Your Phone. Your Life.
Your Privacy.

Your employer can see more of your phone than you think. Here is what they see, what they should not, and what you can do about it right now.

The #MAFOChallenge is live — First 1,000 employees get Hypori free for 2 months!
The #MAFOChallenge is live — First 1,000 employees get Hypori free for 2 months!
MAFO Challenge
MAM Around and Find Out.

Your employer's Mobile Application Management policy lives on your personal phone. In March 2026, that turned out to be a problem for tens of thousands of employees. The #MAFOChallenge is our response. Every employee whose employer uses Microsoft Intune MDM or MAM deserves better. We're proving it for free.

The Stryker Incident  ·  March 2026

When MDM Became a Weapon

Attackers compromised Stryker's MDM credentials and used them to remotely wipe tens of thousands of employee personal devices, destroying photos, contacts, financial apps, and years of data. Employees had signed BYOD agreements that gave their employer, and ultimately the attackers, the keys to their personal device.

GOT QUESTIONS
Questions you're probably already asking.
Can Hypori see what's on my personal phone?
What happens after the 2 free months?
Does this work on both iPhone and Android?

🏷 Limited Offer

First 1,000 employees get Hypori free for 2 months.

Register at [www.hypori.com/user-privacy#MAFO-Registration](https://www.hypori.com/user-privacy#MAFO-Registration), confirm your employer uses Intune MDM or MAM, download the Hypori client, and let Intune manage the workspace — not your phone. No new IT ticket. No extra approval to request. This is your device and your choice.

2 months of Hypori Zero-Trust Virtual Workspace, free

Available on iOS and Android — install in minutes

Your BYOD Bill of Rights, enforced by architecture

Eligible: employees subject to Intune MDM or MAM BYOD policy

The BYOD Bill of Rights

Before you install anything else on your personal phone, read this. These are not promises. Every right below is guaranteed by architecture - technically impossible to violate.

I

The Right to Absolute Privacy

Your texts, photos, browsing history, and personal apps are yours. Not because we promise not to look. Because the architecture makes looking impossible. No agent on your device, no data transmitted. Nothing to see.

II

The Right to Keep Your Personal Data Untouched

If you leave the company, your photos stay on your phone. No remote wipe, no accidental loss. Only company data can ever be removed — and only from company infrastructure, not your device.

III

The Right to Move Through the World Unmonitored

Doctor's appointments, places of worship, political meetings, Saturday errands. Your employer has no business knowing where you are. Your location is yours.

IV

The Right to a Real Work-Life Boundary

Close the app and walk away. No background agents draining your battery, no corporate process running silently while you live your life. Your workday ends when you end it.

V

The Right to Own Your Own Device

It is your phone. You make the rules. No enrollment profiles, no device management frameworks, no risk that your device becomes evidence in a company investigation because of work data that should never have been on it.

Analyze Your AUP
Your employer already wrote the rules for your personal device. Most people have never actually read them. Find out what yours really says in under five minutes.

Copy the prompt below into Claude, ChatGPT, or any AI tool, along with your company's Acceptable Use Policy. It'll tell you exactly where your BYOD coverage is thin.
The prompt
Act as a workplace policy analyst. I'm going to share my company's Acceptable Use Policy (AUP). Review it specifically for BYOD (Bring Your Own Device) coverage — do not evaluate general AUP quality, focus only on personal device provisions. Respond in exactly this structure: RISK SCORE: [Low, Medium, or High — risk to my personal device privacy] IDENTIFIED GAPS: - [bulleted list: specific BYOD provisions that are missing, vague, or overly broad] MISSING POLICY AREAS: (check the document against each of these and list which are absent or unclear) - Remote wipe scope limits (device-wide vs. corporate-data-only) - Personal data separation - Device offboarding / return process - Location tracking disclosure - Personal app monitoring disclosure - Employee consent language RECOMMENDED ADDITIONS: - [bulleted list: specific clauses the policy should add] Here is my company's AUP: [paste your AUP text here, or attach the file]
Then open one of these

Not sure what you'll get back?

Here's what a real answer tends to look like — most standard MDM-based AUPs land in medium or high.

Medium Risk

Identified Gaps

  • Policy allows remote wipe but doesn't specify whether it's limited to corporate data or the whole device
  • No mention of what happens to personal data after employment ends

Missing Policy Areas

  • Remote wipe scope limits
  • Device offboarding / return process
High Risk

Identified Gaps

  • Policy grants full-device wipe authority with no carve-out for personal photos, contacts, or apps
  • Location tracking is enabled by the MDM profile with no disclosure to the employee
  • No consent language — enrollment is a condition of employment, not a choice

Missing Policy Areas

  • Remote wipe scope limits
  • Personal data separation
  • Location tracking disclosure
  • Employee consent language

If your answer landed medium or high, your privacy is a policy, not a guarantee.

The first 1,000 employees on Intune MDM or MAM get Hypori free for 2 months. No IT approval needed. Join the #MAFOChallenge
#MAFOChallenge — MAM Around and Find Out
Deep Dive

These articles go deeper on why MDM and MAM were never the right answers, what your work app is really collecting, and what a real privacy guarantee looks like.

The Wipe Command That Should Worry Every Bank in America

MDM gave attackers one command to wipe thousands of devices across 79 countries. Every major bank runs the same architecture. Are financial institutions next?

How Bad is MAM?

Think MAM secures your BYOD devices? Think again. Discover the fundamental security flaws of Mobile Application Management and why it fails to deliver zero trust.

The Latest MAM Failure: Why Data on Devices Will Always Be a Problem

Another week, another MAM failure. Microsoft's latest Intune issue erasing security configurations is just the latest reminder that managing data on devices will always be problematic. We've been saying it for years: the only way to truly secure mobile data is to keep it off the device entirely.

FAQs
App Protection Attestation Settings — Microsoft Intune (MAM)

This reference covers the Conditional Launch settings available under Mobile Application Management (MAM) app protection policies in Microsoft Intune. These settings apply when the Hypori Virtual Workspace (VW) app is managed through app protection policy only, without full device (MDM) enrollment.

Each setting only takes effect if it is configured within your app protection policy — if a setting is not enabled, it has no effect on Hypori VW. Settings referred to as attestation settings rely on a device or app integrity attestation service.

You must have the Intune App Protection Policy administrator role (or equivalent) in Microsoft Intune to view or edit these settings.

1. Open the Managed App Protection Policy
Navigate to: Intune Admin Center > Apps > Managed Apps > Protection > {{Policy Name}}

2. Open Conditional Launch
Select Properties > Conditional Launch to view the App Conditions and Device Conditions tables.

3. Review Each Device Condition
Compare each configured setting against the reference table below. Additional device conditions, including Samsung Knox device attestation, can be added from the Select one dropdown.

SettingTypeRecommendation / Considerations
Jailbroken/rooted devicesStandardN/A
Min OS versionStandardCould be a problem if the Android version is not within range.
Max OS versionStandardCould be a problem if the Android version is not within range.
Min patch versionStandardCould be a problem if the Android patch level is not within range.
Device manufacturer(s)StandardHypori
Play integrity verdictAttestationBest if removed. Can continue to work if the action is set to Warn, though this will affect user experience.
Require threat scan on appsStandardRequires Cloud Antivirus to be set up and configured.
Play Integrity verdict evaluation typeAttestationBest if removed. Can continue to work if the Play integrity verdict action is set to Warn, though this will affect user experience.
Require device lockStandardWill require a screen lock on the VW.
Min Company Portal versionStandardCould be a problem if the app version is not within range.
Max Company Portal version age (days)StandardCould be a problem if the app version is not within range.
Samsung Knox device attestationAttestationN/A
Max allowed device threat levelStandardRequires Cloud Antivirus to be set up and configured.
Primary MTD serviceStandardN/A — used to set up Cloud Antivirus.

If the Play integrity verdict setting cannot be removed, set its action to Warn rather than Block. This allows the Hypori VW app to continue functioning; however, end users will see a warning message that may be mistaken for a security or connectivity problem with the app.

Settings not listed require full Intune device (MDM) enrollment. Once enrolled, these can be controlled with greater precision using Microsoft Entra Conditional Access Policies, Intune Enrollment Restrictions, and App Protection Policies together. Where a Warn action is available on an MDM-based setting, it will allow the VW to continue working, but may affect user experience, as users may believe something is wrong with, or insecure about, the app.

Conditional Access Policy — Microsoft Entra ID (GovCloud)

This guide is intended for GovCloud customers using Hypori on AWS GovCloud infrastructure. It walks your IT administrator through the steps required to configure a Named Location in Microsoft Entra ID and update an existing Conditional Access Policy to exclude the Hypori Virtual Workspace (VW) IP address. Completing these steps ensures that Hypori VW traffic is correctly exempted from access-blocking policies.

You must have at least the Conditional Access Administrator role in Microsoft Entra ID to complete these steps.

1. Sign in to Microsoft Entra ID
Navigate to the Microsoft Entra admin center and sign in with an account that has Conditional Access Administrator privileges. Go to: Conditional Access → Named Locations.

2. Add a New Named Location
Select + IP ranges location from the toolbar. The Named Locations list will be empty if this is a fresh environment.

3. Configure the IP Range
In the Update location (IP ranges) panel that opens on the right, enter the following details:

Name: Hypori VW (or your preferred naming convention)
IP Address / Range: 3.32.42.138/32

Click Add, then click Create to save the named location.

4. Navigate to Conditional Access Policies
From the left-hand menu, select Policies under the Conditional Access section. Identify the policy that is currently blocking Hypori VW access and click on its name to open it for editing.

5. Configure the Network Exclusion
Within the policy, locate the Network section and apply the following settings:

Configure: Yes
Active tab: Exclude
Selection: Selected networks and locations
Location to exclude: Hypori VW (the named location created in Step 3)

6. Save the Policy
Review your changes, then click Save to apply the updated policy. The Hypori VW IP address will now be excluded from the blocking policy and traffic will flow correctly.