Skip to content
Intune MAM for Personal Windows Devices is now Generally Available

Intune MAM for Personal Windows Devices is now Generally Available

Written By Sumitha P
Last Updated September 22, 2023
Posted In Intune
SHARE

Intune MAM for Personal Windows Devices is now Generally Available with the Intune 2309 version update. This MAM feature for Windows was in preview, and it was released back with Intune version 2306.

Intune MAM for Windows depends on the Microsoft Edge version as well. So, it’s important to note that your BYO device should have an updated version of Windows 11 and Microsoft Edge browser.

The MAM feature is available only with the Microsoft Edge browser now. In the MAM scenario, you don’t need to enrol BYO devices into Intune. Managing personal devices using corporate device management solutions such as Intune is not something all regulators or governments will allow in certain regions.

With the Intune 2309 release, you can now enable protected MAM (Intune App Protection Policies) access to org data via Microsoft Edge on personal Windows devices.

Patch My PC
Intune MAM for Personal Windows Devices is now Generally Available Fig.1
Intune MAM for Personal Windows Devices is now Generally Available Fig.1 Creds to Microsoft

Prerequisites – Intune MAM for Personal Windows

Now, look into the prerequisites to enable Intune MAM for Personal Windows devices. You need to ensure that Microsoft Edge, Microsoft Intune, and Windows versions are up to date as per the below table to enable this feature.

  • NOTE! – Sovereign cloud support is expected in the future.
Intune MAM for Personal Windows DevicesMinimum Version Requirements
Windows Operating SystemWindows 11, build 10.0.22621 (22H2) or later
Microsoft IntuneMicrosoft Intune (2309 release or later)
Microsoft EdgeMS Edge Browser v117 stable branch and later
Windows Security CenterWindows Security (aka Defender) v 1.0.2309.xxxxx and late
Intune MAM for Personal Windows Devices is now Generally Available – Table 1

Also, ensure that the MAM scope is set to ALL from Azure AD (Entra ID portal) or Intune portal DevicesWindows Enrollment Auto Enrollment options. This setting helps enable personal devices to enrol in Intune MAM management.

  • Navigate to Intune portal DevicesWindows Enrollment Auto Enrollment options.
  • Default MAM Discovery URL – https://wip.mam.manage.microsoft.com/Enroll
Intune MAM for Personal Windows Devices is now Generally Available Fig. 2
Intune MAM for Personal Windows Devices is now Generally Available Fig. 2

Priority | Conflicts – MAM Vs. Full Management of Windows personal devices

You must look into three scenarios while implementing the Intune MAM policies for Windows personal devices. All those scenarios are explained below. This is a very important scenario that you need to understand how Intune avoids conflicts by giving Priority to fully managed scenarios when dealing with MAM Vs. Full Management of Windows personal devices.

Intune MAM on Windows supports unmanaged devices. Intune MAM enrollment will be blocked if a device is already managed, and APP settings will not be applied. APP settings will no longer be applied if a device becomes managed after MAM enrollment.

Conflicting Scenarios – MAM vS. Fully ManagedMAM for WindowsFull Management of Windows
Already Fully managed devices getting MAM policiesEnrollment will be blocked, and policies won’t applyWinner
A device becomes Fully managed after MAM enrollmentPolicies won’t no longer be appliedWinner
Intune MAM for Personal Windows Devices is now Generally Available – Table 2
Intune MAM for Personal Windows Devices is now Generally Available - Fig 3
Intune MAM for Personal Windows Devices is now Generally Available – Fig 3

4 Pillars of MAM for Windows Personal Device

MAM for Windows personal devices includes 4 main pillars: Microsoft EdgeConditional access policiesApp protection policies, and Windows Defender. The App Protection Conditional Access (MAM CA) is in Public Preview.

Resource – You can get more details on the MAM Policy creation process – App protection policy settings for Windows – Microsoft Intune | Microsoft Learn

Intune MAM for Personal Windows Devices is now Generally Available Fig. 4
Intune MAM for Personal Windows Devices is now Generally Available Fig. 4

Author

Sumitha was introduced to the world of computers when she was very young. She loves to help users with their Windows 11 and related queries. She is here to share quick news, tips and tricks with Windows security.

Written by

Sumitha was introduced to the world of computers when she was very young. She loves to help users with their Windows 11 and related queries. She is here to share quick tips and tricks with Windows security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read