Skip to content
How to use Entra Require App Protection Policy in Conditional Access for Secure Access

How to use Entra Require App Protection Policy in Conditional Access for Secure Access

Written By Anoop C Nair
Last Updated March 24, 2025
Posted In Azure AD
SHARE

Hey there, Let’s discuss about enable the Require app protection policy setting in conditional access. The “Require app protection policy” setting in Conditional Access is a security feature designed to ensure that access to corporate resources is only granted through apps that have specific protection policies applied.

What is conditional access? yes, we all know that Conditional Access is a security feature in Microsoft Azure Active Directory (Azure AD) that allows organizations to enforce granular access controls based on specific conditions. It acts as a gatekeeper, ensuring that only authorized users, devices, and applications can access corporate resources, while protecting against potential threats.

It is typically applied to mobile apps to prevent unauthorized or insecure apps from accessing sensitive data. By enforcing this policy, organizations can reduce the risk of data breaches, ensure compliance, and protect corporate information from being accessed or leaked through unmanaged or unprotected applications.

It enforces policies that require additional verification steps or restrict access based on risk. Through this post we need to ensure that our Grant settings in Conditional Access are configured to use the “Require app protection policy” setting to enforce secure access to corporate resources.

Patch My PC

What is the Purpose of Require App Protection Policy?


It ensures that only apps with Intune App Protection Policies can access corporate data, and protects against data leakage by enforcing encryption, PIN requirements, and other security controls.

How to use Entra Require App Protection Policy in Conditional Access for Secure Access

Sign in to the Microsoft Entra admin center as at least a Conditional Access Administrator. Browse to Protection > Conditional Access > Policies. Select a policy that uses the approved client app grant. Under Access controls > select Grant access. Then select Require approved client app and Require app protection policy.

A Require Approved Client AppRequire App Protection Policy
No longer enforced from March 2026. Only checks that the app supports app protection policiesOnly allow access if the app supports app protection policies and an app protection policy is applied for the account.
Enable the Require app Protection Policy Setting in Conditional Access – Table.1
How to use Entra Require App Protection Policy in Conditional Access for Secure Access - Fig.1
How to use Entra Require App Protection Policy in Conditional Access for Secure Access – Fig.1

For multiple controls select Require one of the selected controls. Confirm your settings and set the Enable policy to Report-only. Select Create to create to enable your policy.

How to use Entra Require App Protection Policy in Conditional Access for Secure Access - Fig.2
How to use Entra Require App Protection Policy in Conditional Access for Secure Access – Fig.2
CatagorySettingDescriptionExample
Data Protection Encryption Ensures data is encrypted at rest and in transit. Require encryptions for all corporate data.EncryptionEnsures data is encrypted at rest and in transitRequire encryption for all corporate data.
How to use Entra Require App Protection Policy in Conditional Access for Secure Access – Table.2

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Resources

LinkedIn post of Scott Breen

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Azure AD

Microsoft Azure Removes Default Internet Access for New Virtual Networks

Key Takeaways Here, we are discussing Microsoft Azure Removes Default Internet Access for New Virtual Networks. According to the latest news coming that After March 31, 2026, any newly created Virtual Network (VNet) will no longer have automatic access to the internet. This update was highlighted by Christiaan Brinkhoff on his social media platform. Microsoft […]

AC Anoop C Nair 4 min read
Azure AD

PowerShell Script to Track Upcoming Microsoft Entra App Secret Expirations

PowerShell Script to Track Upcoming Microsoft Entra App Secret Expirations! In this article, I’ll walk you through a powerful automation designed to enhance proactive security and lifecycle management for Microsoft Entra applications. You’ll learn how to monitor Entra app registrations and automate the detection of upcoming secret key expirations, ensuring your identity infrastructure stays secure […]

SN Sujin Nelladath 7 min read
Azure AD

How New TURN Relay IP Range Enhances RDP Shortpath for AVD and Windows 365

Let’s discuss How New TURN Relay IP Range Enhances RDP Shortpath for AVD and Windows 365. Microsoft is going to launch a new improvement on Windows 365 and Azure Virtual Desktop called TURN relay. This is a dedicated IP range across the Microsoft Azure public cloud. TURN Relays new range 51.5.0.0/16 enhances RDP Shortpath connectivity […]

AC Anoop C Nair 4 min read