Support Tip: Devices not receiving APP/MAM policies due to missing IP addresses
Published Nov 09 2020 03:18 PM 4,395 Views

We recently received a customer support case where the App Protection Policy (APP also known as MAM) was not being delivered to the device due to a missing IP address exemption. If your organization uses a firewall or network protection system which targets or restricts reachable IP addresses, we recommend that you update your network configuration to allow network traffic to and from all MAM IP ranges as outlined in Network endpoints for Microsoft Intune, in case you run into the same issue.


For Windows devices, if you use a Defender Firewall profile to configure your IP address settings, below are the steps you can use to update these:

  1. Log in to Microsoft Endpoint Manager
  2. Go to Devices Configuration profiles 
  3. Select the Windows 10 and later with a Profile Type listed as Endpoint protection 
  4. Select Properties and click edit next to Configuration settings 
  5. Click Microsoft Defender Firewall 
  6. Scroll down to Firewall rules and edit the rule to update the IP address settings


For more information about firewall settings, see the following documents:


Let us know if you have any additional questions on this by replying to this post or by tagging @IntuneSuppTeam out on Twitter.

Version history
Last update:
‎Dec 19 2023 01:19 PM
Updated by: