MD-101 Mobile Application Management and App Protection 1 — Questions and Answers
Question 1: What is the primary difference between Mobile Device Management (MDM) and Mobile Application Management (MAM) in Intune?
- MDM manages apps only; MAM manages the entire device
- MDM enrolls and manages the entire device; MAM protects corporate data within apps without full device enrollment (Correct answer)
- MDM is for iOS only; MAM is for Android only
- MAM requires device compliance; MDM does not
Correct answer: MDM enrolls and manages the entire device; MAM protects corporate data within apps without full device enrollment
MDM requires device enrollment for full device management, while MAM uses App Protection Policies to protect corporate data in apps on unenrolled personal devices.
Question 2: Which Intune feature prevents users from copying corporate data from a managed app and pasting it into a personal app?
- Conditional Access
- App Protection Policy — Restrict cut, copy, and paste (Correct answer)
- Device compliance policy
- Windows Information Protection
Correct answer: App Protection Policy — Restrict cut, copy, and paste
App Protection Policies include data transfer restrictions that control cut, copy, and paste operations between managed (corporate) and unmanaged (personal) apps.
Question 3: What is 'MAM without enrollment' (MAM-WE) specifically designed for?
- Enrolling devices without user interaction
- Protecting corporate data in Office apps on personal (BYOD) devices that are not enrolled in Intune MDM (Correct answer)
- Applying compliance policies to unenrolled devices
- Deploying apps to devices that cannot enroll
Correct answer: Protecting corporate data in Office apps on personal (BYOD) devices that are not enrolled in Intune MDM
MAM-WE allows App Protection Policies to protect corporate data in supported apps on personal devices without requiring full MDM device enrollment.
Question 4: Which setting in an Intune App Protection Policy requires users to authenticate with a PIN or biometric before accessing corporate apps?
- Require device lock
- Access requirements — PIN for access (Correct answer)
- Conditional launch — Max PIN attempts
- Data protection — Encrypt org data
Correct answer: Access requirements — PIN for access
The 'PIN for access' setting under Access requirements in an App Protection Policy enforces PIN or biometric authentication before accessing the protected app.
Question 5: An App Protection Policy is set to 'Wipe org data from app' after 5 failed PIN attempts. What data is removed?
- All data including personal data is wiped from the device
- Only the corporate data and documents within the managed app are removed (Correct answer)
- The device is factory reset
- The app is uninstalled and reinstalled
Correct answer: Only the corporate data and documents within the managed app are removed
Selective wipe through App Protection Policies removes only the corporate data and tokens within the managed app, leaving personal data intact.
Question 6: Which App Protection Policy setting prevents users from saving corporate files to personal cloud storage like Google Drive?
- Block screen capture
- Save copies of org data — restrict to approved locations only (Correct answer)
- Require managed browser
- Encrypt org data
Correct answer: Save copies of org data — restrict to approved locations only
The 'Save copies of org data' setting controls where users can save files, restricting saves to approved managed locations like OneDrive for Business.
What is the primary difference between Mobile Device Management (MDM) and Mobile Application Management (MAM) in Intune?