Glossary

MAM-WE

Mobile Application Management without enrolment — protecting corporate data inside apps on personal devices.

Mobile Application Management without enrolment (MAM-WE) is the Intune capability that protects corporate data inside specific apps on personal mobile devices without requiring the device to be enrolled in MDM. App-level controls (PIN, encryption, no-copy-paste to personal apps, remote wipe of corporate data) enforce the corporate data boundary; personal data on the same device is untouched. The right model for bring-your-own-device scenarios where users keep their personal phone unmanaged but corporate apps (Outlook, Teams, OneDrive) need data protection. Enforced via Intune app protection policies assigned to users, surfaced when the user signs into a supported app with their work account. Different from full MDM, which manages the entire device.