Fix Edge App Protection Policy Applying to Excluded Co-Owned Devices
Question details
The user needs to resolve an issue where an Edge App Protection Policy, intended strictly for personal devices, is actively applying to co-owned devices despite explicit exclusions.
- Product
- Microsoft Entra ID / Microsoft Edge
- Device & OS
- not provided
- Scenario
- Managing mobile application management (MAM) and device policies in a mixed-ownership environment without restricting corporate or co-owned hardware.
- Observed behavior
- Co-owned devices are receiving the Edge app protection policy that was meant only for personal devices, ignoring the exclusions configured in the Conditional Access policy.
Gather your Microsoft Entra ID tenant credentials, verify the exact Conditional Access policy configuration, and confirm the specific Intune enrollment status of the affected co-owned devices.
Verify Device Filters and Escalate to Microsoft Engineering
Since App Protection Policies (MAM) and Conditional Access evaluate device state differently, you must verify your Intune assignment filters and consult Entra ID specialists.
Conditional Access exclusions rely on the device being properly recognized by Entra ID. If a co-owned device is not accurately tagged or managed by Intune, the App Protection Policy might default to applying the restriction. Complex exclusion failures typically require a review of tenant-specific routing and logs.
Navigate to the Microsoft Intune admin center. Go to Devices > All devices, locate the affected co-owned devices, and verify that the 'Ownership' attribute is correctly set to 'Corporate' rather than 'Personal'.
Log into the Azure portal, navigate to Microsoft Entra ID > Security > Conditional Access. Open the specific policy, click on 'Conditions', then 'Filter for devices', and ensure the syntax specifically excludes your co-owned device parameters.
Go to Microsoft Entra ID > Monitoring > Sign-in logs. Filter by the affected user and check the 'Conditional Access' tab on the log entry to see exactly which policies were applied and why the exclusion failed.
Gather your configuration details and post the issue in the Microsoft Entra ID section of Microsoft Q&A. Specialized Microsoft engineers can review backend policy misalignments and provide specific tenant diagnostics.
Looking for a Lightweight, Enterprise-Ready Office Suite?
While navigating complex Microsoft enterprise policies and access controls, you may also be looking for a simpler, cost-effective productivity solution for your hardware. WPS Office provides a powerful, free alternative to Microsoft Office that is easy to deploy across both personal and co-owned devices without extensive configuration.
- 1. Download the installer: Visit the official WPS website and download the free installer for your specific operating system.
- 2. Install WPS Office: Run the setup file and follow the on-screen instructions to deploy the lightweight office suite on your device.
- 3. Open existing documents: Launch WPS Office and open your existing Microsoft Office files seamlessly without worrying about format conversion issues.

Frequently Asked Questions
Why does an app protection policy ignore my Conditional Access exclusion?
App Protection Policies (MAM) and Conditional Access policies operate on different evaluation engines. Even if a Conditional Access policy is successfully bypassed, a MAM policy might still apply if it is targeted directly to the user group without a corresponding Intune assignment filter that excludes managed or co-owned devices.
How does Microsoft Entra determine if a device is co-owned or personal?
Device ownership is typically determined during the enrollment process. Devices enrolled via corporate methods (like Windows Autopilot or Apple Business Manager) are flagged as Corporate. Devices enrolled via standard user-driven methods default to Personal unless manually changed by an administrator.
Can I apply Edge app protection only to unmanaged devices?
Yes. When creating or editing an App Protection Policy in Intune, you can use the 'Target to apps on all device types' setting to 'No', and then select 'Unmanaged' in the device management types. This ensures the policy does not affect your fully managed corporate or co-owned devices.




