Field note
Cyber Essentials Plus BYOD and Mobile MAM Policy
BYOD is one of the most common stumbling blocks in Cyber Essentials Plus audits: personal phones need isolation, encryption and wipe controls without alienating employees.
Personal smartphones and tablets accessing Microsoft 365 email, Teams, or OneDrive are one of the most common audit traps in UK Cyber Essentials Plus assessments.
When employees check work email on an iPhone or Android phone, that device enters the assessment scope. Assessors need proof that business data is protected by biometrics or a PIN, that corporate data cannot be copied to personal storage, and that the company can revoke access immediately if a device is lost, stolen, or an employee departs.
Full Mobile Device Management (MDM) enrollment across personal handsets often triggers immediate pushback from staff concerned about privacy or company visibility. Mobile Application Management (MAM) with Microsoft Intune App Protection Policies provides the exact compliant middle ground.
Quick answer
You do not need full MDM device enrollment on employee-owned personal phones to pass Cyber Essentials Plus. Configure Microsoft Intune App Protection Policies (MAM without enrollment) combined with Microsoft Entra Conditional Access to require approved client apps and app protection. This enforces app-level PINs, device lock compliance, copy/paste containment, and selective corporate data wipe without touching personal photos or messages.
Who this affects
This applies to UK organisations undergoing Cyber Essentials or Cyber Essentials Plus where staff access Microsoft 365 services (Exchange Online, Teams, SharePoint, OneDrive) on personal iOS or Android handsets.
It matters most for businesses on Microsoft 365 Business Premium or E3/E5 licenses where personal phones have historically connected via basic active sync, native mail apps, or unmanaged browser sessions without centralised configuration.
What usually goes wrong
| Gap | Why it matters |
|---|---|
| Native mobile mail apps | Built-in mail clients bypass Intune MAM sandbox protections and store data unencrypted |
| Incomplete Conditional Access | Users can access Outlook Web in Safari or Chrome without any container protection |
| No selective wipe procedure | When a staff member leaves, corporate mail and cached documents remain on the handset |
| Missing PIN or biometric policy | Cyber Essentials requires authentication before accessing organisation data |
| Jailbroken or rooted devices allowed | Operating system integrity is not verified before granting access to tenant resources |
Allowing staff to use native iOS Mail or unmanaged Samsung email apps is an immediate compliance failure because those apps do not support Intune data protection sandboxes or remote app wiping.
What to check first
Before an assessor schedules device sampling, verify your mobile access controls across these areas:
| Check | Where to look | Bad sign |
|---|---|---|
| Conditional Access mobile rules | Entra admin center > Conditional Access | Users can sign in from mobile browsers without app protection |
| Intune App Protection status | Intune admin center > Apps > App protection policies | No active iOS or Android policies deployed to all licensed users |
| Approved client app enforcement | Conditional Access grant controls | Legacy ActiveSync or unapproved third-party mail apps allowed |
| Copy/paste transfer restrictions | Intune policy data transfer settings | Corporate data can be pasted into personal WhatsApp or notes |
| Minimum OS version rules | Intune app protection conditional launch | Devices running unsupported iOS or Android versions can authenticate |
Evidence to collect
When preparing for Cyber Essentials Plus verification, the assessor will review policy configurations and sample several user devices to verify practical enforcement:
| Requirement | Evidence to prepare |
|---|---|
| App protection policies active | Export or screenshot of Intune App Protection Policies for iOS and Android |
| Conditional Access grant controls | Screenshot showing "Require app protection policy" targeted at Office 365 cloud apps |
| Data containment proof | Demonstration that copying text from Outlook or Teams into personal Notes is blocked |
| App PIN enforcement | Verification that opening Outlook on a mobile device prompts for face ID, fingerprint or PIN |
| Selective wipe capability | Documented procedure and Intune test record demonstrating retired corporate data removal |
Keep your evidence cleanly organized with the policy names, target user groups, and matching timestamped screenshots.
Fix path
- Deploy Intune App Protection Policies for iOS and Android: Navigate to Microsoft Intune admin center > Apps > App protection policies. Create separate baseline policies for iOS/iPadOS and Android targeting all licensed users.
- Configure Data Protection Settings: Restrict cut, copy, and paste between work and personal apps (set to "Blocked" or "Policy managed apps with paste in"). Block saving copies of corporate files to personal cloud storage (e.g. iCloud, Google Drive, personal device storage).
- Configure Access Requirements: Enforce PIN for access, requiring numeric or alphanumeric PIN, and allow biometrics (Touch ID, Face ID, Android fingerprint) in place of PIN.
- Define Conditional Launch Checks: Set a maximum PIN attempt limit (e.g. 5 attempts before wipe), require jailbroken/rooted device detection with "Block access", and enforce minimum operating system versions supported by Apple and Google.
- Enforce via Entra ID Conditional Access: Create a Conditional Access policy targeting Mobile Apps and Desktop Clients on iOS and Android. In Grant controls, select "Require app protection policy" and "Require approved client app".
- Block Mobile Browser Bypasses: In the same Conditional Access framework, restrict mobile browser access to sensitive resources or route mobile browsers through managed application containers.
- Test on a Sample BYOD Device: Verify that downloading the Microsoft Outlook app prompts for organizational account configuration, triggers the Intune MAM registration prompt, requires biometric/PIN confirmation, and successfully restricts external file sharing.
Common mistakes
The most common mistake is assuming that setting up an Intune App Protection Policy alone enforces security. Without an active Entra ID Conditional Access policy requiring that protection policy, users can simply bypass Intune by signing in through an unmanaged mobile web browser or a generic IMAP client.
Another frequent failure is neglecting to document the selective wipe process. Assessors want to see that if an employee hands in their notice, an administrator can trigger an App Selective Wipe in Intune that erases all cached corporate data, emails, and SharePoint files without deleting personal photos, text messages, or personal apps.
Related route
For full audit preparation, evidence gathering, and technical remediation across your Microsoft 365 tenant, explore our Cyber Essentials Plus readiness consulting.
References
Related notes
05 May 2026 · 4 min
Related: cyber essentials plus readiness, microsoft 365 security readiness, ce+ microsoft intune defender.
04 May 2026 · 3 min
Related: cyber essentials plus, intune, defender for endpoint.
12 Mar 2026 · 3 min
Related: cyber essentials plus, audit logs, microsoft purview.
Need help mapping this to your own tenant, controls, or assessment timeline?