Smartsheet mobile app security FAQ

These questions and answers relate to the application security available for the Smartsheet mobile app.

Who can use this?

Plans:

  • Pro
  • Business
  • Enterprise

Do users need to enroll their devices in Intune?

No. Smartsheet uses MAM-WE (Mobile Application Management Without Enrollment). Policies apply at the app level, not the device level. Users do not need to enroll their personal or corporate devices.

Can users use Smartsheet on personal devices?

Yes. With MAM-WE, users can install Smartsheet on personal devices. Only corporate data within the Smartsheet app is protected and managed. Personal data and other apps are not affected.

What happens if a user leaves the organization?

When a user account is deactivated or deleted:
 
  1. The user can’t sign in to Smartsheet.
  2. In Microsoft Intune, an Intune Administrator can perform a selective wipe to remove corporate data from the app.
  3. The app itself remains installed, but cannot access corporate data

How long does it take for policies to apply?

Here are the timeframes for various scenarios:
 
  • Initial policy creation: 5-10 minutes to propagate
  • Policy updates: 8-24 hours for existing users
  • New user sign-in: Immediate (policies apply on first sign-in)

Can I have different policies for different user groups?

Yes. You can create app protection policies (APP) and assign them to different Azure Active Directory (AD) user groups. If a user is in multiple groups with conflicting policies, the most restrictive policy wins.

What kind of data do app protection policies protect?

Here are examples of what policies do and don’t protect.
 
Policies protect:
 
  • Data accessed through the Smartsheet app (for example, sheets, reports, dashboards)
  • Files downloaded within the app
  • Cached data and offline content
  • Copy/paste operations from the app
 
Policies don’t protect:
 
  • Data outside the Smartsheet app
  • Other apps on the device
  • Device settings or personal data

Do policies work on both Android and iOS?

Yes, but you must create separate policies for each platform. The policy settings are similar but platform-specific.

Can users access Smartsheet on web browsers?

Yes. App protection policies only apply to the Smartsheet mobile app. Web browser access is controlled separately through:
 
  • Azure AD Conditional Access policies
  • Smartsheet's own access controls

    Consider configuring Conditional Access to require managed browsers (Edge, Chrome with Intune) for web access.

What happens during the offline grace period?

Here’s what happens in specific scenarios:
 
  • Before the grace period expires, the app works normally offline
  • After a short grace period (e.g., 12 hours), the app blocks access until the device connects to the internet and checks in with Intune
  • After a long grace period (e.g., 90 days), the app performs a selective wipe, removing all corporate data

How do I update policies after deployment?

You can update app protection policies in the Microsoft Intune Admin Center. Changes propagate within 8-24 hours.

Can I test policies before rolling out to all users?

Yes. Here’s a recommended approach:
 
  1. Create a pilot user group (5-10 users).
  2. Assign policies only to the pilot group.
  3. Test for 1-2 weeks.
  4. Gather feedback and adjust the policies.
  5. Expand the policies to broader user groups.
  6. Eventually, assign the policies to all users.

What versions of Android and iOS are supported?

The required versions for the Smartsheet mobile app, as specified in Google Play 
(for Android) and Apple Store (for iOS and iPadOS), are supported.

How do I monitor policy compliance?

In Microsoft Intune, here’s how you can monitor compliance:
 
  • Check app protection status.
  • Check user status within the app protection policy.
  • Check device status within the app protection policy.
  • Check app configuration status.
  • Set up alerts for policy violations or compliance issues.

Can policies be bypassed by uninstalling and reinstalling the app?

No. Policies are tied to the user's Azure Active Directory (AD) identity. When the user signs back in after reinstalling, policies are immediately re-applied.

What's the difference between app protection policies and Device Compliance Policies?

Here’s the answer:
 
  • App protection policies (APP) protect data within specific apps, have app-level controls, and don’t require device enrollment. APP (MAM-WE) provides maximum flexibility.
  • Device Compliance Policies require device enrollment and device-level controls, and assess overall device health.

Do I need to configure anything in the Smartsheet admin console?

No. Integration is configured entirely within Microsoft Intune and Azure Active Directory (AD). No changes are needed in Smartsheet's admin console.