iOS: Microsoft Intune app protection profile settings
These settings correspond to Intune app protection policy settings. If you want more information about a setting, see the Microsoft Intune documentation.
|
Intune app protection profile setting |
Description |
|---|---|
|
Encrypt app data |
This setting specifies when app data is encrypted.
|
|
Prevent iTunes and iCloud backups |
This setting specifies whether app data can be backed up to iTunes or iCloud. |
|
App package IDs |
This setting specifies the package IDs of the apps that this profile applies to. You can enter the package ID or select from the list of available Intune-managed apps. |
|
Restrict web content transfer with other apps |
This setting specifies which browser opens web links in apps.
|
|
Allow Face ID instead of PIN |
This setting specifies whether the user is allowed to use Face ID to access the app instead of using their PIN. |
|
Transfer messaging data to |
This setting specifies whether protected messaging data can be transferred by any messaging app, a specific messaging app (you must provide the messaging app URL scheme, for example, sms), or if messaging data cannot be transferred between apps. |
|
Enter universal links to exempt |
This setting specifies universal links to open in a specified unmanaged app instead of the protected browser specified in "Restrict web content transfer with other apps". Follow the format of the target app (you may need the app vendor's format). Wildcards are supported, as allowed by Intune. Note that misconfigured links can increase the risk of data exfiltration. |
|
Enter managed universal links |
This setting specifies universal links to open in a specified managed app instead of the protected browser specified in "Restrict web content transfer with other apps". Intune will try to open the policy-managed target app if possible, and if it cannot, the behavior will fall back to your defined protected browser. Follow the format of the target app. |
|
Genmoji |
This setting specifies whether to allow or block Genmoji. |
|
Screen capture |
This setting specifies whether to allow or block screen capture. |
|
Writing Tools |
This setting specifies whether to allow or block Writing Tools. |
|
Org data notifications |
This setting specifies how Org data is shared through OS notifications:
|
|
Require minimum iOS version |
Select this setting to specify a minimum iOS version to use this app. If the iOS version on the device does not meet the requirement, the user can't use the app. You can specify a single decimal point (for example, 12.0). |
|
Require minimum iOS version (Warning only) |
Select this setting to specify a minimum recommended iOS version to use this app. If the iOS version on the device does not meet the requirement, the user receives a notification that can be dismissed. You can specify a single decimal point (for example, 12.0). |
|
Require minimum app version |
Select this setting to specify a minimum app version to use this app. If the app version on the device does not meet the requirement, the user can't use the app. You can specify a single decimal point (for example, 4.2). Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app. |
|
Require minimum app version (Warning only) |
Select this setting to specify a minimum recommended app version to use this app. If the app version on the device does not meet the requirement, the user receives a notification that can be dismissed. You can specify a single decimal point (for example, 4.2). Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app. |
|
Require minimum SDK version |
This setting specifies the minimum Intune SDK version that is required from an app. If the SDK version does not meet the requirement, the user is blocked from accessing the app. |
Max OS version |
This setting specifies the action to take when the OS version on a device exceeds a
maximum version that you specify. Select any of the following actions and specify the
maximum OS version that must be exceeded before the action is executed on the device:
Specify the OS version in the format [major].[minor], [major].[minor].[build], or [major].[minor].[build].[revision]. |
Disabled account |
This setting specifies the action to take if the user's account is disabled in
Entra ID:
|
Device model(s) |
This setting specifies the iOS/iPadOS device models that are allowed and the action
to take if a user tries to access a protected app using a device model that is not
allowed:
Specify the device models by iOS/iPadOS Model Identifiers separated by semicolons
(for example, |
Max allowed device threat level |
This setting specifies the maximum risk level that is allowed (Secured, Low, Medium,
or High), as determined by your integrated Mobile Threat Defense service. If the
specified risk level is exceeded, an enforcement action is executed on the device:
|
Primary MTD service |
This setting specifies the security service that is the primary source for device health status: Microsoft Defender for Endpoint or Mobile Threat Defense (Non-Microsoft). |
Non-working time |
This setting specifies the action to take if a user accesses protected apps outside
of scheduled working hours, and requires integration with the Working Time API. The
available options for actions are:
|