iOS: Microsoft Intune app protection profile settings

These settings correspond to Intune app protection policy settings. If you want more information about a setting, see the Microsoft Intune documentation.

Intune app protection profile setting

Description

Encrypt app data

This setting specifies when app data is encrypted.

  • When device is locked: This option encrypts all app data when the device is locked.
  • When device is locked and files are open: This option encrypts app data when the device is locked. Data in open files is not encrypted
  • After device restart: This option encrypts app data when the device is restarted until the device is unlocked for the first time.
  • Use device settings: This option encrypts app data according to the default settings on the device. This option requires users to set a password on the device.

Prevent iTunes and iCloud backups

This setting specifies whether app data can be backed up to iTunes or iCloud.

App package IDs

This setting specifies the package IDs of the apps that this profile applies to. You can enter the package ID or select from the list of available Intune-managed apps.

Restrict web content transfer with other apps

This setting specifies which browser opens web links in apps.

  • Any app: The user can choose which app opens the web link.
  • Intune Managed Browser: Web links can open in any browser managed by Intune.
  • Microsoft Edge: Web links open in Microsoft Edge.
  • BlackBerry Access: Web links open in BlackBerry Access.
  • Unmanaged browser: Web links can open in any browser not managed by Intune. You must specify the protocol used to open web links.

Unmanaged browser protocol

Specify the browser protocol that must be used to open web links, for example http or https. Web links can open in any browser that supports the protocol.

Require minimum iOS version

Select this setting to specify a minimum iOS version to use this app. If the iOS version on the device does not meet the requirement, the user can't use the app.

You can specify a single decimal point (for example, 12.0).

Require minimum iOS version (Warning only)

Select this setting to specify a minimum recommended iOS version to use this app. If the iOS version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify a single decimal point (for example, 12.0).

Require minimum app version

Select this setting to specify a minimum app version to use this app. If the app version on the device does not meet the requirement, the user can't use the app.

You can specify a single decimal point (for example, 4.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Require minimum app version (Warning only)

Select this setting to specify a minimum recommended app version to use this app. If the app version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify a single decimal point (for example, 4.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Minimum SDK version

This setting specifies the minimum Intune SDK version that is required from an app. If the SDK version does not meet the requirement, the user is blocked from accessing the app.

Face ID instead of PIN for access

This setting specifies whether the user is allowed to use Face ID to access the app instead of using their PIN.