Forum Discussion
kdjones03
Jun 30, 2025Brass Contributor
Windows App Application Protection Policy
I have been testing out an Intune MAM policy to restrict copy/paste and drive redirection to AVD session hosts based on the link here: https://learn.microsoft.com/en-us/windows-app/require-device-sec...
NoahHelp
Jul 21, 2026Tin Contributor
Do not attempt to sign in as `local@debugonly`; it is normally an internal hand-off page, not a user identity. Start with a Conditional Access policy that only requires the expected grant controls, confirm a successful AVD sign-in in Entra sign-in logs, and then add the App Protection requirement. That staged approach identifies which control introduces the Edge profile loop and preserves a working policy baseline.