What Can Intune App Protection Policy Protect on Windows Devices?
You have a Microsoft 365 E5 subscription. All Windows devices are enrolled in Microsoft Intune. You need to create an app protection policy named Policy1 and apply Policy1 to the devices. What can you protect by using Policy1?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the Windows-specific limitation of Intune app protection policies: only Microsoft Edge is supported, while the common trap is assuming Outlook, OneDrive, or Teams are also covered because they are on mobile platforms.
In a Microsoft 365 E5 tenant with Windows devices enrolled in Intune, an app protection policy can protect only Microsoft Edge for organizational data access. This page confirms why the answer is Edge (D) and not Outlook, OneDrive, or Teams.
Choosing Microsoft Outlook (A) because it handles sensitive email, but on Windows, Outlook is not a supported app for Intune app protection policies.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
For Windows devices managed by Intune, app protection policies (also called MAM) support only Microsoft Edge. The official "App protection policy settings for Windows" documentation states that you can enable protected MAM access to organizational data via Microsoft Edge on personal Windows devices. When you create a new app protection policy for the Windows platform in the Intune admin center, Edge is the sole app you can select. Therefore, Policy1 can protect only Microsoft Edge among the listed options. This matches the exam's intended Windows-specific scoping.Why the Other Options Are Wrong
Microsoft Outlook (A), OneDrive (B), and Teams (C) are all valid targets for app protection policies on Android and iOS, but not on Windows. On Windows, those apps are protected through other mechanisms such as Windows Information Protection (WIP) or Conditional Access, not through Intune app protection policies. Selecting any of them would incorrectly assume the mobile MAM support matrix applies to Windows. The question's emphasis on "Windows devices enrolled in Intune" is the key differentiator that narrows the answer to Edge.Community Comment Notes
RomanV cited the Microsoft doc confirming "protected MAM access to org data via Microsoft Edge on personal Windows devices." dabhelia tested this in a tenant and found that when creating a new app protection policy, Edge is the only app available to choose. Meek_Learner suspected a typo and argued all four apps can be protected, but that reasoning applies to other policy types or platforms. 6060 also confirmed from tenant testing that "For Windows platform, app protection only covers Edge." EUC_PRO simply concluded "D Edge is correct."Official Reference
Exam Strategy
Memorize the platform-specific support matrix: app protection policies on Windows = Edge only, while iOS/Android support Office apps. When a question specifies Windows devices, eliminate Outlook, OneDrive, and Teams immediately.
Frequently Asked Questions
Why can't Outlook be protected by an app protection policy on Windows?
Intune app protection policies on Windows only support Microsoft Edge. Outlook MAM policies apply to iOS and Android devices, not Windows.
If devices are enrolled in Intune, do app protection policies still apply?
Yes, but on Windows the only supported app for app protection policies is Microsoft Edge; device configuration profiles handle other settings.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →