Forum Discussion
kdjones03
Jun 30, 2025Brass Contributor
Windows App Application Protection Policy
I have been testing out an Intune MAM policy to restrict copy/paste and drive redirection to AVD session hosts based on the link here: https://learn.microsoft.com/en-us/windows-app/require-device-sec...
Allan Solomon Mejia
Jul 20, 2026Tin Contributor
Hi kdjones03,
I haven't encountered this exact behavior, but it looks more like an authentication or Conditional Access loop than an issue with the App Protection Policy itself. A few things I'd check:
- Confirm Microsoft Edge for Business is being used and that profile sign-in is working correctly.
- Review your Conditional Access policies for conflicts, especially those requiring compliant devices or app protection.
- Exclude the test account from other CA policies to rule out policy interactions.
- Check the Microsoft Entra sign-in logs for the failed authentication or repeated "Switch Edge Profile" events, they usually point to the policy causing the loop.
If you're following the Microsoft guidance, I'd also recommend validating the configuration against the official documentation and opening a support case if everything matches but the behavior persists. It could be a tenant-specific issue or product bug.