BYODPolicy.org
Primary sources, restated with receipts. No products. No vendor opinions.
A-000
ANALYSIS
Core BYOD Policy
Last verified 2026-09-10
Framework breakdown ↓

ANALYSIS — Can MAM be used for CUI on a BYOD device?

This is an analysis page. It applies reasoning across several sources. Each claim is labeled STATED (a source says it), DERIVED (follows from cited text by a step shown here), ANALYSIS (this site's judgment), NOT ESTABLISHED (the evidence needed to establish it has not been identified), or VERIFY LIVE. For what each source says on its own, follow the Q-page links.

The question and why the answer is neither "yes" nor "no"
DoD policy permits MAM on personal devices for data up to CUI. That is settled by the text of two memoranda and is not disputed here. [C1, STATED]

But a personal device handling CUI sits inside several frameworks at once, and they are not a hierarchy in which the most authoritative one settles the matter. A statute, a regulation, a policy memorandum, a guideline, and a certification scheme each impose their own conditions and evidence burdens. Compliance means meeting all that apply. The useful question is therefore not "is MAM allowed" but "what does each framework require of a MAM deployment, and which requirements are unresolved on the sources' text." That framing is this site's. [C2, ANALYSIS]

A note on who this applies to. DoD's own BYOD programs (the "AMD" programs of the August 2022 memorandum) and defense contractors' BYOD programs are governed by overlapping but different rules, particularly on sanitization. Where they diverge, this page says so.

Framework 1 — DoD Policy: permits the architecture, with conditions

What the sources state.
The October 24, 2025 MFA memorandum names "either a Mobile Application Management (MAM) implementation or a Virtual Desktop Interface (VDI)" for CAC-holders using derived non-PKI MFA from a personal device; permits M365 data "up to (and including) CUI"; requires isolation "if technologically feasible" and management "to the extent possible"; and requires, "For MAM, limit access to applications that can be policy enforced."

‍What this means. The policy anticipated MAM specifically and wrote conditions for it. Two of those conditions carry the weight of everything below: the EMM must be NIAP validated (Framework 2), and DoD data must be removable without touching personal data (Framework 3). Neither memorandum names a product or a configuration.

Framework 2 — NIAP: certificate scope, and a date

What the sources state.

For a DoD AMD program, "EMM system must be NIAP validated" is a DIRECT requirement (Framework 1, C3). Intune satisfies it today as an MDM system. Two questions follow. First, whether an app-protection-only (MAM/MAM-WE) deployment is the "EMM system" that was validated: the certificate attests to an enrollment-based configuration, and the Validation Report places other functionality outside the evaluation. Whether an AO reads "NIAP validated" as attaching to the product or to the evaluated configuration is not answered by either memorandum. [C8, NOT ESTABLISHED] Second, if VID 11298 is archived after 2026-12-31 without maintenance, the requirement is unmet for any Intune-based AMD program until a successor certificate exists, regardless of MDM or MAM mode. [C9, DERIVED from C3, C5, C6]

Counter-reading. The MFA memorandum lists FIPS-140 or NIAP validation as a factor DoD CIO "may deem appropriate" in E2P review of unlisted MFAs; it does not itself require the MAM implementation to be NIAP-certified. The NIAP requirement comes from the 2022 memorandum, and that memorandum says "EMM system," not "EMM configuration." A reasonable AO could conclude that a validated product satisfies the text. [C10, ANALYSIS] C24

Framework 3 — CUI destruction and sanitization: a burden of evidence, not a prohibition

This framework is where the most overstatement occurs, in both directions. The chain below separates DoD's own programs from contractors' programs because their governing texts differ.

3a. What DoD's BYOD rule itself requires

The AMD memorandum's removal requirement is the operative DoD-specific text: all DoD data removed (e.g., wiped) on termination, loss, or compromise, and "Users' personal information and applications on the device should not be impacted." [C3, STATED — S-004 §3.b(5)]
‍
That is a requirement for selective removal. A whole-device Purge or factory reset would satisfy the first sentence and violate the second. Any argument that DoD BYOD policy demands whole-device sanitization runs against DoD's own text. The memorandum does not use the words Clear, Purge, or Destroy and does not cite SP 800-88 in its Attachment. [C11, DERIVED — Q-032-C14, C16]

3b. The CUI destruction standard

DoDI 5200.48 requires destroyed CUI, including electronic CUI, to be "unreadable, indecipherable, and irrecoverable," and identifies SP 800-88 methods as an example ("such as") of acceptable means. It sets an outcome standard, not a tier. [C12, STATED — S-032; Q-041]

3c. SP 800-171: which text applies

‍What this means. For a contractor, the 800-171 hook for "a personal device leaving control" does not exist in the assessed text; the sanitization expectation has to come from DoDI 5200.48's outcome standard via the contract, from 32 CFR 2002.14, or from SP 800-88's own scope. For a DoD Component, the MP-6 "out of organizational control" trigger applies directly. [C15, DERIVED]

3d. SP 800-88 Rev. 2: what it actually says about this fact pattern

3e. What Microsoft's public documentation says about the mechanism

Microsoft's app-protection-policy documentation describes selective wipe as removal of organization data from the managed app when the app next checks in, distinguishes it from full-device wipe under enrollment, and documents cases where data copied outside the managed boundary (for example, contacts synced to a native app) is not removed by selective wipe. [C22, STATED — S-020; pinpoints to be confirmed against current Microsoft Learn pages]

On the public documentation reviewed, this site has not identified evidence that Intune MAM selective wipe: invokes a device sanitize command or an IEEE 2883 technique; performs a documented cryptographic erase with key zeroization traceable to SP 800-88 §3.2; addresses all storage locations where managed-app data may reside (caches, previews, notification stores, backups); or has been validated against SP 800-88 Purge by an independent party. [C23, NOT ESTABLISHED]

3f. Putting Framework 3 together

For a DoD AMD program: the governing texts require selective removal that spares personal data (3a) and an outcome of unreadable/indecipherable/irrecoverable (3b). SP 800-88 says selective sanitization is legitimate, is best achieved by per-file or per-region CE, carries assurance risks, and is acceptable where whole-media sanitization is not an option (3d). Whole-media sanitization is not an option here, by DoD's own rule. The question an AO must answer is therefore: does the EMM's selective removal achieve the 5200.48 outcome with the assurance the Component's sanitization policy requires, and can that be documented? On the public evidence, for Intune MAM, that has not been established (3e). It has not been refuted either. [C24, ANALYSIS]
‍
‍For a defense contractor: the assessed 800-171 text has no leaving-control trigger (3c). The sanitization expectation for a personal device is whatever the contractor's own media-protection policy, its System Security Plan, and its assessor accept, informed by 5200.48 through the contract and by SP 800-88 as guidance. SP 800-88 permits risk-based acceptance of Clear for moderate data (3d). A contractor that documents MAM selective wipe as its sanitization technique, states the residual risk, and has the assessor accept it is not out of compliance on the text. A contractor that asserts Purge-level assurance without evidence is. [C25, ANALYSIS]

‍Strongest counter-readings, and responses.

Framework 4 — FAR 52.204-27: an obligation MAM does not by itself discharge

What the sources state.

What this means. The contractor's obligation attaches to the device. MAM's documented scope is the managed container; it does not give visibility into or control over other applications. The obligation must be met some other way: attestation and policy, device-wide enrollment, an architecture under which the device is arguably not "used in performance," or a CO exception. Neither the clause nor the preamble prescribes a technical method. Notably, DoD's own AMD text scopes the EMM's application-blocking duty to the managed segment, which is consistent with a policy-plus-attestation approach for the rest of the device. [C32, ANALYSIS]

Counter-reading. The clause prohibits "having or using," not "failing to technically prevent." A signed attestation may satisfy it. Whether it does is a Contracting Officer and ultimately a legal question. [C33, ANALYSIS]

Framework 5 — CMMC (32 CFR Part 170): scoping consequence, currently in flux

What the sources state.‍

What this means. A managed container on a personal device processes and stores CUI; on the text of §170.19 that points to CUI Asset treatment unless the boundary is documented otherwise. A VDI architecture that renders CUI without writing it to the device has a more direct argument for a lighter category. This is an inference from the regulation's categories, not a statement about MAM or VDI. With third-party assessment paused, the practical consequence today is a self-assessment and SPRS representation, which carries False Claims Act exposure rather than a C3PAO finding. [C37, ANALYSIS]

Counter-reading. Assessors evaluate the documented boundary, not a technology label. A well-documented MAM deployment may be accepted with a narrowed boundary; a poorly documented VDI deployment may not. [C38, ANALYSIS]

Summary

Framework
What the sources state
Status of the "problem for MAM"
DoD policy (2025 MFA memo; 2022 AMD memo)
MAM permitted; EMM must be NIAP validated; DoD data removable without impacting personal data
No prohibition; two conditions carry forward
NIAP
Intune certified as an MDM system through 2026-12-31; other functionality not assessed; no maintenance filed as of 2026-09-10
Scope question (NOT ESTABLISHED for MAM-only); hard date
CUI destruction / sanitization
5200.48 outcome standard; 800-171 Rev. 2 (contractors) has no leaving-control trigger, Rev. 3/MP-6 (DoD) does; 800-88 permits selective CE and risk-based Clear for moderate data
Burden of evidence; Purge-level assurance for MAM selective wipe NOT ESTABLISHED on public evidence
FAR 52.204-27
Obligation attaches to employee-owned devices used in performance; CO exception available
Must be met by some means; MAM alone does not document device-wide control
CMMC
CUI Asset scoping by what the asset does; Level 2 = Rev. 2; Phase 2 paused
Inference toward CUI Asset scoping; enforcement mechanism currently self-assessment

What would resolve the open items

For the implementer: documentation, in the authorization package or SSP, of (a) which NIAP certificate the EMM relies on, its scope, and its status on the date of authorization; (b) how the managed container stores and keys CUI, what selective wipe does to those keys, whether any plaintext or copies exist outside the container, and the SP 800-88 §3.2.5 traceability items; (c) how the FAR 52.204-27 obligation is met for the whole device; (d) the CMMC asset category and boundary rationale. None of these is a product question; all are deployment-documentation questions, and none is answered by a policy sentence saying "MAM is approved."

For the vendor: publishing the §3.2.5 traceability information for selective wipe would move C23 from NOT ESTABLISHED to STATED in one direction or the other.

Where this site's position changed

How to verify this yourself

Claims

ID
Claim
Status
Source and pinpoint
C1
2025 memo permits MAM/VDI for BYOD up to CUI with conditions.
STATED
S-001, Att. 4, Table 2
C2
Compliance is a conjunction of independent frameworks.
ANALYSIS
-
C3
2022 memo: EMM required (MDM/MAM/MCM/VMI); EMM NIAP validated and STIG-configured; DoD data removed on termination without impacting personal data.
STATED
S-004 §3.a(1)–(2), §3.b(5)
C4
Two conditions carry forward; no product/configuration named.
DERIVED
S-001; S-004
C5
Intune VID 11298 scope and dates; other functionality not assessed.
STATED
S-025 §§1, 6; S-008
C6
Maintenance Update blank; nothing in evaluation, 2026-09-10.
STATED / VERIFY LIVE
S-008 screenshots
C7
BYOD use-case invokes MDF PP and DoD Annex.
STATED
S-001 p. 26
C8
Whether "NIAP validated EMM system" is satisfied by a MAM-only deployment of a product validated as MDM.
NOT ESTABLISHED
S-004 §3.a(2); S-025 §6
C9
If archived after 2026-12-31, the 2022 memo's requirement is unmet for Intune-based AMD programs pending a successor.
DERIVED
C3, C5, C6
C10
Counter-reading: "EMM system" may be read at product level.
ANALYSIS
-
C11
DoD BYOD rule requires selective removal; whole-device Purge would violate §3.b(5)(i); no Clear/Purge/Destroy or 800-88 in Attachment.
DERIVED
S-004 §3.b(5)
C12
DoDI 5200.48 outcome standard; 800-88 as example.
STATED
S-032
C13
Rev. 2 3.8.3 text; contractors assessed against Rev. 2.
STATED
S-027; S-030; S-031
C14
Rev. 3 03.08.03 text with mobile devices.
STATED
S-028
C15
Contractor vs. DoD Component trigger difference.
DERIVED
C13, C14
C16
Purge preferred "when possible."
STATED
S-019 §3.1.2
C17
Risk acceptance of Clear for moderate data; CUI at moderate.
STATED (800-88) / confirm 2002.14 pinpoint
S-019 §4.3; 32 CFR 2002.14
C18
Selective/partial sanitization provisions.
STATED
S-019 §4.2
C19
CE preconditions and traceability.
STATED
S-019 §3.2
C20
Validation may reject narrow scope.
STATED
S-019 §4.5.2
C21
Leaving-control examples; never-owned media not addressed.
STATED / DERIVED
S-019 §4.3.4
C22
Microsoft selective wipe description and limitations.
STATED - CONFIRM PINPOINTS
S-020
C23
No public evidence of Purge-level mechanism or validation for Intune MAM selective wipe.
NOT ESTABLISHED
Review of S-020 and related Microsoft Learn pages
C24
DoD AMD synthesis.
ANALYSIS
-
C25
Contractor synthesis.
ANALYSIS
-
C26
Counter-reading 1 and response.
ANALYSIS
-
C27
Counter-reading 2 and response.
ANALYSIS
-
C28
Counter-reading 3 and response.
ANALYSIS
-
C29
FAR clause text.
STATED
S-013
C30
Preamble BYOD statements.
STATED
S-014
C31
2022 memo: block prohibited apps within managed segment; device remains subject to private-device restrictions.
STATED
S-004 §3.a(3)(iii), §3.c(3)
C32
Obligation attaches; MAM alone does not document device-wide control; DoD scopes EMM blocking to managed segment.
ANALYSIS
-
C33
Counter-reading: attestation may suffice.
ANALYSIS
-
C34
§170.19(c)(1) asset categories.
STATED - CONFIRM PINPOINT
S-017
C35
Level 2 identical to Rev. 2.
STATED
S-031 §170.14
C36
Phase 2 paused July 13, 2026; class deviation; 7012 unchanged.
STATED / VERIFY LIVE
S-033
C37
Container processes CUI → CUI Asset inference; self-assessment/FCA posture.
ANALYSIS
-
C38
Counter-reading: documented boundary governs.
ANALYSIS
-

Related entries

CHANGELOG
  • 2026-09-10 (rev. 3) — Framework 3 rebuilt on the full texts of SP 800-88r2, the Aug 2022 AMD memo Attachment, DoDI 5200.48 destruction paragraphs, and SP 800-171 Rev. 2/Rev. 3 requirement text. Framework 2 adds the 2022 memo's EMM-NIAP requirement. Framework 5 adds the CMMC Phase 2 pause. Claim set renumbered C1–C38. NOT ESTABLISHED status introduced (C8, C23).
  • 2026-09-10 (rev. 2) — Framework 2 updated from the NIAP Validation Report and PCL screenshots.
  • 2026-09-10 (rev. 1) — Page rebuilt and relabeled ANALYSIS; conclusion changed from "No — E2P required."
  • 2026-07-07 — Original entry created as Q-000 "flagship."

This is an analysis page. It is not legal, contracting, or compliance advice. Authorizing decisions rest with the cognizant Authorizing Official; contract interpretation with the Contracting Officer; assessment findings with the assessor. Corrections: [email protected]