logo
search
Conditional Access Problems

How to Use Intune to Block Microsoft 365 Apps on Personal Devices Except Teams

Maira MehtabMaira Mehtab Sep 28, 2026 869 views

Question details

An organization needs to restrict access to specific Microsoft 365 applications like Outlook, OneDrive, and SharePoint on unmanaged personal mobile devices, while explicitly allowing access to Microsoft Teams.

Product
Microsoft Intune
Device & OS
not provided
Scenario
Applying Conditional Access and App Protection Policies to personal (BYOD) devices to segment application availability.
Observed behavior
Currently, users can access all Microsoft 365 apps on personal devices, but the administrative goal is to limit this access strictly to Microsoft Teams.
Before you start

Ensure you have Microsoft Intune administrator privileges and that your Microsoft Entra ID (formerly Azure AD) supports Conditional Access policies, which requires a Premium P1 or P2 license.

Solution 1Recommended

Seek Specialized Microsoft Q&A Support

Because Conditional Access policies can inadvertently lock users out of their corporate environment, complex app exclusions are best verified by Microsoft deployment experts.

Configuring policies that block core apps like Outlook while allowing Teams involves careful interaction between Endpoint Manager, App Protection Policies (MAM), and Entra ID Conditional Access. To ensure a flawless deployment, consulting the official Microsoft community is highly recommended.

1
Navigate to Microsoft Q&A

Open your web browser and go to the official Microsoft Q&A community forums.

2
Select Intune Enrollment

Use the search or tag system to locate the 'Microsoft Intune Enrollment' or 'Conditional Access' topic sections.

3
Post Your Scenario

Describe your exact requirement: blocking Outlook, OneDrive, and SharePoint on unmanaged BYOD devices while allowing Teams via App Protection Policies or Conditional Access.

Free Microsoft Office alternative

Looking for a Lightweight Office Solution for BYOD Devices?

Managing Microsoft 365 licensing and strict Intune Conditional Access policies across personal devices can be complex for IT teams. WPS Office provides a free, lightweight, and highly compatible alternative for users needing reliable document editing without strict enterprise overhead.

  1. 1. Download the App: Get WPS Office for free from the official website or your device's respective app store.
  2. 2. Install on Personal Devices: Follow the simple installation prompts to set up the lightweight client on your Windows, Mac, iOS, or Android device.
  3. 3. Open Office Formats Instantly: Open, view, and edit standard Word, Excel, and PowerPoint files seamlessly without navigating corporate lockouts.
Fully compatible with Microsoft Office formats (.docx, .xlsx, .pptx)No complex Intune conditional access setup required for basic document editingLightweight application suitable for personal mobile devices and laptopsFree to use with a familiar, easy-to-navigate user interface
microsoft office alternative - wps office

Frequently Asked Questions

Can I block specific Microsoft 365 apps using just basic MDM?

Usually, Mobile Device Management (MDM) manages the entire device at the OS level. To selectively block specific applications like Outlook while allowing Teams on personal devices, Mobile Application Management (MAM) combined with Conditional Access is the preferred method.

Does Conditional Access require a specific Microsoft license?

Yes, configuring and enforcing Conditional Access policies requires your tenant to have Microsoft Entra ID (formerly Azure AD) Premium P1 or P2 licenses.

Why is Microsoft Teams often grouped with other Office apps in Conditional Access?

Microsoft Teams is categorized under the broader 'Office 365' cloud app suite within Conditional Access dependencies. To manage it separately, administrators must utilize targeted App Protection Policies and carefully filter device states.