Your company uses Microsoft Intune to manage corporate devices. The security team wants to prevent users from copying sensitive data from corporate apps to personal apps on mobile devices. Which Intune policy should you configure?
App protection policies (APPs) are the correct choice because they are specifically designed to prevent corporate data leakage in mobile apps. These MAM (mobile application management) policies apply directly to applications like Outlook or Teams and can restrict data transfer actions such as copy/paste, screen capture, or saving corporate data to unmanaged apps/cloud services. They work independently of device enrollment, so they remain effective even if the device is a personal phone, directly addressing the concern of safeguarding data in unmanaged apps.
Why this answer
App protection policies (APP) are the correct Intune policy to prevent data transfer from corporate apps to personal apps on mobile devices. These policies apply at the application layer, allowing you to configure data protection settings such as 'Restrict cut, copy, and paste' and 'Allow app to transfer data to other apps' specifically for managed apps, regardless of the device enrollment state.
Exam trap
The trap here is confusing device-level policies (compliance or configuration) with app-level data protection, leading candidates to select device compliance policies or device configuration policies instead of app protection policies.
How to eliminate wrong answers
Option A is wrong because device configuration policies manage device-level settings (e.g., Wi-Fi, VPN, certificates) and do not control data sharing between apps on mobile devices. Option C is wrong because Windows Information Protection (WIP) is a Windows-only feature for desktop devices and does not apply to mobile platforms like iOS or Android. Option D is wrong because device compliance policies enforce device-level security requirements (e.g., jailbreak detection, minimum OS version) and do not restrict app-to-app data transfer.