IntuneAppProtectionPolicyAndroid¶
Parameters¶
| Parameter | Attribute | DataType | Description | Allowed Values |
|---|---|---|---|---|
| DisplayName | Key | String | Display name of the Android App Protection Policy. | |
| Description | Write | String | Description of the Android App Protection Policy. | |
| RoleScopeTagIds | Write | String[] | List of Scope Tags for this Entity instance. | |
| AllowedAndroidDeviceManufacturers | Write | String | Semicolon separated list of device manufacturers allowed, as a string, for the managed app to work. | |
| AllowedAndroidDeviceModels | Write | String[] | List of allowed Android device models. | |
| AllowedOutboundClipboardSharingExceptionLength | Write | UInt32 | Maximum length of outbound clipboard sharing exceptions. | |
| BiometricAuthenticationBlocked | Write | Boolean | Indicates whether biometric authentication is blocked. | |
| BlockAfterCompanyPortalUpdateDeferralInDays | Write | UInt32 | Number of days to block access after a company portal update deferral. | |
| BlockDataIngestionIntoOrganizationDocuments | Write | Boolean | Indicates whether data ingestion into organization documents is blocked. | |
| ConnectToVpnOnLaunch | Write | Boolean | Indicates whether to connect to VPN on launch. | |
| CustomDialerAppDisplayName | Write | String | Display name of the custom dialer app. | |
| CustomDialerAppPackageId | Write | String | Package ID of the custom dialer app. | |
| DeviceLockRequired | Write | Boolean | Indicates whether device lock is required. | |
| FingerprintAndBiometricEnabled | Write | Boolean | Indicates whether fingerprint and biometric authentication are enabled. | |
| KeyboardsRestricted | Write | Boolean | Indicates whether keyboards are restricted. | |
| MessagingRedirectAppDisplayName | Write | String | Display name of the messaging redirect app. | |
| MessagingRedirectAppPackageId | Write | String | Package ID of the messaging redirect app. | |
| MinimumWipeAppVersion | Write | String | Versions less than the specified version will wipe the managed app and the associated company data. | |
| MinimumWipeCompanyPortalVersion | Write | String | Minimum version of the Company portal that must be installed on the device or the company data on the app will be wiped | |
| MinimumWipeOsVersion | Write | String | Versions less than the specified version will wipe the managed app and the associated company data. | |
| MinimumWipePatchVersion | Write | String | Minimum required patch version for wipe. | |
| PreviousPinBlockCount | Write | UInt32 | Number of previous PIN block counts. | |
| WarnAfterCompanyPortalUpdateDeferralInDays | Write | UInt32 | Number of days to warn after a company portal update deferral. | |
| WipeAfterCompanyPortalUpdateDeferralInDays | Write | UInt32 | Number of days to wipe after a company portal update deferral. | |
| Alloweddataingestionlocations | Write | String[] | Sources from which data is allowed to be transferred. | |
| AppActionIfAccountIsClockedOut | Write | String | Defines a managed app behavior, either block or warn, if the user is clocked out (non-working time). Possible values are: block, wipe, warn, blockWhenSettingIsSupported. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfAndroidDeviceManufacturerNotAllowed | Write | String | Defines a managed app behavior, either block or wipe, if the specified device manufacturer is not allowed. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfAndroidDeviceModelNotAllowed | Write | String | Defines a managed app behavior, either block or wipe, if the specified device model is not allowed. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfAndroidSafetyNetAppsVerificationFailed | Write | String | Defines a managed app behavior, either warn or block, if the specified Android App Verification requirement fails. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfAndroidSafetyNetDeviceAttestationFailed | Write | String | Defines a managed app behavior, either warn or block, if the specified Android SafetyNet Attestation requirement fails. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfDeviceComplianceRequired | Write | String | Defines a managed app behavior, either block or wipe, when the device is either rooted or jailbroken, if DeviceComplianceRequired is set to true. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfDeviceLockNotSet | Write | String | Defines a managed app behavior, either warn, block, or wipe, if the screen lock is required on an Android device but is not set. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfDevicePasscodeComplexityLessThanHigh | Write | String | If the device does not have a passcode of high complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfDevicePasscodeComplexityLessThanLow | Write | String | If the device does not have a passcode of low complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfDevicePasscodeComplexityLessThanMedium | Write | String | If the device does not have a passcode of medium complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfMaximumPinRetriesExceeded | Write | String | Defines a managed app behavior, either block or wipe, based on the maximum number of incorrect pin retry attempts. | block, wipe, warn, blockWhenSettingIsSupported |
| AppActionIfSamsungKnoxAttestationRequired | Write | String | Defines the behavior of a managed app when Samsung Knox Attestation is required. Possible values are null, warn, block & wipe. If the admin does not set this action, the default is null, which indicates this setting is not configured. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. | block, wipe, warn, blockWhenSettingIsSupported |
| appActionIfUnableToAuthenticateUser | Write | String | Specifies what action to take in the case where the user is unable to check in because their authentication token is invalid, such as when the user is deleted or disabled in Azure AD. | block, wipe, warn, BlockWhenSettingIsSupported |
| MobileThreatDefensePartnerPriority | Write | String | Indicates how to prioritize which Mobile Threat Defense (MTD) partner is enabled for a given platform, when more than one is enabled. An app can only be actively using a single Mobile Threat Defense partner. When NULL, Microsoft Defender will be given preference. Otherwise setting the value to defenderOverThirdPartyPartner or thirdPartyPartnerOverDefender will make explicit which partner to prioritize. Possible values are: null, defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender and unknownFutureValue. Default value is null. Possible values are: defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender, unknownFutureValue. | defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender |
| MobileThreatDefenseRemediationAction | Write | String | Determines what action to take if the mobile threat defense threat threshold isn't met. Warn isn't a supported value for this property. | block, wipe, warn, blockWhenSettingIsSupported |
| DialerRestrictionLevel | Write | String | The classes of dialer apps that are allowed to click-to-open a phone number. Inherited from managedAppProtection. | allApps, managedApps, customApp, blocked |
| MaximumAllowedDeviceThreatLevel | Write | String | Maximum allowed device threat level, as reported by the MTD app. Inherited from managedAppProtection. | notConfigured, secured, low, medium, high |
| NotificationRestriction | Write | String | Specify app notification restriction. Inherited from managedAppProtection. | allow, blockOrganizationalData, block |
| ProtectedMessagingRedirectAppType | Write | String | Defines how app messaging redirection is protected by an App Protection Policy. Default is anyApp. Inherited from managedAppProtection. | anyApp, anyManagedApp, specificApps, blocked |
| PurviewContentEvaluationRequired | Write | String | Determines whether a Microsoft Purview content evaluation is required. The possible values are: notRequired, requiredWhenOnline, required. | notRequired, requiredWhenOnline, required |
| RequiredAndroidSafetyNetAppsVerificationType | Write | String | Defines the Android SafetyNet Apps Verification requirement for a managed app to work. | none, enabled |
| RequiredAndroidSafetyNetDeviceAttestationType | Write | String | Defines the Android SafetyNet Device Attestation requirement for a managed app to work. | none, basicIntegrity, basicIntegrityAndDeviceCertification |
| RequiredAndroidSafetyNetEvaluationType | Write | String | Defines the Android SafetyNet evaluation type requirement for a managed app to work. | basic, hardwareBacked |
| TargetedAppManagementLevels | Write | String | The intended app management levels for this policy. Inherited from targetedManagedAppProtection. | unspecified, unmanaged, mdm, androidEnterprise, androidEnterpriseDedicatedDevicesWithAzureAdSharedMode, androidOpenSourceProjectUserAssociated, androidOpenSourceProjectUserless, unknownFutureValue |
| ApprovedKeyboards | Write | String[] | If Keyboard Restriction is enabled, only keyboards in this approved list will be allowed. A key should be Android package id for a keyboard and value should be a friendly name. | |
| ExemptedAppPackages | Write | String[] | App packages in this list will be exempt from the policy and will be able to receive data from managed apps. | |
| GracePeriodToBlockAppsDuringOffClockHours | Write | String | A grace period before blocking app access during off clock hours. | |
| PeriodOfflineBeforeAccessCheck | Write | String | The period after which access is checked when the device is not connected to the internet. Must be an ISO8601 timespan format. | |
| PeriodOnlineBeforeAccessCheck | Write | String | The period after which access is checked when the device is connected to the internet. Must be an ISO8601 timespan format. | |
| PinRequiredInsteadOfBiometricTimeout | Write | String | Timeout in minutes for an app pin instead of non biometrics passcode | |
| AllowedInboundDataTransferSources | Write | String | Sources from which data is allowed to be transferred. Possible values are: allApps, managedApps, none. | allApps, managedApps, none |
| AllowedOutboundDataTransferDestinations | Write | String | Destinations to which data is allowed to be transferred. Possible values are: allApps, managedApps, none. | allApps, managedApps, none |
| OrganizationalCredentialsRequired | Write | Boolean | Indicates whether organizational credentials are required for app use. | |
| AllowedOutboundClipboardSharingLevel | Write | String | The level to which the clipboard may be shared between apps on the managed device. Possible values are: allApps, managedAppsWithPasteIn, managedApps, blocked. | allApps, managedAppsWithPasteIn, managedApps, blocked |
| DataBackupBlocked | Write | Boolean | Indicates whether the backup of a managed app's data is blocked. | |
| DeviceComplianceRequired | Write | Boolean | Indicates whether device compliance is required. | |
| ManagedBrowserToOpenLinksRequired | Write | Boolean | Indicates whether internet links should be opened in the managed browser app, or any custom browser specified by CustomBrowserProtocol (for Android) or CustomBrowserPackageId/CustomBrowserDisplayName (for Android). | |
| SaveAsBlocked | Write | Boolean | Indicates whether users may use the Save As menu item to save a copy of protected files. | |
| PeriodOfflineBeforeWipeIsEnforced | Write | String | The amount of time an app is allowed to remain disconnected from the internet before all managed data it is wiped. Must be an ISO8601 timespan format. | |
| PinRequired | Write | Boolean | Indicates whether an app-level pin is required. | |
| DisableAppPinIfDevicePinIsSet | Write | Boolean | Indicates whether use of the app pin is required if the device pin is set. | |
| MaximumPinRetries | Write | UInt32 | Maximum number of incorrect pin retry attempts before the managed app is either blocked or wiped. | |
| SimplePinBlocked | Write | Boolean | Block simple PIN and require complex PIN to be set. | |
| MinimumPinLength | Write | UInt32 | Minimum pin length required for an app-level pin if PinRequired is set to True. | |
| PinCharacterSet | Write | String | Character set which may be used for an app-level pin if PinRequired is set to True. Possible values are: numeric, alphanumericAndSymbol. | numeric, alphanumericAndSymbol |
| AllowedDataStorageLocations | Write | String[] | Data storage locations where a user may store managed data. | |
| ContactSyncBlocked | Write | Boolean | Indicates whether contacts can be synced to the user's device. | |
| PeriodBeforePinReset | Write | String | TimePeriod before the all-level pin must be reset if PinRequired is set to True. Must be an ISO8601 timespan format. | |
| PrintBlocked | Write | Boolean | Indicates whether printing is allowed from managed apps. | |
| RequireClass3Biometrics | Write | Boolean | Require user to apply Class 3 Biometrics on their Android device. | |
| RequirePinAfterBiometricChange | Write | Boolean | A PIN prompt will override biometric prompts if class 3 biometrics are updated on the device. | |
| FingerprintBlocked | Write | Boolean | Indicates whether use of the fingerprint reader is allowed in place of a pin if PinRequired is set to True. | |
| Apps | Write | String[] | List of IDs representing the Android apps controlled by this protection policy. | |
| Assignments | Write | MSFT_DeviceManagementConfigurationPolicyAssignments[] | Assignments of the Android Protection Policy. | |
| Ensure | Write | String | Present ensures the policy exists, absent ensures it is removed. | Present, Absent |
| Credential | Write | PSCredential | Credentials of the Intune Admin | |
| ApplicationId | Write | String | ID of the Azure Active Directory application to authenticate with. | |
| TenantId | Write | String | ID of the Azure Active Directory tenant used for authentication. | |
| ApplicationSecret | Write | PSCredential | Secret of the Azure Active Directory tenant used for authentication. | |
| CertificateThumbprint | Write | String | Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication. | |
| CertificatePassword | Write | PSCredential | Username can be made up to anything but password will be used for CertificatePassword | |
| CertificatePath | Write | String | Path to certificate used in service principal usually a PFX file. | |
| ManagedIdentity | Write | Boolean | Managed ID being used for authentication. | |
| ManagedBrowser | Write | String | Indicates in which managed browser(s) that internet links should be opened. Used in conjunction with CustomBrowserPackageId, CustomBrowserDisplayName and ManagedBrowserToOpenLinksRequired. Possible values are: notConfigured, microsoftEdge. | notConfigured, microsoftEdge |
| MaximumRequiredOsVersion | Write | String | Versions bigger than the specified version will block the managed app from accessing company data. | |
| MaximumWarningOsVersion | Write | String | Versions bigger than the specified version will block the managed app from accessing company data. | |
| MaximumWipeOsVersion | Write | String | Versions bigger than the specified version will block the managed app from accessing company data. | |
| MinimumRequiredAppVersion | Write | String | Versions less than the specified version will block the managed app from accessing company data. | |
| MinimumRequiredCompanyPortalVersion | Write | String | Minimum version of the Company portal that must be installed on the device or app access will be blocked | |
| MinimumRequiredOSVersion | Write | String | Versions less than the specified version will block the managed app from accessing company data. | |
| MinimumRequiredPatchVersion | Write | String | Versions less than the specified version will block the managed app from accessing company data. | |
| MinimumWarningAppVersion | Write | String | Versions less than the specified version will result in warning message on the managed app | |
| MinimumWarningCompanyPortalVersion | Write | String | Minimum version of the Company portal that must be installed on the device or the user will receive a warning | |
| MinimumWarningOSVersion | Write | String | Versions less than the specified version will result in warning message on the managed app | |
| MinimumWarningPatchVersion | Write | String | Versions less than the specified version will result in warning message on the managed app | |
| AppGroupType | Write | String | The apps controlled by this protection policy, overrides any values in Apps unless this value is 'selectedPublicApps'. | allApps, allMicrosoftApps, allCoreMicrosoftApps, selectedPublicApps |
| ScreenCaptureBlocked | Write | Boolean | Indicates whether or not to Block the user from taking Screenshots. | |
| EncryptAppData | Write | Boolean | Indicates whether or not the 'Encrypt org data' value is enabled. True = require | |
| DisableAppEncryptionIfDeviceEncryptionIsEnabled | Write | Boolean | Indicates whether or not the 'Encrypt org data on enrolled devices' value is enabled. False = require. Only functions if EncryptAppData is set to True | |
| CustomBrowserDisplayName | Write | String | The application name for browser associated with the 'Unmanaged Browser ID'. This name will be displayed to users if the specified browser is not installed. | |
| CustomBrowserPackageId | Write | String | The application ID for a single browser. Web content (http/s) from policy managed applications will open in the specified browser. | |
| Id | Write | String | Id of the Intune policy. To avoid creation of duplicate policies DisplayName will be searched for if the ID is not found | |
| AccessTokens | Write | String[] | Access token used for authentication. |
Embedded Instances¶
MSFT_DeviceManagementConfigurationPolicyAssignments¶
Parameters¶
| Parameter | Attribute | DataType | Description | Allowed Values |
|---|---|---|---|---|
| dataType | Required | String | The type of the target assignment. | #microsoft.graph.cloudPcManagementGroupAssignmentTarget, #microsoft.graph.groupAssignmentTarget, #microsoft.graph.allLicensedUsersAssignmentTarget, #microsoft.graph.allDevicesAssignmentTarget, #microsoft.graph.exclusionGroupAssignmentTarget, #microsoft.graph.configurationManagerCollectionAssignmentTarget |
| deviceAndAppManagementAssignmentFilterType | Write | String | The type of filter of the target assignment i.e. Exclude or Include. Possible values are:none, include, exclude. | none, include, exclude |
| deviceAndAppManagementAssignmentFilterId | Write | String | The Id of the filter for the target assignment. | |
| deviceAndAppManagementAssignmentFilterDisplayName | Write | String | The display name of the filter for the target assignment. | |
| groupId | Write | String | The group Id that is the target of the assignment. | |
| groupDisplayName | Write | String | The group Display Name that is the target of the assignment. | |
| collectionId | Write | String | The collection Id that is the target of the assignment.(ConfigMgr) |
Description¶
This resource configures an Intune app protection policy for an Android Device.
Permissions¶
Graph¶
To authenticate with the Graph API, this resource requires the following permissions:
Delegated permissions¶
- Read
-
GroupMember.Read.All, DeviceManagementApps.Read.All, DeviceManagementRBAC.Read.All
-
Update
- GroupMember.Read.All, DeviceManagementApps.ReadWrite.All, DeviceManagementRBAC.Read.All
Application permissions¶
- Read
-
GroupMember.Read.All, DeviceManagementApps.Read.All, DeviceManagementRBAC.Read.All
-
Update
- GroupMember.Read.All, DeviceManagementApps.ReadWrite.All, DeviceManagementRBAC.Read.All
Examples¶
Example 1¶
This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.
Configuration Example
{
param
(
[Parameter()]
[System.String]
$ApplicationId,
[Parameter()]
[System.String]
$TenantId,
[Parameter()]
[System.String]
$CertificateThumbprint
)
Import-DscResource -ModuleName Microsoft365DSC
Node localhost
{
IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
{
DisplayName = 'Android App Protection - Corporate'
AllowedAndroidDeviceManufacturers = 'Samsung;Google;Motorola'
AllowedAndroidDeviceModels = @('SM-G991B', 'SM-A546B', 'Pixel 8')
Alloweddataingestionlocations = @('oneDriveForBusiness', 'sharePoint', 'camera', 'photoLibrary')
AllowedDataStorageLocations = @('oneDriveForBusiness', 'sharePoint')
AllowedInboundDataTransferSources = 'managedApps'
AllowedOutboundClipboardSharingExceptionLength = 0
AllowedOutboundClipboardSharingLevel = 'managedAppsWithPasteIn'
AllowedOutboundDataTransferDestinations = 'managedApps'
AppActionIfAccountIsClockedOut = 'warn'
AppActionIfAndroidDeviceManufacturerNotAllowed = 'block'
AppActionIfAndroidDeviceModelNotAllowed = 'block'
AppActionIfAndroidSafetyNetAppsVerificationFailed = 'block'
AppActionIfAndroidSafetyNetDeviceAttestationFailed = 'block'
AppActionIfDeviceComplianceRequired = 'block'
AppActionIfDeviceLockNotSet = 'block'
AppActionIfDevicePasscodeComplexityLessThanHigh = 'warn'
AppActionIfDevicePasscodeComplexityLessThanLow = 'block'
AppActionIfDevicePasscodeComplexityLessThanMedium = 'warn'
AppActionIfMaximumPinRetriesExceeded = 'block'
AppActionIfSamsungKnoxAttestationRequired = 'warn'
appActionIfUnableToAuthenticateUser = 'block'
AppGroupType = 'selectedPublicApps'
ApprovedKeyboards = @('com.google.android.inputmethod.latin|Gboard', 'com.samsung.android.honeyboard|Samsung Keyboard')
Apps = @('com.microsoft.emmx', 'com.microsoft.office.outlook', 'com.microsoft.skydrive', 'com.microsoft.teams')
Assignments = @(
MSFT_DeviceManagementConfigurationPolicyAssignments{
dataType = '#microsoft.graph.groupAssignmentTarget'
deviceAndAppManagementAssignmentFilterType = 'none'
groupDisplayName = 'Field Technicians'
groupId = '3f7e6d2a-8b45-4c19-9f0e-1a2b3c4d5e6f'
}
MSFT_DeviceManagementConfigurationPolicyAssignments{
dataType = '#microsoft.graph.exclusionGroupAssignmentTarget'
deviceAndAppManagementAssignmentFilterType = 'none'
groupDisplayName = 'Mobile Application Management Exclusions'
groupId = '9c4b1e07-52da-4f83-a6d1-7e8f9a0b1c2d'
}
)
BiometricAuthenticationBlocked = $false
BlockAfterCompanyPortalUpdateDeferralInDays = 60
BlockDataIngestionIntoOrganizationDocuments = $true
ConnectToVpnOnLaunch = $false
ContactSyncBlocked = $false
CustomBrowserDisplayName = 'Contoso Secure Browser'
CustomBrowserPackageId = 'com.contoso.securebrowser'
CustomDialerAppDisplayName = 'Contoso Softphone'
CustomDialerAppPackageId = 'com.contoso.softphone'
DataBackupBlocked = $true
Description = 'Protects company data in the Android apps used by field technicians'
DeviceComplianceRequired = $true
DeviceLockRequired = $true
DialerRestrictionLevel = 'customApp'
DisableAppEncryptionIfDeviceEncryptionIsEnabled = $false
DisableAppPinIfDevicePinIsSet = $false
EncryptAppData = $true
ExemptedAppPackages = @('com.android.chrome|Google Chrome', 'com.google.android.apps.maps|Google Maps')
FingerprintAndBiometricEnabled = $true
FingerprintBlocked = $false
GracePeriodToBlockAppsDuringOffClockHours = 'PT1H'
KeyboardsRestricted = $true
ManagedBrowser = 'notConfigured'
ManagedBrowserToOpenLinksRequired = $true
MaximumAllowedDeviceThreatLevel = 'medium'
MaximumPinRetries = 5
MaximumRequiredOsVersion = '15.0'
MaximumWarningOsVersion = '15.0'
MaximumWipeOsVersion = '16.0'
MessagingRedirectAppDisplayName = 'Contoso Secure Messenger'
MessagingRedirectAppPackageId = 'com.contoso.securemessenger'
MinimumPinLength = 6
MinimumRequiredAppVersion = '16.0'
MinimumRequiredCompanyPortalVersion = '5.0.5484.0'
MinimumRequiredOSVersion = '11.0'
MinimumRequiredPatchVersion = '2023-01-01'
MinimumWarningAppVersion = '16.5'
MinimumWarningCompanyPortalVersion = '5.0.5545.0'
MinimumWarningOSVersion = '12.0'
MinimumWarningPatchVersion = '2024-01-01'
MinimumWipeAppVersion = '15.0'
MinimumWipeCompanyPortalVersion = '5.0.5333.0'
MinimumWipeOsVersion = '10.0'
MinimumWipePatchVersion = '2022-01-01'
MobileThreatDefensePartnerPriority = 'defenderOverThirdPartyPartner'
MobileThreatDefenseRemediationAction = 'block'
NotificationRestriction = 'blockOrganizationalData'
OrganizationalCredentialsRequired = $false
PeriodBeforePinReset = 'P90D'
PeriodOfflineBeforeAccessCheck = 'PT12H'
PeriodOfflineBeforeWipeIsEnforced = 'P90D'
PeriodOnlineBeforeAccessCheck = 'PT30M'
PinCharacterSet = 'numeric'
PinRequired = $true
PinRequiredInsteadOfBiometricTimeout = 'PT30M'
PreviousPinBlockCount = 5
PrintBlocked = $true
ProtectedMessagingRedirectAppType = 'specificApps'
PurviewContentEvaluationRequired = 'requiredWhenOnline'
RequireClass3Biometrics = $true
RequiredAndroidSafetyNetAppsVerificationType = 'enabled'
RequiredAndroidSafetyNetDeviceAttestationType = 'basicIntegrityAndDeviceCertification'
RequiredAndroidSafetyNetEvaluationType = 'hardwareBacked'
RequirePinAfterBiometricChange = $true
RoleScopeTagIds = @('0')
SaveAsBlocked = $true
ScreenCaptureBlocked = $true
SimplePinBlocked = $true
TargetedAppManagementLevels = 'unspecified'
WarnAfterCompanyPortalUpdateDeferralInDays = 30
WipeAfterCompanyPortalUpdateDeferralInDays = 90
Ensure = 'Present'
ApplicationId = $ApplicationId;
TenantId = $TenantId;
CertificateThumbprint = $CertificateThumbprint;
}
}
}
Example 2¶
This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.
Configuration Example
{
param
(
[Parameter()]
[System.String]
$ApplicationId,
[Parameter()]
[System.String]
$TenantId,
[Parameter()]
[System.String]
$CertificateThumbprint
)
Import-DscResource -ModuleName Microsoft365DSC
Node localhost
{
IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
{
DisplayName = 'Android App Protection - Corporate'
AllowedAndroidDeviceManufacturers = 'Samsung;Google;Motorola'
AllowedAndroidDeviceModels = @('SM-G991B', 'SM-A546B', 'Pixel 8')
Alloweddataingestionlocations = @('oneDriveForBusiness', 'sharePoint', 'camera', 'photoLibrary')
AllowedDataStorageLocations = @('oneDriveForBusiness', 'sharePoint')
AllowedInboundDataTransferSources = 'managedApps'
AllowedOutboundClipboardSharingExceptionLength = 0
AllowedOutboundClipboardSharingLevel = 'managedAppsWithPasteIn'
AllowedOutboundDataTransferDestinations = 'managedApps'
AppActionIfAccountIsClockedOut = 'warn'
AppActionIfAndroidDeviceManufacturerNotAllowed = 'block'
AppActionIfAndroidDeviceModelNotAllowed = 'block'
AppActionIfAndroidSafetyNetAppsVerificationFailed = 'block'
AppActionIfAndroidSafetyNetDeviceAttestationFailed = 'block'
AppActionIfDeviceComplianceRequired = 'block'
AppActionIfDeviceLockNotSet = 'block'
AppActionIfDevicePasscodeComplexityLessThanHigh = 'warn'
AppActionIfDevicePasscodeComplexityLessThanLow = 'block'
AppActionIfDevicePasscodeComplexityLessThanMedium = 'warn'
AppActionIfMaximumPinRetriesExceeded = 'block'
AppActionIfSamsungKnoxAttestationRequired = 'warn'
appActionIfUnableToAuthenticateUser = 'block'
AppGroupType = 'selectedPublicApps'
ApprovedKeyboards = @('com.google.android.inputmethod.latin|Gboard', 'com.samsung.android.honeyboard|Samsung Keyboard')
Apps = @('com.microsoft.emmx', 'com.microsoft.office.outlook', 'com.microsoft.skydrive', 'com.microsoft.teams')
Assignments = @(
MSFT_DeviceManagementConfigurationPolicyAssignments{
dataType = '#microsoft.graph.groupAssignmentTarget'
deviceAndAppManagementAssignmentFilterType = 'none'
groupDisplayName = 'Field Technicians'
groupId = '3f7e6d2a-8b45-4c19-9f0e-1a2b3c4d5e6f'
}
MSFT_DeviceManagementConfigurationPolicyAssignments{
dataType = '#microsoft.graph.exclusionGroupAssignmentTarget'
deviceAndAppManagementAssignmentFilterType = 'none'
groupDisplayName = 'Mobile Application Management Exclusions'
groupId = '9c4b1e07-52da-4f83-a6d1-7e8f9a0b1c2d'
}
)
BiometricAuthenticationBlocked = $false
BlockAfterCompanyPortalUpdateDeferralInDays = 60
BlockDataIngestionIntoOrganizationDocuments = $true
ConnectToVpnOnLaunch = $false
ContactSyncBlocked = $true # Updated Property
CustomBrowserDisplayName = 'Contoso Secure Browser'
CustomBrowserPackageId = 'com.contoso.securebrowser'
CustomDialerAppDisplayName = 'Contoso Softphone'
CustomDialerAppPackageId = 'com.contoso.softphone'
DataBackupBlocked = $true
Description = 'Protects company data in the Android apps used by field technicians'
DeviceComplianceRequired = $true
DeviceLockRequired = $true
DialerRestrictionLevel = 'customApp'
DisableAppEncryptionIfDeviceEncryptionIsEnabled = $false
DisableAppPinIfDevicePinIsSet = $false
EncryptAppData = $true
ExemptedAppPackages = @('com.android.chrome|Google Chrome', 'com.google.android.apps.maps|Google Maps')
FingerprintAndBiometricEnabled = $true
FingerprintBlocked = $false
GracePeriodToBlockAppsDuringOffClockHours = 'PT1H'
KeyboardsRestricted = $true
ManagedBrowser = 'notConfigured'
ManagedBrowserToOpenLinksRequired = $true
MaximumAllowedDeviceThreatLevel = 'medium'
MaximumPinRetries = 5
MaximumRequiredOsVersion = '15.0'
MaximumWarningOsVersion = '15.0'
MaximumWipeOsVersion = '16.0'
MessagingRedirectAppDisplayName = 'Contoso Secure Messenger'
MessagingRedirectAppPackageId = 'com.contoso.securemessenger'
MinimumPinLength = 6
MinimumRequiredAppVersion = '16.0'
MinimumRequiredCompanyPortalVersion = '5.0.5484.0'
MinimumRequiredOSVersion = '11.0'
MinimumRequiredPatchVersion = '2023-01-01'
MinimumWarningAppVersion = '16.5'
MinimumWarningCompanyPortalVersion = '5.0.5545.0'
MinimumWarningOSVersion = '12.0'
MinimumWarningPatchVersion = '2024-01-01'
MinimumWipeAppVersion = '15.0'
MinimumWipeCompanyPortalVersion = '5.0.5333.0'
MinimumWipeOsVersion = '10.0'
MinimumWipePatchVersion = '2022-01-01'
MobileThreatDefensePartnerPriority = 'defenderOverThirdPartyPartner'
MobileThreatDefenseRemediationAction = 'block'
NotificationRestriction = 'blockOrganizationalData'
OrganizationalCredentialsRequired = $false
PeriodBeforePinReset = 'P90D'
PeriodOfflineBeforeAccessCheck = 'PT12H'
PeriodOfflineBeforeWipeIsEnforced = 'P90D'
PeriodOnlineBeforeAccessCheck = 'PT30M'
PinCharacterSet = 'numeric'
PinRequired = $true
PinRequiredInsteadOfBiometricTimeout = 'PT30M'
PreviousPinBlockCount = 5
PrintBlocked = $true
ProtectedMessagingRedirectAppType = 'specificApps'
PurviewContentEvaluationRequired = 'requiredWhenOnline'
RequireClass3Biometrics = $true
RequiredAndroidSafetyNetAppsVerificationType = 'enabled'
RequiredAndroidSafetyNetDeviceAttestationType = 'basicIntegrityAndDeviceCertification'
RequiredAndroidSafetyNetEvaluationType = 'hardwareBacked'
RequirePinAfterBiometricChange = $true
RoleScopeTagIds = @('0')
SaveAsBlocked = $true
ScreenCaptureBlocked = $true
SimplePinBlocked = $true
TargetedAppManagementLevels = 'unspecified'
WarnAfterCompanyPortalUpdateDeferralInDays = 30
WipeAfterCompanyPortalUpdateDeferralInDays = 90
Ensure = 'Present'
ApplicationId = $ApplicationId;
TenantId = $TenantId;
CertificateThumbprint = $CertificateThumbprint;
}
}
}
Example 3¶
This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.
Configuration Example
{
param
(
[Parameter()]
[System.String]
$ApplicationId,
[Parameter()]
[System.String]
$TenantId,
[Parameter()]
[System.String]
$CertificateThumbprint
)
Import-DscResource -ModuleName Microsoft365DSC
Node localhost
{
IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
{
DisplayName = 'Android App Protection - Corporate'
Ensure = 'Absent'
ApplicationId = $ApplicationId;
TenantId = $TenantId;
CertificateThumbprint = $CertificateThumbprint;
}
}
}