Your employer can see more of your phone than you think. Here is what they see, what they should not, and what you can do about it right now.
.webp)
Your employer's Mobile Application Management policy lives on your personal phone. In March 2026, that turned out to be a problem for tens of thousands of employees. The #MAFOChallenge is our response. Every employee whose employer uses Microsoft Intune MDM or MAM deserves better. We're proving it for free.
The Stryker Incident · March 2026
When MDM Became a Weapon
Attackers compromised Stryker's MDM credentials and used them to remotely wipe tens of thousands of employee personal devices, destroying photos, contacts, financial apps, and years of data. Employees had signed BYOD agreements that gave their employer, and ultimately the attackers, the keys to their personal device.
🏷 Limited Offer
First 1,000 employees get Hypori free for 2 months.
Register at [www.hypori.com/user-privacy#MAFO-Registration](https://www.hypori.com/user-privacy#MAFO-Registration), confirm your employer uses Intune MDM or MAM, download the Hypori client, and let Intune manage the workspace — not your phone. No new IT ticket. No extra approval to request. This is your device and your choice.
2 months of Hypori Zero-Trust Virtual Workspace, free
Available on iOS and Android — install in minutes
Your BYOD Bill of Rights, enforced by architecture
Eligible: employees subject to Intune MDM or MAM BYOD policy
Before you install anything else on your personal phone, read this. These are not promises. Every right below is guaranteed by architecture - technically impossible to violate.
The Right to Absolute Privacy
Your texts, photos, browsing history, and personal apps are yours. Not because we promise not to look. Because the architecture makes looking impossible. No agent on your device, no data transmitted. Nothing to see.
The Right to Keep Your Personal Data Untouched
If you leave the company, your photos stay on your phone. No remote wipe, no accidental loss. Only company data can ever be removed — and only from company infrastructure, not your device.
The Right to Move Through the World Unmonitored
Doctor's appointments, places of worship, political meetings, Saturday errands. Your employer has no business knowing where you are. Your location is yours.
The Right to a Real Work-Life Boundary
Close the app and walk away. No background agents draining your battery, no corporate process running silently while you live your life. Your workday ends when you end it.
The Right to Own Your Own Device
It is your phone. You make the rules. No enrollment profiles, no device management frameworks, no risk that your device becomes evidence in a company investigation because of work data that should never have been on it.
Copy the prompt below into Claude, ChatGPT, or any AI tool, along with your company's Acceptable Use Policy. It'll tell you exactly where your BYOD coverage is thin.
Not sure what you'll get back?
Here's what a real answer tends to look like — most standard MDM-based AUPs land in medium or high.
Identified Gaps
- Policy allows remote wipe but doesn't specify whether it's limited to corporate data or the whole device
- No mention of what happens to personal data after employment ends
Missing Policy Areas
- Remote wipe scope limits
- Device offboarding / return process
Identified Gaps
- Policy grants full-device wipe authority with no carve-out for personal photos, contacts, or apps
- Location tracking is enabled by the MDM profile with no disclosure to the employee
- No consent language — enrollment is a condition of employment, not a choice
Missing Policy Areas
- Remote wipe scope limits
- Personal data separation
- Location tracking disclosure
- Employee consent language
If your answer landed medium or high, your privacy is a policy, not a guarantee.
The first 1,000 employees on Intune MDM or MAM get Hypori free for 2 months. No IT approval needed. Join the #MAFOChallengeThese articles go deeper on why MDM and MAM were never the right answers, what your work app is really collecting, and what a real privacy guarantee looks like.

Secure Mobility for the Global Executive
Hypori delivers international travel mobile security with virtual devices that protect data across borders without compromising privacy.
This reference covers the Conditional Launch settings available under Mobile Application Management (MAM) app protection policies in Microsoft Intune. These settings apply when the Hypori Virtual Workspace (VW) app is managed through app protection policy only, without full device (MDM) enrollment.
Each setting only takes effect if it is configured within your app protection policy — if a setting is not enabled, it has no effect on Hypori VW. Settings referred to as attestation settings rely on a device or app integrity attestation service.
You must have the Intune App Protection Policy administrator role (or equivalent) in Microsoft Intune to view or edit these settings.
1. Open the Managed App Protection Policy
Navigate to: Intune Admin Center > Apps > Managed Apps > Protection > {{Policy Name}}
2. Open Conditional Launch
Select Properties > Conditional Launch to view the App Conditions and Device Conditions tables.
3. Review Each Device Condition
Compare each configured setting against the reference table below. Additional device conditions, including Samsung Knox device attestation, can be added from the Select one dropdown.
| Setting | Type | Recommendation / Considerations |
|---|---|---|
| Jailbroken/rooted devices | Standard | N/A |
| Min OS version | Standard | Could be a problem if the Android version is not within range. |
| Max OS version | Standard | Could be a problem if the Android version is not within range. |
| Min patch version | Standard | Could be a problem if the Android patch level is not within range. |
| Device manufacturer(s) | Standard | Hypori |
| Play integrity verdict | Attestation | Best if removed. Can continue to work if the action is set to Warn, though this will affect user experience. |
| Require threat scan on apps | Standard | Requires Cloud Antivirus to be set up and configured. |
| Play Integrity verdict evaluation type | Attestation | Best if removed. Can continue to work if the Play integrity verdict action is set to Warn, though this will affect user experience. |
| Require device lock | Standard | Will require a screen lock on the VW. |
| Min Company Portal version | Standard | Could be a problem if the app version is not within range. |
| Max Company Portal version age (days) | Standard | Could be a problem if the app version is not within range. |
| Samsung Knox device attestation | Attestation | N/A |
| Max allowed device threat level | Standard | Requires Cloud Antivirus to be set up and configured. |
| Primary MTD service | Standard | N/A — used to set up Cloud Antivirus. |
If the Play integrity verdict setting cannot be removed, set its action to Warn rather than Block. This allows the Hypori VW app to continue functioning; however, end users will see a warning message that may be mistaken for a security or connectivity problem with the app.
Settings not listed require full Intune device (MDM) enrollment. Once enrolled, these can be controlled with greater precision using Microsoft Entra Conditional Access Policies, Intune Enrollment Restrictions, and App Protection Policies together. Where a Warn action is available on an MDM-based setting, it will allow the VW to continue working, but may affect user experience, as users may believe something is wrong with, or insecure about, the app.
This guide is intended for GovCloud customers using Hypori on AWS GovCloud infrastructure. It walks your IT administrator through the steps required to configure a Named Location in Microsoft Entra ID and update an existing Conditional Access Policy to exclude the Hypori Virtual Workspace (VW) IP address. Completing these steps ensures that Hypori VW traffic is correctly exempted from access-blocking policies.
You must have at least the Conditional Access Administrator role in Microsoft Entra ID to complete these steps.
1. Sign in to Microsoft Entra ID
Navigate to the Microsoft Entra admin center and sign in with an account that has Conditional Access Administrator privileges. Go to: Conditional Access → Named Locations.
2. Add a New Named Location
Select + IP ranges location from the toolbar. The Named Locations list will be empty if this is a fresh environment.
3. Configure the IP Range
In the Update location (IP ranges) panel that opens on the right, enter the following details:
Name: Hypori VW (or your preferred naming convention)
IP Address / Range: 3.32.42.138/32
Click Add, then click Create to save the named location.
4. Navigate to Conditional Access Policies
From the left-hand menu, select Policies under the Conditional Access section. Identify the policy that is currently blocking Hypori VW access and click on its name to open it for editing.
5. Configure the Network Exclusion
Within the policy, locate the Network section and apply the following settings:
Configure: Yes
Active tab: Exclude
Selection: Selected networks and locations
Location to exclude: Hypori VW (the named location created in Step 3)
6. Save the Policy
Review your changes, then click Save to apply the updated policy. The Hypori VW IP address will now be excluded from the blocking policy and traffic will flow correctly.