GuideInformationCybersecurityIT

Review the protection boundary before connecting work and personal Android apps

Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseGuide · 2 min read
Executive summary

What you need to know

Treat cross-profile app integration as a deliberate data-sharing decision, with an explicit removal procedure.

Potentially affected

Supported apps on Android 11 or later personally owned or corporate-owned work-profile devices.

DSE recommendation

Approve the cross-profile data use explicitly and test policy unassignment as the removal path.

Source facts

On supported Android 11 or later work-profile devices, connected apps can integrate the personal and work instances of an app. Microsoft warns that work data in the personal app is not protected by an app protection policy.

Changing Connected apps to Not Configured does not remove the configuration. Microsoft requires unassigning the related policy to remove that functionality. Conflicting connected-app settings for the same app and device cause connected apps to be disallowed. Independently of this configuration, some device manufacturers can connect certain apps automatically or request user approval for connections not configured by the administrator. Microsoft Learn.

Applicability

Confirm the exact enrollment mode, Android version, supported app, and every policy targeting that app. Consult the source’s connected-app requirements before proposing an exception; do not assume every app implements the feature.

DSE recommendation

DSE recommends asking the data owner to identify which information may cross into the personal instance and whether that use is acceptable. Record the approved app and user population, the intended user experience, and who can revoke the exception. Preserve the targeting record so removal is an intentional change rather than a vague reset to defaults.

Verification

In an approved pilot, exercise the intended cross-profile interaction using nonsensitive data. Inspect effective policy and any conflict, then unassign the relevant policy and verify the actual resulting behavior, including any manufacturer-provided connections. Document what was observed without claiming that removing the setting erased data already transferred.

Official references

Microsoft Learn: Add App Configuration Policies for Managed Android Enterprise Devices. Source retrieved September 9, 2026.

Primary reference

Review the official source

Add App Configuration Policies for Managed Android Enterprise Devices - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE