Android: Microsoft Intune app protection profile settings
These settings correspond to Intune app protection policy settings. If you want more information about a setting, see the Microsoft Intune documentation.
|
Intune app protection profile setting |
Description |
|---|---|
|
Encrypt app data |
This setting specifies whether app data is encrypted. If you select this rule, app data is encrypted synchronously during all file input and output tasks. |
|
Prevent Android backups |
This setting specifies whether app data can be backed up to the Android Backup Service. |
|
Block screen capture and Android Assistant |
This setting specifies whether screen capture and Android Assistant app scanning capabilities are allowed when using a protected app. |
|
App package IDs |
This setting specifies the package IDs of the apps that this profile applies to. You can enter the package ID or select from the list of available Intune-managed apps. |
|
Restrict web content transfer with other apps |
This setting specifies which browser opens web links in apps.
|
|
Transfer messaging data to |
This setting specifies whether protected messaging data can be transferred by any messaging app, a specific messaging app (you must provide the messaging app package ID and app name), any policy-managed messaging app, or if messaging data cannot be transferred between apps. |
|
Transfer telecommunications data to |
This setting specifies whether telecommunications data can be transferred by any dialer app, a specific dialer app (you must provide the dialer app package ID and app name), any policy-managed dialer app, or if telecommunications data cannot be transferred between apps. |
|
Restrict keyboards to an approved list |
This setting specifies the approved keyboard apps that users can use with protected apps. Other keyboard apps are not allowed for use with protected apps. You must provide the package ID and display name for each approved keyboard app. If you enable this setting, you must add at least one approved keyboard app. |
|
Org data notifications |
This setting specifies how Org data is shared through OS notifications:
|
|
Require Class 3 biometrics |
This setting specifies whether users are required to sign in with class 3 biometrics. If you want to force users to use their PIN to sign in after biometric updates, select the "Override biometrics with PIN after biometric updates" check box. |
|
Select number of previous PIN values to maintain |
This setting specifies how many previous PIN values are retained. Retained PIN values cannot be reused. |
|
Disable app encryption |
This setting specifies whether app encryption is disabled if device encryption is enabled. |
|
Require minimum Android version |
Select this setting to specify a minimum Android version to use this app. If the Android version on the device does not meet the requirement, the user can't use the app. You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2). |
|
Require minimum Android version (Warning only) |
Select this setting to specify a minimum recommended Android version to use this app. If the Android version on the device does not meet the requirement, the user receives a notification that can be dismissed. You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2). |
|
Require minimum Android patch version |
Select this setting to specify a minimum Android patch version to use this app. If the Android patch version on the device does not meet the requirement, the user can't use the app. Specify the version using the date format YYYY-MM-DD. |
|
Require minimum Android patch version (Warning only) |
Select this setting to specify a minimum recommended Android patch version to use this app. If the Android patch version on the device does not meet the requirement, the user receives a notification that can be dismissed. Specify the version using the date format YYYY-MM-DD. |
|
Require minimum app version |
Select this setting to specify a minimum app version to use this app. If the app version on the device does not meet the requirement, the user can't use the app. You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2). Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app. |
|
Require minimum app version (Warning only) |
Select this setting to specify a minimum recommended app version to use this app. If the app version on the device does not meet the requirement, the user receives a notification that can be dismissed. You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2). Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app. |
|
Max OS version |
This setting specifies the action to take when the OS version on a device exceeds a maximum version that you specify. Select any of the following actions and specify the maximum OS version that must be exceeded before the action is executed on the device:
Specify versions in the format [major].[minor] (for example, 16.0 or 16.1). |
|
Restrict access by device manufacturer |
This setting specifies whether access to protected apps is allowed only by devices from allowed manufacturers. Specify allowed manufacturers by OEM/manufacturer names, separated by semi-colons (for example: Google;Samsung). Select the enforcement action to execute if a user tries to access a protected app from a non-approved manufacturer:
|
|
Require Play integrity verdict |
This setting specifies the Google Play Integrity verdict that is required before the user can access protected apps. Select the minimum verdict required and the action to execute if that minimum verdict is not met:
|
|
Require threat scan on apps |
This setting specifies whether Google app scanning must be turned on on the user's device before they can access protected apps. Select the action to execute if Google app scanning is not enabled:
|
|
Require device lock |
This setting specifies whether the device must have a screen lock mechanism (PIN, pattern, or password) in place before the user can access protected apps. When you enable, select the applicable complexity levels and the action to take if the complexity requirement is not met:
|
|
Minimum Company Portal version |
This setting specifies the minimum version of Company Portal that must be present on the device. When enabled, you select any of the following actions and specify the minimum version in any of the following formats: [major].[minor], [major].[minor].[build], or [major].[minor].[build].[revision]:
|
|
Maximum Company Portal version age |
This setting specifies the maximum age of Company Portal, in days (0 to 365), that is allowed before an enforcement action is executed. The purpose of this setting is to ensure that users are in a permitted range of Company Portal releases. When enabled, you select any of the following actions and specify the maximum age in days:
|
|
Samsung Knox device attestation |
This setting specifies whether the Samsung Knox device attestation check is required for the user to access protected apps, and the action to execute if attestation requirements are not met:
|
|
Max allowed device threat level |
This setting specifies the maximum risk level that is allowed (Secured, Low, Medium, or High), as determined by your integrated Mobile Threat Defense service, before an enforcement action is executed on the device:
|
|
Primary MTD service |
This setting specifies the security service that is the primary source for device health status: Microsoft Defender for Endpoint or Mobile Threat Defense (Non-Microsoft). |
|
Disabled account |
This setting specifies the action to take if the user's account is disabled in Entra ID:
|
|
Non-working time |
This setting specifies the action to take if a user accesses protected apps outside of scheduled working hours, and requires integration with the Working Time API. The available options for actions are:
|