Q-001
Core BYOD Policy
Last verified 2026-07-07
7 claims on this page
6 verified against primary source
1 requires live verification
Provenance ledger ↓
Can Microsoft MAM be used on a DoW network?
Short answer
Yes, conditionally. The DoW CIO memorandum of October 24, 2025 names Mobile Application Management as one of two approved architectures — alongside Virtual Desktop Interface — for personal devices (BYOD) accessing DoW environments or data. The user's non-PKI MFA must be derived from their DoW-approved PKI credential. IT Privileged User Accounts are blocked from BYOD access entirely, regardless of MAM or VDI. Personal devices may never reach the DoW Secret Fabric or any classified network under this use case.
The nuance the short answer hides
"MAM is approved" is true, but it's not a blank approval of any Microsoft MAM configuration — it's approval of a specific use case with specific conditions attached, and the policy is explicit that those conditions are what make it acceptable. The use case description in the memo covers "users authenticating with DoW approved non-PKI MFAs to DoW environments or data via personal mobile device, using either a Mobile Application Management (MAM) implementation or a Virtual Desktop Interface (VDI)." C1 The MFA itself isn't a standalone credential — it must be derived from the user's existing DoW-approved PKI (e.g., their CAC), enrolled through the PKI-based identity-proofing process described in Attachment 3. C2
Two restrictions apply regardless of which architecture (MAM or VDI) is used. First, access to IT Privileged User Accounts is blocked from a BYOD device under this use case, whether the device is using MAM or VDI. C3 Second, personal devices and BYOD may not be used to access the DoW Secret Fabric or any other classified network or system — this is categorical, with no exception carved out for MAM. C4
On data handling: the policy directs that where technologically feasible, DoW-related activity should be isolated from the rest of the personal device (e.g., via a sandbox or VM), and that DoW-managed applications on the device should be managed and isolated from the rest of the device to the extent possible. C5 For Microsoft 365 specifically, the memo states users may access M365 applications and services hosting data up to and including CUI, regardless of whether the overall cloud impact level of the hosting environment is IL2, IL4, or IL5. C6 The memo does not spell out, at the level of a specific product configuration, exactly which Intune MAM mode (enrolled vs. unenrolled / "MAM-WE") satisfies the isolation and management requirements described — that determination sits with the Authorizing Official reviewing the specific implementation. C7
What's actually required, at a glance
Conditions attached to the DoW BYOD (personal device) use case
| Requirement | What the policy says |
| Architecture | MAM implementation or VDI — either is named as approved. |
| Credential | Non-PKI MFA derived from the user's DoW-approved PKI credential. |
| Device management guidance | Must comply with named DoW guidance on non-government-owned devices and unclassified mobile applications (see Evidence Chain, C5). |
| Privileged accounts | Blocked entirely from BYOD access — MAM or VDI makes no difference. |
| Classified networks | Never permitted. Personal devices cannot reach the Secret Fabric under this use case. |
| Data residency | Isolate DoW activity from the rest of the personal device where feasible; prevent server-side storage of passkeys and biometric data. |
| M365 access ceiling | Up to and including CUI, regardless of the M365 environment's cloud impact level. |
Evidence chain
- [C1] The use case "Authentication From a Personal Mobile Device (i.e., Bring Your Own Device (BYOD))" is described as covering users authenticating with DoW-approved non-PKI MFAs to DoW environments or data via personal mobile device, using either a MAM implementation or a VDI. Source: DoW CIO Memorandum, "Multi-Factor Authentication (MFA) for Unclassified & Secret DoW Networks," Oct 24, 2025 (cleared for open publication Dec 1, 2025), Attachment 4, Table 2.
- [C2] The non-PKI MFA used must be derived from the user's DoW-approved PKI, in accordance with the "Identity-proofing for Users Who Have a DoW-approved PKI Credential" section of Attachment 3. Source: same memo, Attachment 4, Table 2, "Authentication From a Personal Mobile Device" row, Credential Lifecycle column.
- [C3] User access must be blocked to IT Privileged User Accounts, regardless of whether the device is using a MAM or VDI. Source: same memo, Attachment 4, Table 2, Access Management column.
- [C4] Personal devices/BYOAD may not be used to access the DoW Secret Fabric or any other classified networks or systems. Source: same memo, Attachment 4, Table 2, final Access Management provision.
- [C5] If technologically feasible, a VM or sandbox should isolate DoW-related activity from the rest of the personal device; DoW applications on the device should be managed and isolated to the extent possible. Device management must also comply with named DoW guidance including "Use of Non-Government Owned Mobile Devices" (Aug 10, 2022) and "Use of Unclassified Mobile Applications in Department of Defense" (Oct 6, 2023). Source: same memo, Attachment 4, Table 2, Device Management and Access Management columns.
- [C6] Users may access M365 applications and services hosting data up to and including CUI regardless of whether the overall cloud impact level of the M365 environment is IL2, IL4, or IL5. Source: same memo, Attachment 4, Table 2, Access Management column.
- [C7] Which specific Intune MAM configuration (enrolled MAM vs. MAM-without-enrollment) satisfies the isolation/management language in C5 is an Authorizing-Official-level determination on the specific implementation, not a fact stated in the memo itself. Verification path: read the AO's system-specific authorization package, or see Q-011 for the related certification-boundary question.
How to verify this yourself
- Read Attachment 4, Table 2 directly. The BYOD use case is short, about half a page, and is the single most load-bearing table for this question.
- Check the referenced device-management memos. "Use of Non-Government Owned Mobile Devices" (Aug 10, 2022) and "Use of Unclassified Mobile Applications in DoW" (Oct 6, 2023) carry the detailed device-management rules the BYOD use case incorporates by reference.
- Confirm no newer memo has superseded this one. Attachments 2 and 4 of the October 2025 memo are explicitly designated living documents, updated at the DoW ICAM community site referenced in the memo.
Context
For background on why DoW moved toward this MAM/VDI framing, see independent commentary from the Center for Strategic and International Studies on the U.S. Army's BYOD pilot (Nov 2022), which argued years before this memo that BYOD should mean secure access without government data stored on the personal device — the architectural principle the October 2025 memo subsequently codified as policy. That commentary predates this memo and does not reflect its specific requirements; read it as historical context, not current policy.
Provenance ledger
Every claim on this page, its source, and its verification status
| ID | Claim | Primary source | Status | Last verified |
| C1 | MAM or VDI named as approved BYOD architectures | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C2 | Non-PKI MFA must be derived from DoW-approved PKI | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C3 | IT Privileged User Accounts blocked, MAM or VDI | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C4 | Personal devices never access Secret Fabric | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C5 | Isolation guidance; referenced device-management memos | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C6 | M365 access up to CUI regardless of IL | DoW CIO memo, Att. 4, Tbl. 2 | VERIFIED | 2026-07-07 |
| C7 | Specific MAM mode vs. isolation requirement | AO-level determination; not stated in memo | VERIFY LIVE | — |
Related entries
CHANGELOG · 2026-07-07 — Entry created; C1–C6 verified against the DoW CIO memo of Oct 24, 2025; C7 marked for live/case-specific verification.
This entry restates primary sources and asserts nothing beyond them. It is not legal or compliance advice; authorizing decisions rest with the cognizant Authorizing Official. Corrections: [email protected]