# Review the protection boundary before connecting work and personal Android apps

> Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:23:46+00:00
- Modified: 2026-09-10T02:08:05+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.

## Potentially affected

Supported apps on Android 11 or later personally owned or corporate-owned work-profile devices.

## DSE recommendation

Approve the cross-profile data use explicitly and test policy unassignment as the removal path.

## Article

## Source facts

On supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.

Changing Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android).

## Applicability

Confirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source’s connected-app requirements before proposing an exception; do not assume every app implements the feature.

## DSE recommendation

DSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.

## Verification

In an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.

## Official references

[Microsoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices](https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android). Source retrieved September 9, 2026.

## Primary reference

- Name: Add App Configuration Policies for Managed Android Enterprise Devices - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/app-management/configuration/configure-managed-android
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Review the protection boundary before connecting work and personal Android apps,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-490-review-the-protection-boundary-before-connecting-work-and-personal-android-apps/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
