Forum Discussion

hw2B440's avatar
hw2B440
Tin Contributor
Apr 08, 2026

App Protection: Custom app vs Partner app

Is there any functional difference in using an app protection policy to manage a public partner app versus a custom application?

 

We have an app vendor that says they wrapped their app with the SDK but it is not on the partner list so we cannot pick it from the public app list. Which leaves us with the custom app option. Is the functionality the same? Will it show up on the app protection report, work with conditional access policies, other Microsoft solutions, etc.?

Thank you - 

Jessie

2 Replies

  • Hi Jessie, if the vendor really integrated the Intune App SDK or wrapped the app correctly, a custom app entry can work for app protection. The partner app list is easier because Microsoft already has the app metadata, but it is not the only path. I’d pilot with one user/device and confirm policy delivery, app protection reporting, and Conditional Access behavior before rolling it out broadly.

    • Allan Solomon Mejia's avatar
      Allan Solomon Mejia
      Tin Contributor

      Good point. One thing I'd add is that being on the Partner app list mainly provides assurance that Microsoft and the ISV have validated the integration it isn't a technical requirement for Intune App Protection Policies. If the vendor has correctly integrated the Intune App SDK (or used the App Wrapping Tool where applicable), a Custom app should receive MAM policies just like a partner app. The areas I'd validate before production are:

      • Policy enforcement (PIN, encryption, data transfer restrictions)
      • App Protection reporting in Intune
      • Conditional Access using Require app protection policy
      • Selective wipe and MAM diagnostics
      • Authentication flow (MSAL/broker support)

      I've seen custom apps work perfectly, but I've also encountered cases where the SDK integration was incomplete, resulting in Conditional Access or reporting issues despite the app claiming to support Intune MAM. A small pilot with representative users is the best way to confirm everything behaves as expected before a wider rollout.