Your company uses Microsoft Intune to manage iOS devices. You need to ensure that corporate data in Microsoft 365 apps is protected even if a device is compromised. Which App Protection Policy setting should you configure?
Trap 1: Configure device compliance policy to require jailbreak detection.
This is device-level, not app-level data protection.
Trap 2: Configure device configuration profile to require device PIN.
This is device-level, not app-level data protection.
Trap 3: Configure App Protection Policy to require app PIN.
App PIN is for access, not data transfer protection.
- A
Configure device compliance policy to require jailbreak detection.
Why it fails: This is device-level, not app-level data protection.
- B
Configure App Protection Policy with 'Restrict cut, copy, and paste' and 'Allow app to transfer data to other apps' set to Policy managed apps.
Setting 'Allow app to transfer data to other apps' to Policy managed apps and restricting cut, copy and paste prevents corporate data leaving the protected app ecosystem into unmanaged apps, protecting Microsoft 365 data even on a compromised device.
- C
Configure device configuration profile to require device PIN.
Why it fails: This is device-level, not app-level data protection.
- D
Configure App Protection Policy to require app PIN.
Why it fails: App PIN is for access, not data transfer protection.