{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
        "slug": "dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/"
        },
        "title": "Review the protection boundary before connecting work and personal Android apps",
        "summary": "Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:23:46+00:00",
        "modified_at": "2026-09-10T02:08:05+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 254,
        "potentially_affected": "Supported apps on Android 11 or later personally owned or corporate-owned work-profile devices.",
        "dse_recommendation": "Approve the cross-profile data use explicitly and test policy unassignment as the removal path.",
        "primary_source": {
            "name": "Add App Configuration Policies for Managed Android Enterprise Devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>On supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.</p>\n<p>Changing Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. <a href=\"https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Confirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source&#8217;s connected-app requirements before proposing an exception; do not assume every app implements the feature.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.</p>\n<h2>Verification</h2>\n<p>In an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nOn supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.\nChanging Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. Microsoft Learn.\nApplicability\nConfirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source’s connected-app requirements before proposing an exception; do not assume every app implements the feature.\nDSE recommendation\nDSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.\nVerification\nIn an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.\nOfficial references\nMicrosoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nOn supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.\n\nChanging Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android).\n\n## Applicability\n\nConfirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source’s connected-app requirements before proposing an exception; do not assume every app implements the feature.\n\n## DSE recommendation\n\nDSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.\n\n## Verification\n\nIn an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.\n\n## Official references\n\n[Microsoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Review the protection boundary before connecting work and personal Android apps",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/",
                "headline": "Review the protection boundary before connecting work and personal Android apps",
                "description": "Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.",
                "abstract": "Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.",
                "articleBody": "Source facts\nOn supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.\nChanging Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. Microsoft Learn.\nApplicability\nConfirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source’s connected-app requirements before proposing an exception; do not assume every app implements the feature.\nDSE recommendation\nDSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.\nVerification\nIn an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.\nOfficial references\nMicrosoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:23:46+00:00",
                "dateModified": "2026-09-10T02:08:05+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Review the protection boundary before connecting work and personal Android apps"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 254,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Add App Configuration Policies for Managed Android Enterprise Devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android"
                }
            }
        ]
    }
}