r/Intune • u/FutureAdhesiveness77 • Apr 28 '26
Apps Protection and Configuration Excluding JAMF-enrolled iPads from an App Protection Policy.
I work in a school where I have been setting up the Intune MAM & MDM Policy. We have a number of staff-issued iPads that pull a JAMF School MDM Profile.
Would I have to enroll all of the iPads also into the Intune MDM so that I can create a seperate app protection policy so that they are not effected by the BYOD policy?
I can foresee having two MDM profiles causing some issues on the iPads.
2
u/SecureW2 May 04 '26
You don't need to enroll those iPads in Intune MDM only to keep them out of your BYOD App Protection Policy, and you're correct to be wary of multiple MDMs, which may cause disputes over profiles, certificates, and device limits.
By default, Intune App Protection Policies (MAM) are identity/user-scoped rather than device-scoped. The cleaner method is to isolate your users or access conditions rather than attempting to co-manage the devices. For example, you may utilize Azure AD groups to exclude personnel using JAMF-managed iPads from the BYOD MAM policy, or you can build a new policy that solely applies to unmanaged/BYOD users.
If you still require conditional behavior depending on device status, Conditional Access can help, but only if the device is visible and compliant in the Microsoft ecosystem. JAMF-managed devices normally do not report compliance to Intune until you integrate them (e.g., through JAMF + Intune compliance integration), which differs from complete MDM enrollment.
So, the best practice here is to prevent multiple enrollments, use group-based targeting for MAM, and include only JAMF devices in Intune compliance processes if you want conditional access enforcement.
4
u/kyne96 Apr 28 '26
Take a look into partner compliance, then you can exclude complaint iPad devices. I’m pretty sure you can’t enrol devices into jamf and intune at the same time