{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
        "slug": "dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/"
        },
        "title": "Test iOS app sign-in at the incoming-data boundary",
        "summary": "Do not mistake IntuneMAMRequireAccounts for an unconditional app-launch sign-in control.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:31+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 230,
        "potentially_affected": "Enrolled iOS/iPadOS devices using targeted managed Microsoft apps.",
        "dse_recommendation": "Test the receipt of organization data with the required app and protection-policy configuration.",
        "primary_source": {
            "name": "Add App Configuration Policies for Managed iOS/iPadOS Devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For enrolled iOS/iPadOS devices, IntuneMAMRequireAccounts can require sign-in to the configured work or school account when a targeted Microsoft app receives organization data. The source explicitly limits this sign-in requirement to incoming organization data.</p>\n<p>The app needs Intune APP SDK for iOS 12.3.3 or later and an assigned app protection policy. That policy&#8217;s Receive data from other apps setting must be All apps with incoming Org data. <a href=\"https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the recipient app, its SDK support, configured account, and the source of the proposed data transfer. Review the managed-device configuration and protection policy together. Keep account-allowlisting requirements separate from the question of when incoming data requires sign-in.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends designing a transfer-specific acceptance test before assigning this setting broadly. Agree which account should receive the material and which policy should govern it. Have the application owner review the actual workflow rather than treating a successful app launch as evidence that the incoming-data requirement has been exercised.</p>\n<h2>Verification</h2>\n<p>Use a nonsensitive organization-owned test document in an approved managed-to-managed transfer. Compare signed-in and signed-out recipient states and verify the account and protection behavior observed on receipt. Record app and policy versions and the transfer origin. If no transfer occurred, label the test incomplete instead of concluding that the sign-in gate failed.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Add App Configuration Policies for Managed iOS/iPadOS Devices</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nFor enrolled iOS/iPadOS devices, IntuneMAMRequireAccounts can require sign-in to the configured work or school account when a targeted Microsoft app receives organization data. The source explicitly limits this sign-in requirement to incoming organization data.\nThe app needs Intune APP SDK for iOS 12.3.3 or later and an assigned app protection policy. That policy’s Receive data from other apps setting must be All apps with incoming Org data. Microsoft Learn.\nApplicability\nIdentify the recipient app, its SDK support, configured account, and the source of the proposed data transfer. Review the managed-device configuration and protection policy together. Keep account-allowlisting requirements separate from the question of when incoming data requires sign-in.\nDSE recommendation\nDSE recommends designing a transfer-specific acceptance test before assigning this setting broadly. Agree which account should receive the material and which policy should govern it. Have the application owner review the actual workflow rather than treating a successful app launch as evidence that the incoming-data requirement has been exercised.\nVerification\nUse a nonsensitive organization-owned test document in an approved managed-to-managed transfer. Compare signed-in and signed-out recipient states and verify the account and protection behavior observed on receipt. Record app and policy versions and the transfer origin. If no transfer occurred, label the test incomplete instead of concluding that the sign-in gate failed.\nOfficial references\nMicrosoft Learn: Add App Configuration Policies for Managed iOS/iPadOS Devices. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nFor enrolled iOS/iPadOS devices, IntuneMAMRequireAccounts can require sign-in to the configured work or school account when a targeted Microsoft app receives organization data. The source explicitly limits this sign-in requirement to incoming organization data.\n\nThe app needs Intune APP SDK for iOS 12.3.3 or later and an assigned app protection policy. That policy’s Receive data from other apps setting must be All apps with incoming Org data. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios).\n\n## Applicability\n\nIdentify the recipient app, its SDK support, configured account, and the source of the proposed data transfer. Review the managed-device configuration and protection policy together. Keep account-allowlisting requirements separate from the question of when incoming data requires sign-in.\n\n## DSE recommendation\n\nDSE recommends designing a transfer-specific acceptance test before assigning this setting broadly. Agree which account should receive the material and which policy should govern it. Have the application owner review the actual workflow rather than treating a successful app launch as evidence that the incoming-data requirement has been exercised.\n\n## Verification\n\nUse a nonsensitive organization-owned test document in an approved managed-to-managed transfer. Compare signed-in and signed-out recipient states and verify the account and protection behavior observed on receipt. Record app and policy versions and the transfer origin. If no transfer occurred, label the test incomplete instead of concluding that the sign-in gate failed.\n\n## Official references\n\n[Microsoft Learn: Add App Configuration Policies for Managed iOS/iPadOS Devices](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Test iOS app sign-in at the incoming-data boundary",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/",
                "headline": "Test iOS app sign-in at the incoming-data boundary",
                "description": "Do not mistake IntuneMAMRequireAccounts for an unconditional app-launch sign-in control.",
                "abstract": "Do not mistake IntuneMAMRequireAccounts for an unconditional app-launch sign-in control.",
                "articleBody": "Source facts\nFor enrolled iOS/iPadOS devices, IntuneMAMRequireAccounts can require sign-in to the configured work or school account when a targeted Microsoft app receives organization data. The source explicitly limits this sign-in requirement to incoming organization data.\nThe app needs Intune APP SDK for iOS 12.3.3 or later and an assigned app protection policy. That policy’s Receive data from other apps setting must be All apps with incoming Org data. Microsoft Learn.\nApplicability\nIdentify the recipient app, its SDK support, configured account, and the source of the proposed data transfer. Review the managed-device configuration and protection policy together. Keep account-allowlisting requirements separate from the question of when incoming data requires sign-in.\nDSE recommendation\nDSE recommends designing a transfer-specific acceptance test before assigning this setting broadly. Agree which account should receive the material and which policy should govern it. Have the application owner review the actual workflow rather than treating a successful app launch as evidence that the incoming-data requirement has been exercised.\nVerification\nUse a nonsensitive organization-owned test document in an approved managed-to-managed transfer. Compare signed-in and signed-out recipient states and verify the account and protection behavior observed on receipt. Record app and policy versions and the transfer origin. If no transfer occurred, label the test incomplete instead of concluding that the sign-in gate failed.\nOfficial references\nMicrosoft Learn: Add App Configuration Policies for Managed iOS/iPadOS Devices. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:22:31+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-565-test-ios-app-sign-in-at-the-incoming-data-boundary/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Test iOS app sign-in at the incoming-data boundary"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 230,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Add App Configuration Policies for Managed iOS/iPadOS Devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-ios"
                }
            }
        ]
    }
}