What Can Intune App Protection Policy Protect on Windows Devices?

Answer Correct answer: D — Microsoft Edge is the only app protected by an Intune app protection policy on Windows devices.

You have a Microsoft 365 E5 subscription. All Windows devices are enrolled in Microsoft Intune. You need to create an app protection policy named Policy1 and apply Policy1 to the devices. What can you protect by using Policy1?

  1. Microsoft Outlook
  2. Microsoft OneDrive
  3. Microsoft Teams
  4. Microsoft Edge Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the Windows-specific limitation of Intune app protection policies: only Microsoft Edge is supported, while the common trap is assuming Outlook, OneDrive, or Teams are also covered because they are on mobile platforms.

In a Microsoft 365 E5 tenant with Windows devices enrolled in Intune, an app protection policy can protect only Microsoft Edge for organizational data access. This page confirms why the answer is Edge (D) and not Outlook, OneDrive, or Teams.

Choosing Microsoft Outlook (A) because it handles sensitive email, but on Windows, Outlook is not a supported app for Intune app protection policies.

Community Discussion (10 comments)

Meek_Learner 👍 2 Selected: D
An app protection policy can protect all apps shown in the answer choices (Outlook, OneDrive, Teams, Edge). I imagine there is a type mistake, the correct question is: You have a Microsoft 365 E5 subscription. All Windows devices are enrolled in Microsoft Intune. You need to create a device configuration policy named Policy1 and apply Policy1 to the devices. What can you protect by using Policy1? a. Microsoft Outlook b. Microsoft OneDrive c. Microsoft Teams d. Microsoft Edge Then option D is the perfect choice.
6060 👍 1 Selected: D
For Windows platform, app protection only covers Edge, tested on Tenant
HardeWerker433 👍 2
Fellas - https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy :) You can do 'em for all.
RomanV 👍 3 Selected: D
"You can enable protected MAM access to org data via Microsoft Edge on personal Windows devices." https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-windows
EUC_PRO 👍 1 Selected: D
D Edge is correct
dabhelia 👍 3 Selected: D
Test when you create new app protection policy the only app that i can choose is Edge.
Pollosor 👍 2 Selected: D
I think there was a "NO" missing here.
smith288 👍 2
It works for Office 365 apps. Outlook is an Office App. https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy#app-protection-policies-for-microsoft-365-office-apps. I vote A.
Frank_2022 👍 2 Selected: A
Outlook is the primary application for handling email, and therefore, it's the most suitable target for an app protection policy to safeguard sensitive email data.
jdr002 👍 2 Selected: D
Correct. https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy-settings-windows

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

For Windows devices managed by Intune, app protection policies (also called MAM) support only Microsoft Edge. The official "App protection policy settings for Windows" documentation states that you can enable protected MAM access to organizational data via Microsoft Edge on personal Windows devices. When you create a new app protection policy for the Windows platform in the Intune admin center, Edge is the sole app you can select. Therefore, Policy1 can protect only Microsoft Edge among the listed options. This matches the exam's intended Windows-specific scoping.

Why the Other Options Are Wrong

Microsoft Outlook (A), OneDrive (B), and Teams (C) are all valid targets for app protection policies on Android and iOS, but not on Windows. On Windows, those apps are protected through other mechanisms such as Windows Information Protection (WIP) or Conditional Access, not through Intune app protection policies. Selecting any of them would incorrectly assume the mobile MAM support matrix applies to Windows. The question's emphasis on "Windows devices enrolled in Intune" is the key differentiator that narrows the answer to Edge.

Community Comment Notes

RomanV cited the Microsoft doc confirming "protected MAM access to org data via Microsoft Edge on personal Windows devices." dabhelia tested this in a tenant and found that when creating a new app protection policy, Edge is the only app available to choose. Meek_Learner suspected a typo and argued all four apps can be protected, but that reasoning applies to other policy types or platforms. 6060 also confirmed from tenant testing that "For Windows platform, app protection only covers Edge." EUC_PRO simply concluded "D Edge is correct."

Official Reference

Exam Strategy

Memorize the platform-specific support matrix: app protection policies on Windows = Edge only, while iOS/Android support Office apps. When a question specifies Windows devices, eliminate Outlook, OneDrive, and Teams immediately.

Frequently Asked Questions

Why can't Outlook be protected by an app protection policy on Windows?

Intune app protection policies on Windows only support Microsoft Edge. Outlook MAM policies apply to iOS and Android devices, not Windows.

If devices are enrolled in Intune, do app protection policies still apply?

Yes, but on Windows the only supported app for app protection policies is Microsoft Edge; device configuration profiles handle other settings.

Related Analysis

Practice All MD-102 Questions

Access 92 questions with complete answers and detailed explanations.

View Full MD-102 Practice Test →

← Back to MD-102 Study Guide