Verify NIAP status directly: niap-ccevs.org/products (filter: "microsoft", status: Certified) - recheck by 2026-10-07
Law, regulation, policy, and technical certification are not a hierarchy where one tier overrides the others. They are independent conditions that all apply at once. A permissive statement at one tier (here, DoW policy) does not excuse an unmet requirement at another tier (NIAP, NIST, statute, or CMMC scoping). Compliance is the AND of every applicable requirement, not the position of the single most authoritative source.
The DoW CIO memorandum of October 24, 2025, Attachment 4, Table 2 ("Authentication From a Personal Mobile Device (BYOD)"), names either a MAM implementation or a VDI as an approved architecture, provided the non-PKI MFA is derived from the user's DoW-approved PKI credential, IT Privileged User Accounts remain blocked, and the Secret Fabric is never reachable from the device. C1 This is true and remains true — it is not overridden by anything below. It is simply not sufficient by itself.
DoD CIO Memorandum, Use of Non-Government Owned Mobile Devices (10 Aug 2022), the governing instrument for Approved Mobile Devices (AMDs), applies directly to this same personal-device-accessing-CUI case. §3.a.(1) requires that access from a personal device be managed by an EMM system, naming MDM, MAM, MCM, or VMI as acceptable types, with containers used to segregate personal and DoD data where applicable. C16§3.a.(2) further requires that the EMM system be NIAP validated and configured per applicable STIGs, which is exactly what Pillars 2 and 4 below test. C17
Microsoft Intune MAM and Microsoft Defender for Endpoint are not NIAP certified, as of July 7, 2026. C2 The NIAP Product Compliant List, filtered to Microsoft and Certified status, returns exactly two results: Windows 11/Server 2025/Azure Stack HCI, and Microsoft Intune (VID 11298) — the latter certified against PP_MDM_V4.0 plus the MDM Agent PP-Module, which is an enrollment-based evaluation. C3 No protection profile exists anywhere in the NIAP catalog for "mobile application management" as its own category — the Application Software PP and the MDM PP are separate, complementary profiles, and MAM sits in neither. C4 Company Portal's certification does not extend to MAM-without-enrollment mode, whereas DISA's BYOAD STIG explicitly mandates native iOS managed/unmanaged application technology as the sole certified separation mechanism. C18 By current understanding, though not yet independently verified against an Apple or NIAP primary source, native iOS managed-app status is conferred strictly through MDM enrollment, while MAM-without-enrollment appears to operate at the application SDK/wrapping layer rather than through that native framework. C24
NIST SP 800-88 Rev. 2's sanitization decision flow requires Purge-or-Destroy for media at any security categorization the moment it is leaving organizational control — which a personal device always is. C5 MAM's selective wipe "simply removes company app data from an app" on the app's next launch check — a Clear-tier logical delete, not a documented, FIPS-140-validated cryptographic erase with the key-sanitization traceability Section 3.2 requires for Purge-tier credit. C6
Under 32 CFR § 170.19(c)(1), an asset that processes, stores, or transmits CUI is a CUI Asset, assessed against all 110 NIST SP 800-171 controls; an asset that merely connects without itself handling CUI can qualify as the lighter Contractor Risk Managed Asset (CRMA) category. C10 BYOD devices are explicitly given as an example of a CRMA — but only when the device is architected so it does not itself process CUI. C11Because MAM writes CUI into an on-device app container, it is difficult to argue the device isn't processing CUI — pushing it toward full CUI Asset treatment unless isolation is documented rigorously enough to survive assessor challenge. C12 VDI, by contrast, writes nothing to the device and has a much stronger CRMA argument.
OpenInManagement controls are conferred strictly via MDM enrollment; MAM without enrollment (MAM-WE) operates strictly at the application SDK/binary wrapping layer and cannot register native managed-app status with the OS. SITE ANALYSIS — not yet verified against an Apple or NIAP primary source; see the ledger status for this row.This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]