Prevent Data Copy Paste Between Excel and Other Apps
You have a Microsoft 365 subscription that uses Microsoft Intune Suite. You use Intune to manage all devise. Users have iOS devices with Microsoft apps installed. You need to prevent users from cutting, copying, and pasting data between Microsoft Excel and other apps installed on the devices. What should you configure?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the specific capability of App Protection Policies to restrict data transfer mechanisms like clipboard sharing between managed and unmanaged applications.
To prevent data cut, copy, and paste operations between Microsoft Excel and other apps on iOS devices using Intune, you must configure an app protection policy. This policy enforces data loss prevention (DLP) controls specifically for managed apps.
Many candidates mistakenly select 'policies for Microsoft Office apps' because they assume Office-specific settings handle cross-app data flow, but DLP controls are centralized in App Protection Policies.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
An App Protection Policy (APP) is the correct configuration for enforcing Data Loss Prevention (DLP) rules within managed apps on iOS devices. Specifically, APPs allow administrators to define restrictions on data transfer, such as preventing users from copying corporate data from a managed app (like Excel) to an unmanaged app or system-wide clipboard. This ensures that sensitive information remains contained within the managed environment.Why the Other Options Are Wrong
App Configuration Policies (Option B) are used to deploy custom settings and preferences to apps (e.g., setting a default server URL), but they do not enforce security boundaries or DLP rules like clipboard restrictions. iOS App Provisioning Profiles (Option C) are primarily for installing and managing app entitlements and certificates, not for runtime data protection. While 'policies for Microsoft Office apps' (Option D) might seem relevant, the granular control over inter-app data movement is a feature of the broader Intune App Protection framework, which applies to all supported managed apps including Office.Community Comment Notes
Community consensus strongly supports Option A. As noted by user Merrybob, official Microsoft documentation confirms that App Protection Policies include features for preventing users from copying and pasting corporate data into personal apps. Other commenters like krzysiek321 and Krayzr simply verified the correctness of this answer without adding conflicting technical details.Official Reference
Exam Strategy
When dealing with data security and isolation in Intune, always look for 'App Protection Policy' first. It is the primary tool for DLP tasks like encryption, authentication, and restricting data transfer between apps.
Frequently Asked Questions
Why not use App Configuration Policies for this?
App Configuration Policies only set app-specific settings (like URLs) and cannot enforce security controls like blocking clipboard access between apps.
Does this work for Android too?
Yes, App Protection Policies also apply to Android devices, allowing similar DLP controls like restricting copy/paste to managed apps.
Related Analysis
Practice All MD-102 Questions
Access 92 questions with complete answers and detailed explanations.
View Full MD-102 Practice Test →