Improved mobile app security - Mobile Application Management (MAM)
The University of Twente is introducing Mobile Application Management (MAM) in phases to better protect UT documentation and data. This measure is necessary to comply with external audit requirements (such as KPMG) and to limit the risks of data leaks when working mobile.
Mobile phones are being used more and more intensively for work. This requires appropriate security.
What is MAM?
MAM is a security measure that is applied to mobile apps in which you work with your UT account, such as Outlook, Teams and OneDrive. The security only applies within these work apps.
Your private phone itself is not managed by the UT.
Why is the UT introducing this?
- To protect research, education, and business information
- To reduce risks in case devices are lost or stolen
- To meet external audit and compliance requirements
- To enable a consistent and professional way of working on the go
What will you notice as an employee?
- Additional security when opening work apps
- You may need to use a PIN or biometric authentication to access work apps
- No impact on your private apps or personal data

Your personal data remains private:
- UT will not be able to access your photos, messages or private apps
- Your phone cannot be remotely erased by UT
- Your location will not be tracked
Phased introduction
MAM will be introduced step by step per service and faculty. This approach ensures that support remains well organized and that any issues can be resolved quickly. You will always be informed in advance when it is your account’s turn.
Dealing with change professionally
Working safely in a digital environment is part of professional conduct at UT. We understand that changes may raise questions, but we expect everyone to approach them in a constructive and respectful manner.
Which parts are configured?
iOS
Below you will find more information about the main settings applied to the managed applications.
Please note: If your smartphone does not meet the minimum requirements, you will no longer have access to the apps. If the latest available update for your smartphone is still too old, consult with your supervisor to order a new device via http://selfservice.utwente.nl, assuming you have a UT-purchased smartphone.
- Access to apps: After entering the PIN code, you will have access to all managed apps. After 30 minutes of inactivity, you will need to re-enter your PIN code.
- Operating system requirements: The apps do not work on an outdated operating system. Make sure you are using at least iOS 18. Jailbroken devices are not supported. We periodically reassess which versions are supported by Apple with security updates to ensure that only operating systems still receiving security updates retain access.
- Encryption: The data in the managed apps is encrypted.
Android
Below you will find more information about the main settings applied to the managed applications.
Please note: If your smartphone does not meet the minimum requirements, you will no longer have access to the apps. If the latest available update for your smartphone is still too old, consult with your supervisor to order a new device via http://selfservice.utwente.nl, assuming you have a UT-purchased smartphone.
- Set access code: Your smartphone must be secured with an access code. Do not use a simple code, such as 1111 or 1234. A pattern (swipe) unlock is considered less secure and is therefore not permitted.
- Operating system requirements: The apps only work on devices with at least Android 13 that are not rooted. We periodically reassess which versions are supported with security updates to ensure that only operating systems still receiving security updates retain access.
- Encryption: The data in the managed apps is encrypted.
What happens once the new rules are active
You don't need to do anything to activate the security measures; this happens automatically. Follow the steps below to continue using the apps.
iOS
- Open an app to which the security policy applies, such as Outlook or Teams.
- Is this the first time you are logging into this app? If so, enter your UT username and password.
- A notification will appear for each app stating that your organisation wants to secure the data in the app.
- The app will close automatically. Reopen the app.
- Set a PIN code (minimum 4 digits) for access. Do not use a simple code, such as 1111 or 1234.
- The app will check whether your phone meets the minimum requirements. Press Continue and log in again with your UT account.
- Use the app like normal. The security policy will now work in the background to protect your data.
Android
Please note: these steps may vary depending on your Android version.
- Open an app to which the security policy applies, such as Outlook or Teams.
- Is this the first time you are logging into this app? If so, enter your UT username and password.
- You will receive a notification that the Microsoft Intune Company Portal app must be installed. This is required in order to apply the security policy.
- Press the Go to Store button and install the Microsoft Intune Company Portal app. You don't need to open or log into this app.
- Reopen the application you opened earlier (step 1).
- A message will appear stating that your organisation wants to secure the data in the app. This is to check whether your phone meets the minimum requirements. Press Continue and log in with your UT account.

- Tap Register under Help us keep your device secure.
- Use the app as you normally would. The security policy will now work in the background to protect your data.
Frequently Asked Questions
Is my phone now managed by the UT?
No. The UT does not manage your phone. Only apps in which you work with your UT account will receive extra security measures. Private use is completely excluded from this.
This answers my question.
Thank you for your feedback
Is MAM mandatory?
Yes. If you use work apps on your private phone, MAM is mandatory. This is part of working safely and professionally at the UT.
This answers my question.
Thank you for your feedback
What if I don't want to use MAM?
Then you can no longer use the work apps in question on your mobile phone. You will continue to have access via desktop or laptop.
This answers my question.
Thank you for your feedback
Will the UT now have access to my photos, messages and other personal data?
No. The UT does not have access to personal data such as photos, messages or private apps. It is also not possible to remotely wipe your phone or track your location.
This answers my question.
Thank you for your feedback
What data is read from the mobile device?
Microsoft Intune only logs technical information that is necessary for security, such as:
- Operating system and version
- Manufacturer and device type
No personal data (such as phone number, IMEI number, photos, messages, call history or internet traffic) is read.
If you would like to know more about the data collected, please visit the following page: Data collection in Intune - Microsoft Intune | Microsoft Learn.
This answers my question.
Thank you for your feedback
Who can read this data?
Access to the data is limited:
- Microsoft uses them exclusively to make the service work
- UT administrators only see technical status information, such as:
- What type of phone you have and which operating system version it is running (for example, iPhone 16 - iOS 26 or Samsung S25 - Android 15)
- Which company apps have the policy applied
- When the app last contacted Intune (“Last Sync”)
Admins can't see personal content or private use.
See Microsoft Intune documentation on data privacy and collection for details: “Privacy and personal data in Intune” and “Data collection in Intune”.
This answers my question.
Thank you for your feedback
Which apps does MAM apply to?
MAM is applied to apps in which you log in with your UT account, such as Microsoft Outlook, Teams and OneDrive. The full list of apps can be found on this page: Supported Microsoft Intune apps | Microsoft Learn.
This answers my question.
Thank you for your feedback
Why is the Company Portal app required on Android, but not on iOS?
On Android, the Intune Company Portal app is required to enable Intune's app protection and management capabilities for work applications. Once installed, the app works in the background and does not need to be opened for normal use.
On iOS, Apple provides built-in management capabilities that allow Intune to apply app protection policies directly through the operating system. Because these capabilities are integrated into iOS, a separate Company Portal app is not required for app-based management.
The Company Portal app does not manage your personal device. In our setup, it acts as a technical link between Android, Microsoft 365 apps and Intune, allowing security policies to be applied to corporate data within managed apps. It does not provide the university with access to personal photos, messages, browsing history or other personal content on your device.
This answers my question.
Thank you for your feedback
I opened the Company Portal app on Android and see a warning about enrollment. What does this mean?
The Company Portal app only needs to be installed, you don't need to open or sign in to it.
The message appears because the UT has intentionally blocked device enrollment. Enrollment would activate Mobile Device Management (MDM), giving the UT more access to your personal device than needed. To protect your privacy, this has been disabled for personal smartphones.
You can close the app. MAM will continue to work correctly in the background.
This answers my question.
Thank you for your feedback
I receive the message “App access blocked” on Android. What should I do?
This message appears when your Android device lock does not meet the security requirements. Set a PIN code or password (minimum 4 characters, no simple or sequential codes like 1234).
Pattern unlock (swipe) and no lock are not supported. After changing this, reopen the app.
This answers my question.
Thank you for your feedback
Why is a PIN code required to access apps on iOS, but not on Android?
On iOS, a device-wide PIN cannot be enforced through App Protection Policies. Therefore, when opening secure apps, an additional authentication step is used.
This answers my question.
Thank you for your feedback
Why is pattern unlock considered unsafe?
Patterns are easier to observe and reproduce than a PIN or password, making them faster to crack.
This answers my question.
Thank you for your feedback
I have forgotten my access code. What should I do?
Choose "Forgotten or change PIN code", log in again with your UT account and set a new PIN code.
This answers my question.
Thank you for your feedback
Why can’t I open the apps on my device running an older version of Android or iOS?
Devices running older operating systems no longer receive essential security updates from Google or Apple. To protect the security of our organization and your data, we therefore block access from outdated systems.
This answers my question.
Thank you for your feedback
Can I disable the security policy?
No. The security policy is mandatory as long as you use work apps with your UT account. Signing out of the app removes the policy for that app.
Alternatively, you can use some services through the web browser, with more limited functionality:
This answers my question.
Thank you for your feedback