Forum Discussion
18th Aug Update - Secure release is now broken for common Intune MAM and BYOD scenarios
Thank you for clearly describing the MAM scenario. We understand that moving from an already-managed native app to a browser changes the experience, and that Safari-based installation does not fit a policy that requires managed Edge.
The Universal Print portal does not require PWA installation. For commercial customers, open https://print.cloud.microsoft directly in Intune-protected Edge, signed in with the work account, then select Secure release and scan from within the portal.
This route avoids Safari/PWA installation and the phone's native-camera/default-browser handoff. It does not require changing the device's default browser.
Your existing Intune and Conditional Access policies still apply; we are not recommending broad exclusions or reduced protections. If the complete flow does not work in managed Edge, please provide the point of failure, device/browser versions, and any sign-in error details through Microsoft Support rather than posting tenant information publicly.
This provides a browser-only option, although we recognize it is a different experience from the standalone app you used before.
- BradHSep 17, 2026Brass Contributor
This is still not a viable option, and you need to take the Microsoft hat off for a few minutes to think how users operate on their personal devices. Not everyone has Edge installed, and or have it set as their default browser an if they do, not all have the "Staff" account enabled inside Edge as their preferred browser instance. We need to think about the workflows on how users operate and you can't force a particular browser onto a personal device.
The Copilot app solves this issue. It's agnostic as a print release option and is signed in and managed under a MAM policy. We aren't forcing a particular browser on their personal devices using this method. The user goes to print, Copilot app deals with it, and you don't have an issue.
Most staff when scanning a QR code will just open their camera app and it's going to break in this above scenario as it will open in their default browser (most likely not Edge) and MAM policies will fail at that point.
I highly recommend having the Copilot app as an available option for Admins to specify for their instance so this opens via this method. Some admins might only opt for the Edge Browser option, but it's not possible in a mostly MAM mobile environment to do it as you are suggesting.
Or just make the Copilot app the default method of release again please. Otherwise, universal print secure release is basically broken in MAM.- RemusDumitruSep 21, 2026
Microsoft
Thanks for clarifying, Brad. Your staff already had a familiar workflow: scan with the phone’s camera and let an already signed-in, MAM-protected app handle the release. We understand that manually starting in a managed browser is not an equivalent replacement.
As the secure-release integration in the Microsoft 365 Copilot app was retired, our priority was to maintain a supported release path through the Universal Print portal. We recognize that keeping the capability available does not, by itself, preserve every existing managed-app workflow.
The Android work-camera guidance also applies only where a managed work profile and an appropriate work browser are available. It does not cover every MAM-only BYOD deployment.
Separately, for commercial customers already using an approved managed browser, https://aka.ms/upcamera provides a direct shortcut into the portal’s camera scanner, with any required sign-in and camera-permission steps. Opening or bookmarking it inside Intune-protected Edge with the work account avoids navigating through the portal first. No PWA installation or change to the device’s default browser is required for that route.
That shortcut reduces navigation; it does not remove the Edge/work-account setup requirements or resolve the native-app experience gap you have raised. We are assessing ways to improve the handoff while preserving existing protections. Your request for an administrator-selectable native, MAM-protected release option is clear, although we do not have a commitment or delivery date to announce for that option.
- BradHSep 21, 2026Brass Contributor
Sorry but this is still not an answer and the workflow is still broken on MAM devices.
You don't comprehend how this has broken it would seem. Just because a camera app is used, doesn't mean that their is a managed browser on that device. We don't force that on the staff. Copilot as an app was simplier and is agnostic to the browser.Copilot was the answer, why was it retired in the first place? It worked very well with this. Provide admins the ability in their managed portal to be able to select this for the environment maybe so that Copilot as an app can be used in this situation. Scanning using the camera will break unless they specifically have this setup in Edge, and in a managed browser which is more overhead for admins
Prior to changes, do you and the team workshop these scenarios? We need things easier for staff, not harder.