Teams. By requiring an App Protection Policy before allowing access to Microsoft 365 services, you ensure that sensitive information remains secure — even on personal devices — without needing to enroll them in full device management.
Log into the Entra Admin Center or click on Home if you are already in Entra.
From the Navigation Pane under Protection, select Conditional Access.
Select + Create New policy.
Name the policy: CA05: Require App Protection Policy
Under Users click on 0 Users and groups selected.
Click on Include then select All users.
Under Exclude, click on the box next to Users and groups.
Note: if the pop-up window does not open automatically, click on 0 users and groups selected.
In the pop-up window, select the Emergency Access Account
Click on Select at the bottom of the screen.
Under Target resources click No target resources selected.
Under Include, select All resources (formerly ‘All cloud apps’)
Under Conditions, click 0 conditions selected
Under Device platforms, click Not configured
Click Yes to configure the settings
Under Include, click Select device platforms then Android and iOS
Click Exclude then click on the boxes next to macOS and Linux.
Click Done.
Under Grant, click 0 controls selected
Click Grant access
Click Require app protection policy
Click Require one of the selected controls
At the bottom of the page under Enable policy, select Report-only then Proceed with selected configuration. The tenant is not configured for macOS and Linux and may receive prompts when the device is checked for compliance
Click on Create to finalize this policy.