Organizations offering BYOD opportunities should implement Mobile Application Management (MAM) for securing company applications and data running on personal devices.
Control Type: Technical
Control Function: Preventive
The previous piece of documentation discussed Mobile Device Management (MDM), which is used to manage an organization’s endpoint devices from a central location regardless of the location of each device. MDM platforms have emerged to meet the changing needs of increasingly mobile workforces. Another change in modern enterprise computing environments is the expansion of Bring Your Own Device (BYOD) opportunities for employees and visitors. Many organizations now allow employees to utilize their personal devices to work and access company resources. However, for this to be done securely, there needs to be some way for the organization to exact control over the resources being used on personal devices.
While MDM places central control of devices in the organization’s hands, MAM moves up a layer and places control of company applications in the organization's hands, while leaving overall control of the operating system and other applications to the employee personally. The apps that are installed under the company’s authority remain monitored and controlled by its administration and can be updated, configured, monitored, and uninstalled by IT.
One of the most straightforward MAM solutions is Microsoft Intune App Management. Microsoft allows organizations to set up a “Company Portal” for employees to choose and install applications from a pre-selected catalog. Think of this as a company-owned and managed App Store. After the apps are installed, employees are directed to connect their work email address to the selected applications. Attaching their company accounts to the applications places them under the control and monitoring of the company's Intune solution, while the rest of the device remains under the control of the employee’s personal account.
A common scenario where MAM would be useful is if an organization wanted to allow users to install Office 365 apps on any device they use to do their work on the go. The organization does not want the overhead of managing entire devices or seizing control away from employees, so they simply upload the Office 365 apps to the Company Portal for the employees to install and use for work purposes. Granular security and configuration settings can be set for the Office 365 Suite, but the controls will be placed on M365 apps only and not on personal apps running on the employee’s device. MAM is often combined with security controls like Data Loss Prevention (DLP) and Conditional Access to prevent data leakage and the introduction of cyber threats stemming from other areas on the employee's device.

