BYODPolicy.org
Primary sources, restated with receipts. No products. No vendor opinions.
Q-000
Flagship
Core BYOD Policy
Last verified 2026-07-07
5 requirement pillars checked
1 permits
4 block or fail
Pillar breakdown ↓

Can MAM be used for CUI on a BYOD device?

Short answer
No. Not without an exception to policy.
Microsoft Intune MAM and Microsoft Defender for Endpoint are not NIAP certified, as of July 7, 2026. DoW policy names MAM as an architecturally approved BYOD option — but policy permission is only one of five requirements that must be satisfied simultaneously. MAM currently fails four of the other five: no NIAP protection profile exists for the MAM category at all; its wipe capability does not meet the sanitization tier required once a device leaves organizational control; it cannot give an organization the device-wide application control DoD's own mobile device policy requires for a device used to access CUI; and it typically pulls the device into the strictest CMMC asset category. Compliance is a conjunction of every applicable requirement — one failure makes the aggregate answer No.

Verify NIAP status directly:  niap-ccevs.org/products (filter: "microsoft", status: Certified) - recheck by 2026-10-07

Why "policy says yes" doesn't end the analysis

Law, regulation, policy, and technical certification are not a hierarchy where one tier overrides the others. They are independent conditions that all apply at once. A permissive statement at one tier (here, DoW policy) does not excuse an unmet requirement at another tier (NIAP, NIST, statute, or CMMC scoping). Compliance is the AND of every applicable requirement, not the position of the single most authoritative source.

The five-pillar breakdown

Every applicable requirement, checked independently
PillarRequirementMAM statusVerdict
1. DoW Policy Oct 24, 2025 DoW CIO memo, Attachment 4, Table 2 — architecture approval for BYOD MAM is explicitly named as an approved architecture alongside VDI YES
2. NIAP Certification DoW posture relies on NIAP-validated product configurations No protection profile exists for "MAM" as a category; Company Portal's cert covers enrollment (MDM) mode only; Defender does not appear on the certified list NO
3. NIST SP 800-88 Rev. 2 Purge-tier sanitization required once media leaves organizational control MAM selective wipe is a Clear-tier app-data-delete action, not a documented Purge-tier cryptographic erase NO
4. Prohibited-Application Control DoD CIO AMD memo (10 Aug 2022) §3.a.(3)iii — EMM must be capable of preventing installation of blocked or prohibited applications and access to non-approved third-party application stores, with detection implemented prior to enrollment and continuously monitored MAM-WE has no visibility into or authority over applications outside its managed container; no capability to prevent installation anywhere on the device NO
5. CMMC (32 CFR 170.19(c)(1)) Lighter Contractor Risk Managed Asset (CRMA) treatment requires the device not process/store CUI MAM does process/store CUI in an on-device container, typically pushing the device to full CUI Asset status — all 110 NIST 800-171 controls CONDITIONAL
Bottom line (CONJUNCTION OF ALL FIVE)
No - deployment requires an Exception to the Policy today

Pillar 1 — Policy permits the architecture

The DoW CIO memorandum of October 24, 2025, Attachment 4, Table 2 ("Authentication From a Personal Mobile Device (BYOD)"), names either a MAM implementation or a VDI as an approved architecture, provided the non-PKI MFA is derived from the user's DoW-approved PKI credential, IT Privileged User Accounts remain blocked, and the Secret Fabric is never reachable from the device. C1 This is true and remains true — it is not overridden by anything below. It is simply not sufficient by itself.
DoD CIO Memorandum, Use of Non-Government Owned Mobile Devices (10 Aug 2022), the governing instrument for Approved Mobile Devices (AMDs), applies directly to this same personal-device-accessing-CUI case. §3.a.(1) requires that access from a personal device be managed by an EMM system, naming MDM, MAM, MCM, or VMI as acceptable types, with containers used to segregate personal and DoD data where applicable. C16§3.a.(2) further requires that the EMM system be NIAP validated and configured per applicable STIGs, which is exactly what Pillars 2 and 4 below test. C17

Pillar 2 — No certified product configuration exists

Microsoft Intune MAM and Microsoft Defender for Endpoint are not NIAP certified, as of July 7, 2026. C2 The NIAP Product Compliant List, filtered to Microsoft and Certified status, returns exactly two results: Windows 11/Server 2025/Azure Stack HCI, and Microsoft Intune (VID 11298) — the latter certified against PP_MDM_V4.0 plus the MDM Agent PP-Module, which is an enrollment-based evaluation. C3 No protection profile exists anywhere in the NIAP catalog for "mobile application management" as its own category — the Application Software PP and the MDM PP are separate, complementary profiles, and MAM sits in neither. C4 Company Portal's certification does not extend to MAM-without-enrollment mode, whereas DISA's BYOAD STIG explicitly mandates native iOS managed/unmanaged application technology as the sole certified separation mechanism. C18 By current understanding, though not yet independently verified against an Apple or NIAP primary source, native iOS managed-app status is conferred strictly through MDM enrollment, while MAM-without-enrollment appears to operate at the application SDK/wrapping layer rather than through that native framework. C24

Pillar 3 — Sanitization tier mismatch

NIST SP 800-88 Rev. 2's sanitization decision flow requires Purge-or-Destroy for media at any security categorization the moment it is leaving organizational control — which a personal device always is. C5 MAM's selective wipe "simply removes company app data from an app" on the app's next launch check — a Clear-tier logical delete, not a documented, FIPS-140-validated cryptographic erase with the key-sanitization traceability Section 3.2 requires for Purge-tier credit. C6

Pillar 4 — Prohibited-application control capability

Architecture requirement from DoD's own mobile device policy — independent of any single app's ownership status
The DoD CIO memorandum, Use of Non-Government Owned Mobile Devices (10 Aug 2022), §3.a.(3)iii, requires that the EMM system managing a personal device be capable of preventing installation of blocked or prohibited applications and access to non-approved third-party application stores by or within the DoD-managed segment — with that detection capability implemented prior to enrollment and continuously monitored thereafter. C15 The technical problem: MAM without enrollment (MAM-WE) has no mechanism to enforce this. It has no visibility into, or authority over, applications outside its own managed container, and no capability to prevent installation anywhere else on the device. C9 Only full-device enrollment (MDM) gives an organization that architecture-level authority — a MAM-only deployment cannot demonstrate the capability the memo requires, regardless of which applications happen to be named as prohibited at any given moment. See Which applications are currently prohibited on federal and DoW devices? for the current app-specific status. That list changes independently of this capability requirement.

Pillar 5 — CMMC scoping consequence

Under 32 CFR § 170.19(c)(1), an asset that processes, stores, or transmits CUI is a CUI Asset, assessed against all 110 NIST SP 800-171 controls; an asset that merely connects without itself handling CUI can qualify as the lighter Contractor Risk Managed Asset (CRMA) category. C10 BYOD devices are explicitly given as an example of a CRMA — but only when the device is architected so it does not itself process CUI. C11Because MAM writes CUI into an on-device app container, it is difficult to argue the device isn't processing CUI — pushing it toward full CUI Asset treatment unless isolation is documented rigorously enough to survive assessor challenge. C12 VDI, by contrast, writes nothing to the device and has a much stronger CRMA argument.

What would resolve this

Evidence chain

  1. [C1] DoW CIO Memorandum, "Multi-Factor Authentication (MFA) for Unclassified & Secret DoW Networks," Oct 24, 2025 (cleared for open publication Dec 1, 2025), Attachment 4, Table 2, "Authentication From a Personal Mobile Device (BYOD)."
  2. [C2] NIAP Product Compliant List, niap-ccevs.org/products, filtered to Vendor "microsoft" + Status "Certified" — verified by direct screenshot, July 7, 2026: exactly two results (Windows 11/Server/Azure Stack HCI; Microsoft Intune VID 11298). No Defender entry present.
  3. [C3] Microsoft Common Criteria Security Target, VID 11298 (commoncriteriaportal.org), defining the TOE as a mobile device management system conformant to PP_MDM_V4.0 and the MDM Agent PP-Module; enrolled devices are issued an X.509 certificate.
  4. [C4] NIAP Protection Profile for Application Software (AppPP), which is designed to be combined with, but is distinct from, the Protection Profile for Mobile Device Management V4.0 — no separate MAM-category profile exists in the NIAP catalog.
  5. [C5] NIST SP 800-88 Rev. 2, "Guidelines for Media Sanitization" (Sept. 2025, supersedes withdrawn Rev. 1), Figure 1, Sanitization and Disposition Decision Flow, Sec. 4.3.
  6. [C6] Microsoft Learn, "App Protection Policies Overview": selective wipe for MAM removes company app data from an app; the Intune App SDK checks periodically for a wipe request. NIST SP 800-88 Rev. 2, Sec. 3.1.1 (Clear) vs. Sec. 3.2 (Purge via Cryptographic Erase, requiring FIPS-140 validation and documented key sanitization).
  7. [C7] Federal Register, 88 FR 36430 (June 2, 2023), "Federal Acquisition Regulation: Prohibition on a ByteDance Covered Application"; FAR 52.204-27(b). Historical basis for the pre-OLC Pillar 4; see C13/C14 for the current predicate.
  8. [C8] Consolidated Appropriations Act, 2023 (Pub. L. 117-328), Div. R, § 102; OMB Memorandum M-23-13 (Feb. 27, 2023), Section IV.B (statutory exception categories: national security, law enforcement, security research). Historical basis for the pre-OLC Pillar 4; see C13/C14 for the current predicate.
  9. [C9] Microsoft Learn, device restriction policy documentation (iOS/iPadOS Blocked App Bundle IDs; Android Enterprise work-profile app restrictions) vs. Intune App Protection Policies Overview (MAM has no visibility into apps outside its managed container).
  10. [C10] 32 CFR § 170.19(c)(1); DoW CMMC Scoping Guide – Level 2.
  11. [C11] DoW CMMC Scoping Guide – Level 2, Table 2 examples of Contractor Risk Managed Assets, including BYOD devices.
  12. [C12] Inference from C10/C11 combined with MAM's on-device data handling (C6); not a direct statement in the Scoping Guide. Verification path: a specific SSP/CRM determination is assessor- and documentation-dependent.
  13. [C13] 50 Op. O.L.C. __ (July 16, 2026), Application of the No TikTok on Government Devices Act to the TikTok USDS Joint Venture (T. Elliot Gaiser, AAG), slip op. at 1, 11: the Act reaches only applications developed or provided by entities in which ByteDance Limited has a controlling ownership stake; TikTok USDS Joint Venture (ByteDance retains 19.9%) falls outside it.
  14. [C14] Same slip opinion, passim: the opinion does not address FAR 52.204-27, contractors, BYOD, personally owned devices, state law, or DoD-specific policy. The FAR clause remains in the FAR and in existing contracts, unamended.
  15. [C15] DoD CIO Memorandum, "Use of Non-Government Owned Mobile Devices," 10 Aug 2022, §3.a.(3)iii: the EMM system must be capable of collecting AMD logs, preventing installation of blocked or prohibited applications or access to non-approved third-party application stores by or within the DoD-managed segment, and detecting jailbreak/root or an outdated/unsupported OS — implemented prior to enrollment and continuously monitored.
  16. [C16] Same memo, §3.a.(1): access from a personal device must be managed by an EMM system; MDM, MAM, MCM, or VMI are named as acceptable types, with containers used to segregate personal and DoD data where applicable.
  17. [C17] Same memo, §3.a.(2): the EMM system must be NIAP validated and configured per applicable STIGs.
  18. [C18] DISA Apple iOS/iPadOS 16 BYOAD Security Technical Implementation Guide (STIG), § SRG-APP-000033-MDF-000005 — defining native iOS managed/unmanaged application containerization (enforced via Apple MDM) as the sole NIAP-certified data separation technology permitted for iOS BYOAD.
  19. [C19] DISA Google Android 13/14/15 Security Technical Implementation Guides (STIGs) — scoped to COPE and COBO use cases only; expressly exclude the BYOAD use case.
  20. [C20] Common Criteria Evaluation and Validation Scheme Validation Report, CCEVS-VR-VID11298-2024 (31 Dec 2024): Target of Evaluation is Microsoft Intune (2411) plus Microsoft Company Portal App (Android) v5.0.6375.0; iOS agents were evaluated under Apple's own iOS evaluations, not this Validation Report.
  21. [C21] Same Validation Report, Validator Comments: Intune server-side updates are not under tenant administrator control; validators recommended additional penetration testing for cloud attack vectors the MDM Protection Profile's requirements don't reach.
  22. [C22] MaineIT Cybersecurity Directive 2023-01 (1 Feb 2023); Public Law 2023 ch. 681; OIT Cybersecurity Directive 2024-02 — covered technologies may not be downloaded on "state-issued or personal (BYOD) devices connected to state systems."
  23. [C23] Governor Abbott directive (7 Dec 2022); Texas statewide model security plan (6 Feb 2023), § 3.3; Tex. Gov't Code ch. 620 (SB 1893) — personnel may not install or operate prohibited applications or technologies on any personal device used to conduct state business.
  24. [C24] Apple Device Management Protocol Specifications & Microsoft Learn ("Intune App Protection Policies Overview") — native iOS managed-app status and OS OpenInManagement controls are conferred strictly via MDM enrollment; MAM without enrollment (MAM-WE) operates strictly at the application SDK/binary wrapping layer and cannot register native managed-app status with the OS. SITE ANALYSIS — not yet verified against an Apple or NIAP primary source; see the ledger status for this row.

How to verify this yourself

Provenance ledger

Every claim on this page, its source, verification status, and what would falsify it
IDClaimSourceStatusLast verifiedFalsifiable if…
C1MAM/VDI named as approved BYOD architecturesDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07The Oct 2025 DoW CIO memo (or successor) is rescinded, or Attachment 4 Table 2 drops MAM/VDI as approved architectures
C2Intune MAM & Defender not on Certified listLive NIAP PCL (screenshot-confirmed)VERIFY LIVE2026-07-07Microsoft obtains NIAP certification for Intune MAM or Defender for Endpoint
C3Intune cert scoped to enrollment (MDM) TOESecurity Target, VID 11298VERIFIED2026-07-07The VID 11298 Security Target is revised to cover an unenrolled, MAM-only TOE
C4No dedicated MAM protection profile existsNIAP AppPP vs. MDM PPVERIFIED2026-07-07NIAP publishes a dedicated Mobile Application Management protection profile
C5Purge required once media leaves org controlNIST SP 800-88 Rev. 2, Fig. 1VERIFIED2026-07-07NIST supersedes SP 800-88 Rev. 2 with different sanitization-tier requirements for media leaving organizational control
C6MAM wipe is Clear-tier, not Purge-tierMS Learn + NIST 800-88r2 Sec. 3.1/3.2VERIFIED2026-07-07Microsoft's MAM selective wipe is upgraded to a documented, FIPS-140-validated cryptographic erase meeting Purge-tier requirements
C7No TikTok Act applies to BYOD devices used in contract performance88 FR 36430; FAR 52.204-27(b)SUPERSEDED IN RELEVANT PART2026-07-29FAR 52.204-27 is amended or rescinded, or agency guidance narrows its BYOD reach — see C13/C14
C8Statutory exceptions only; not policy-waivablePub. L. 117-328; OMB M-23-13SUPERSEDED IN RELEVANT PART2026-07-29A statutory or OMB amendment adds a policy-level waiver beyond the named exceptions — see C13/C14
C9Only full MDM enrollment blocks app installation device-wideMS Learn device restriction docsVERIFIED2026-07-07A MAM vendor ships app-protection-without-enrollment policies with device-wide install-blocking authority
C10CUI Asset vs. CRMA scoping mechanism32 CFR § 170.19(c)(1)VERIFIED2026-07-0732 CFR 170.19(c)(1) is amended to change the CUI Asset / CRMA distinction
C11BYOD given as CRMA exampleDoW CMMC Scoping Guide L2VERIFIED2026-07-07The DoW CMMC Scoping Guide is revised to remove BYOD as a CRMA example
C12MAM likely pushes device to full CUI Asset statusSite analysis — combines C10/C11/C6VERIFY LIVEA specific SSP/CRM determination documents that MAM containerization isolates CUI enough to avoid full CUI Asset status
C13Act reaches only entities in which ByteDance has a controlling stake; TikTok USDS outside50 Op. O.L.C. __ (16 Jul 2026)VERIFIED2026-07-29OLC withdraws or is superseded by a later opinion, or ByteDance's TikTok USDS stake rises to a controlling level
C14OLC did not construe FAR 52.204-27; clause remains in FAR and in existing contractsSlip op., passim; FAR 52.204-27VERIFIED2026-07-29The FAR Council amends 52.204-27, or an agency issues guidance construing "covered application" consistent with OLC's holding
C15EMM must be able to prevent installation of prohibited apps / non-approved app storesAMD memo §3.a.(3)iiiVERIFIED2026-07-29The AMD memo §3.a.(3)iii is rescinded or superseded by a memo dropping the app-blocking requirement
C16AMD memo names MDM, MAM, MCM, or VMI as acceptable EMM typesSame, §3.a.(1)VERIFIED2026-07-29A superseding memo narrows or changes the acceptable EMM types
C17EMM must be NIAP validated and STIG-configuredSame, §3.a.(2)VERIFIED2026-07-29§3.a.(2) is amended to drop either the NIAP-validation or STIG-configuration requirement
C18Only NIAP-certified iOS data separation technology is native managed/unmanaged app technologyApple iOS/iPadOS 16 BYOAD STIGVERIFIED2026-07-29NIAP certifies an additional iOS data-separation technology, or a newer iOS BYOAD STIG names a different mechanism
C19Google Android STIGs exclude the BYOAD use caseGoogle Android 13/14/15 STIGsVERIFIED2026-07-29DISA publishes a Google Android BYOAD STIG
C20Intune TOE is Intune 2411 + Company Portal (Android); iOS agents evaluated under Apple's own evaluationsCCEVS-VR-VID11298-2024VERIFIED2026-07-29A superseding Validation Report changes evaluation scope for the iOS agent
C21Intune server updates not under tenant administrator controlSame, Validator CommentsVERIFIED2026-07-29Microsoft changes the update model to give tenant admins control, per new documentation
C22Maine directive reaches personal BYOD connected to state systemsMaineIT Cybersecurity Directive 2023-01VERIFIED2026-07-29Maine rescinds Directive 2023-01 / ch. 681, or narrows scope to state-owned devices only
C23Texas prohibited-technologies regime reaches personal devices used for state businessAbbott directive 7 Dec 2022 + DIR model policyVERIFIED2026-07-29Texas rescinds the Abbott directive or the DIR model policy's personal-device clause
C24iOS managed-app status is conferred via MDM; MAM-WE operates at SDK layerSITE ANALYSIS — UNVERIFIEDApple or NIAP primary documentation confirms or refutes whether an app-protection policy without MDM enrollment confers native managed-app status

Related entries

CHANGELOG · 2026-07-30 — Pillar 4 reframed; predicate correction.Pillar 4 previously rested on the No TikTok on Government Devices Act as applied through FAR 52.204-27. DOJ OLC concluded (advice 10 Mar 2026; opinion 16 Jul 2026) that the Act reaches only applications developed or provided by entities in which ByteDance holds a controlling ownership stake, and that TikTok USDS falls outside it. The predicate for the pillar as written no longer held. OLC did not construe FAR 52.204-27, which remains in the FAR and in existing contracts — the pillar is therefore recorded as predicate undermined, not false. Pillar 4 is replaced with an app-agnostic capability requirement drawn from the DoD CIO memo "Use of Non-Government Owned Mobile Devices" (10 Aug 2022) §3.a.(3)iii. The bottom-line answer is unchanged — Pillars 2, 3 and 5 are independent of this predicate. Process note: this correction was missed by a recheck performed 27 Jul 2026, four months after the operative advice.

This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]