
Explanation:
Box 1: Client
Ensure that when users use the Intune Managed Browser to access Office 365 web interfaces, they can only copy data to applications that are managed by the company.
Box 2: Conditional Access
Allow only the Microsoft Intune Managed Browser to access Office 365 web interfaces.
Organizations can use Azure AD Conditional Access policies to ensure that users can only access work or school content using Edge for iOS and Android. To do this, you will need a conditional access policy that targets all potential users. These policies are described in Conditional Access: Require approved client apps or app protection policy.
Reference:
https://docs.microsoft.com/en-us/intune/app-configuration-managed-browser#application- protection-policies-for-protected-browsers