Intune

Intune App Protection in Edge for Business on Windows

3分钟阅读

摘要

Microsoft announced public preview support for Intune App Protection Policies in Edge for Business work profiles on Windows, allowing organizations to protect corporate data in the browser even on PCs already managed by another tenant. This matters because it gives contractors and partner users secure access to business apps without requiring full device enrollment, while enforcing controls like download redirection, copy/paste restrictions, and clearer Entra-based onboarding.

需要Intune方面的帮助?咨询专家

Introduction: why this matters

For many organizations, the browser has become the primary workspace for SaaS apps, internal portals, and AI tools. But when contractors use Windows PCs that are already enrolled in another organization’s tenant, traditional “manage the whole device” approaches don’t work—creating data protection blind spots. Microsoft’s latest updates shift protection from the device to the work context in the browser, aligning Edge for Business, Entra, Intune, and Purview.

What’s new

1) Intune APP support for Edge for Business work profiles on agency-managed PCs (Public Preview)

Edge for Business now extends Intune app protection policies to the Edge work profile on Windows devices managed by a different organization.

Key capabilities:

  • Browser-level protection boundary: Apply APP directly to the Edge for Business profile so corporate data is handled within a managed work context.
  • No full device enrollment required: Contractors can access corporate resources without your tenant taking device ownership or conflicting with the home agency’s management.
  • Tenant-scoped controls in the browser: Options include redirecting downloads to OneDrive for Business, restricting copy/paste, and enforcing data boundaries within the managed Edge profile.

2) Simplified onboarding via updated Entra sign-in flow in Edge on Windows

Microsoft Entra improvements modernize the registration experience and reduce unintended enrollment scenarios.

Highlights:

  • Clearer registration guidance: Users get better prompts distinguishing account registration from device enrollment.
  • Prevent accidental MDM enrollment: Admins can enable “Disable MDM enrollment when adding work or school account” to block device-enrollment prompts and route users into the APP-based approach instead.

3) Inline Microsoft Purview DLP in Edge for Business—without device onboarding

Purview Data Loss Prevention is built into Edge for Business and applies to the user’s work profile, helping protect sensitive data even when the Windows PC is unmanaged by your organization.

Purview DLP in Edge for Business can:

  • Detect/control sensitive actions like uploads, downloads, copy/paste, and printing across browser-based apps.
  • Extend protection to unenrolled cloud apps, helping reduce oversharing during web workflows.
  • Reduce leakage while maintaining productivity (controls focus on risky actions vs. blocking site access).

Impact on IT admins and end users

  • Admins can apply consistent data protection for external/contractor scenarios without negotiating device enrollment or causing cross-tenant management conflicts.
  • Users/contractors get a more predictable sign-in and onboarding experience, with protections confined to the work profile rather than the whole PC.

Action items / next steps

  1. Evaluate the public preview for Intune APP in Edge for Business work profiles on agency-managed Windows PCs and identify contractor use cases (high-risk web apps, data types, and workflows).
  2. In Entra, review and consider enabling Disable MDM enrollment when adding work or school account to reduce accidental device enrollment prompts.
  3. Pilot Purview DLP in Edge for Business for key browser actions (download/upload/copy/print) and validate policy behavior across both managed and unmanaged cloud apps.
  4. Use Microsoft’s deployment guidance (“Secure Your Corporate Data in Intune with Microsoft Edge for Business”) to map controls to your target tier (Basic/Enhanced/High) and avoid overlapping/conflicting policies.

需要Intune方面的帮助?

我们的专家可以帮助您实施和优化Microsoft解决方案。

咨询专家

获取微软技术最新资讯

Microsoft Edge for BusinessIntune APPMicrosoft EntraMicrosoft Purview DLPcontractor access

相关文章

Intune

Microsoft Intune App Security for AI Workflows

Microsoft is expanding Intune’s app security capabilities with enhanced app inventory in May and Enterprise Application Management auto-updates in July, giving IT teams better visibility into managed and user-installed Windows apps and faster deployment of software updates. These changes matter because they help organizations spot risky or unauthorized apps sooner, reduce version drift, and lower exposure to vulnerabilities as AI-driven workflows increasingly depend on secure endpoint applications.

Intune

Microsoft Intune for MSPs Adds 3 Multi-Tenant Partners

Microsoft has added three new validated multi-tenant partners to its Intune for MSPs ecosystem—AvePoint Confidence Platform: Elements Edition, CyberDrain CIPP, and SoftwareCentral Tenant Manager—expanding tools for centralized automation, governance, security visibility, and policy standardization across customer tenants. This matters because it gives managed service providers more Microsoft-aligned options to reduce manual work, replace custom scripts, and manage multi-tenant environments more securely and efficiently.

Intune

Microsoft Intune February Update: Multi-Admin Approval & Apple DDM

Microsoft’s February Intune update adds multi-admin approval for device configuration and compliance policies, requiring a second admin to approve critical changes before they take effect. The release also improves Advanced Analytics device query results and expands Apple Declarative Device Management support, helping organizations strengthen change control, reduce configuration risk, and manage Apple devices more precisely at scale.

Intune

Intune 2026年1月更新:Win32脚本安装与EPM提权

Intune 2026 年 1 月更新聚焦企业终端管理中的高频痛点:新增 Win32 应用 PowerShell 脚本安装支持、EPM 提权可保留当前用户上下文并支持 scope tags,同时 Admin tasks 正式发布,集中管理提权审批、安全任务与下线流程。此次更新的重要性在于,它一方面降低了应用部署与更新成本、提升自动化和可审计性,另一方面也增强了合规隔离与终端用户体验,并在 Apple 设备注册中通过 ACME 证书和更多 Setup Assistant 控制进一步提升安全与管控能力。

Intune

Intune Admin Tasks GA:统一处理 EPM、Defender 与多管理员审批

Microsoft 宣布 Intune Admin Tasks 正式 GA,将 EPM 提权请求、Defender 安全修复任务和多管理员审批(MAA)整合进 Intune 管理中心中的统一优先级队列,管理员可在同一处完成审批、修复与审计追踪。此更新的重要性在于它能缩短高风险操作的响应时间、强化合规与 Zero Trust 治理,并结合 Security Copilot 与公开预览的 Device Offboarding Agent,为 AI 辅助安全运营提供更集中的监督与执行入口。

Intune

Microsoft Intune Technical Takeoff 2026:3月每周一直播与AMA

Microsoft 宣布 Intune Technical Takeoff 2026 将于 3 月每周一在 Tech Community 直播,围绕 Zero Trust、安全、部署迁移、跨平台管理、自动化 AI、应用与报表等主题展开,并提供 AMA、Live Q&A、提前提问及字幕与录播支持。此活动的重要性在于管理员可直接从工程团队获得实操指导、验证产品方向,并更高效应对现代端点管理、安全与云化管理日益复杂的挑战。