Intune App Protection Policies
App protection policies protect company data inside an app, rather than configuring the device the app runs on. They are how you require a PIN before Outlook will open work mail, stop a user pasting from a work document into a personal one, or wipe company data out of an app without touching the rest of the phone.
From Secure > Intune > App Management > Protection you can:
See every app protection policy currently deployed in the selected tenant
Capture an existing policy from a connected tenant and save it as a reusable template
Group templates into baselines that deploy together
Deploy a template or baseline into a tenant with the assignments you choose
Edit or delete a deployed policy
The page has two views, selected with the tabs at the top:
Policies — the app protection policies that exist in the tenant you have selected
Templates — your reusable template library and baselines, shared across all your companies
Access. You need the Manage permission on Intune. With View you can see the Policies list, but the Templates tab, the Deploy menu and the row actions are hidden.
Two things can block this page. If the customer is not licensed for Intune, the Policies view shows a "not authorized for this feature" message with a contact address for Augmentt sales. Separately, if the customer is a CSP child tenant whose GDAP relationship is missing the Intune Administrator role, a warning banner appears at the top: the Graph calls that create, update and delete app management policies will fail until that role is added on the Integrations - CSP Setup page.
