[9.4.1] iOS: MAM-Only vs Full Management – There Is No Middle Ground


The most common iOS management mistake is looking for a middle ground that doesn’t exist. Organizations want some device control without full management, or they want to protect data without requiring full enrollment. Android has a model for this – Work Profile. iOS does not.

On iOS you have two meaningful options: MAM-only, where you protect corporate data within managed applications without enrolling the device, or full supervised management, where the device is corporate-owned, enrolled through Apple Business Manager, and managed at the platform level. Everything in between – enrolling a personal iPhone into MDM, applying a management profile to a personal device, hoping to get “some” device control – produces a configuration that gives you neither the clean data protection of MAM nor the reliable enforcement of supervised management. It creates user friction without meaningful security gain.


MAM-Only

MAM-only on iOS means deploying App Protection Policies to managed applications – Outlook, Teams, Edge, OneDrive, and any other Intune SDK-enabled apps – without enrolling the device. The user installs the apps from the App Store, signs in with their work account, and the MAM policies apply within those apps. The device has no management profile. Intune has no authority over the OS, the device configuration, or anything outside the managed application boundary.

What MAM-only protects: data movement between managed and unmanaged apps, saving to personal storage, copy and paste to personal apps, screenshots within managed apps in some configurations, and the ability to remotely wipe corporate data from managed applications when the user leaves. What it doesn’t protect: the device itself, the OS, hardware features, or any application that isn’t Intune SDK-enabled.

Conditional Access is what connects MAM-only to access enforcement. A CA policy requiring app protection policy for mobile access to Microsoft 365 means users can only access corporate data through MAM-managed applications, even on unenrolled personal devices. That’s the security model – data is contained within managed apps, and CA ensures users can’t route around it by using the browser or unmanaged apps.

MAM-only on iOS isn’t a half-measure. For personal device scenarios, it’s often the right measure – better data protection with less friction and no device ownership implications than MDM enrollment on a personal iPhone.

The user experience with MAM-only is close to normal – the managed apps look and function like their standard counterparts, with some behaviors restricted based on APP configuration. Users who open Outlook on their personal iPhone with MAM policies applied will find that they can’t forward corporate emails to their personal Gmail or save attachments to iCloud. That restriction is working as designed. The phone itself is untouched.


Full Supervised Management

Full supervised management requires the device to be corporate-owned and enrolled through Apple Business Manager using Automated Device Enrollment. Supervision is applied during device setup before the user first logs in. The management profile is non-removable. The device is under organizational authority at the platform level – not just within managed applications.

Supervision unlocks additional configuration capabilities that unsupervised MDM doesn’t provide: Single App Mode for kiosk scenarios, tighter app management, enforced compliance with configuration profiles that can’t be removed by the user, and more reliable policy application. Even supervised, Apple reserves core OS behavior – iOS is more restrictive with administrators than Android is by design. But supervised management is meaningfully more capable than unsupervised.

The “Two Outlooks” framing is the clearest way to explain this to users and decision-makers. On Android with Work Profile, a user has two Outlook apps – one personal, one work – with a clear boundary between them. On iOS with full management, there’s one Outlook, and it’s the work one. If the user wants a personal Outlook experience, they’re using the same app with the same account restrictions. There’s no equivalent to the Android Work Profile separation on iOS – the platform doesn’t support it. For personally owned iPhones, this is why MAM-only is the right model. For corporate-owned iPhones, supervised management with a single managed account is the right model and the tradeoff is explicit – it’s a work device.

Trying to enroll a personal iPhone into full MDM to get “some” device control gives you a management profile the user can remove, limited additional enforcement capability over MAM, and a user who feels their personal phone is being managed. None of that is worth it.

The Decision

Personal iPhone, knowledge worker, data protection is the goal: MAM-only enforced through Conditional Access. Corporate-owned iPhone, user-assigned: Apple Business Manager, Automated Device Enrollment, supervised management. Corporate-owned iPhone, shared or single-purpose: supervised management with Shared Device Mode or Single App Mode depending on the use case.

The decision point is device ownership, not the level of control you want. If you want more control than MAM provides, the answer is corporate ownership and ABM – not MDM enrollment on a personal device. That path produces the worst of both models: user resistance, limited enforcement, and a management relationship that depends on a management profile the user can remove.


Intune Deployment Guide · Phase 9: Mobile and BYOD
‹ Previous: [9.4] iOS Management Reality
Next: [9.4.2] iOS Supervised Mode: What It Unlocks and What It Still Can’t Do