Setting up and managing device configurations using Intune
The recommended method is to separate browser access for Edge from desktop client access, and use Require App Protection policy for Edge instead of Require device to be marked as compliant.
- Create a Conditional Access policy for browser access on Windows BYOD:
- Users or agents (Preview): target the BYOD Users group
- Target resources: Office 365 or the protected resources
- Conditions → Client apps: Browser
- Conditions → Device platforms: Windows
- Grant: Require App Protection policy
- Create an Intune App Protection policy for Windows:
- In Intune admin center, go to Apps → Protection → Create → Windows
- Under Apps, select Microsoft Edge
- Configure the required data protection settings
- Assign the policy to the same BYOD Users group targeted by the Conditional Access browser policy
- Do not require Require compliant device for the Edge MAM onboarding flow on unmanaged Windows devices.
- A policy that targets Mobile apps and desktop clients and grants Require device to be marked as compliant can block MAM enrollment.
- The documented guidance for Windows app protection specifically marks Require compliant device as not supported for this scenario because users will be blocked from MAM enrollment.
- For the user sign-in flow in Edge on BYOD Windows:
- Users sign in to the protected site in Edge
- Select Switch Edge profile if prompted
- Select Yes when Windows offers to remember the account and sign in to apps, websites, and services
- If the MDM enrollment prompt appears, select No. Selecting Yes enrolls the device in MDM, not MAM, and can interfere with the intended BYOD MAM flow.
- To block Outlook Desktop, Teams Desktop, OneDrive Sync, and other desktop clients on unmanaged devices without breaking Edge onboarding:
- Keep a separate Conditional Access policy for Mobile apps and desktop clients
- Apply Require device to be marked as compliant there
- Do not use that control as the mechanism for Edge browser access on unmanaged Windows devices
This achieves the design goal:
- Edge on unmanaged Windows BYOD: allowed through Require App Protection policy with Edge MAM
- Desktop clients on unmanaged devices: blocked by the separate Mobile apps and desktop clients + Require compliant device policy
If users still get prompted after the You're all set page, the documented causes include:
- MAM enrollment is still processing
- This app only was selected on the heads-up page
- enrollment expired or the user is not compliant with organizational requirements
- a preexisting unregistered Edge account/profile is blocking proper MAM enrollment
In that case, wait a few minutes and retry in a new tab, or have the administrator verify that Intune MAM policies are applying correctly.
- Protect corporate data in Microsoft Edge using Intune App Protection (MAM)
- Require an app protection policy on Windows devices
- Require an app protection policy on Windows devices
- Require an app protection policy on Windows devices
- Data Protection for Windows MAM
- Archived release notes for Microsoft Edge Stable Channel