Thank you Rudy. Does it clear it up? Sort of. I noted in your matrix -which is appreciated - that you don't show a 'hybrid join' device. In any case, MSFT in all it's wisdom (cough cough) has once again over complicated what seems to be a simple thing. Just tell us that MAM configured to NONE here is valid when you are NOT intending to use any Windows BYOD devices. Otherwise, you can allow 'ALL' (with no impact to 'Corp' devices in MDM), or "Some" and specify some group of users who actually may want to use their personal Windows devices which can have their apps managed (WIP). I was not confused at all that this setting is for Windows devices only, but I can see where that can happen. Thank you again for your feedback. Caso cerrado (case closed).