Forum Discussion

kdjones03's avatar
kdjones03
Brass Contributor
Jun 30, 2025

Windows App Application Protection Policy

I have been testing out an Intune MAM policy to restrict copy/paste and drive redirection to AVD session hosts based on the link here: https://learn.microsoft.com/en-us/windows-app/require-device-security-compliance-intune?tabs=web#related-contentHowever, I've run into problems (in two separate tenants) that have halted me from being able to test.

Setup

  • Intune App Protection Policy targeting Windows Devices & Microsoft Edge\
  • Conditional Access Policy enforcing App Protection Policy when users access 'Azure Virtual Desktop' target resource via https://windows.cloud.microsoft.com

Results

  • First
    • When signing into a user account targeted by the policy, they are prompted to Switch Edge Profile which signs in the user to a new Edge profile for 'Work or School Account'. 
    • The account has to sign in again. 
    • The account can access Windows App resources
    • When launching a desktop session, this authentication page pops up for an account "local@debugonly" 
  • Second
    • When signing into a user account targeted by the policy, they are prompted to Switch Edge Profile which signs in the user to a new Edge profile for 'Work or School Account'. 
    • The account has to sign in again. 
    • After sign in, the account loops with 'Switch Edge Profile' and gets stuck here

       

I'm curious if anyone has gotten this to work and what was your setup? Or if Microsoft or provide some assistance or if this is in the wrong forum, any help would be appreciated.

No RepliesBe the first to reply

Resources