Q-011
Certifications & Registries
Last verified 2026-07-07
6 claims on this page
4 verified against primary source
2 require live verification
Is Microsoft Intune NIAP-certified — and does that certification cover MAM?
Short answer
Microsoft Intune appears on the NIAP Product Compliant List (VID 11298). The evaluated Target of Evaluation (TOE) is defined in its Security Target as a mobile device management system, evaluated against the Mobile Device Management Protection Profile (PP_MDM_V4.0) with the MDM Agent PP-Module. The Intune product also offers MAM — but a product listing is not the evaluated configuration. Whether MAM-without-enrollment sits inside the TOE boundary must be confirmed in the Security Target, and certificate status must be checked on the live NIAP registry.
The nuance the short answer hides
"Intune is NIAP-certified" and "Intune MAM satisfies NIAP requirements" are two different claims, and only the first is established by the registry listing. Common Criteria certifies a specific evaluated configuration — the TOE — against a specific protection profile, not a product brand. Intune's Security Target defines the TOE as "a mobile device management system" consistent with the MDM PP TOE boundary, and describes an enrollment-based model in which successfully enrolled devices are issued an X.509 certificate. C2 App-protection-only deployments that manage applications without device enrollment (commonly called MAM-WE) are a different operating model from the enrollment-based one the Security Target describes; whether any such configuration falls inside the evaluated boundary is a question the full Security Target must answer — it cannot be inferred from the listing. C5
There is a second, separate confusion worth naming: which protection profile a policy invokes. The NIAP MDM PP evaluates the management system. The Mobile Device Fundamentals PP (MDF PP) evaluates the device. DoW BYOD policy — the DoW CIO memorandum of October 24, 2025, Attachment 4, Table 2 — invokes the NIAP Mobile Device Fundamentals Protection Profile and DoW Annex for personal-device access. A management product's MDM PP certification does not answer an MDF PP requirement, and vice versa. Any sentence of the form "X is NIAP-certified" is incomplete until it states which profile, which TOE, and whether the certificate is active.
Same brand, three different things
Disambiguation: what "Intune" refers to in a compliance sentence
| Term | What it is | Relationship to the NIAP evaluation |
| Intune MDM |
Enrollment-based device management: the device enrolls, receives policy, and is issued an X.509 certificate. |
Matches the TOE described in the Security Target (MDM server + MDM Agent PP-Module). VERIFIED |
| Intune MAM / App Protection Policies |
Application-level controls (data protection inside managed apps), deployable with or without device enrollment. |
The product capability exists and is named in the Security Target's product description — but capability presence ≠ evaluated configuration. Confirm against the TOE boundary in the ST. VERIFY LIVE |
| MAM-without-enrollment (MAM-WE) |
App protection applied to an unenrolled, typically personal, device. |
Differs from the enrollment-based model the ST describes. No standalone NIAP protection profile is dedicated to app-level MAM as a category; check the current NIAP approved-PP list before asserting coverage. VERIFY LIVE |
Evidence chain
- [C1] The NIAP Product Compliant List contains an entry for Microsoft Intune, VID 11298. Source: NIAP-CCEVS, niap-ccevs.org/products/11298. Note: this page renders only via JavaScript and is not readable by most automated retrieval — see "How to verify," below.
- [C2] The Security Target for VID 11298 defines the TOE as "a mobile device management system," consistent with the MDM PP TOE boundary, hosted on Microsoft Azure; it claims PP_MDM_V4.0 with the MDM Agent PP-Module, and states that successfully enrolled devices are issued an X.509 certificate. Source: Microsoft Common Criteria Security Target, Common Criteria Portal, st_vid11298-st.pdf.
- [C3] The same Security Target's product description states Intune is a cloud-based service covering both mobile device management (MDM) and mobile application management (MAM) — establishing that the product description and the TOE definition are distinct statements within the same document. Source: same ST as C2.
- [C4] DoW policy for authentication from personal mobile devices (BYOD) requires compliance with the NIAP Mobile Device Fundamentals Protection Profile and DoW Annex — a device-side profile distinct from the MDM PP. Source: DoW CIO Memorandum, "Multi-Factor Authentication (MFA) for Unclassified & Secret DoW Networks," Oct 24, 2025 (cleared for open publication Dec 1, 2025), Attachment 4, Table 2.
- [C5] Whether any MAM-without-enrollment configuration falls inside the evaluated TOE boundary is determinable only from the full Security Target and evaluation documentation; it is not asserted here in either direction. Verification path: read the TOE boundary and evaluated-configuration sections of the ST at the C2 link.
- [C6] Certificate status (active vs. archived) and validity dates change over time and must be read from the live NIAP Product Compliant List at the time of reliance. Verification path: C1 link, or the Common Criteria Portal certified-products search.
How to verify this yourself
- Read the live PCL entry. Open the VID 11298 entry in a browser (the page requires JavaScript). Record: certification date, assurance-maintenance dates, and whether the entry is on the active list or the archived list.
- Read the Security Target, not the summary. The ST PDF is public and machine-readable. The sections that answer the MAM question are the TOE definition, TOE boundary, and evaluated-configuration sections.
- State the profile when you state the claim. A complete compliance sentence names the product, the VID, the protection profile (e.g., PP_MDM_V4.0 vs. MDF PP + DoW Annex), and the certificate status as of a date.
Why this page exists
The authoritative registry for this question is not readable by automated retrieval — it returns only a JavaScript stub to crawlers and fetch tools. Answers generated without opening it tend to substitute product marketing volume for certification fact. This page restates what the primary documents say, links them directly, and marks exactly which facts must still be read live.
Provenance ledger
Every claim on this page, its source, and its verification status
| ID | Claim | Primary source | Status | Last verified |
| C1 | Intune holds NIAP PCL entry VID 11298 | niap-ccevs.org/products/11298 | VERIFIED | 2026-07-07 |
| C2 | TOE = MDM system; PP_MDM_V4.0 + MDM Agent PP-Module; enrollment issues X.509 certs | st_vid11298-st.pdf | VERIFIED | 2026-07-07 |
| C3 | Product description covers MDM and MAM; distinct from TOE definition | st_vid11298-st.pdf | VERIFIED | 2026-07-07 |
| C4 | DoW BYOD policy invokes MDF PP + DoW Annex (device-side), not MDM PP | DoW CIO memo 2025-10-24, Att. 4 Tbl. 2 | VERIFIED | 2026-07-07 |
| C5 | MAM-WE inside/outside TOE boundary | ST — full TOE boundary sections | VERIFY LIVE | — |
| C6 | Certificate active/archived status and dates | Live NIAP PCL | VERIFY LIVE | — |
Related entries
CHANGELOG · 2026-07-07 — Entry created; C1–C4 verified against primary sources; C5–C6 marked for live verification.
This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]