iOS: Microsoft Intune app protection profile settings

These settings correspond to Intune app protection policy settings. If you want more information about a setting, see the Microsoft Intune documentation.

Intune app protection profile setting

Description

Encrypt app data

This setting specifies when app data is encrypted.
  • When device is locked: This option encrypts all app data when the device is locked.
  • When device is locked and files are open: This option encrypts app data when the device is locked. Data in open files is not encrypted.
  • After device restart: This option encrypts app data when the device is restarted until the device is unlocked for the first time.
  • Use device settings: This option encrypts app data according to the default settings on the device. This option requires users to set a password on the device.

Prevent iTunes and iCloud backups

This setting specifies whether app data can be backed up to iTunes or iCloud.

App package IDs

This setting specifies the package IDs of the apps that this profile applies to. You can enter the package ID or select from the list of available Intune-managed apps.

Restrict web content transfer with other apps

This setting specifies which browser opens web links in apps.

  • Any app: The user can choose which app opens the web link.
  • Intune Managed Browser: Web links can open in any browser managed by Intune.
  • Microsoft Edge: Web links open in Microsoft Edge.
  • BlackBerry Access: Web links open in BlackBerry Access.
  • Unmanaged browser: Specify the browser protocol (for example, http or https) that must be used to open web links. Web links can open in any browser that supports the protocol and is not managed by Intune.

Allow Face ID instead of PIN

This setting specifies whether the user is allowed to use Face ID to access the app instead of using their PIN.

Transfer messaging data to

This setting specifies whether protected messaging data can be transferred by any messaging app, a specific messaging app (you must provide the messaging app URL scheme, for example, sms), or if messaging data cannot be transferred between apps.

Enter universal links to exempt

This setting specifies universal links to open in a specified unmanaged app instead of the protected browser specified in "Restrict web content transfer with other apps". Follow the format of the target app (you may need the app vendor's format). Wildcards are supported, as allowed by Intune. Note that misconfigured links can increase the risk of data exfiltration.

Enter managed universal links

This setting specifies universal links to open in a specified managed app instead of the protected browser specified in "Restrict web content transfer with other apps". Intune will try to open the policy-managed target app if possible, and if it cannot, the behavior will fall back to your defined protected browser. Follow the format of the target app.

Genmoji

This setting specifies whether to allow or block Genmoji.

Screen capture

This setting specifies whether to allow or block screen capture.

Writing Tools

This setting specifies whether to allow or block Writing Tools.

Org data notifications

This setting specifies how Org data is shared through OS notifications:
  • Block: Don't share notifications.
  • Block org data: Org data is not shared in notifications.
  • Allow: Org data is shared in notifications.

Require minimum iOS version

Select this setting to specify a minimum iOS version to use this app. If the iOS version on the device does not meet the requirement, the user can't use the app.

You can specify a single decimal point (for example, 12.0).

Require minimum iOS version (Warning only)

Select this setting to specify a minimum recommended iOS version to use this app. If the iOS version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify a single decimal point (for example, 12.0).

Require minimum app version

Select this setting to specify a minimum app version to use this app. If the app version on the device does not meet the requirement, the user can't use the app.

You can specify a single decimal point (for example, 4.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Require minimum app version (Warning only)

Select this setting to specify a minimum recommended app version to use this app. If the app version on the device does not meet the requirement, the user receives a notification that can be dismissed.

You can specify a single decimal point (for example, 4.2).

Because different apps usually have distinct versioning schemes, if you want to specify a minimum app version, you should create a separate profile for each app.

Require minimum SDK version

This setting specifies the minimum Intune SDK version that is required from an app. If the SDK version does not meet the requirement, the user is blocked from accessing the app.

Max OS version

This setting specifies the action to take when the OS version on a device exceeds a maximum version that you specify. Select any of the following actions and specify the maximum OS version that must be exceeded before the action is executed on the device:
  • Block access: Blocks access to protected apps.
  • Wipe data: The user account that is associated with the application is wiped from the device.
  • Warn: Warns the user but allows access.

Specify the OS version in the format [major].[minor], [major].[minor].[build], or [major].[minor].[build].[revision].

Disabled account

This setting specifies the action to take if the user's account is disabled in Entra ID:
  • Block access: Blocks access to protected apps.
  • Wipe data: Removes all organization data associated with the account from the device.

Device model(s)

This setting specifies the iOS/iPadOS device models that are allowed and the action to take if a user tries to access a protected app using a device model that is not allowed:
  • Block access: Blocks access to protected apps.
  • Wipe data: Removes all organization data associated with the account from the device.

Specify the device models by iOS/iPadOS Model Identifiers separated by semicolons (for example, iPhone16,1;iPad14,3).

Max allowed device threat level

This setting specifies the maximum risk level that is allowed (Secured, Low, Medium, or High), as determined by your integrated Mobile Threat Defense service. If the specified risk level is exceeded, an enforcement action is executed on the device:
  • Block access: Blocks access to protected apps.
  • Wipe data: Removes all organization data associated with the account from the device.

Primary MTD service

This setting specifies the security service that is the primary source for device health status: Microsoft Defender for Endpoint or Mobile Threat Defense (Non-Microsoft).

Non-working time

This setting specifies the action to take if a user accesses protected apps outside of scheduled working hours, and requires integration with the Working Time API. The available options for actions are:
  • Block access: The user cannot open the app outside of the defined working time period.
  • Warn: The user is allowed access to the app but receives a notification about accessing the app outside of a defined working time period.