Solutions
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24" fill="none"> <path d="M21.25 12C21.25 13.2426 20.2426 14.25 19 14.25C17.7574 14.25 16.75 13.2426 16.75 12C16.75 10.7574 17.7574 9.75 19 9.75C20.2426 9.75 21.25 10.7574 21.25 12Z" stroke="black" stroke-width="1.5"/><path d="M7.25 12C7.25 13.2426 6.24264 14.25 5 14.25C3.75736 14.25 2.75 13.2426 2.75 12C2.75 10.7574 3.75736 9.75 5 9.75C6.24264 9.75 7.25 10.7574 7.25 12Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 16.1143C15.4512 15.4931 16.827 15.8617 17.4482 16.9377C18.0694 18.0137 17.7008 19.3895 16.6248 20.0107C15.5488 20.6319 14.173 20.2633 13.5518 19.1873C12.9306 18.1113 13.2992 16.7355 14.3752 16.1143Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 3.98927C8.45117 3.36805 9.82701 3.73671 10.4482 4.81269C11.0694 5.88867 10.7008 7.26451 9.62481 7.88573C8.54883 8.50695 7.17298 8.13829 6.55177 7.06231C5.93055 5.98633 6.29921 4.61048 7.37519 3.98927Z" stroke="black" stroke-width="1.5"/><path d="M7.37519 20.0107C6.29921 19.3895 5.93055 18.0137 6.55177 16.9377C7.17298 15.8617 8.54883 15.4931 9.62481 16.1143C10.7008 16.7355 11.0694 18.1113 10.4482 19.1873C9.82701 20.2633 8.45117 20.6319 7.37519 20.0107Z" stroke="black" stroke-width="1.5"/><path d="M14.3752 7.88573C13.2992 7.26451 12.9306 5.88867 13.5518 4.81269C14.173 3.73671 15.5488 3.36805 16.6248 3.98927C17.7008 4.61048 18.0694 5.98633 17.4482 7.06231C16.827 8.13829 15.4512 8.50695 14.3752 7.88573Z" stroke="black" stroke-width="1.5"/> </svg>

Modern Work

Modern workplaces and collaboration.

Effective solutions
We solve the IT challenges that most hinder Swiss SMEs. From Modern Work and Cyber Security to Cloud Migration.
Discover all solutions
Services
Craftsmanship Excellence
We support you from strategy consulting to seamless 24/7 operations. Professional, proactive, and individually tailored to your infrastructure.
Compare Service Models
About
Our story
100 years of experience. Your partner for innovation since 1925.
Blog Artikel
01.06.2026
4 min read

Microsoft Mobile Application Management (MAM): Protecting sensitive business data on mobile devices

Person working on a laptop and tablet overlaid with a glowing data graphic.

Das Wichtigste in Kürze

  • MAM protects company data at the app level (Outlook, Teams, OneDrive) without accessing the entire device
  • Ideal for BYOD: selective data control, encryption, targeted wiping of company data only
  • Microsoft Intune manages Windows, iOS and Android centrally and applies policies such as PIN protection or copy-paste blocking uniformly

In today's working world, mobile devices are indispensable. Employees use smartphones, tablets, and laptops to work productively from anywhere. But how can you organize this as an employer - especially in terms of security? How can you protect company data when employees use their own devices? Should employees carry around two smartphones? Or is it possible to implement "BYOD - Bring Your Own Device" without compromising security?

Every company and organization should answer these questions individually for themselves and their employees. But when it comes to security, there are no compromises to be made. Microsoft customers can rely on two proven concepts that we use at Baggenstos and which we will present in two articles: Today, we will be looking at Microsoft Mobile Application Management (MAM), i.e. the management of mobile applications. In the next blog post, we will be looking at Microsoft Mobile Device Management (MDM), i.e. the management of mobile devices.

Microsoft Intune

It’s one service that covers and manages both areas: Microsoft Intune is the cloud-based solution for managing and securing mobile devices and applications. It allows companies to manage both devices and apps to protect corporate data.

One of the key features of Intune is Microsoft Mobile Application Management (MAM). It enables the protection and management of corporate data at the app level without requiring full device management - as would be the case with Mobile Device Management (MDM).

As a rule of thumb: MAM is particularly suitable for BYOD devices (Bring Your Own Device) of employees, while MDM is intended for company-owned devices that are to be centrally managed. Both approaches allow companies to ensure that sensitive information remains protected within business-relevant apps, regardless of whether the devices are private or company-owned.

The benefits of Mobile Application Management (MAM) for companies

1. Protect corporate data without managing the device

Not all employees want to integrate their private devices into a Mobile Device Management (MDM) system. MAM allows companies to manage and protect specific apps without having access to the entire device. This also ensures the privacy of employees in all other applications.

2. Selective data control in app

With MAM, organizations can enforce policies for enterprise apps, such as:

  • Preventing data leakage: Companies can control whether content from enterprise apps can be copied and pasted into personal apps.
  • Encrypting enterprise data: Data in business apps remains encrypted.
  • Wiping enterprise data: If an employee leaves the company, only the enterprise data can be removed from the app without wiping the entire device.

3. Unterstützung von BYOD («Bring Your Own Device»)

Many companies use BYOD strategies, where employees use their own devices for work. MAM allows for secure use of enterprise apps on these devices without compromising the privacy of employees.

How does MAM work in practice?

Microsoft Intune offers MAM policies that can be applied to Microsoft 365 apps (like Outlook, Teams, or OneDrive) and third-party apps. Administrators can centrally manage and customize these policies to meet the security requirements of the company.
Hier einige beispielhafte MAM-Richtlinien:

  • Access control: Employees must log in to company apps using a PIN or biometric authentication.
  • Data control: Company data can only be stored or shared in specific apps.
  • Deletion on inactivity: Company data is automatically deleted if an app is not used for a certain period of time.

Baggenstos' experience with MAM

Of course, Windows laptops have always been easy to manage centrally in a Microsoft environment. However, smartphones and tablets running Android and iOS have been a challenge in the past. With the integration of Microsoft Intune, our customers can now manage and secure all endpoints, whether Windows, iOS/iPadOS, or Android (and to a limited extent, macOS) centrally. This allows them to implement security policies uniformly, manage devices and apps efficiently, and protect corporate data from unauthorized access. Our customers benefit from a comprehensive solution that offers flexible and secure device and app management.

Conclusion

Microsoft MAM is the ideal solution for companies that want to protect their data without having full control over their employees' devices. It offers the perfect balance between security and user-friendliness - a crucial factor for modern, flexible work environments.
Companies that already use Microsoft 365 or Microsoft Intune should include MAM as an important addition to their IT security strategy to effectively minimize data loss and security risks.

This is the first part of our two-part series on securely managing mobile devices and applications. The second part will focus on "Microsoft Mobile Device Management" (MDM) where the entire device is managed in the cloud.

Source and further links

No items found.

Share article

Zwei Mitarbeiter im Gespräch am Tisch, einer lächelt im Vordergrund

Welcher Service ist der Richtige für Sie?