Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Implements Mobile Application Management (MAM) policies to protect enterprise data on managed and unmanaged mobile devices through app-level controls including data loss prevention, selective wipe, app configuration, and containerization. Use when securing corporate apps on BYOD devices, implementing Intune App Protection Policies, or enforcing data separation between personal and work apps. Activates for requests involving MAM deployment, app protection policies, mobile containerization, or BYOD security.
.claude/skills/implementing-mobile-application-management/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-02 | ✗→✓ | ▲ Improved | — | — |
| case-12 | ✗→✓ | ▲ Improved | — | — |
| case-07 | ✗→✓ | ▲ Improved | — | — |
| case-09 | ✗→✓ | ▲ Improved | — | — |
| case-13 | ✗→✓ | ▲ Improved | — | — |
Use this skill when:
Do not use when full device management (MDM) is already deployed and sufficient -- MAM adds complexity when MDM already provides the needed controls.
Classify data sensitivity and define protection tiers:
| Tier | Data Type | Controls | |------|-----------|----------| | Tier 1 - Basic | General corporate email | Require PIN, block screenshots | | Tier 2 - Enhanced | Financial data, HR records | Encrypt app data, restrict cut/copy/paste | | Tier 3 - High | PII, healthcare, legal | Selective wipe, offline access limits, DLP |
Android App Protection Policy:
json{ "displayName": "Corporate App Protection - Tier 2", "platform": "android", "dataProtectionSettings": { "allowedDataStorageLocations": ["oneDriveForBusiness", "sharePoint"], "blockDataTransferToOtherApps": "managedApps", "blockDataTransferFromOtherApps": "managedApps", "saveAsBlocked": true, "clipboardSharingLevel": "managedAppsWithPasteIn", "screenCaptureBlocked": true, "encryptAppData": true, "backupBlocked": true }, "accessSettings": { "pinRequired": true, "minimumPinLength": 6, "biometricEnabled": true, "offlineGracePeriod": 720, "offlineWipeInterval": 90 }, "conditionalLaunchSettings": { "maxOsVersion": "15.0", "minOsVersion": "12.0", "jailbreakBlocked": true, "maxPinRetries": 5 } }
Deploy managed app configuration for automatic endpoint setup:
json{ "displayName": "Email App Configuration", "targetedManagedApps": ["com.microsoft.outlooklite"], "settings": [ {"key": "com.microsoft.outlook.EmailProfile.AccountType", "value": "ModernAuth"}, {"key": "com.microsoft.outlook.EmailProfile.ServerName", "value": "outlook.office365.com"}, {"key": "com.microsoft.outlook.EmailProfile.AllowedDomains", "value": "corporate.com"} ] }
Azure AD > Conditional Access > New Policy:
- Users: All users with corporate apps
- Cloud apps: Office 365, custom LOB apps
- Conditions: All platforms
- Grant: Require app protection policy
- Session: App enforced restrictionsTest each policy control on both platforms:
bash# Verify data transfer restrictions 1. Open managed app (Outlook) 2. Copy text from email body 3. Attempt paste in unmanaged app (Notes) -- should be blocked 4. Attempt paste in managed app (Teams) -- should work # Verify selective wipe 1. Enroll test device with MAM 2. Access corporate data in managed apps 3. Trigger selective wipe from Intune portal 4. Verify corporate data removed, personal data intact # Verify offline grace period 1. Access managed app while connected 2. Disconnect from network 3. After grace period expires, verify app access blocked
Configure MAM monitoring dashboards:
| Term | Definition | |------|-----------| | MAM | Mobile Application Management - app-level policies without requiring full device enrollment | | App Protection Policy | Set of rules enforcing data protection at the app level (encryption, DLP, access controls) | | Selective Wipe | Removing only corporate data from managed apps while preserving personal data | | App Wrapping | Post-build process applying MAM SDK policies to apps without source code modification | | Containerization | Isolating corporate app data in an encrypted container separate from personal apps |
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-21 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-17 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-06 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-02 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-04 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-12 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-07 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-22 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-10 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-08 | pass→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-19 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-09 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-05 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-13 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-11 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-03 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-20 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-14 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-01 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-15 | fail→pass | — | — | — | — | — | — | — | — | — | — | — | — |
case-16 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
case-18 | fail→fail | — | — | — | — | — | — | — | — | — | — | — | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +32 percentage points is the difference between those two pass rates over the 22 comparable cases.
The per-case answers from this run were removed by the retention sweep, so the case table below shows the verdicts without the text either arm produced. The counts above were recorded at the time and are unaffected. Answers are now kept for 180 days.
Other measured skills in the registry, with their headline benchmark lift.