
Enterprise high data protection (Level 3) introduces advanced data protection mechanisms, enhanced PIN configuration, and APP Mobile Threat Defense.This is the configuration that is applicable to most mobile users accessing work or school data. Enterprise enhanced data protection (Level 2) introduces APP data leakage prevention mechanisms and minimum OS requirements.This is an entry level configuration that provides similar data protection control in Exchange Online mailbox policies and introduces IT and the user population to APP.

For Android devices, this level validates Android device attestation.


For more information, see App-based Conditional Access with Intune. For Android devices, the Intune Company Portal app is required. To leverage app-based conditional access policies, the Microsoft Authenticator app must be installed on iOS devices.
