Menu
Modern Workplace Blog
  • Home
  • About: Kenneth van Surksum
  • Cookie Policy
  • Links
Modern Workplace Blog
October 5, 2026October 5, 2026

Opening other apps and sharing data from Intune protected apps on Apple mobile and Android

Introduction

An App Protection Policy (APP) that restricts data transfer controls two things: which other apps a managed app may open, and which apps may receive its data. Opening an unmanaged app can be allowed with an exemption. Sharing documents with an unmanaged app cannot. Users notice the first as a link that does nothing or that opens a web page in Microsoft Edge instead of the app they expected.

Two cases from a production tenant show the pattern. The first involves DigiD, the digital identity that people in the Netherlands use to sign in to government websites. A user signs in to such a website in Edge and taps the button to confirm with the DigiD app, but the DigiD app never opens. In the second case a user taps an address in an Outlook mail with Waze set as navigation app, and lands on the Waze website in Edge.

DigiD is used by more than 13.5 million people. It gives access to the online services of government organisations and bodies with a public task, such as ministries, municipalities, healthcare and educational institutions and pension organisations. The sign-in on a phone is confirmed in a separate DigiD app, which is comparable to a national eID or bank ID app in other countries. For a Dutch employee it is a normal expectation that this works on the phone they also use for work.

Both cases have the same cause and the same type of fix. The difficult part is finding out what to exempt. On iOS and iPadOS the policy needs the exact URL scheme or Universal Link host that the app is called with, and Microsoft offers no method to find it. On Android the policy needs the package name of the app, which is public. This article describes how managed apps reach other apps on both platforms, how the exemption lists work, and how to read the required value from the Intune diagnostic log on each platform.

Table of Contents
  • Introduction
    • Open-in and Share on iOS and iPadOS
    • IntuneMAMUPN and IntuneMAMOID on enrolled iOS and iPadOS devices
    • Different policies for managed devices and BYOD
    • Cut, copy and paste: the character limit
    • The routes on Android
  • Exemptions on iOS and iPadOS
    • Select apps to exempt (URL schemes)
    • Exempt Universal Links and Managed Universal Links
    • What Intune does under the hood
  • Exemptions on Android
    • How it differs from iOS
    • Default exemptions
    • Find the package name
  • What is not possible
  • Finding out what to exempt
    • Options to find the value
    • iOS and iPadOS: collect the log
    • iOS and iPadOS: the log lines that matter
    • Android: collect and read the log
  • Reading the log with the Intune MAM Link Analyzer
  • Worked examples
    • iOS: DigiD, a Universal Link from Edge
    • iOS: Waze, an address in Outlook
    • iOS: a test mail to verify both routes
    • Android: the same test on a Samsung device
  • Summary
  • References
RouteWhat it isControlled byCan be exempted
Open-in and ShareThe user sends a file or content to another app through the iOS share sheetSend org data to other appsNo. Microsoft states that data transfer exemptions do not apply to Open-in
Cut, copy and pasteClipboard between appsRestrict cut, copy, and paste between other appsNot per app. A character limit can allow short text for all apps
URL schemeThe app calls another app by a custom scheme, for example waze:// or comgooglemaps://Send org data to other appsYes, with Select apps to exempt
Universal LinkAn https link that iOS opens in the app that claims the host, for example https://app.digid.nl/...Restrict web content transfer with other appsYes, with Exempt Universal Links

In most baselines Send org data to other apps is set to Policy managed apps or Policy managed apps with Open-In/Share filtering, and web content is restricted to Microsoft Edge. With those settings the default behaviour is:

  • A URL scheme call only reaches other managed apps.
  • An https link opens in Edge, also when an installed unmanaged app claims that link.

This is the intended result for company data. It becomes a problem when the target app is harmless and the user needs it, such as an authentication app, a navigation app or a meeting client.

Open-in and Share on iOS and iPadOS

Open-in and Share hand the content itself to another app, where a URL scheme or Universal Link only starts another app with an address. That difference is the reason why an exemption cannot solve an Open-in or Share problem.

The user starts this route from the iOS share sheet: Open in, Share, or an action from a share extension. The sending app passes a file, text or image to the app the user picks. A URL call carries at most a few parameters, such as an address or a meeting ID. Open-in carries the document.

The value of Send org data to other apps decides what happens:

ValueBehaviour for Open-in and Share
All appsAny app can receive the data and can read and edit it
NoneNo transfer, also not to other policy managed apps. A transferred document is encrypted and unreadable
Policy managed appsOnly policy managed apps can use the data. Unmanaged apps may still be listed in the share sheet, but Intune encrypts the content and they cannot read it
Policy managed apps with OS sharingAs above, plus file transfer to other MDM managed apps. Applies to enrolled devices only
Policy managed apps with Open-In/Share filteringAs Policy managed apps, and the share sheet only shows policy managed apps. Both apps need Intune SDK 8.1.1 or later

The two values that are confused most often are Policy managed apps and Policy managed apps with Open-In/Share filtering. Both protect the data in the same way. The difference is what the user sees in the share sheet.

 Policy managed appsPolicy managed apps with Open-In/Share filtering
Who can use the dataOnly policy managed appsOnly policy managed apps
Apps shown in the share sheetAll apps that iOS offers, managed and unmanagedOnly policy managed apps
When the user picks an unmanaged appThe transfer happens, but Intune encrypts the content and the app cannot read itNot possible, the app is not offered
What the user experiencesA file that will not open in the chosen app, without an explanationA shorter list with only apps that work
RequirementNoneThe sending app and the receiving app both need Intune SDK 8.1.1 or later
Value in the diagnostic logEnableOpenInFilter is 0EnableOpenInFilter is 1

In short, without filtering the protection is enforced after the user has made a choice that cannot work. With filtering the wrong choice is taken away. The filtering value therefore saves support questions about files that seem broken.

One exception applies to both values. An unmanaged app that supports the Intune data type can still appear as a target, for example through its own share extension. The content it receives stays encrypted.

Points to know:

  • The exemption lists do not apply to this route. Microsoft states that the exempt app must be invoked through a URL protocol, and that Open-in is not based on it. An exempt app can be opened, but it cannot be given a document.
  • A user who shares a file to an unmanaged app does not always see an error. Without filtering, the app appears in the share sheet and receives encrypted content that it cannot open. With filtering, the app is not listed at all.
  • On enrolled devices the iOS Open-in management feature takes part in the decision. Intune needs the IntuneMAMUPN and IntuneMAMOID app configuration keys on the sending app to identify the managed account. The next subsection explains them.
  • The opposite direction has its own setting, Receive data from other apps.
  • Spotlight search and Siri shortcuts are blocked unless the value is All apps.

When a user must hand a document to an app, the options are to bring that app under management, or to use Save copies of org data with an allowed storage location. An exemption will not help. The rest of this article covers the URL scheme and Universal Link routes.

IntuneMAMUPN and IntuneMAMOID on enrolled iOS and iPadOS devices

IntuneMAMUPN and IntuneMAMOID are two app configuration keys that tell a managed app which account on an enrolled iOS or iPadOS device is the organisation’s account. Without them, Intune cannot connect the two kinds of management on the device, and sharing between managed apps does not work as configured.

The reason is that two systems look at the same app. iOS knows which apps were installed through MDM, and its Open-in management decides which of those apps may exchange files. App protection works per account inside an app. The keys link the two: they state that the MDM enrolled user and the account in the app are the same identity.

KeyValue in IntuneMeaningNeeded for
IntuneMAMUPN{{userprincipalname}}The sign-in name of the enrolled userAll MDM managed apps
IntuneMAMOID{{userid}}The Microsoft Entra object ID of the enrolled userAll MDM managed apps
IntuneMAMDeviceID{{deviceID}}The Intune device IDThird-party and line-of-business apps

What the keys make possible:

  • Send org data to other apps with Policy managed apps with OS sharing can transfer files to other MDM managed apps.
  • Receive data from other apps with All apps with incoming Org data marks incoming data without an identity as data of this user, so that it is protected.
  • App protection applies when the account the user signs in with matches the configured UPN.

For some apps Intune now sends the keys by itself. Since the September 2024 service release (2409), Intune sends IntuneMAMUPN, IntuneMAMOID and IntuneMAMDeviceID automatically to Excel, Outlook, PowerPoint, Teams and Word on Intune enrolled iOS devices, and Microsoft is extending that list. For those apps a manual policy is no longer needed. For all other managed apps, and for devices enrolled in a third-party MDM, the keys must still be deployed. Microsoft Edge and the Microsoft 365 Copilot app are examples: they are not on the published list at the time of writing, so they need the app configuration policy described below.

The keys also decide which policy an app receives. Intune treats an iOS or iPadOS device as unmanaged when the MDM does not pass IntuneMAMUPN. Microsoft warns that with incorrect values the policy may not be delivered, or the wrong policy may be delivered. This matters when a tenant has separate app protection policies for managed and unmanaged devices.

How to deploy them where it is still needed:

  1. Create an app configuration policy with enrolment type Managed devices.
  2. Add both user keys, IntuneMAMUPN and IntuneMAMOID, with the values from the table. For third-party and line-of-business apps also add the third key, IntuneMAMDeviceID.
  3. Assign it to each managed app that sends data. For the receiving app the keys are optional.
  4. Make sure the app is installed through Intune, as a required app or from the Company Portal. A copy the user installed from the App Store does not receive the configuration.

Important: the app must be managed by Intune, not only present on the device. The keys travel over the MDM channel, and that channel only reaches apps that Intune installed or took under management. An app that the user installed from the App Store looks the same on the home screen, but it never receives the keys. The result is that Intune treats this app as running on an unmanaged device, even though the device is enrolled:

  • The app receives the policy for unmanaged devices, when the tenant has separate policies.
  • Sharing with other MDM managed apps through Policy managed apps with OS sharing does not work for this app.
  • The problem is invisible to the user and easy to miss for the administrator, because the policy and the app configuration both look correct in the portal.

Check this first when an enrolled device behaves like a personal device. Assign the app as required, so that Intune manages it, and verify in the diagnostic log that the app reports the account that matches the enrolled user.

Points to know:

  • The keys apply to devices managed by Intune or by a third-party MDM. A device without enrolment has no MDM to pass them and counts as unmanaged.
  • In most apps the work account must match the MDM enrolled user. The exception is an app that supports Multiple Managed Accounts (MMA). In such an app one account can be managed by MDM and app protection together, and additional accounts are protected by app protection only. Microsoft is rolling this out gradually. At the time of writing it lists Teams (8.10.0 or later) and Outlook (5.2626.0 or later) on iOS and iPadOS.
  • Setting IntuneMAMAllowedAccountsOnly limits an app to one managed account on a managed device, which also switches off MMA for that app.

Different policies for managed devices and BYOD

An app protection policy is assigned to users, so by default the same policy applies on an enrolled device and on a personal device. An assignment filter for managed apps splits this: one policy for unmanaged devices with strict data transfer rules, and one for MDM managed devices where the rules and the exemption lists can be wider.

The filter uses the managed app property deviceManagementType. Two rules cover the basic split:

Policy forFilter rule
BYOD, no enrolment(app.deviceManagementType -eq "Unmanaged")
MDM managed devices(app.deviceManagementType -ne "Unmanaged")

Create the filter for the managed apps platform, then select it on the Assignments page of the app protection policy with Edit filter.

The property also has values per enrolment type, so that a policy can target one kind of managed device:

PlatformValues
iOS/iPadOSAutomated Device Enrollment user-associated devices, Automated Device Enrollment userless devices, Account Driven User Enrollment, Device Enrollment with Company Portal and Web Enrollment
AndroidCorporate-owned fully managed, Corporate-owned with work profile, Personally-owned work profile, Corporate-owned dedicated devices with or without Entra ID Shared mode, AOSP user-associated devices, AOSP userless devices

How Intune decides whether a device is managed differs per platform:

  • iOS/iPadOS: the app is told through app configuration. The keys IntuneMAMUPN and IntuneMAMOID from the previous subsection, delivered through the MDM channel, mark the app as running on a managed device. Without them the device counts as unmanaged and receives the BYOD policy, also when it is enrolled.
  • Android: Intune detects the management state itself. No app configuration is needed. A device managed by a third-party MDM counts as unmanaged.

This is also the difference between the two types of app configuration policy:

App configuration typeChannelReaches
Managed devicesMDM channel of the operating systemOnly apps that Intune deployed on an enrolled device. This is the channel for the IntuneMAM keys
Managed appsApp protection (MAM) channelAny app with the Intune SDK that has an app protection policy, whatever the enrolment state

Points to know:


  • The values per enrolment type are rolling out, and the older values Managed (iOS/iPadOS) and Android Enterprise are being replaced. Existing filters are mapped automatically.


    The table under this list shows the old and the new values side by side.



  • The granular values need a device that is registered in Microsoft Entra. The managed apps configuration key com.microsoft.intune.mam.IntuneMAMOnly.RequireAADRegistration with value Enabled forces that registration.


    Microsoft names this requirement and the key in the notes under managed app properties for assignment filters, without further detail.


  • On a device managed by a third-party MDM the granular values do not match.
  • For the subject of this article the split is useful in one specific way: an exemption that is acceptable on a company device, where the target app is also managed, does not have to be opened up on personal devices.

Old and new values of deviceManagementType, as described by Microsoft under managed app properties for assignment filters:

PlatformOld value (one for all managed devices)New values (one per enrolment type)
iOS/iPadOSManagedAutomated Device Enrollment user-associated devices, Automated Device Enrollment userless devices, Account Driven User Enrollment, Device Enrollment with Company Portal and Web Enrollment
AndroidAndroid EnterpriseCorporate-owned fully managed, Corporate-owned with work profile, Personally-owned work profile, Corporate-owned dedicated devices with Entra ID Shared mode, Corporate-owned dedicated devices without Entra ID Shared mode
BothUnmanagedUnmanaged, not changed

An example makes the change concrete. An existing filter with the rule (app.deviceManagementType -eq "Managed") matched every enrolled iPhone and iPad. That rule keeps working: Intune now reads Managed as all four new iOS/iPadOS values together. With the new values a filter can be narrower, for example (app.deviceManagementType -eq "Account Driven User Enrollment") for a policy that should apply only to personal devices with user enrolment. Microsoft will remove the old values later and has not given a date, so new filters are best written with Unmanaged or with the new values.

Cut, copy and paste: the character limit

The clipboard has no exemption list, but it has a character limit. The setting Cut and copy character limit for any app defines how many characters a user may cut or copy from a managed app to any other app, also when Restrict cut, copy, and paste between other apps blocks the clipboard. It exists on both iOS/iPadOS and Android, and the default is 0.

Tip: set the limit to 1024. That is enough to copy a URL in the exceptional case where a link must be opened outside the managed apps, for example when an app cannot be exempted. It is not enough to copy a document.

Two points to keep in mind:

  • The limit applies to all apps and to any text, not only to URLs. A user can also copy 1024 characters of mail or document text to an unmanaged app, so this is a deliberate choice to document in the baseline.
  • In the diagnostic log the value is shown as ClipboardCharacterLengthException, next to ClipboardSharingLevel for the restriction itself.

The routes on Android

Android uses the same policy setting but a different unit of exemption. Intune identifies the target app by its package name, so the route that the calling app uses does not matter.

TopiciOS and iPadOSAndroid
Unit of exemptionURL scheme or Universal Link hostApp package name, for example com.cisco.webex.meetings
Exemption listsSelect apps to exempt and Exempt Universal LinksSelect apps to exempt only
Links that open an appUniversal Links, controlled by Restrict web content transfer with other apps and its two listsAndroid App Links, controlled by Send org data to other apps
How to find the valueNot documented by Microsoft. Read it from the diagnostic logGoogle Play store URL of the app, or the diagnostic log
Phone and messagingtel and sms schemes, or Transfer telecommunication data toTransfer telecommunications data to and Transfer messaging data to

Exemptions on iOS and iPadOS

The iOS/iPadOS App Protection Policy has two exemption lists, one per route. An entry in the wrong list has no effect, so the first question for every app is which route it uses.

Select apps to exempt (URL schemes)

This list holds the URL schemes that managed apps may call, also when the target app is unmanaged. Enter the scheme without ://, for example waze.

Default entryTarget
app-settingsiOS Settings
itms; itmss; itms-apps; itms-appss; itms-servicesApp Store
calshowNative Calendar

Points to know:

  • An exemption only covers the URL scheme call. The exempt app still cannot receive data through Open-in or Share, as described under Open-in and Share above, and the clipboard restriction still applies.
  • Policies created before 15 June 2020 contain tel;telprompt;. Microsoft advises to remove these and use Transfer telecommunication data to instead, when the calling apps use Intune SDK 12.7.0 or later.
  • With Intune SDK 14.5.0 or later, sms and mailto allow org data to go into the native message and mail compose views. Add these only as a deliberate decision.

Exempt Universal Links and Managed Universal Links

A Universal Link is a normal https link that iOS opens in an app when that app is installed and claims the host. With Restrict web content transfer with other apps set to Microsoft Edge, Intune keeps such links in the managed browser. Two lists change that behaviour.

ListTarget appBehaviourDefaults
Exempt Universal LinksUnmanagedThe link opens the unmanaged appApple Maps and FaceTime (maps.apple.com, facetime.apple.com)
Managed Universal LinksManaged, with Intune SDKThe link opens the managed app. If that is not possible, it opens in the protected browserOneDrive, SharePoint, Teams, Power Apps, Power BI, Stream, To Do, Viva Engage, ServiceNow, Zoom

Both lists accept wildcards, for example https://app.digid.nl/* or https://*.sharepoint.com/*. Microsoft warns that the target of an exempt Universal Link is unmanaged and that an exemption can lead to data leaks, so keep each entry as narrow as the scenario allows.

What Intune does under the hood

The diagnostic log shows how the Intune SDK enforces these lists. This behaviour is read from the logs of a production device, not from Microsoft documentation.

SituationWhat the SDK does
URL scheme, not exemptRewrites the scheme to <scheme>-intunemam. Only managed apps register that name, so an unmanaged app never receives the call
URL scheme, exemptPasses the call unchanged
Universal Link, not exemptCancels the navigation and reloads the link in the managed browser (microsoft-edge-https://...)
Universal Link, exemptMarks the link as a Universal Link and hands it to iOS, which opens the app

The exemption applies to every managed app that the policy targets. A DigiD or Waze exemption made for Edge or Outlook therefore also works from Teams, OneDrive and the Office apps.

Exemptions on Android

On Android one list covers all routes: add the package name of the app to Select apps to exempt. The option is available when Send org data to other apps is set to Policy managed apps.

The settings in this section come from Microsoft documentation. The blocking behaviour and the log patterns were verified with a test on a Samsung device with Android 12.

How it differs from iOS

  • The exemption names the app, not the way it is called. One entry covers a share action, an intent and an Android App Link to that app.
  • Android App Links are controlled by Send org data to other apps, not by the web content setting. A link that belongs to an unmanaged app is blocked until the package name of that app is exempt.
  • Restrict web content transfer with other apps only decides which browser opens normal http and https links. The SDK cannot determine whether a target app is a browser, so other managed browsers that support the http and https intent are also allowed.
  • Phone numbers and messaging have their own settings: Transfer telecommunications data to and Transfer messaging data to, each with an option for a specific app by package ID.

Default exemptions

Intune already allows a set of system apps and services. These need no entry in the policy.

PackageApp or serviceScope
com.android.phoneNative phone appFull
com.android.vendingGoogle Play StoreFull
com.google.android.webview, com.android.webviewWebViewFull
com.google.android.ttsGoogle Text-to-speechFull
com.android.providers.settings, com.android.settingsAndroid system settingsFull
com.azure.authenticatorMicrosoft AuthenticatorFull
com.microsoft.windowsintune.companyportalIntune Company PortalFull
com.android.providers.contacts, com.samsung.android.providers.contactsContacts providersFull
com.android.providers.blockednumberBlock number providerFull
com.android.chromeGoogle ChromeConditional. Used for some WebView components, data flow stays restricted
com.android.providers.mediaMedia content providerConditional. Only ringtone selection
com.google.android.gms, com.google.android.gsfGoogle Play ServicesConditional. Google Cloud Messaging actions such as push notifications
com.google.android.apps.mapsGoogle MapsConditional. Addresses for navigation
com.android.documentsui, com.google.android.documentsuiDocument PickerConditional. When opening or creating a file

Google Maps is the only navigation app on this list. A user who prefers Waze needs the Waze package name in Select apps to exempt, which is the Android counterpart of the Waze example later in this article.

In the test, a tap on a normal Google Maps web link (https://maps.google.com/?q=...) was still blocked from Outlook and Edge. The default exemption for Google Maps is conditional and does not cover every way of opening the app. When users need Google Maps from a link, add com.google.android.apps.maps to the list.

Find the package name

The package name is in the Google Play store URL of the app, after id=. Microsoft gives these examples:

AppEntry in Select apps to exempt
Webexcom.cisco.webex.meetings
Native SMS apps across vendorscom.google.android.apps.messaging, com.android.mms and com.samsung.android.messaging

The SMS example shows the main Android caveat. Device vendors ship their own apps for the same function, so one scenario can need several package names.

What is not possible

An exemption lets a managed app open an unmanaged app. It does not extend data protection to that app, and it does not open the other routes. The table lists requests that come up in practice and cannot be met with an exemption.

PlatformRequestPossibleReason and alternative
BothAllow copy and paste to one unmanaged appNoThe clipboard restriction has no exemptions per app. The alternative is the character limit, which allows short text such as a URL to all apps
BothLet an unmanaged app read a file that Intune encryptedNoOnly apps that support the Intune data type can read it
BothProtect the data after it reached an exempt appNoThe exempt app is unmanaged. Whatever it receives is outside Intune protection
BothExempt an app for Outlook onlyNot within one policyAn exemption applies to every app the policy targets. A separate policy for that app is the only way
iOS/iPadOSShare a document from a managed app to an unmanaged appNoExemptions do not apply to Open-in and Share. Manage the target app, or use Save copies of org data with an allowed location
iOS/iPadOSLimit what a managed app passes in an exempt URL callNoIntune allows or blocks the call. It does not inspect the parameters
iOS/iPadOSFind the URL scheme of a third-party app in the Intune admin centerNoMicrosoft offers no method. Use the diagnostic log or the app developer
iOS/iPadOSSee in the log whether a host belongs to an installed appNoThe log records the host, not the app behind it
AndroidExempt only one way of opening an app, for example the link but not the share actionNoThe exemption names the package, so it covers every way of reaching that app
AndroidUse Android Instant Apps with managed appsNoIntune does not support Instant Apps and blocks any data connection to or from the app

The consequence for a baseline is that every exemption is a controlled gap. The scheme, host or package name decides which app may be opened. What the user does in that app afterwards is no longer covered by the policy.

Finding out what to exempt

The Intune diagnostic log on the device records every app call that the SDK handled, including the scheme or host, so it shows exactly what to exempt. Microsoft’s own guidance is to ask the app developer, and the documentation states that Microsoft has no method to find the URL protocol of a third-party app. In practice the developer is often hard to reach, and the log gives the answer in a few minutes.

On Android the value is a package name. It is in the Google Play store URL of the app, and the diagnostic log also records the package name of every app that was blocked. The Android steps are at the end of this section.

Options to find the value

MethodResultEffort
Intune diagnostic logThe scheme, host or package that was really called in the user scenarioLow. Reproduce, collect, read
App developer documentation or supportThe officially supported valueDepends on the vendor
Info.plist and entitlements from the app packageAll schemes and Universal Link hosts the app registersHigh. Needs a Mac and the app package
Community lists of URL schemesA first guessLow, but often outdated and never authoritative

The log is the preferred method, because it shows only what the scenario needs. An app often registers several schemes, and there is no reason to exempt all of them.

iOS and iPadOS: collect the log

  1. Reproduce the problem on the device. Tap the link once and note the time.
  2. Open Microsoft Edge and enter about:intunehelp in the address bar.
  3. Select Get Started, then Share Logs.
  4. Send the log to yourself and open it on a computer.

Collect the log directly after the test. Each app keeps two rotating log files, so in a busy app older events disappear after a few weeks. The export is one text file that contains the logs and the policy of all managed apps, and it can be around 100 MB.

iOS and iPadOS: the log lines that matter

Log lineMeaningAction
openURL URL: '<scheme>://...' followed by Restricted URL: '<scheme>-intunemam://...'A URL scheme call was blocked for unmanaged appsAdd the scheme to Select apps to exempt
openURL URL: '<scheme>://...' followed by Restricted URL with the same schemeThe scheme is exempt and the call was allowedNone
Returning FALSE from canOpenURL due to policy settingThe app asked whether a scheme can be opened and policy answered noAdd the scheme when the app needs it
Protecting link: https://<host>/... with shouldPassThrough=0A tapped web link was kept in the managed app or browserAdd https://<host>/* to Exempt Universal Links when the host belongs to an installed app
openURL URL: 'https://<host>/...' followed by microsoft-edge-httpsAn app sent a web link to the managed browserSame as above
Wkwebview link https://<host>/... shouldProtect is 0, isULType is 1The Universal Link is exempt and was handed to iOSNone

The log scrubs the path and query of every URL, but the scheme and host stay readable. That is the part the policy needs.

Three details prevent wrong conclusions:

  • iOS only opens an app from a Universal Link when the user taps the link. A reload or a restored tab always stays in the browser, so test with a new tap after a policy change.
  • The host in the address bar can differ from the host that was called. Outlook calls https://waze.com, and Edge then redirects to https://www.waze.com. The exemption must match the first one.
  • The active policy of an app is in the EffectivePolicies block of its IntuneMAMDiagnosticInfo.txt section. Other blocks in the same section hold older cached records.

Android: collect and read the log

On Android the logs are saved from the Company Portal app and copied to a computer. Each managed app has its own log file, and that file names every package the app was not allowed to open.

  1. Sign in to the Company Portal app on the device.
  2. Open the menu, go to Settings and turn on verbose logging.
  3. Reproduce the problem. Tap the link once and note the time.
  4. In Settings, select Save logs and choose a folder on the device.
  5. Connect the device to a Windows computer with USB and copy the saved files.

Opening about:intunehelp in Edge on Android uploads the logs to Microsoft and returns an incident ID. It does not give you the files, so use Save logs for this purpose.

The saved set contains more files than needed:

FileContentNeeded
<package>.log.zip, for example com.microsoft.office.outlook.log.zipMAM_0.0.log with the app protection decisions of that appYes
DiagnosticsInfo.logThe policy per managed app, including PackageExclusions (Select apps to exempt) and the last check-inYes
OMADMLog_*.log, CompanyPortal_*.logCompany Portal and enrolment activityNo
broker.*.txtSign-in broker activityNo

The log lines that matter in MAM_0.0.log:

Log lineMeaningAction
PackageManagerPolicyFactory Disallowing access to package <package>The managed app may not open this appAdd the package name to Select apps to exempt
Disallowing package <package> disallowed using TRANSFER_ONLYThe block is a data transfer restrictionNone, it confirms the cause
WebLinkRule Web link resolution was not a deep linked app, using browserThe link falls back to the managed browserNone
MAMResolverUIBehaviorImpl No apps available. <... scheme=...>No allowed app was found for this linkLook at the blocked package at the same time

Times in these files are in UTC. One tap writes several lines in the same second. A block of com.android.chrome appears with every web link. It is the redirect to Microsoft Edge and needs no action.

Reading the log with the Intune MAM Link Analyzer

The Intune MAM Link Analyzer is a single HTML page that reads the diagnostic logs and lists every app, URL scheme and Universal Link that managed apps tried to open, with the result. Searching a 100 MB text file by hand works for one case, but it is slow and easy to misread.

The report reads both platforms: the iOS and iPadOS export, and the Android files (the app zip files and DiagnosticsInfo.log). Several files can be loaded at once, and the zip files do not need to be unpacked.

The page runs in the browser and reads the files locally. Nothing is uploaded, which matters because the logs contain user and tenant information. It is available online and needs no installation.

Suggested additions and the result of a test mail opened in Outlook

The first screenshot shows the result of a test mail opened in Outlook on iOS. The top card suggests what to add and where: the blocked schemes whatsapp and waze for Select apps to exempt, and https://waze.com/* for Exempt Universal Links. Each value has a copy button and a line that says which apps called it and when.

Suggested package names and the blocked apps per managed app for Android

The second screenshot shows the same test on Android. The suggestion is a list of package names, and the table shows per managed app which package was blocked and how often.

Part of the pageWhat it shows
Suggested additionsThe values to consider, grouped per policy setting, in the format the policy expects. Microsoft and system targets are left out
Universal Links allowediOS: links on the exemption list that were handed to iOS
Links kept inside the managed appiOS: tapped web links that stayed in the app or browser
Links sent to the managed browseriOS: web links an app such as Outlook passed on to Edge
URL schemes callediOS: scheme calls with the result, allowed or blocked
Android: apps blockedPackages a managed app was not allowed to open
Android: no allowed app for a linkLinks for which Intune found no allowed app
Effective policy per appThe exemption lists and the last check-in time per managed app

Each row has two status columns. Policy now compares the row with the policy the app had when the log was collected. Result at the time is what the log recorded for the event. After a policy change these two differ until the user repeats the test, which makes it visible whether a fix has been verified.

Filters limit the view to a start time, an app, or a scheme or host. Microsoft and iOS hosts and internal schemes are hidden by default and can be shown with one option.

One limitation applies. The list of links kept inside the managed app contains every tapped web link, so normal websites appear there too. The log cannot tell whether a host belongs to an installed app. That judgement stays with the administrator.

Worked examples

iOS: DigiD, a Universal Link from Edge

The fix for DigiD is one entry in Exempt Universal Links: https://app.digid.nl/*.

  1. The user signed in on a website in Edge and tapped the button to open the DigiD app. The app did not open.
  2. The Edge log showed Protecting link: https://app.digid.nl/... with shouldPassThrough=0. DigiD is called through a Universal Link on host app.digid.nl, not through a custom URL scheme.
  3. After the entry was added, the policy arrived in each app at its next check-in. The EffectivePolicies block of every managed app showed the new value.
  4. A new sign-in with a new tap on the button opened the DigiD app.

The first test after the change seemed to fail, because the old tab was reloaded instead of tapped. A reload never triggers a Universal Link.

iOS: Waze, an address in Outlook

The fix for Waze is https://waze.com/* in Exempt Universal Links.

  1. Outlook for iOS was set to open addresses in Waze. A tap on an address opened the Waze website in Edge.
  2. The Outlook log showed openURL URL: 'https://waze.com/...', rewritten to microsoft-edge-https://waze.com/.... Edge then redirected to www.waze.com.
  3. The host to exempt is waze.com, without www.
  4. After the entry was added and Outlook had checked in, a new tap on the address opened Waze.

A direct waze:// link in a mail or on a web page is a different route. It needs waze in Select apps to exempt. For the address scenario only the Universal Link entry is required.

iOS: a test mail to verify both routes

A mail with one link per route gives a verified reference for each log pattern. Send it to a test user, open it in Outlook on the device, tap each link once and collect the log.

Link in the mailPolicy listResult in the log
waze://?q=AmsterdamNot exemptRewritten to waze-intunemam, blocked
whatsapp://send?text=testNot exemptRewritten to whatsapp-intunemam, blocked
comgooglemaps://?q=AmsterdamExemptPassed unchanged, allowed
maps://?q=AmsterdamExemptPassed unchanged, allowed
sms:?body=testExemptPassed unchanged, allowed
https://waze.com/ul?q=AmsterdamNot exemptSent to Edge
https://maps.apple.com/?q=AmsterdamExempt by defaultHanded to iOS, app opens

Custom scheme links stay clickable in Outlook for iOS, so a mail is enough for this test. The exempt entries in this table come from the policy of the test tenant and will differ per tenant.

Android: the same test on a Samsung device

On Android every unmanaged app from the test was blocked by package name, whichever link type was used. The test ran on a Samsung SM-A217F with Android 12, with a mail opened in Outlook.

Package blockedFrom OutlookFrom Edge
com.wazeYesYes
com.whatsappYesYes
com.spotify.musicYesNot seen
com.google.android.youtubeYesNot seen
com.google.android.apps.mapsYesYes

Outlook handled each tap as a web link and passed it to Edge. In Edge the WhatsApp page then called whatsapp://, and the log shows that no allowed app was available.

The test also found an entry without effect. The exemption list on the device contained com.google.maps, while the device reports Google Maps as com.google.android.apps.maps. A package name that does not match exactly does nothing, and the log is a quick way to find such entries.

Summary

An unmanaged app that must open from a managed app needs an exemption. On iOS and iPadOS the entry goes in the list that matches the route: Select apps to exempt for a URL scheme, Exempt Universal Links for an https link. On Android the package name of the app goes in Select apps to exempt, whatever the route. On both platforms the Intune diagnostic log shows the value: the scheme or host on iOS and iPadOS, the package name on Android.

The method in five steps:

  1. Reproduce the problem with one tap and note the time.
  2. Collect the log: about:intunehelp in Edge on iOS and iPadOS, Save logs in Company Portal on Android.
  3. Open the log in the Intune MAM Link Analyzer and filter on the time of the test.
  4. Add the suggested scheme, host or package name to the matching list in the App Protection Policy.
  5. Wait for the app to check in, test with a new tap and confirm that the block is gone.

Governance points for a baseline:

  • Exempt only what a documented scenario needs, and prefer a narrow Universal Link host over a broad wildcard.
  • An exemption applies to all managed apps that the policy targets, not only to the app where the problem was reported.
  • Record each entry with the app, the reason, the date and the approver, so that the lists can be reviewed during drift checks.
  • Review inherited entries. tel;telprompt; should be replaced by the telecommunication setting, and sms or mailto allow org data into native compose views.
  • On Android, check whether a scenario needs more than one package name, because device vendors ship their own apps for the same function.
  • Tell users and customers what an exemption does not do: it opens the app, but it does not allow documents or clipboard content to go to that app.

References

  • iOS/iPadOS app protection policy settings: data transfer exemptions and Universal Links, Microsoft Learn
  • How to create exceptions to the Intune App Protection Policy data transfer policy, Microsoft Learn
  • Troubleshooting exemptions to data transfer policies, Microsoft Learn
  • How to manage data transfer between iOS apps, Microsoft Learn
  • Troubleshooting app protection policy deployment: collect device data with Microsoft Edge, Microsoft Learn
  • App configuration policies: diagnostic logs, Microsoft Learn
  • Review client app protection logs, Microsoft Learn
  • Android app protection policy settings: data transfer exemptions, Microsoft Learn
  • Report a problem in Company Portal or Intune app for Android: save logs, Microsoft Learn
  • Intune App SDK for Android: understanding Company Portal logs, Microsoft Learn
  • DigiD, NL Digital Government
  • Create and assign app protection policies: device management types, Microsoft Learn
  • Multiple managed accounts for app protection policies, Microsoft Learn
  • Assignment filter properties: managed app properties, Microsoft Learn
  • App configuration policies: managed devices and managed apps, Microsoft Learn

The log patterns and the SDK behaviour described in this article come from diagnostic logs of test devices, not from Microsoft documentation: an iPhone with Intune SDK 21.x on iOS 27, and a Samsung SM-A217F with Android 12 and Company Portal 5.0.7080.0.

Tweet
Follow me
Tweet #WPNinjasNL

Continue Reading

← MAM vs. MDM: Choosing the Right Mobile Management Approach

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Founding member of:

Recent Posts

  • Opening other apps and sharing data from Intune protected apps on Apple mobile and Android
  • From IST to SOLL: A Field Guide to Modernizing Entra ID Authentication
  • Require Risk Remediation in Entra Conditional Access
  • Bringing Order to Microsoft’s Fast‑Moving Copilot Rollout in Microsoft 365
  • Governing access to app stores in Microsoft 365 apps

Books

System Center 2012 Service Manager Unleashed
Amazon
System Center 2012 R2 Configuration Manager Unleashed: Supplement to System Center 2012 Configuration Manager
Amazon
System Center Configuration Manager Current Branch Unleashed
Amazon
Mastering Windows 7 Deployment
Amazon
System Center 2012 Configuration Manager (SCCM) Unleashed
Amazon

Archives

  • October 2026
  • August 2026
  • February 2026
  • October 2025
  • February 2025
  • January 2025
  • September 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • September 2023
  • August 2023
  • February 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • May 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021
  • October 2021
  • September 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • December 2019
  • November 2019
  • October 2019
  • August 2019
  • July 2019
  • November 2016
  • November 2015
  • June 2015
  • May 2015
  • November 2014
  • July 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014
  • November 2013
  • August 2013
  • April 2013
  • March 2013
  • January 2013
  • December 2012
  • November 2012
  • August 2012
  • July 2012
  • June 2012

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Categories

  • ABM (4)
  • Advanced Threat Protection (4)
  • Announcement (44)
  • Azure (3)
  • AzureAD (73)
  • Certification (2)
  • Cloud App Security (5)
  • Conditional Access (63)
  • Configuration Manager (24)
  • Entra (6)
  • Entra Id (9)
  • Events (14)
  • Exchange Online (10)
  • Identity Protection (6)
  • Intune (31)
  • Licensing (2)
  • Microsoft Defender (1)
  • Microsoft Defender for Endpoint (1)
  • Microsoft Endpoint Manager (35)
  • Mobile Application Management (6)
  • Modern Workplace (76)
  • Office 365 (12)
  • Overview (11)
  • Power Platform (1)
  • PowerShell (2)
  • Presentations (9)
  • Privileged Identity Management (5)
  • Role Based Access Control (2)
  • Security (66)
  • Service Manager (4)
  • Speaking (30)
  • Troubleshooting (4)
  • Uncategorized (11)
  • Windows 10 (15)
  • Windows 11 (5)
  • Windows Update for Business (4)
  • WMUG.nl (16)
  • WPNinjasNL (32)

Tags

#ABM #AzureAD #community #conditionalaccess #IAM #Intune #m365 #MEM #MEMCM #microsoft365 #modernworkplace #office365 #security #webinar #wmug_nl ATP authentication method policies authentication strength AzureAD Branding Community Conditional Access ConfigMgr ConfigMgr 2012 EXO Identity Intune iOS M365 MCAS MFA Modern Workplace OSD passkeys PIM Policy Sets Presentation RBAC roles Security System Center troubleshooting webinar Windows 10 Zero Trust

Recent Comments

  • Welke mobiele beheeroplossing past bij jouw organisatie? – Microsoft modern workplace – Secure At Work on MAM vs. MDM: Choosing the Right Mobile Management Approach
  • Welke mobiele beheeroplossing past bij jouw organisatie – Microsoft modern workplace – Secure At Work on MAM vs. MDM: Choosing the Right Mobile Management Approach
  • Jakub Kowalski on Configuring Conditional Access for Guest Users: Allowing Only Office 365 and Essential Apps
  • PasskeyPilot on From IST to SOLL: A Field Guide to Modernizing Entra ID Authentication
  • Seth on Configuring Conditional Access for Guest Users: Allowing Only Office 365 and Essential Apps

This information is provided “AS IS” with no warranties, confers no rights and is not supported by the author.

Copyright © 2021 by Kenneth van Surksum. All rights reserved. No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

Shorthand: Don’t pass off my work as yours, it’s not nice.

©2026 Modern Workplace Blog | Powered by WordPress and Superb Themes!
This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT