BYODPolicy.org
Primary sources, restated with receipts. No products. No vendor opinions.
Q-001
Core BYOD Policy
Last verified 2026-07-07
7 claims on this page
6 verified against primary source
1 requires live verification
Provenance ledger ↓

Can Microsoft MAM be used on a DoW network?

Short answer
Yes, conditionally. The DoW CIO memorandum of October 24, 2025 names Mobile Application Management as one of two approved architectures — alongside Virtual Desktop Interface — for personal devices (BYOD) accessing DoW environments or data. The user's non-PKI MFA must be derived from their DoW-approved PKI credential. IT Privileged User Accounts are blocked from BYOD access entirely, regardless of MAM or VDI. Personal devices may never reach the DoW Secret Fabric or any classified network under this use case.

The nuance the short answer hides

"MAM is approved" is true, but it's not a blank approval of any Microsoft MAM configuration — it's approval of a specific use case with specific conditions attached, and the policy is explicit that those conditions are what make it acceptable. The use case description in the memo covers "users authenticating with DoW approved non-PKI MFAs to DoW environments or data via personal mobile device, using either a Mobile Application Management (MAM) implementation or a Virtual Desktop Interface (VDI)." C1 The MFA itself isn't a standalone credential — it must be derived from the user's existing DoW-approved PKI (e.g., their CAC), enrolled through the PKI-based identity-proofing process described in Attachment 3. C2

Two restrictions apply regardless of which architecture (MAM or VDI) is used. First, access to IT Privileged User Accounts is blocked from a BYOD device under this use case, whether the device is using MAM or VDI. C3 Second, personal devices and BYOD may not be used to access the DoW Secret Fabric or any other classified network or system — this is categorical, with no exception carved out for MAM. C4

On data handling: the policy directs that where technologically feasible, DoW-related activity should be isolated from the rest of the personal device (e.g., via a sandbox or VM), and that DoW-managed applications on the device should be managed and isolated from the rest of the device to the extent possible. C5  For Microsoft 365 specifically, the memo states users may access M365 applications and services hosting data up to and including CUI, regardless of whether the overall cloud impact level of the hosting environment is IL2, IL4, or IL5. C6 The memo does not spell out, at the level of a specific product configuration, exactly which Intune MAM mode (enrolled vs. unenrolled / "MAM-WE") satisfies the isolation and management requirements described — that determination sits with the Authorizing Official reviewing the specific implementation. C7

What's actually required, at a glance

Conditions attached to the DoW BYOD (personal device) use case
RequirementWhat the policy says
ArchitectureMAM implementation or VDI — either is named as approved.
CredentialNon-PKI MFA derived from the user's DoW-approved PKI credential.
Device management guidanceMust comply with named DoW guidance on non-government-owned devices and unclassified mobile applications (see Evidence Chain, C5).
Privileged accountsBlocked entirely from BYOD access — MAM or VDI makes no difference.
Classified networksNever permitted. Personal devices cannot reach the Secret Fabric under this use case.
Data residencyIsolate DoW activity from the rest of the personal device where feasible; prevent server-side storage of passkeys and biometric data.
M365 access ceilingUp to and including CUI, regardless of the M365 environment's cloud impact level.

Evidence chain

How to verify this yourself

Context

For background on why DoW moved toward this MAM/VDI framing, see independent commentary from the Center for Strategic and International Studies on the U.S. Army's BYOD pilot (Nov 2022), which argued years before this memo that BYOD should mean secure access without government data stored on the personal device — the architectural principle the October 2025 memo subsequently codified as policy. That commentary predates this memo and does not reflect its specific requirements; read it as historical context, not current policy.

Provenance ledger

Every claim on this page, its source, and its verification status
IDClaimPrimary sourceStatusLast verified
C1MAM or VDI named as approved BYOD architecturesDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C2Non-PKI MFA must be derived from DoW-approved PKIDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C3IT Privileged User Accounts blocked, MAM or VDIDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C4Personal devices never access Secret FabricDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C5Isolation guidance; referenced device-management memosDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C6M365 access up to CUI regardless of ILDoW CIO memo, Att. 4, Tbl. 2VERIFIED2026-07-07
C7Specific MAM mode vs. isolation requirementAO-level determination; not stated in memoVERIFY LIVE

Related entries

CHANGELOG · 2026-07-07 — Entry created; C1–C6 verified against the DoW CIO memo of Oct 24, 2025; C7 marked for live/case-specific verification.

This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]