Block Unmanaged App Email Access with Intune
You have a Microsoft 365 subscription that includes Microsoft Intune. You create a new Android app protection policy named Policy1 that prevents screen captures in all Microsoft apps. You discover that an unmanaged email client installed on Android devices can still capture screens. You need to ensure that users can only use Microsoft apps to access email. What should you do?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
App protection policies only apply to managed apps; Conditional Access is required to block unmanaged apps from accessing corporate data like email.
This scenario tests enforcing corporate email access through managed Microsoft apps on Android devices. The page establishes that Conditional Access is the correct solution to block unmanaged clients from accessing data.
Choosing to modify the app protection policy assignments or settings, which fails because app protection policies cannot restrict unmanaged apps that are not targeted by the policy.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Creating a Conditional Access policy allows administrators to enforce that corporate data, such as email, can only be accessed through approved applications. By configuring a Conditional Access policy to require an approved client app (like Outlook), you effectively block unmanaged email clients from connecting to Exchange Online. This directly addresses the requirement to ensure users only use Microsoft apps for email access.Why the Other Options Are Wrong
Modifying the assignments or data protection settings of Policy1 will not prevent the unmanaged email client from accessing email or capturing screens, because App Protection Policies only apply to apps that are managed or targeted by Intune. A compliance policy evaluates device health but does not directly block unmanaged apps from accessing corporate data at the application level.Community Comment Notes
Commenters agree that Conditional Access is the logical choice to "block access from anything not approved," as servL noted. Frank_2022 highlighted that a Conditional Access policy can "require users to use an Intune-managed app" to access email services, which indirectly solves the screen capture issue by eliminating the unmanaged client.Official Reference
Exam Strategy
When asked to block unmanaged apps from accessing corporate data, look for Conditional Access as the solution. App protection policies only protect data within managed apps and cannot restrict unmanaged apps.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →