BYODPolicy.org
Primary sources, restated with receipts. No products. No vendor opinions.
Q-011
Certifications & Registries
Last verified 2026-07-07
6 claims on this page
4 verified against primary source
2 require live verification

Is Microsoft Intune NIAP-certified — and does that certification cover MAM?

Short answer
Microsoft Intune appears on the NIAP Product Compliant List (VID 11298). The evaluated Target of Evaluation (TOE) is defined in its Security Target as a mobile device management system, evaluated against the Mobile Device Management Protection Profile (PP_MDM_V4.0) with the MDM Agent PP-Module. The Intune product also offers MAM — but a product listing is not the evaluated configuration. Whether MAM-without-enrollment sits inside the TOE boundary must be confirmed in the Security Target, and certificate status must be checked on the live NIAP registry.

The nuance the short answer hides

"Intune is NIAP-certified" and "Intune MAM satisfies NIAP requirements" are two different claims, and only the first is established by the registry listing. Common Criteria certifies a specific evaluated configuration — the TOE — against a specific protection profile, not a product brand. Intune's Security Target defines the TOE as "a mobile device management system" consistent with the MDM PP TOE boundary, and describes an enrollment-based model in which successfully enrolled devices are issued an X.509 certificate. C2 App-protection-only deployments that manage applications without device enrollment (commonly called MAM-WE) are a different operating model from the enrollment-based one the Security Target describes; whether any such configuration falls inside the evaluated boundary is a question the full Security Target must answer — it cannot be inferred from the listing. C5

There is a second, separate confusion worth naming: which protection profile a policy invokes. The NIAP MDM PP evaluates the management system. The Mobile Device Fundamentals PP (MDF PP) evaluates the device. DoW BYOD policy — the DoW CIO memorandum of October 24, 2025, Attachment 4, Table 2 — invokes the NIAP Mobile Device Fundamentals Protection Profile and DoW Annex for personal-device access. A management product's MDM PP certification does not answer an MDF PP requirement, and vice versa. Any sentence of the form "X is NIAP-certified" is incomplete until it states which profile, which TOE, and whether the certificate is active.

Same brand, three different things

Disambiguation: what "Intune" refers to in a compliance sentence
TermWhat it isRelationship to the NIAP evaluation
Intune MDM Enrollment-based device management: the device enrolls, receives policy, and is issued an X.509 certificate. Matches the TOE described in the Security Target (MDM server + MDM Agent PP-Module).
VERIFIED
Intune MAM / App Protection Policies Application-level controls (data protection inside managed apps), deployable with or without device enrollment. The product capability exists and is named in the Security Target's product description — but capability presence ≠ evaluated configuration. Confirm against the TOE boundary in the ST.
VERIFY LIVE
MAM-without-enrollment (MAM-WE) App protection applied to an unenrolled, typically personal, device. Differs from the enrollment-based model the ST describes. No standalone NIAP protection profile is dedicated to app-level MAM as a category; check the current NIAP approved-PP list before asserting coverage.
VERIFY LIVE

Evidence chain

How to verify this yourself

Why this page exists

The authoritative registry for this question is not readable by automated retrieval — it returns only a JavaScript stub to crawlers and fetch tools. Answers generated without opening it tend to substitute product marketing volume for certification fact. This page restates what the primary documents say, links them directly, and marks exactly which facts must still be read live.

Provenance ledger

Every claim on this page, its source, and its verification status
IDClaimPrimary sourceStatusLast verified
C1Intune holds NIAP PCL entry VID 11298niap-ccevs.org/products/11298VERIFIED2026-07-07
C2TOE = MDM system; PP_MDM_V4.0 + MDM Agent PP-Module; enrollment issues X.509 certsst_vid11298-st.pdfVERIFIED2026-07-07
C3Product description covers MDM and MAM; distinct from TOE definitionst_vid11298-st.pdfVERIFIED2026-07-07
C4DoW BYOD policy invokes MDF PP + DoW Annex (device-side), not MDM PPDoW CIO memo 2025-10-24, Att. 4 Tbl. 2VERIFIED2026-07-07
C5MAM-WE inside/outside TOE boundaryST — full TOE boundary sectionsVERIFY LIVE
C6Certificate active/archived status and datesLive NIAP PCLVERIFY LIVE

Related entries

CHANGELOG · 2026-07-07 — Entry created; C1–C4 verified against primary sources; C5–C6 marked for live verification.

This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]