Intune MAM for Personal Windows Devices is now Generally Available

Intune MAM for Personal Windows Devices is now Generally Available with the Intune 2309 version update. This MAM feature for Windows was in preview, and it was released back with Intune version 2306.

Intune MAM for Windows depends on the Microsoft Edge version as well. So, it’s important to note that your BYO device should have an updated version of Windows 11 and Microsoft Edge browser.

The MAM feature is available only with the Microsoft Edge browser now. In the MAM scenario, you don’t need to enrol BYO devices into Intune. Managing personal devices using corporate device management solutions such as Intune is not something all regulators or governments will allow in certain regions.

With the Intune 2309 release, you can now enable protected MAM (Intune App Protection Policies) access to org data via Microsoft Edge on personal Windows devices.

Patch My PC
Intune MAM for Personal Windows Devices is now Generally Available Fig.1
Intune MAM for Personal Windows Devices is now Generally Available Fig.1 Creds to Microsoft

Prerequisites – Intune MAM for Personal Windows

Now, look into the prerequisites to enable Intune MAM for Personal Windows devices. You need to ensure that Microsoft Edge, Microsoft Intune, and Windows versions are up to date as per the below table to enable this feature.

  • NOTE! – Sovereign cloud support is expected in the future.
Intune MAM for Personal Windows DevicesMinimum Version Requirements
Windows Operating SystemWindows 11, build 10.0.22621 (22H2) or later
Microsoft IntuneMicrosoft Intune (2309 release or later)
Microsoft EdgeMS Edge Browser v117 stable branch and later
Windows Security CenterWindows Security (aka Defender) v 1.0.2309.xxxxx and late
Intune MAM for Personal Windows Devices is now Generally Available – Table 1

Also, ensure that the MAM scope is set to ALL from Azure AD (Entra ID portal) or Intune portal DevicesWindows Enrollment Auto Enrollment options. This setting helps enable personal devices to enrol in Intune MAM management.

Adaptiva
  • Navigate to Intune portal DevicesWindows Enrollment Auto Enrollment options.
  • Default MAM Discovery URL – https://wip.mam.manage.microsoft.com/Enroll
Intune MAM for Personal Windows Devices is now Generally Available Fig. 2
Intune MAM for Personal Windows Devices is now Generally Available Fig. 2

Priority | Conflicts – MAM Vs. Full Management of Windows personal devices

You must look into three scenarios while implementing the Intune MAM policies for Windows personal devices. All those scenarios are explained below. This is a very important scenario that you need to understand how Intune avoids conflicts by giving Priority to fully managed scenarios when dealing with MAM Vs. Full Management of Windows personal devices.

Intune MAM on Windows supports unmanaged devices. Intune MAM enrollment will be blocked if a device is already managed, and APP settings will not be applied. APP settings will no longer be applied if a device becomes managed after MAM enrollment.

Conflicting Scenarios – MAM vS. Fully ManagedMAM for WindowsFull Management of Windows
Already Fully managed devices getting MAM policiesEnrollment will be blocked, and policies won’t applyWinner
A device becomes Fully managed after MAM enrollmentPolicies won’t no longer be appliedWinner
Intune MAM for Personal Windows Devices is now Generally Available – Table 2
Intune MAM for Personal Windows Devices is now Generally Available - Fig 3
Intune MAM for Personal Windows Devices is now Generally Available – Fig 3

4 Pillars of MAM for Windows Personal Device

MAM for Windows personal devices includes 4 main pillars: Microsoft EdgeConditional access policiesApp protection policies, and Windows Defender. The App Protection Conditional Access (MAM CA) is in Public Preview.

Resource – You can get more details on the MAM Policy creation process – App protection policy settings for Windows – Microsoft Intune | Microsoft Learn

Intune MAM for Personal Windows Devices is now Generally Available Fig. 4
Intune MAM for Personal Windows Devices is now Generally Available Fig. 4

Author

Sumitha was introduced to the world of computers when she was very young. She loves to help users with their Windows 11 and related queries. She is here to share quick news, tips and tricks with Windows security.

Leave a Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.