diff --git a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md b/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md
index d3cbbb8dc6..75c7a4d95a 100644
--- a/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md
+++ b/windows/security/information-protection/windows-information-protection/create-wip-policy-using-intune-azure.md
@@ -23,10 +23,10 @@ Microsoft Intune helps you create and deploy your Windows Information Protection
>This topic covers creating a Windows Information Protection (WIP) policy for organizations already managing devices by using Mobile Device Management (MDM) solutions. If your organization uses a mobile application management (MAM) solution to deploy your WIP policy to Intune apps without managing devices, you must follow the instructions in the [Create a Windows Information Protection (WIP) policy with MAM using the Azure portal for Microsoft Intune](create-wip-policy-using-mam-intune-azure.md) topic.
## Add a WIP policy
-After you’ve set up Intune for your organization, you must create a WIP-specific policy.
+Follow these steps to add a WIP policy using Intune.
**To add a WIP policy**
-1. Open the Microsoft Intune and click **Mobile apps**.
+1. Open Microsoft Intune and click **Mobile apps**.

@@ -51,26 +51,35 @@ After you’ve set up Intune for your organization, you must create a WIP-specif
4. Click **Protected apps** and then click **Add apps**.

+
+ You can add these types of apps:
+
+ - [Recommended apps](#add-recommended-apps)
+ - [Store apps](#add-store-apps)
+ - [Desktop apps](#add-desktop-apps)
-5. Under **Recommended apps**, select each app you want to access your enterprise data, and then click **OK**.
+### Add recommended apps
+
+To add **Recommended apps**, select each app you want to access your enterprise data, and then click **OK**.
- The **Allowed apps** blade updates to show you your selected apps.
+The **Allowed apps** blade updates to show you your selected apps.
- 
+
-6. Alternatively, you can add a Store or desktop app by using the app name and publisher. For example, to add the Power BI Mobile App from the Store, select **Store apps** and type the following and click **OK**:
+### Add Store apps
- - **Name**: Microsoft Power BI
- - **Publisher**: `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
- - **Product Name** is `Microsoft.MicrosoftPowerBIForWindows`
+To add **Store apps**, type the app product name and publisher and click **OK**. For example, to add the Power BI Mobile App from the Store, type the following:
- 
+- **Name**: Microsoft Power BI
+- **Publisher**: `CN=Microsoft Corporation, O=Microsoft Corporation, L=Redmond, S=Washington, C=US`
+- **Product Name**: `Microsoft.MicrosoftPowerBIForWindows`
- To add multiple Store apps, click the elipsis **…**.
+
-If you don't know the publisher or product name, you can find them for both desktop devices and Windows 10 Mobile phones by following these steps.
+To add multiple Store apps, click the elipsis **…**.
+
+If you don't know the Store app publisher or product name, you can find them for both desktop devices and Windows 10 Mobile phones by following these steps.
-**To find the publisher and product name values for Store apps without installing them**
1. Go to the [Microsoft Store for Business](https://go.microsoft.com/fwlink/p/?LinkID=722910) website, and find your app. For example, *Power BI Mobile App*.
2. Copy the ID value from the app URL. For example, the Power BI Mobile App ID URL is https://www.microsoft.com/en-us/store/p/microsoft-power-bi/9nblgggzlxn1, and you'd copy the ID value, `9nblgggzlxn1`.
@@ -86,24 +95,24 @@ If you don't know the publisher or product name, you can find them for both desk
}
```
-4. Copy the `publisherCertificateName` value into the **Publisher** box and copy the `packageIdentityName` value into the **Name** box of Intune.
+4. Copy the `publisherCertificateName` value into the **Publisher** box and copy the `packageIdentityName` value into the **Name** box of Intune.
>[!Important]
>The JSON file might also return a `windowsPhoneLegacyId` value for both the **Publisher Name** and **Product Name** boxes. This means that you have an app that’s using a XAP package and that you must set the **Product Name** as `windowsPhoneLegacyId`, and set the **Publisher Name** as `CN=` followed by the `windowsPhoneLegacyId`.
For example:
{
-**To find the publisher and product name values for apps installed on Windows 10 mobile phones**
-1. If you need to add mobile apps that aren't distributed through the Store for Business, you must use the **Windows Device Portal** feature.
- >**Note**
"windowsPhoneLegacyId": "ca05b3ab-f157-450c-8c49-a1f127f5e71d",
}
Your PC and phone must be on the same wireless network.
+If you need to add Windows 10 mobile apps that aren't distributed through the Store for Business, you must use the **Windows Device Portal** feature.
-2. On the Windows Phone, go to **Settings**, choose **Update & security**, and then choose **For developers**.
+>**Note**
Your PC and phone must be on the same wireless network.
-3. In the **For developers** screen, turn on **Developer mode**, turn on **Device Discovery**, and then turn on **Device Portal**.
+1. On the Windows Phone, go to **Settings**, choose **Update & security**, and then choose **For developers**.
-4. Copy the URL in the **Device Portal** area into your device's browser, and then accept the SSL certificate.
+2. In the **For developers** screen, turn on **Developer mode**, turn on **Device Discovery**, and then turn on **Device Portal**.
-5. In the **Device discovery** area, press **Pair**, and then enter the PIN into the website from the previous step.
+3. Copy the URL in the **Device Portal** area into your device's browser, and then accept the SSL certificate.
+
+4. In the **Device discovery** area, press **Pair**, and then enter the PIN into the website from the previous step.
6. On the **Apps** tab of the website, you can see details for the running apps, including the publisher and product names.
@@ -115,76 +124,65 @@ If you don't know the publisher or product name, you can find them for both desk
>The JSON file might also return a `windowsPhoneLegacyId` value for both the **Publisher Name** and **Product Name** boxes. This means that you have an app that’s using a XAP package and that you must set the **Product Name** as `windowsPhoneLegacyId`, and set the **Publisher Name** as `CN=` followed by the `windowsPhoneLegacyId`.
For example:
{
-### Add a Desktop app to your Allowed apps list
-For this example, we’re going to add WordPad, a desktop app, to the **Allowed apps** list.
+### Add Desktop apps
-**To add a Desktop app**
-1. From the **App policy** blade, click the name of your policy, and then click **Allowed apps** from the menu that appears.
+To add **Desktop apps**, complete the following fields, based on what results you want returned.
- The **Allowed apps** blade appears, showing you any apps that are already included in the list for this policy.
-
-2. From the **Allowed apps** blade, click **Add apps**.
-
-3. On the **Add apps** blade, click **Desktop apps** from the dropdown list.
-
- The blade changes to show boxes for you to add the following, based on what results you want returned:
-
-
"windowsPhoneLegacyId": "ca05b3ab-f157-450c-8c49-a1f127f5e71d",
}
Field | -Manages | -|||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
All fields marked as “*” | -All files signed by any publisher. (Not recommended) | -|||||||||||||||
Publisher only | -If you only fill out this field, you’ll get all files signed by the named publisher. This might be useful if your company is the publisher and signer of internal line-of-business apps. |
- |||||||||||||||
Publisher and Name only | +
Field | +Manages | +
---|---|
All fields marked as “*” | +All files signed by any publisher. (Not recommended) | +
Publisher only | +If you only fill out this field, you’ll get all files signed by the named publisher. This might be useful if your company is the publisher and signer of internal line-of-business apps. |
+
Publisher and Name only | If you only fill out these fields, you’ll get all files for the specified product, signed by the named publisher. | -
Publisher, Name, and File only | -If you only fill out these fields, you’ll get any version of the named file or package for the specified product, signed by the named publisher. | -
Publisher, Name, File, and Min version only | -If you only fill out these fields, you’ll get the specified version or newer releases of the named file or package for the specified product, signed by the named publisher. This option is recommended for enlightened apps that weren't previously enlightened. |
-
Publisher, Name, File, and Max version only | -If you only fill out these fields, you’ll get the specified version or older releases of the named file or package for the specified product, signed by the named publisher. | -
All fields completed | -If you fill out all fields, you’ll get the specified version of the named file or package for the specified product, signed by the named publisher. | -