logo
search
Conditional Access Problems

Fix Edge App Protection Policy Applying to Excluded Co-Owned Devices

Maira MehtabMaira Mehtab Sep 22, 2026 869 views

Question details

The user needs to resolve an issue where an Edge App Protection Policy, intended strictly for personal devices, is actively applying to co-owned devices despite explicit exclusions.

Product
Microsoft Entra ID / Microsoft Edge
Device & OS
not provided
Scenario
Managing mobile application management (MAM) and device policies in a mixed-ownership environment without restricting corporate or co-owned hardware.
Observed behavior
Co-owned devices are receiving the Edge app protection policy that was meant only for personal devices, ignoring the exclusions configured in the Conditional Access policy.
Before you start

Gather your Microsoft Entra ID tenant credentials, verify the exact Conditional Access policy configuration, and confirm the specific Intune enrollment status of the affected co-owned devices.

Solution 1Recommended

Verify Device Filters and Escalate to Microsoft Engineering

Since App Protection Policies (MAM) and Conditional Access evaluate device state differently, you must verify your Intune assignment filters and consult Entra ID specialists.

Conditional Access exclusions rely on the device being properly recognized by Entra ID. If a co-owned device is not accurately tagged or managed by Intune, the App Protection Policy might default to applying the restriction. Complex exclusion failures typically require a review of tenant-specific routing and logs.

1
Check device ownership status

Navigate to the Microsoft Intune admin center. Go to Devices > All devices, locate the affected co-owned devices, and verify that the 'Ownership' attribute is correctly set to 'Corporate' rather than 'Personal'.

2
Review Conditional Access exclusions

Log into the Azure portal, navigate to Microsoft Entra ID > Security > Conditional Access. Open the specific policy, click on 'Conditions', then 'Filter for devices', and ensure the syntax specifically excludes your co-owned device parameters.

3
Examine Entra ID sign-in logs

Go to Microsoft Entra ID > Monitoring > Sign-in logs. Filter by the affected user and check the 'Conditional Access' tab on the log entry to see exactly which policies were applied and why the exclusion failed.

4
Consult specialized engineers

Gather your configuration details and post the issue in the Microsoft Entra ID section of Microsoft Q&A. Specialized Microsoft engineers can review backend policy misalignments and provide specific tenant diagnostics.

Important Distinction: Keep in mind that Intune App Protection Policies (MAM) have their own assignment filters separate from Entra Conditional Access. Ensure you are excluding the devices at the MAM policy assignment level as well.
Free Microsoft Office alternative

Looking for a Lightweight, Enterprise-Ready Office Suite?

While navigating complex Microsoft enterprise policies and access controls, you may also be looking for a simpler, cost-effective productivity solution for your hardware. WPS Office provides a powerful, free alternative to Microsoft Office that is easy to deploy across both personal and co-owned devices without extensive configuration.

  1. 1. Download the installer: Visit the official WPS website and download the free installer for your specific operating system.
  2. 2. Install WPS Office: Run the setup file and follow the on-screen instructions to deploy the lightweight office suite on your device.
  3. 3. Open existing documents: Launch WPS Office and open your existing Microsoft Office files seamlessly without worrying about format conversion issues.
Fully compatible with Microsoft Word, Excel, and PowerPoint formats (.docx, .xlsx, .pptx)Lightweight installation suitable for all device ownership modelsBuilt-in PDF editing, signing, and cloud collaboration toolsCost-effective solution for both personal (BYOD) and co-owned enterprise devices
microsoft office alternative - wps office

Frequently Asked Questions

Why does an app protection policy ignore my Conditional Access exclusion?

App Protection Policies (MAM) and Conditional Access policies operate on different evaluation engines. Even if a Conditional Access policy is successfully bypassed, a MAM policy might still apply if it is targeted directly to the user group without a corresponding Intune assignment filter that excludes managed or co-owned devices.

How does Microsoft Entra determine if a device is co-owned or personal?

Device ownership is typically determined during the enrollment process. Devices enrolled via corporate methods (like Windows Autopilot or Apple Business Manager) are flagged as Corporate. Devices enrolled via standard user-driven methods default to Personal unless manually changed by an administrator.

Can I apply Edge app protection only to unmanaged devices?

Yes. When creating or editing an App Protection Policy in Intune, you can use the 'Target to apps on all device types' setting to 'No', and then select 'Unmanaged' in the device management types. This ensures the policy does not affect your fully managed corporate or co-owned devices.