How to Use Intune to Block Microsoft 365 Apps on Personal Devices Except Teams
Question details
An organization needs to restrict access to specific Microsoft 365 applications like Outlook, OneDrive, and SharePoint on unmanaged personal mobile devices, while explicitly allowing access to Microsoft Teams.
- Product
- Microsoft Intune
- Device & OS
- not provided
- Scenario
- Applying Conditional Access and App Protection Policies to personal (BYOD) devices to segment application availability.
- Observed behavior
- Currently, users can access all Microsoft 365 apps on personal devices, but the administrative goal is to limit this access strictly to Microsoft Teams.
Ensure you have Microsoft Intune administrator privileges and that your Microsoft Entra ID (formerly Azure AD) supports Conditional Access policies, which requires a Premium P1 or P2 license.
Seek Specialized Microsoft Q&A Support
Because Conditional Access policies can inadvertently lock users out of their corporate environment, complex app exclusions are best verified by Microsoft deployment experts.
Configuring policies that block core apps like Outlook while allowing Teams involves careful interaction between Endpoint Manager, App Protection Policies (MAM), and Entra ID Conditional Access. To ensure a flawless deployment, consulting the official Microsoft community is highly recommended.
Open your web browser and go to the official Microsoft Q&A community forums.
Use the search or tag system to locate the 'Microsoft Intune Enrollment' or 'Conditional Access' topic sections.
Describe your exact requirement: blocking Outlook, OneDrive, and SharePoint on unmanaged BYOD devices while allowing Teams via App Protection Policies or Conditional Access.
Configure Conditional Access with App Protection Policies (MAM)
A standard architectural approach to segmenting app access on personal devices without requiring full Mobile Device Management (MDM) enrollment.
Looking for a Lightweight Office Solution for BYOD Devices?
Managing Microsoft 365 licensing and strict Intune Conditional Access policies across personal devices can be complex for IT teams. WPS Office provides a free, lightweight, and highly compatible alternative for users needing reliable document editing without strict enterprise overhead.
- 1. Download the App: Get WPS Office for free from the official website or your device's respective app store.
- 2. Install on Personal Devices: Follow the simple installation prompts to set up the lightweight client on your Windows, Mac, iOS, or Android device.
- 3. Open Office Formats Instantly: Open, view, and edit standard Word, Excel, and PowerPoint files seamlessly without navigating corporate lockouts.

Frequently Asked Questions
Can I block specific Microsoft 365 apps using just basic MDM?
Usually, Mobile Device Management (MDM) manages the entire device at the OS level. To selectively block specific applications like Outlook while allowing Teams on personal devices, Mobile Application Management (MAM) combined with Conditional Access is the preferred method.
Does Conditional Access require a specific Microsoft license?
Yes, configuring and enforcing Conditional Access policies requires your tenant to have Microsoft Entra ID (formerly Azure AD) Premium P1 or P2 licenses.
Why is Microsoft Teams often grouped with other Office apps in Conditional Access?
Microsoft Teams is categorized under the broader 'Office 365' cloud app suite within Conditional Access dependencies. To manage it separately, administrators must utilize targeted App Protection Policies and carefully filter device states.




