CA-05: Require App Protection for Mobile Access

Frequently asked questions about implementing and managing the CA-05 security control in Microsoft 365 and Entra ID.

Q
What is CA-05 (Require App Protection for Mobile Access)?
A

CA-05 is a security control that mobile devices accessing corporate data should use apps with protection policies. this prevents data leakage through unmanaged apps and ensures corporate data remains protected on personal devices. It requires that a conditional access policy requires approved or compliant applications for mobile and policy targets ios and android platforms, office 365 or all cloud apps are protected.

Related controls:CA-05
Q
Why is Require App Protection for Mobile Access important for Microsoft 365 security?
A

Mobile devices accessing corporate data should use apps with protection policies. This prevents data leakage through unmanaged apps and ensures corporate data remains protected on personal devices.

Related controls:CA-05
Q
How do I implement CA-05 in my tenant?
A

TrueConfig provides one-click remediation for CA-05. Creates a CA policy requiring app protection for mobile devices. PREREQUISITE: Intune App Protection Policies must be configured.

Related controls:CA-05
Q
What license do I need for CA-05?
A

This control requires Azure AD Premium P1 (included in Microsoft 365 E3) or higher.

Related controls:CA-05
Q
Which security baseline includes CA-05?
A

CA-05 is included in the Enhanced Security baseline (Level 2). This level adds stricter controls for security-conscious organizations.

Related controls:CA-05

5

Questions

1

Related Controls

Categorized

Related Resources

Still have questions?

Our security experts are here to help. Start a free trial and get personalized guidance for your Microsoft 365 environment.

Start Free Trial