App protection policies
Security considerations for managing Surface Duo
SE CUR IT Y L EVELSE CUR IT Y L EVEL TARG ET ED TOTA RGE TED TO SU MMARYSUM M A RY SE TT INGS I NF OSE TT INGS I NF O
Work profile basic security Level 1
Personal devices with access
to work or school data.
Introduces password
requirements, separates
work and personal data,
and validates Android
device attestation.
Work profile level 1 settings
Work profile high security Level 3
(Due to framework
conventions, this is the next
level above Level 1.)
**
Devices used by users or
groups who are uniquely
high risk. For example,
users who handle highly
sensitive data where
unauthorized disclosure
causes considerable
material loss.
Introduces mobile threat
defense or Microsoft
Defender ATP, sets the
minimum Android version
to 8.0, enacts stronger
password policies, and
further restricts work and
personal separation.
Work profile level 3 settings
Fully managed basic
security -Level 1
Minimum-security
configuration for an
enterprise device, applicable
to most mobile users
accessing work or school
data.
Introduces password
requirements, sets the
minimum Android version
to 8.0, and enacts certain
device restrictions.
Fully managed Level 1
settings
Fully managed enhanced
security Level 2
Devices where users access
sensitive or confidential
information.
Enacts stronger password
policies and disables
user/account capabilities.
Fully managed Level 2
settngs
Fully managed high security
Level 3
Devices used by users or
groups who are uniquely
high risk. For example,
users who handle highly
sensitive data where
unauthorized disclosure
causes considerable
material loss.
Increases the minimum
Android version to 10.0,
introduces mobile threat
defense or Microsoft
Defender ATP, and enforces
additional device
restrictions.
Fully managed Level 3
settings
App protection policies (APP) are rules that ensure an organization's data remains safe or contained in a
managed app. A policy can be a rule that is enforced when the user attempts to access or move "corporate" data,
or a set of actions that are prohibited or monitored when the user is inside the app. A managed app is an app
that has app protection policies applied to it and can be managed by Intune.
App protection policies allow you to manage and protect your organization's data within an application. Many
productivity apps, such as the Microsoft Office apps, can be managed by Intune MAM. See the official list of
Microsoft Intune protected apps available for public use.
The growing number of policy settings available in mobile device management solutions enable organizations
to adjust protection levels to meet their specific needs. To help organizations prioritize security settings for
Surface Duo (or any other Android device), Intune has introduced its Android Enterprise security configuration
framework organized into several distinct configuration scenarios, providing guidance for work profile and fully
managed scenarios.
As with any framework , settings within a corresponding level may need to be adjusted based on the needs of
the organization as security must evaluate the threat environment, risk appetite, and impact to usability.