Using Microsoft 365 App Protection for Desktop Apps on Personal Devices
Question details
Users want to know if Conditional Access and Windows app protection policies can secure company data when volunteers use Microsoft 365 desktop applications (like Microsoft Publisher) on personal devices.

- Product
- Microsoft 365 Business Premium
- Device & OS
- Windows
- Scenario
- Securing organizational data on volunteers' personal unmanaged devices using Conditional Access and Intune app protection policies.
- Observed behavior
- Windows app protection policies primarily support Microsoft Edge for web access, leaving unsupported desktop apps like Microsoft Publisher unable to be natively protected or accessed via a web version.
Before configuring app protection policies, ensure you have an active Microsoft 365 Business Premium license and administrative access to the Microsoft Endpoint Manager admin center.
Configure Intune App Protection Policies for Supported Apps
Use Intune App Protection Policies (MAM) to protect organizational data on personal devices without requiring full device enrollment.
Intune app protection policies can restrict data transfer, enforce access requirements like a PIN, and require encryption on personal devices. However, for Windows environments, app protection currently primarily supports Microsoft Edge for secure web access to Office for the Web.
Sign in to the Microsoft Endpoint Manager admin center (Intune) with your administrator credentials.
Navigate to Apps > App protection policies and click Create policy. Select the appropriate policy type (e.g., Windows Information Protection) for your environment.
Add supported applications, such as Microsoft Edge, to the protected apps list. This ensures organizational data accessed through the browser is managed.
Set up data protection and access settings, such as restricting copy/paste between work and personal apps, requiring a PIN, or blocking saving to personal storage.

Address Limitations with Microsoft Publisher
Understand the support limitations of App Protection with desktop applications like Microsoft Publisher and find alternative workflows.
Looking for a Lightweight and Compatible Office Alternative?
If managing complex Microsoft 365 Conditional Access policies and dealing with heavy, unsupported desktop apps is slowing down your volunteer team, consider WPS Office. It provides a lightweight, highly compatible alternative for viewing and editing standard documents across all personal devices.
- 1. Download the Installer: Visit the official WPS Office website and download the free installer for Windows, Mac, or Linux.
- 2. Install on Personal Devices: Have volunteers run the lightweight installer on their personal devices with standard permissions.
- 3. Open and Edit Documents: Launch WPS Office and seamlessly open standard Office formats (.docx, .xlsx, .pptx) to continue working efficiently.

Frequently Asked Questions
Does Windows App Protection support Microsoft Publisher?
No, Microsoft Publisher is currently not supported for Windows App Protection policies, and it does not offer a web-based version for secure browser access.
Can I prevent users from copying company data to personal apps?
Yes, using Intune App Protection Policies, you can restrict data transfer actions like copy, paste, and 'save as' between managed organizational applications and unmanaged personal apps.
What browser should be used for Conditional Access app protection on personal Windows devices?
Microsoft Edge is the officially supported browser for securely accessing organizational data via Office for the Web when utilizing Windows app protection policies.
Do volunteers need to fully enroll their personal devices to use app protection?
No, Intune App Protection Policies (MAM) can be applied to specific applications to secure company data without requiring full Mobile Device Management (MDM) enrollment, keeping personal and work data separate.




