How to monitor app protection policies

You can monitor the status of the app protection policies that you've applied to users from the Intune app protection pane in Intune. Additionally, you can find information about the users affected by app protection policies, policy compliance status, and any issues that your users might be experiencing.

App protection data is retained for a minimum of 90 days. Any app instances that have checked in to the Intune service within the past 90 days is included in the app protection status report.

For iOS 16 and later devices, the Device Name value in all app protection reports will be a generic device name. For related information, see Apple Developer documentation.

View the App protection status report

  1. Sign in to the Microsoft Intune admin center.
  2. Select Apps >Monitor >App protection status.

The Last Sync column represents the same value in both the in-console User status report and the App Protection Policy exportable .csv report. The difference is a small delay in synchronization between the value in the two reports.

The time referenced in Last Sync is when Intune last saw the app instance. When a user launches an app, it might notify the Intune App Protection service at that launch time, depending on when it last checked in. See the retry interval times for App Protection Policy check-in. If a user hasn't used that particular app in the last check-in interval (which is usually 30 minutes for active usage), and they launch the app, then:

For example, consider a targeted and licensed user who launches a protected app at 12:00 PM:

See also