πΌ Management Samenvatting
App gegevensbescherming (MAM - Mobile Application Management) design implementeert Intune App bescherming Policies voor iOS en Android om corporate data binnen managed apps te beschermen met copy/paste restrictions, versleuteling, conditional launch en gegevenslekken prevention zonder volledige device enrollment (BYOD-friendly).
β MAM
β App bescherming
MAM biedt gegevensbescherming Zonder device enrollment (BYOD scenario waar users geen volledige MDM willen): Corporate data isolated binnen managed apps (Outlook, Teams, OneDrive), gegevenslekken prevention (geen copy/paste naar personal apps), Conditional launch (PIN vereist, jailbreak detectie Blokkeert app), Selective wipe (remove corporate data, keep personal). Zonder MAM: Corporate data in unmanaged apps (screenshot mogelijk, save to personal opslag), No versleuteling enforcement, gegevenslekken via copy/paste, Lost device is data exposure.
Implementatie
MAM design: (1) App bescherming Policies per platform (iOS, Android), (2) gegevensbescherming: versleuteling bij rest (app-level versleuteling), Data transfer restrictions (only to managed apps), Copy/paste blocked (or managed apps only), Save-as restrictions (Blokkeer save to personal opslag), Screenshot prevention (Blokkeer voor iOS, warn voor Android); (3) Conditional Launch: PIN/biometric vereist (app-level authentication), Max offline period (30 days β wipe), Jailbreak/root detectie (Blokkeer app launch), Min OS version, Max app version (force updates); (4) Managed apps: Microsoft apps (Outlook, Teams, OneDrive, Edge, Office), derde partij apps (Intune SDK integrated).
Vereisten
- Intune Licenties (standalone of M365 E3/E5)
- App bescherming Policies defined (iOS, Android)
- Managed apps list (Outlook, Teams, OneDrive minimum)
- Conditional launch settings (PIN, jailbreak detectie)
- User communication (MAM requirements, app setup)
- BYOD policy (if applicable)
Implementatie
Maak aan App bescherming Policies: iOS policy (data transfer restricted, save-as blocked, PIN vereist, jailbreak blocked), Android policy (same settings), assign to alle gebruikers of specific groups, implementeren managed apps (Company Portal), Test data isolation, user training.
Compliance en Auditing
MAM policies voldoen aan: BIO 11.02 (Mobile device gegevensbescherming), ISO 27001 A.6.2.1 (Mobile device policy), AVG Artikel 32 (gegevensbescherming door design - versleuteling, Toegangscontrole en authenticaties), NIS2 (Gegevenslekage prevention).
Monitoring
Gebruik PowerShell-script app-data-protection.ps1 (functie Invoke-Monitoring) β Controleren.
Remediatie
Gebruik PowerShell-script app-data-protection.ps1 (functie Invoke-Remediation) β Herstellen.
Compliance & Frameworks
- BIO: 11.02.07 - Mobile app gegevensbescherming
- ISO 27001:2022: A.6.2.1 - Mobile device policy
Automation
Gebruik het onderstaande PowerShell script om deze security control te monitoren en te implementeren. Het script bevat functies voor zowel monitoring (-Monitoring) als remediation (-Remediation).
Risico zonder implementatie
Management Samenvatting
App Data Protection (MAM): Intune App Protection Policies - Data isolation (corporate vs personal), Block copy/paste to personal apps, Require app PIN (secondary auth), Jailbreak/root detection (block compromised devices), Selective wipe (remove corporate data only - preserve personal), Encryption. BYOD-friendly (no full device enrollment needed). Activatie: Intune β App protection policies β iOS/Android. Gratis (Intune included M365). Verplicht AVG 32, BIO 11.02. Implementatie: 8-24 uur. CRITICAL BYOD security - data isolation without MDM.
- Implementatietijd: 24 uur
- FTE required: 0.1 FTE