Android: Microsoft Intune app protection profile settings

These settings correspond to Intune app protection policy settings. If you want more information about a setting, see the Microsoft Intune documentation.

Intune app protection profile setting

Description

Encrypt app data

This setting specifies whether app data is encrypted. If you select this rule, app data is encrypted synchronously during all file input and output tasks.

Prevent Android backups

This setting specifies whether app data can be backed up to the Android Backup Service.

Block screen capture and Android Assistant

This setting specifies whether screen capture and Android Assistant app scanning capabilities are allowed when using a protected app.

App package IDs

This setting specifies the package IDs of the apps that this profile applies to. You can enter the package ID or select from the list of available Intune-managed apps.

Restrict web content transfer with other apps

This setting specifies which browser opens web links in apps.

  • Any app: The user can choose which app opens the web link.
  • Intune Managed Browser: Web links can open in any browser managed by Intune.
  • Microsoft Edge: Web links open in Microsoft Edge.
  • BlackBerry Access: Web links open in BlackBerry Access.
  • Unmanaged browser: Specify a browser not managed by Intune that opens web links. Specify the app package ID and name for the browser that opens web links. If the user doesn't have the app installed, this name appears in the notification informing users to install the app.

Transfer messaging data to

This setting specifies whether protected messaging data can be transferred by any messaging app, a specific messaging app (you must provide the messaging app package ID and app name), any policy-managed messaging app, or if messaging data cannot be transferred between apps.

Transfer telecommunications data to

This setting specifies whether telecommunications data can be transferred by any dialer app, a specific dialer app (you must provide the dialer app package ID and app name), any policy-managed dialer app, or if telecommunications data cannot be transferred between apps.

Restrict keyboards to an approved list

This setting specifies the approved keyboard apps that users can use with protected apps. Other keyboard apps are not allowed for use with protected apps. You must provide the package ID and display name for each approved keyboard app. If you enable this setting, you must add at least one approved keyboard app.

Org data notifications

This setting specifies how Org data is shared through OS notifications:
  • Block: Don't share notifications.
  • Block org data: Org data is not shared in notifications.
  • Allow: Org data is shared in notifications.

Require Class 3 biometrics

This setting specifies whether users are required to sign in with class 3 biometrics. If you want to force users to use their PIN to sign in after biometric updates, select the "Override biometrics with PIN after biometric updates" check box.

Select number of previous PIN values to maintain

This setting specifies how many previous PIN values are retained. Retained PIN values cannot be reused.

Disable app encryption

This setting specifies whether app encryption is disabled if device encryption is enabled.

Require minimum Android version

Select this setting to specify a minimum Android version to use this app. If the Android version on the device does not meet the requirement, the user can't use the app.

You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2).

Require minimum Android version (Warning only)

Select this setting to specify a minimum recommended Android version to use this app. If the Android version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2).

Require minimum Android patch version

Select this setting to specify a minimum Android patch version to use this app. If the Android patch version on the device does not meet the requirement, the user can't use the app.

Specify the version using the date format YYYY-MM-DD.

Require minimum Android patch version (Warning only)

Select this setting to specify a minimum recommended Android patch version to use this app. If the Android patch version on the device does not meet the requirement, the user receives a notification that can be dismissed.

Specify the version using the date format YYYY-MM-DD.

Require minimum app version

Select this setting to specify a minimum app version to use this app. If the app version on the device does not meet the requirement, the user can't use the app.

You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Require minimum app version (Warning only)

Select this setting to specify a minimum recommended app version to use this app. If the app version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify up to four release identifiers. Separate release identifiers with periods (for example, 10.3 or 10.3.14.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Max OS version

This setting specifies the action to take when the OS version on a device exceeds a maximum version that you specify. Select any of the following actions and specify the maximum OS version that must be exceeded before the action is executed on the device:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account that is associated with the application is wiped from the device.
  • Warn: Warn the user but allow access.

Specify versions in the format [major].[minor] (for example, 16.0 or 16.1).

Restrict access by device manufacturer

This setting specifies whether access to protected apps is allowed only by devices from allowed manufacturers. Specify allowed manufacturers by OEM/manufacturer names, separated by semi-colons (for example: Google;Samsung). Select the enforcement action to execute if a user tries to access a protected app from a non-approved manufacturer:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account that is associated with the application is wiped from the device.

Require Play integrity verdict

This setting specifies the Google Play Integrity verdict that is required before the user can access protected apps. Select the minimum verdict required and the action to execute if that minimum verdict is not met:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account that is associated with the application is wiped from the device.
  • Warn: Warns the user but allows access.

Require threat scan on apps

This setting specifies whether Google app scanning must be turned on on the user's device before they can access protected apps. Select the action to execute if Google app scanning is not enabled:
  • Block access: Blocks access to protected apps.
  • Warn: Warns the user but allows access.

Require device lock

This setting specifies whether the device must have a screen lock mechanism (PIN, pattern, or password) in place before the user can access protected apps. When you enable, select the applicable complexity levels and the action to take if the complexity requirement is not met:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account associated with the app is wiped from the device.
  • Warn: Warns the user but allows access.

Minimum Company Portal version

This setting specifies the minimum version of Company Portal that must be present on the device. When enabled, you select any of the following actions and specify the minimum version in any of the following formats: [major].[minor], [major].[minor].[build], or [major].[minor].[build].[revision]:
  • Block access below version
  • Wipe managed data below version
  • Warn below version

Maximum Company Portal version age

This setting specifies the maximum age of Company Portal, in days (0 to 365), that is allowed before an enforcement action is executed. The purpose of this setting is to ensure that users are in a permitted range of Company Portal releases. When enabled, you select any of the following actions and specify the maximum age in days:
  • Block access when older than (days)
  • Wipe managed data when older than (days)
  • Warn when older than (days)

Samsung Knox device attestation

This setting specifies whether the Samsung Knox device attestation check is required for the user to access protected apps, and the action to execute if attestation requirements are not met:
  • Warn: Warns the user but allows access.
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account associated with the app is wiped from the device.
  • Block access on supported devices: Block access to protected apps, but only for Samsung devices with Android 15 or later with One UI 7.0 or later.

Max allowed device threat level

This setting specifies the maximum risk level that is allowed (Secured, Low, Medium, or High), as determined by your integrated Mobile Threat Defense service, before an enforcement action is executed on the device:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account associated with the app is wiped from the device.

Primary MTD service

This setting specifies the security service that is the primary source for device health status: Microsoft Defender for Endpoint or Mobile Threat Defense (Non-Microsoft).

Disabled account

This setting specifies the action to take if the user's account is disabled in Entra ID:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account associated with the app is wiped from the device.

Non-working time

This setting specifies the action to take if a user accesses protected apps outside of scheduled working hours, and requires integration with the Working Time API. The available options for actions are:
  • Block access: The user cannot open the app outside of the defined working time period.
  • Warn: The user is allowed access to the app but receives a notification about accessing the app outside of a defined working time period.