{"id":97,"date":"2025-06-02T07:32:36","date_gmt":"2025-06-02T07:32:36","guid":{"rendered":"https:\/\/prs.me.uk\/?p=97"},"modified":"2025-06-02T08:19:08","modified_gmt":"2025-06-02T08:19:08","slug":"m365-access-controls-unmanaged-windows-and-macos","status":"publish","type":"post","link":"https:\/\/prs.me.uk\/?p=97","title":{"rendered":"M365 Access Controls for Unmanaged Windows and macOS Endpoints"},"content":{"rendered":"\n<p>Yes, I\u2019m deliberately saying \u201cunmanaged\u201d rather than \u201cBYOD.\u201d You might wonder, what\u2019s the difference? In practice, I\u2019ve found that BYOD tends to spark a different kind of conversation.<\/p>\n\n\n\n<p>Paraphrasing slightly: even if your organisation doesn\u2019t officially support, allow, or encourage BYOD there\u2019s a good chance you still have use cases where users, execs, contractors, or third parties etc. need access to Microsoft 365 resources from devices that aren\u2019t company managed.<\/p>\n\n\n\n<p>Whether or not you call that BYOD is beside the point &#8211; the challenge is real.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Why Focus on Desktop-Class Devices?<\/h2>\n\n\n\n<p>For this post, I\u2019m narrowing the scope. Let&#8217;s set aside iOS and Android (mobiles deserve their own discussion) and focus instead on unmanaged desktop-class endpoints. Think Windows, macOS, and yes, even Linux.<\/p>\n\n\n\n<p>These devices won\u2019t be enrolled in Intune or joined to your domain, but access is still being requested from them, and you need to control how that happens.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Are Our Options?<\/h2>\n\n\n\n<p>If we\u2019ve accepted that some level of access from unmanaged endpoints are required, the next step is understanding what Microsoft-native controls or features are available to help govern that access.<\/p>\n\n\n\n<p>Here are four core options:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>App Enforced Restrictions<\/li>\n\n\n\n<li>Mobile Application Management (MAM) on Windows<\/li>\n\n\n\n<li>Conditional Access App Control (via Defender for Cloud Apps)<\/li>\n\n\n\n<li>Windows 365 or Azure Virtual Desktop (AVD)<\/li>\n<\/ul>\n\n\n\n<p>Each of these have strengths, limitations, and ideal scenarios \u2013 you may find you need a combination!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">App Enforced Restrictions<\/h2>\n\n\n\n<p>App Enforced Restrictions are a lightweight yet effective way to control user actions when accessing Exchange Online, SharePoint Online, and OneDrive from unmanaged devices.<\/p>\n\n\n\n<p>Instead of blocking access entirely, this method allows you to permit access via a web browser only, then layer on session-based restrictions to limit what users can do within that session.<\/p>\n\n\n\n<p>App Enforced Restrictions are enforced through Entra Conditional Access policies. However, they also require administrative configurations within SharePoint Online and Exchange Online to achieve the desired functionality.<\/p>\n\n\n\n<p>Some examples of what you can enforce are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Browser-only editing<\/strong>: Restrict access so that users can only view or edit documents within the browser \u2013 this blocks the use of Microsoft 365 desktop apps or any locally installed applications from opening or editing company data.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Download, sync, and print restrictions:<\/strong>&nbsp;Stop users from downloading files, syncing libraries, or printing content. Files, including email attachments, remain contained within the browser session, preventing file data exfiltration. Use of M365 desktop apps and the OneDrive client are blocked.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Read-only access:<\/strong>&nbsp;Prevent users from editing files in the browser entirely, making documents view-only during the session.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Hide Outlook attachments:<\/strong>&nbsp;Fully remove visibility of attachments in Outlook on the web to eliminate even the option to preview or open them.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Idle session timeout:<\/strong>&nbsp;Automatically sign users out after a defined period of inactivity in the browser.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Considerations<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Viewing and editing documents within a browser session (Office Online) will still allow users to copy &amp; paste (exfiltrate) content like text and pictures.<\/li>\n\n\n\n<li>There is no dedicated auditing or deep session analytics, however:<ul><li>User actions are reflected indirectly in the Microsoft 365 Unified Audit Log, primarily through activities in SharePoint Online, OneDrive, or Exchange Online.<\/li><\/ul>\n<ul class=\"wp-block-list\">\n<li>User sessions that are subject to App Enforced Restrictions can be identified within the Entra Sign-in logs.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li>Outlook on the Web (OWA) mailbox policies will also apply to the new Outlook for Windows app e.g. hiding attachments.<\/li>\n\n\n\n<li>Conditional Access capabilities are included with Entra ID P1, so no additional licences like Microsoft Intune or any E5 SKUs are required.<\/li>\n\n\n\n<li>The controls are operating system agnostic; you just need to be using a supported browser.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"2560\" height=\"1434\" src=\"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png\" alt=\"Using Edge on unmanaged Ubuntu to access OWA and App Enforced Restrictions are controlling what can be done with the email attachments. They can only be used within the browser, downloads are blocked.\" class=\"wp-image-104\" srcset=\"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png 2560w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-300x168.png 300w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-1024x574.png 1024w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-768x430.png 768w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-1536x861.png 1536w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-2048x1147.png 2048w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-421x236.png 421w\" sizes=\"auto, (max-width: 2560px) 100vw, 2560px\" \/><\/figure>\n\n\n\n<p>Here we have an example of using Ubuntu to access OWA and App Enforced Restrictions are controlling what can be done with the email attachments.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Mobile Application Management (MAM) on Windows<\/h2>\n\n\n\n<p>MAM on Windows brings Intune App Protection Policy (APP) capabilities, previously associated mostly with mobiles, into the desktop space.<\/p>\n\n\n\n<p>Currently only supported by Microsoft Edge, this feature enables you to enforce granular data protection policies at the application level without managing or enrolling the device which continues to be fully \u201cunmanaged\u201d.<\/p>\n\n\n\n<p>The magic happens when the user accesses a company resource in the browser \u2013 if they are already using Microsoft Edge, they are directed to create a new work profile and register the app, or if using another browser like Google Chrome they are prompted to switch over to Edge to get access.<\/p>\n\n\n\n<p>Once a work profile is created and signed in, the protection controls available to us are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>File Uploads:&nbsp;<\/strong>restrict file data ingress<strong>&nbsp;<\/strong>\u2013 allow or prevent users from attaching documents to company emails or uploading files to their OneDrive from the file system of the unmanaged device.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>File Downloads:&nbsp;<\/strong>restrict file data egress \u2013 allow or prevent file downloads from company locations such as email, OneDrive or SharePoint to the file system of the unmanaged device.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cut, Copy, and Paste:<\/strong>&nbsp;control data ingress\/egress \u2013 allow or block cut, copy and paste functionality within the web content area of the work profile. Unfortunately, this control isn&#8217;t very granular. It&#8217;s all or nothing &#8211; which means when you disable it, even basic in-document copy\/paste is blocked.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Printing:<\/strong>&nbsp;allow or block the ability to print company documents or emails. This will also control \u201cPrint to PDF\u201d functionality.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Health Checks:&nbsp;<\/strong>use signals from the Windows Security Centre on unmanaged devices to prevent access to company resources if the device is reporting as unhealthy.<\/li>\n<\/ul>\n\n\n\n<p>You can also deploy app configuration policies to customise the Edge work profile. This lets you set things like the home page, new tab behaviour, required extensions, and default search engine &#8211; creating a curated, seamless work experience.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Considerations<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>MAM for Edge is currently&nbsp;Windows-only. The same functionality isn&#8217;t supported on macOS or Linux.<\/li>\n\n\n\n<li>The work profile setup screen can be very confusing. It&#8217;s easy to pick the wrong option, so clear user comms are essential &#8211; you\u2019ll also need to block personal device enrolment to avoid the consequences.<\/li>\n<\/ul>\n\n\n\n<figure class=\"wp-block-image size-full\"><img loading=\"lazy\" decoding=\"async\" width=\"994\" height=\"964\" src=\"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/AnnoyingMAMRegistration.png\" alt=\"A horrible dialogue box presented when enrolling Edge for MAM on unmanaged Windows. Very confusing to user, they need to answer &quot;Yes, all apps&quot;\" class=\"wp-image-103\" srcset=\"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/AnnoyingMAMRegistration.png 994w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/AnnoyingMAMRegistration-300x291.png 300w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/AnnoyingMAMRegistration-768x745.png 768w, https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/AnnoyingMAMRegistration-309x300.png 309w\" sizes=\"auto, (max-width: 994px) 100vw, 994px\" \/><\/figure>\n\n\n\n<p>You need to answer \u201cYes, all apps\u201d for MAM to work, and also ensure the box is unchecked. It\u2019s a horrible screen and this is the latest Windows 11 24H2 incarnation &#8211; users and admins both hate it!<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>It even works with Microsoft Edge on Windows 11 Home edition!<\/li>\n\n\n\n<li>We\u2019re not just limited to controlling access to M365 resources \u2013 any on-premises web apps published via Entra App Proxy can also require access via MAM controlled Edge.<\/li>\n\n\n\n<li>Conditional Access capabilities are included with Entra ID P1, but we\u2019ll now also need a Microsoft Intune licence to apply the MAM policies (APP).<\/li>\n\n\n\n<li>Only a single MAM controlled work profile is supported \u2013 adding additional ones will cause strange behaviour.&nbsp;<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Conditional Access App Control<\/h2>\n\n\n\n<p>Conditional Access App Control uses Microsoft Defender for Cloud Apps (still often referred to as MCAS) to provide real-time, proxy-based session control over access to Microsoft 365 and connected SaaS applications.<\/p>\n\n\n\n<p>When a user signs in from an unmanaged device, their session is routed through Microsoft\u2019s reverse proxy, allowing you to monitor activity, enforce policies and respond in real-time. This method offers the deepest level of control and visibility, making it particularly useful for high-risk scenarios or when interacting with sensitive data.<\/p>\n\n\n\n<p>Examples of the protection controls available to us are:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Similar functionality as described with App Enforced Restrictions, but with very granular control, improved targeting and extensive monitoring and auditing capabilities. Examples include:\n<ul class=\"wp-block-list\">\n<li>Allow access to Teams but don\u2019t allow the sending of any messages.<\/li>\n\n\n\n<li>Control&nbsp;<strong>Cut, Copy, and Paste for specific apps&nbsp;<\/strong>&#8211; allow within Outlook but prevent within Teams.<\/li>\n\n\n\n<li>Allow file downloads but automatically block any bulk file downloads.<\/li>\n<\/ul>\n<\/li>\n\n\n\n<li><strong>Real-time Alerts:<\/strong>&nbsp;get notified about suspicious activities.<\/li>\n<\/ul>\n\n\n\n<p>Additionally, with Microsoft Purview integration we can enhance things further:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Content Aware Access Policies:<\/strong>&nbsp;use Purview sensitivity labels to determine file access, for example block documents labelled \u201chighly confidential\u201d from being downloaded whilst allowing others.<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Inline DLP:<\/strong>&nbsp;inspect file contents during uploads or downloads and enforce Microsoft Purview policies in real time &#8211; such as blocking the upload of files containing personally identifiable information (PII).<\/li>\n<\/ul>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Watermarking:<\/strong>&nbsp;apply dynamic watermarks that overlay a user\u2019s email address and the current date\/time on open documents to discourage screenshots or photographs and help make tracing easier in the case of data leakage.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Considerations<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>May negatively impact user experience and or performance due to the in-session proxy functionality, but not for much longer &#8211; check out the new \u201cin-browser protection\u201d feature below!<\/li>\n\n\n\n<li>This is enterprise class functionality which requires M365 E5 licencing to enable all product features, or Office 365 E5 at a minimum for a smaller subset of features. Please see&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-cloud-apps\/editions-cloud-app-security-o365\">here<\/a>&nbsp;for a full feature comparison.<\/li>\n\n\n\n<li>Lots of power and flexibility could add tiers of complexity if not well managed and maintained.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Preview Feature \u2013 In-Browser Protection<\/h3>\n\n\n\n<p>In-browser protection enables real-time enforcement of session policies like the blocking or monitoring of file downloads, uploads, copy\/cut\/paste, and printing all natively from within Microsoft Edge \u2013 no <strong>.mcas.ms<\/strong> suffix on the address bar, reverse proxying or Edge MAM required!<\/p>\n\n\n\n<p>Supported on Edge for macOS and Windows via work profile &#8211; learn more&nbsp;<a href=\"https:\/\/learn.microsoft.com\/en-us\/defender-cloud-apps\/in-browser-protection\">here<\/a>!<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Windows 365 or Azure Virtual Desktop<\/h2>\n\n\n\n<p>While the other options in this post focus on limiting or managing what users can do on unmanaged devices, there\u2019s another route entirely and that is to not let sensitive data touch an unmanaged device at all.<\/p>\n\n\n\n<p>With Windows 365 Cloud PCs or Azure Virtual Desktop, you provide users with access to a fully managed Windows environment hosted in Azure. Users interact with corporate resources through a remote desktop session that you fully control and manage.<\/p>\n\n\n\n<p>Examples of the controls we have in this scenario include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cut, Copy, and Paste:<\/strong>&nbsp;allow full functionality in the remote session, but prevent data exchange between the host and unmanaged client device.<\/li>\n\n\n\n<li><strong>Redirection:<\/strong>&nbsp;prevent capabilities like printing or drive mapping from the remote session to the client.<\/li>\n\n\n\n<li><strong>Screen Capture Protection:<\/strong>&nbsp;remote screens show as a black empty window on any screen shots or if shared via collaboration tools like Teams on the unmanaged device.<\/li>\n\n\n\n<li><strong>Watermarking:<\/strong>&nbsp;Working alongside screen capture protection you can choose to overlay a QR code that represents the session or device ID to help discourage taking photographs of the screen.<\/li>\n<\/ul>\n\n\n\n<h3 class=\"wp-block-heading\">Considerations<\/h3>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Very compelling if you need access to desktop apps or functionality not available with browser-based access.<\/li>\n\n\n\n<li>Licensing costs, Windows 365 is per-user subscription, while AVD is more flexible but billed based on consumption. These would be in addition to any productivity or management licences for Entra, Intune or Office 365 etc.<\/li>\n\n\n\n<li>You can apply your standard endpoint security, compliance, and DLP policies to the remote session as if it were a company-owned laptop.<\/li>\n\n\n\n<li>Not all control features can apply in all scenarios or use cases \u2013 for example, with screen capture protection enabled you cannot connect via web browser but must use the Windows App.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\">Unmanaged Device Access &#8211; Choose What Fits<\/h2>\n\n\n\n<p>Whether you call it BYOD or just acknowledge that users, partners, and execs will access Microsoft 365 from unmanaged devices, the need to balance flexibility and control is a reality.<\/p>\n\n\n\n<p>Fortunately, Microsoft offer several approaches each suited to different use cases, risk levels, and organisational requirements.&nbsp;<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>App Enforced Restrictions<\/strong>: quick and simple browser-based access with limited functionality.<\/li>\n\n\n\n<li><strong>Windows MAM:<\/strong>&nbsp;persistent, identity-aware controls at the app level, without managing the device.<\/li>\n\n\n\n<li><strong>Conditional Access App Control<\/strong>: powerful, session-aware enforcement based on activity, risk, and content.<\/li>\n\n\n\n<li><strong>Windows 365 or AVD<\/strong>: a fully managed remote desktop experience that keeps data off the device entirely.<\/li>\n<\/ul>\n\n\n\n<p>As is quite often the case there is no one size fits all. In many environments, it will be a combination of these approaches that will provide the best solution.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Yes, I\u2019m deliberately saying \u201cunmanaged\u201d rather than \u201cBYOD.\u201d You might wonder, what\u2019s the difference? In practice, I\u2019ve found that BYOD tends to spark a different &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[15,21,33,34],"tags":[31,28,32,27,35],"class_list":["post-97","post","type-post","status-publish","format-standard","hentry","category-cloud","category-intune","category-m365","category-security","tag-byod","tag-cloudnative","tag-m365","tag-modernmanagement","tag-modernworkplace"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk<\/title>\n<meta name=\"description\" content=\"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/prs.me.uk\/?p=97\" \/>\n<meta property=\"og:locale\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk\" \/>\n<meta property=\"og:description\" content=\"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/prs.me.uk\/?p=97\" \/>\n<meta property=\"og:site_name\" content=\"prs.me.uk\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-02T07:32:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2025-06-02T08:19:08+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png\" \/>\n\t<meta property=\"og:image:width\" content=\"2560\" \/>\n\t<meta property=\"og:image:height\" content=\"1434\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Paul\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Paul\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimated reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97\"},\"author\":{\"name\":\"Paul\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/#\\\/schema\\\/person\\\/957efde043113745b6aea24520cc808b\"},\"headline\":\"M365 Access Controls for Unmanaged Windows and macOS Endpoints\",\"datePublished\":\"2025-06-02T07:32:36+00:00\",\"dateModified\":\"2025-06-02T08:19:08+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97\"},\"wordCount\":1969,\"image\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/prs.me.uk\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/OWA-Unmanaged-Ubuntu-scaled.png\",\"keywords\":[\"BYOD\",\"CloudNative\",\"M365\",\"ModernManagement\",\"ModernWorkplace\"],\"articleSection\":[\"Cloud\",\"Intune\",\"M365\",\"Security\"],\"inLanguage\":\"en-GB\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97\",\"url\":\"https:\\\/\\\/prs.me.uk\\\/?p=97\",\"name\":\"M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/prs.me.uk\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/OWA-Unmanaged-Ubuntu-scaled.png\",\"datePublished\":\"2025-06-02T07:32:36+00:00\",\"dateModified\":\"2025-06-02T08:19:08+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/#\\\/schema\\\/person\\\/957efde043113745b6aea24520cc808b\"},\"description\":\"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#breadcrumb\"},\"inLanguage\":\"en-GB\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/prs.me.uk\\\/?p=97\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#primaryimage\",\"url\":\"https:\\\/\\\/prs.me.uk\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/OWA-Unmanaged-Ubuntu-scaled.png\",\"contentUrl\":\"https:\\\/\\\/prs.me.uk\\\/wp-content\\\/uploads\\\/2025\\\/06\\\/OWA-Unmanaged-Ubuntu-scaled.png\",\"width\":2560,\"height\":1434},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/?p=97#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/prs.me.uk\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"M365 Access Controls for Unmanaged Windows and macOS Endpoints\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/#website\",\"url\":\"https:\\\/\\\/prs.me.uk\\\/\",\"name\":\"prs.me.uk\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/prs.me.uk\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-GB\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/prs.me.uk\\\/#\\\/schema\\\/person\\\/957efde043113745b6aea24520cc808b\",\"name\":\"Paul\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-GB\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g\",\"caption\":\"Paul\"},\"sameAs\":[\"https:\\\/\\\/prs.me.uk\"],\"url\":\"https:\\\/\\\/prs.me.uk\\\/?author=1\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk","description":"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/prs.me.uk\/?p=97","og_locale":"en_GB","og_type":"article","og_title":"M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk","og_description":"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.","og_url":"https:\/\/prs.me.uk\/?p=97","og_site_name":"prs.me.uk","article_published_time":"2025-06-02T07:32:36+00:00","article_modified_time":"2025-06-02T08:19:08+00:00","og_image":[{"width":2560,"height":1434,"url":"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png","type":"image\/png"}],"author":"Paul","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Paul","Estimated reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/prs.me.uk\/?p=97#article","isPartOf":{"@id":"https:\/\/prs.me.uk\/?p=97"},"author":{"name":"Paul","@id":"https:\/\/prs.me.uk\/#\/schema\/person\/957efde043113745b6aea24520cc808b"},"headline":"M365 Access Controls for Unmanaged Windows and macOS Endpoints","datePublished":"2025-06-02T07:32:36+00:00","dateModified":"2025-06-02T08:19:08+00:00","mainEntityOfPage":{"@id":"https:\/\/prs.me.uk\/?p=97"},"wordCount":1969,"image":{"@id":"https:\/\/prs.me.uk\/?p=97#primaryimage"},"thumbnailUrl":"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png","keywords":["BYOD","CloudNative","M365","ModernManagement","ModernWorkplace"],"articleSection":["Cloud","Intune","M365","Security"],"inLanguage":"en-GB"},{"@type":"WebPage","@id":"https:\/\/prs.me.uk\/?p=97","url":"https:\/\/prs.me.uk\/?p=97","name":"M365 Access Controls for Unmanaged Windows and macOS Endpoints - prs.me.uk","isPartOf":{"@id":"https:\/\/prs.me.uk\/#website"},"primaryImageOfPage":{"@id":"https:\/\/prs.me.uk\/?p=97#primaryimage"},"image":{"@id":"https:\/\/prs.me.uk\/?p=97#primaryimage"},"thumbnailUrl":"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png","datePublished":"2025-06-02T07:32:36+00:00","dateModified":"2025-06-02T08:19:08+00:00","author":{"@id":"https:\/\/prs.me.uk\/#\/schema\/person\/957efde043113745b6aea24520cc808b"},"description":"Secure Microsoft 365 access from unmanaged BYOD Windows and macOS devices using App Enforced Restrictions, Edge MAM, CA App Control, and more.","breadcrumb":{"@id":"https:\/\/prs.me.uk\/?p=97#breadcrumb"},"inLanguage":"en-GB","potentialAction":[{"@type":"ReadAction","target":["https:\/\/prs.me.uk\/?p=97"]}]},{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/prs.me.uk\/?p=97#primaryimage","url":"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png","contentUrl":"https:\/\/prs.me.uk\/wp-content\/uploads\/2025\/06\/OWA-Unmanaged-Ubuntu-scaled.png","width":2560,"height":1434},{"@type":"BreadcrumbList","@id":"https:\/\/prs.me.uk\/?p=97#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/prs.me.uk\/"},{"@type":"ListItem","position":2,"name":"M365 Access Controls for Unmanaged Windows and macOS Endpoints"}]},{"@type":"WebSite","@id":"https:\/\/prs.me.uk\/#website","url":"https:\/\/prs.me.uk\/","name":"prs.me.uk","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/prs.me.uk\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-GB"},{"@type":"Person","@id":"https:\/\/prs.me.uk\/#\/schema\/person\/957efde043113745b6aea24520cc808b","name":"Paul","image":{"@type":"ImageObject","inLanguage":"en-GB","@id":"https:\/\/secure.gravatar.com\/avatar\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8e159a2fc2b1a9c2d75d7d2de19ee296968bb11943897dca1fa179ef78b560c4?s=96&d=mm&r=g","caption":"Paul"},"sameAs":["https:\/\/prs.me.uk"],"url":"https:\/\/prs.me.uk\/?author=1"}]}},"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/97","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prs.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=97"}],"version-history":[{"count":21,"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/97\/revisions"}],"predecessor-version":[{"id":120,"href":"https:\/\/prs.me.uk\/index.php?rest_route=\/wp\/v2\/posts\/97\/revisions\/120"}],"wp:attachment":[{"href":"https:\/\/prs.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=97"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prs.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=97"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prs.me.uk\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=97"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}