Skip to content

IntuneAppProtectionPolicyAndroid

Parameters

Parameter Attribute DataType Description Allowed Values
DisplayName Key String Display name of the Android App Protection Policy.
Description Write String Description of the Android App Protection Policy.
RoleScopeTagIds Write String[] List of Scope Tags for this Entity instance.
AllowedAndroidDeviceManufacturers Write String Semicolon separated list of device manufacturers allowed, as a string, for the managed app to work.
AllowedAndroidDeviceModels Write String[] List of allowed Android device models.
AllowedOutboundClipboardSharingExceptionLength Write UInt32 Maximum length of outbound clipboard sharing exceptions.
BiometricAuthenticationBlocked Write Boolean Indicates whether biometric authentication is blocked.
BlockAfterCompanyPortalUpdateDeferralInDays Write UInt32 Number of days to block access after a company portal update deferral.
BlockDataIngestionIntoOrganizationDocuments Write Boolean Indicates whether data ingestion into organization documents is blocked.
ConnectToVpnOnLaunch Write Boolean Indicates whether to connect to VPN on launch.
CustomDialerAppDisplayName Write String Display name of the custom dialer app.
CustomDialerAppPackageId Write String Package ID of the custom dialer app.
DeviceLockRequired Write Boolean Indicates whether device lock is required.
FingerprintAndBiometricEnabled Write Boolean Indicates whether fingerprint and biometric authentication are enabled.
KeyboardsRestricted Write Boolean Indicates whether keyboards are restricted.
MessagingRedirectAppDisplayName Write String Display name of the messaging redirect app.
MessagingRedirectAppPackageId Write String Package ID of the messaging redirect app.
MinimumWipeAppVersion Write String Versions less than the specified version will wipe the managed app and the associated company data.
MinimumWipeCompanyPortalVersion Write String Minimum version of the Company portal that must be installed on the device or the company data on the app will be wiped
MinimumWipeOsVersion Write String Versions less than the specified version will wipe the managed app and the associated company data.
MinimumWipePatchVersion Write String Minimum required patch version for wipe.
PreviousPinBlockCount Write UInt32 Number of previous PIN block counts.
WarnAfterCompanyPortalUpdateDeferralInDays Write UInt32 Number of days to warn after a company portal update deferral.
WipeAfterCompanyPortalUpdateDeferralInDays Write UInt32 Number of days to wipe after a company portal update deferral.
Alloweddataingestionlocations Write String[] Sources from which data is allowed to be transferred.
AppActionIfAccountIsClockedOut Write String Defines a managed app behavior, either block or warn, if the user is clocked out (non-working time). Possible values are: block, wipe, warn, blockWhenSettingIsSupported. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfAndroidDeviceManufacturerNotAllowed Write String Defines a managed app behavior, either block or wipe, if the specified device manufacturer is not allowed. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfAndroidDeviceModelNotAllowed Write String Defines a managed app behavior, either block or wipe, if the specified device model is not allowed. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfAndroidSafetyNetAppsVerificationFailed Write String Defines a managed app behavior, either warn or block, if the specified Android App Verification requirement fails. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfAndroidSafetyNetDeviceAttestationFailed Write String Defines a managed app behavior, either warn or block, if the specified Android SafetyNet Attestation requirement fails. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfDeviceComplianceRequired Write String Defines a managed app behavior, either block or wipe, when the device is either rooted or jailbroken, if DeviceComplianceRequired is set to true. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfDeviceLockNotSet Write String Defines a managed app behavior, either warn, block, or wipe, if the screen lock is required on an Android device but is not set. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfDevicePasscodeComplexityLessThanHigh Write String If the device does not have a passcode of high complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfDevicePasscodeComplexityLessThanLow Write String If the device does not have a passcode of low complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfDevicePasscodeComplexityLessThanMedium Write String If the device does not have a passcode of medium complexity or higher, trigger the stored action. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfMaximumPinRetriesExceeded Write String Defines a managed app behavior, either block or wipe, based on the maximum number of incorrect pin retry attempts. block, wipe, warn, blockWhenSettingIsSupported
AppActionIfSamsungKnoxAttestationRequired Write String Defines the behavior of a managed app when Samsung Knox Attestation is required. Possible values are null, warn, block & wipe. If the admin does not set this action, the default is null, which indicates this setting is not configured. Possible values are: block, wipe, warn, blockWhenSettingIsSupported. block, wipe, warn, blockWhenSettingIsSupported
appActionIfUnableToAuthenticateUser Write String Specifies what action to take in the case where the user is unable to check in because their authentication token is invalid, such as when the user is deleted or disabled in Azure AD. block, wipe, warn, BlockWhenSettingIsSupported
MobileThreatDefensePartnerPriority Write String Indicates how to prioritize which Mobile Threat Defense (MTD) partner is enabled for a given platform, when more than one is enabled. An app can only be actively using a single Mobile Threat Defense partner. When NULL, Microsoft Defender will be given preference. Otherwise setting the value to defenderOverThirdPartyPartner or thirdPartyPartnerOverDefender will make explicit which partner to prioritize. Possible values are: null, defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender and unknownFutureValue. Default value is null. Possible values are: defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender, unknownFutureValue. defenderOverThirdPartyPartner, thirdPartyPartnerOverDefender
MobileThreatDefenseRemediationAction Write String Determines what action to take if the mobile threat defense threat threshold isn't met. Warn isn't a supported value for this property. block, wipe, warn, blockWhenSettingIsSupported
DialerRestrictionLevel Write String The classes of dialer apps that are allowed to click-to-open a phone number. Inherited from managedAppProtection. allApps, managedApps, customApp, blocked
MaximumAllowedDeviceThreatLevel Write String Maximum allowed device threat level, as reported by the MTD app. Inherited from managedAppProtection. notConfigured, secured, low, medium, high
NotificationRestriction Write String Specify app notification restriction. Inherited from managedAppProtection. allow, blockOrganizationalData, block
ProtectedMessagingRedirectAppType Write String Defines how app messaging redirection is protected by an App Protection Policy. Default is anyApp. Inherited from managedAppProtection. anyApp, anyManagedApp, specificApps, blocked
PurviewContentEvaluationRequired Write String Determines whether a Microsoft Purview content evaluation is required. The possible values are: notRequired, requiredWhenOnline, required. notRequired, requiredWhenOnline, required
RequiredAndroidSafetyNetAppsVerificationType Write String Defines the Android SafetyNet Apps Verification requirement for a managed app to work. none, enabled
RequiredAndroidSafetyNetDeviceAttestationType Write String Defines the Android SafetyNet Device Attestation requirement for a managed app to work. none, basicIntegrity, basicIntegrityAndDeviceCertification
RequiredAndroidSafetyNetEvaluationType Write String Defines the Android SafetyNet evaluation type requirement for a managed app to work. basic, hardwareBacked
TargetedAppManagementLevels Write String The intended app management levels for this policy. Inherited from targetedManagedAppProtection. unspecified, unmanaged, mdm, androidEnterprise, androidEnterpriseDedicatedDevicesWithAzureAdSharedMode, androidOpenSourceProjectUserAssociated, androidOpenSourceProjectUserless, unknownFutureValue
ApprovedKeyboards Write String[] If Keyboard Restriction is enabled, only keyboards in this approved list will be allowed. A key should be Android package id for a keyboard and value should be a friendly name.
ExemptedAppPackages Write String[] App packages in this list will be exempt from the policy and will be able to receive data from managed apps.
GracePeriodToBlockAppsDuringOffClockHours Write String A grace period before blocking app access during off clock hours.
PeriodOfflineBeforeAccessCheck Write String The period after which access is checked when the device is not connected to the internet. Must be an ISO8601 timespan format.
PeriodOnlineBeforeAccessCheck Write String The period after which access is checked when the device is connected to the internet. Must be an ISO8601 timespan format.
PinRequiredInsteadOfBiometricTimeout Write String Timeout in minutes for an app pin instead of non biometrics passcode
AllowedInboundDataTransferSources Write String Sources from which data is allowed to be transferred. Possible values are: allApps, managedApps, none. allApps, managedApps, none
AllowedOutboundDataTransferDestinations Write String Destinations to which data is allowed to be transferred. Possible values are: allApps, managedApps, none. allApps, managedApps, none
OrganizationalCredentialsRequired Write Boolean Indicates whether organizational credentials are required for app use.
AllowedOutboundClipboardSharingLevel Write String The level to which the clipboard may be shared between apps on the managed device. Possible values are: allApps, managedAppsWithPasteIn, managedApps, blocked. allApps, managedAppsWithPasteIn, managedApps, blocked
DataBackupBlocked Write Boolean Indicates whether the backup of a managed app's data is blocked.
DeviceComplianceRequired Write Boolean Indicates whether device compliance is required.
ManagedBrowserToOpenLinksRequired Write Boolean Indicates whether internet links should be opened in the managed browser app, or any custom browser specified by CustomBrowserProtocol (for Android) or CustomBrowserPackageId/CustomBrowserDisplayName (for Android).
SaveAsBlocked Write Boolean Indicates whether users may use the Save As menu item to save a copy of protected files.
PeriodOfflineBeforeWipeIsEnforced Write String The amount of time an app is allowed to remain disconnected from the internet before all managed data it is wiped. Must be an ISO8601 timespan format.
PinRequired Write Boolean Indicates whether an app-level pin is required.
DisableAppPinIfDevicePinIsSet Write Boolean Indicates whether use of the app pin is required if the device pin is set.
MaximumPinRetries Write UInt32 Maximum number of incorrect pin retry attempts before the managed app is either blocked or wiped.
SimplePinBlocked Write Boolean Block simple PIN and require complex PIN to be set.
MinimumPinLength Write UInt32 Minimum pin length required for an app-level pin if PinRequired is set to True.
PinCharacterSet Write String Character set which may be used for an app-level pin if PinRequired is set to True. Possible values are: numeric, alphanumericAndSymbol. numeric, alphanumericAndSymbol
AllowedDataStorageLocations Write String[] Data storage locations where a user may store managed data.
ContactSyncBlocked Write Boolean Indicates whether contacts can be synced to the user's device.
PeriodBeforePinReset Write String TimePeriod before the all-level pin must be reset if PinRequired is set to True. Must be an ISO8601 timespan format.
PrintBlocked Write Boolean Indicates whether printing is allowed from managed apps.
RequireClass3Biometrics Write Boolean Require user to apply Class 3 Biometrics on their Android device.
RequirePinAfterBiometricChange Write Boolean A PIN prompt will override biometric prompts if class 3 biometrics are updated on the device.
FingerprintBlocked Write Boolean Indicates whether use of the fingerprint reader is allowed in place of a pin if PinRequired is set to True.
Apps Write String[] List of IDs representing the Android apps controlled by this protection policy.
Assignments Write MSFT_DeviceManagementConfigurationPolicyAssignments[] Assignments of the Android Protection Policy.
Ensure Write String Present ensures the policy exists, absent ensures it is removed. Present, Absent
Credential Write PSCredential Credentials of the Intune Admin
ApplicationId Write String ID of the Azure Active Directory application to authenticate with.
TenantId Write String ID of the Azure Active Directory tenant used for authentication.
ApplicationSecret Write PSCredential Secret of the Azure Active Directory tenant used for authentication.
CertificateThumbprint Write String Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
ManagedBrowser Write String Indicates in which managed browser(s) that internet links should be opened. Used in conjunction with CustomBrowserPackageId, CustomBrowserDisplayName and ManagedBrowserToOpenLinksRequired. Possible values are: notConfigured, microsoftEdge. notConfigured, microsoftEdge
MaximumRequiredOsVersion Write String Versions bigger than the specified version will block the managed app from accessing company data.
MaximumWarningOsVersion Write String Versions bigger than the specified version will block the managed app from accessing company data.
MaximumWipeOsVersion Write String Versions bigger than the specified version will block the managed app from accessing company data.
MinimumRequiredAppVersion Write String Versions less than the specified version will block the managed app from accessing company data.
MinimumRequiredCompanyPortalVersion Write String Minimum version of the Company portal that must be installed on the device or app access will be blocked
MinimumRequiredOSVersion Write String Versions less than the specified version will block the managed app from accessing company data.
MinimumRequiredPatchVersion Write String Versions less than the specified version will block the managed app from accessing company data.
MinimumWarningAppVersion Write String Versions less than the specified version will result in warning message on the managed app
MinimumWarningCompanyPortalVersion Write String Minimum version of the Company portal that must be installed on the device or the user will receive a warning
MinimumWarningOSVersion Write String Versions less than the specified version will result in warning message on the managed app
MinimumWarningPatchVersion Write String Versions less than the specified version will result in warning message on the managed app
AppGroupType Write String The apps controlled by this protection policy, overrides any values in Apps unless this value is 'selectedPublicApps'. allApps, allMicrosoftApps, allCoreMicrosoftApps, selectedPublicApps
ScreenCaptureBlocked Write Boolean Indicates whether or not to Block the user from taking Screenshots.
EncryptAppData Write Boolean Indicates whether or not the 'Encrypt org data' value is enabled. True = require
DisableAppEncryptionIfDeviceEncryptionIsEnabled Write Boolean Indicates whether or not the 'Encrypt org data on enrolled devices' value is enabled. False = require. Only functions if EncryptAppData is set to True
CustomBrowserDisplayName Write String The application name for browser associated with the 'Unmanaged Browser ID'. This name will be displayed to users if the specified browser is not installed.
CustomBrowserPackageId Write String The application ID for a single browser. Web content (http/s) from policy managed applications will open in the specified browser.
Id Write String Id of the Intune policy. To avoid creation of duplicate policies DisplayName will be searched for if the ID is not found
AccessTokens Write String[] Access token used for authentication.

Embedded Instances

MSFT_DeviceManagementConfigurationPolicyAssignments

Parameters

Parameter Attribute DataType Description Allowed Values
dataType Required String The type of the target assignment. #microsoft.graph.cloudPcManagementGroupAssignmentTarget, #microsoft.graph.groupAssignmentTarget, #microsoft.graph.allLicensedUsersAssignmentTarget, #microsoft.graph.allDevicesAssignmentTarget, #microsoft.graph.exclusionGroupAssignmentTarget, #microsoft.graph.configurationManagerCollectionAssignmentTarget
deviceAndAppManagementAssignmentFilterType Write String The type of filter of the target assignment i.e. Exclude or Include. Possible values are:none, include, exclude. none, include, exclude
deviceAndAppManagementAssignmentFilterId Write String The Id of the filter for the target assignment.
deviceAndAppManagementAssignmentFilterDisplayName Write String The display name of the filter for the target assignment.
groupId Write String The group Id that is the target of the assignment.
groupDisplayName Write String The group Display Name that is the target of the assignment.
collectionId Write String The collection Id that is the target of the assignment.(ConfigMgr)

Description

This resource configures an Intune app protection policy for an Android Device.

Permissions

Graph

To authenticate with the Graph API, this resource requires the following permissions:

Delegated permissions

  • Read
  • GroupMember.Read.All, DeviceManagementApps.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • GroupMember.Read.All, DeviceManagementApps.ReadWrite.All, DeviceManagementRBAC.Read.All

Application permissions

  • Read
  • GroupMember.Read.All, DeviceManagementApps.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • GroupMember.Read.All, DeviceManagementApps.ReadWrite.All, DeviceManagementRBAC.Read.All

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
        {
            DisplayName                                        = 'Android App Protection - Corporate'
            AllowedAndroidDeviceManufacturers                  = 'Samsung;Google;Motorola'
            AllowedAndroidDeviceModels                         = @('SM-G991B', 'SM-A546B', 'Pixel 8')
            Alloweddataingestionlocations                      = @('oneDriveForBusiness', 'sharePoint', 'camera', 'photoLibrary')
            AllowedDataStorageLocations                        = @('oneDriveForBusiness', 'sharePoint')
            AllowedInboundDataTransferSources                  = 'managedApps'
            AllowedOutboundClipboardSharingExceptionLength     = 0
            AllowedOutboundClipboardSharingLevel               = 'managedAppsWithPasteIn'
            AllowedOutboundDataTransferDestinations            = 'managedApps'
            AppActionIfAccountIsClockedOut                     = 'warn'
            AppActionIfAndroidDeviceManufacturerNotAllowed     = 'block'
            AppActionIfAndroidDeviceModelNotAllowed            = 'block'
            AppActionIfAndroidSafetyNetAppsVerificationFailed  = 'block'
            AppActionIfAndroidSafetyNetDeviceAttestationFailed = 'block'
            AppActionIfDeviceComplianceRequired                = 'block'
            AppActionIfDeviceLockNotSet                        = 'block'
            AppActionIfDevicePasscodeComplexityLessThanHigh    = 'warn'
            AppActionIfDevicePasscodeComplexityLessThanLow     = 'block'
            AppActionIfDevicePasscodeComplexityLessThanMedium  = 'warn'
            AppActionIfMaximumPinRetriesExceeded               = 'block'
            AppActionIfSamsungKnoxAttestationRequired          = 'warn'
            appActionIfUnableToAuthenticateUser                = 'block'
            AppGroupType                                       = 'selectedPublicApps'
            ApprovedKeyboards                                  = @('com.google.android.inputmethod.latin|Gboard', 'com.samsung.android.honeyboard|Samsung Keyboard')
            Apps                                               = @('com.microsoft.emmx', 'com.microsoft.office.outlook', 'com.microsoft.skydrive', 'com.microsoft.teams')
            Assignments                                        = @(
                MSFT_DeviceManagementConfigurationPolicyAssignments{
                    dataType                                   = '#microsoft.graph.groupAssignmentTarget'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    groupDisplayName                           = 'Field Technicians'
                    groupId                                    = '3f7e6d2a-8b45-4c19-9f0e-1a2b3c4d5e6f'
                }
                MSFT_DeviceManagementConfigurationPolicyAssignments{
                    dataType                                   = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    groupDisplayName                           = 'Mobile Application Management Exclusions'
                    groupId                                    = '9c4b1e07-52da-4f83-a6d1-7e8f9a0b1c2d'
                }
            )
            BiometricAuthenticationBlocked                     = $false
            BlockAfterCompanyPortalUpdateDeferralInDays        = 60
            BlockDataIngestionIntoOrganizationDocuments        = $true
            ConnectToVpnOnLaunch                               = $false
            ContactSyncBlocked                                 = $false
            CustomBrowserDisplayName                           = 'Contoso Secure Browser'
            CustomBrowserPackageId                             = 'com.contoso.securebrowser'
            CustomDialerAppDisplayName                         = 'Contoso Softphone'
            CustomDialerAppPackageId                           = 'com.contoso.softphone'
            DataBackupBlocked                                  = $true
            Description                                        = 'Protects company data in the Android apps used by field technicians'
            DeviceComplianceRequired                           = $true
            DeviceLockRequired                                 = $true
            DialerRestrictionLevel                             = 'customApp'
            DisableAppEncryptionIfDeviceEncryptionIsEnabled    = $false
            DisableAppPinIfDevicePinIsSet                      = $false
            EncryptAppData                                     = $true
            ExemptedAppPackages                                = @('com.android.chrome|Google Chrome', 'com.google.android.apps.maps|Google Maps')
            FingerprintAndBiometricEnabled                     = $true
            FingerprintBlocked                                 = $false
            GracePeriodToBlockAppsDuringOffClockHours          = 'PT1H'
            KeyboardsRestricted                                = $true
            ManagedBrowser                                     = 'notConfigured'
            ManagedBrowserToOpenLinksRequired                  = $true
            MaximumAllowedDeviceThreatLevel                    = 'medium'
            MaximumPinRetries                                  = 5
            MaximumRequiredOsVersion                           = '15.0'
            MaximumWarningOsVersion                            = '15.0'
            MaximumWipeOsVersion                               = '16.0'
            MessagingRedirectAppDisplayName                    = 'Contoso Secure Messenger'
            MessagingRedirectAppPackageId                      = 'com.contoso.securemessenger'
            MinimumPinLength                                   = 6
            MinimumRequiredAppVersion                          = '16.0'
            MinimumRequiredCompanyPortalVersion                = '5.0.5484.0'
            MinimumRequiredOSVersion                           = '11.0'
            MinimumRequiredPatchVersion                        = '2023-01-01'
            MinimumWarningAppVersion                           = '16.5'
            MinimumWarningCompanyPortalVersion                 = '5.0.5545.0'
            MinimumWarningOSVersion                            = '12.0'
            MinimumWarningPatchVersion                         = '2024-01-01'
            MinimumWipeAppVersion                              = '15.0'
            MinimumWipeCompanyPortalVersion                    = '5.0.5333.0'
            MinimumWipeOsVersion                               = '10.0'
            MinimumWipePatchVersion                            = '2022-01-01'
            MobileThreatDefensePartnerPriority                 = 'defenderOverThirdPartyPartner'
            MobileThreatDefenseRemediationAction               = 'block'
            NotificationRestriction                            = 'blockOrganizationalData'
            OrganizationalCredentialsRequired                  = $false
            PeriodBeforePinReset                               = 'P90D'
            PeriodOfflineBeforeAccessCheck                     = 'PT12H'
            PeriodOfflineBeforeWipeIsEnforced                  = 'P90D'
            PeriodOnlineBeforeAccessCheck                      = 'PT30M'
            PinCharacterSet                                    = 'numeric'
            PinRequired                                        = $true
            PinRequiredInsteadOfBiometricTimeout               = 'PT30M'
            PreviousPinBlockCount                              = 5
            PrintBlocked                                       = $true
            ProtectedMessagingRedirectAppType                  = 'specificApps'
            PurviewContentEvaluationRequired                   = 'requiredWhenOnline'
            RequireClass3Biometrics                            = $true
            RequiredAndroidSafetyNetAppsVerificationType       = 'enabled'
            RequiredAndroidSafetyNetDeviceAttestationType      = 'basicIntegrityAndDeviceCertification'
            RequiredAndroidSafetyNetEvaluationType             = 'hardwareBacked'
            RequirePinAfterBiometricChange                     = $true
            RoleScopeTagIds                                    = @('0')
            SaveAsBlocked                                      = $true
            ScreenCaptureBlocked                               = $true
            SimplePinBlocked                                   = $true
            TargetedAppManagementLevels                        = 'unspecified'
            WarnAfterCompanyPortalUpdateDeferralInDays         = 30
            WipeAfterCompanyPortalUpdateDeferralInDays         = 90
            Ensure                                             = 'Present'
            ApplicationId                                      = $ApplicationId;
            TenantId                                           = $TenantId;
            CertificateThumbprint                              = $CertificateThumbprint;
        }
    }
}

Example 2

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
        {
            DisplayName                                        = 'Android App Protection - Corporate'
            AllowedAndroidDeviceManufacturers                  = 'Samsung;Google;Motorola'
            AllowedAndroidDeviceModels                         = @('SM-G991B', 'SM-A546B', 'Pixel 8')
            Alloweddataingestionlocations                      = @('oneDriveForBusiness', 'sharePoint', 'camera', 'photoLibrary')
            AllowedDataStorageLocations                        = @('oneDriveForBusiness', 'sharePoint')
            AllowedInboundDataTransferSources                  = 'managedApps'
            AllowedOutboundClipboardSharingExceptionLength     = 0
            AllowedOutboundClipboardSharingLevel               = 'managedAppsWithPasteIn'
            AllowedOutboundDataTransferDestinations            = 'managedApps'
            AppActionIfAccountIsClockedOut                     = 'warn'
            AppActionIfAndroidDeviceManufacturerNotAllowed     = 'block'
            AppActionIfAndroidDeviceModelNotAllowed            = 'block'
            AppActionIfAndroidSafetyNetAppsVerificationFailed  = 'block'
            AppActionIfAndroidSafetyNetDeviceAttestationFailed = 'block'
            AppActionIfDeviceComplianceRequired                = 'block'
            AppActionIfDeviceLockNotSet                        = 'block'
            AppActionIfDevicePasscodeComplexityLessThanHigh    = 'warn'
            AppActionIfDevicePasscodeComplexityLessThanLow     = 'block'
            AppActionIfDevicePasscodeComplexityLessThanMedium  = 'warn'
            AppActionIfMaximumPinRetriesExceeded               = 'block'
            AppActionIfSamsungKnoxAttestationRequired          = 'warn'
            appActionIfUnableToAuthenticateUser                = 'block'
            AppGroupType                                       = 'selectedPublicApps'
            ApprovedKeyboards                                  = @('com.google.android.inputmethod.latin|Gboard', 'com.samsung.android.honeyboard|Samsung Keyboard')
            Apps                                               = @('com.microsoft.emmx', 'com.microsoft.office.outlook', 'com.microsoft.skydrive', 'com.microsoft.teams')
            Assignments                                        = @(
                MSFT_DeviceManagementConfigurationPolicyAssignments{
                    dataType                                   = '#microsoft.graph.groupAssignmentTarget'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    groupDisplayName                           = 'Field Technicians'
                    groupId                                    = '3f7e6d2a-8b45-4c19-9f0e-1a2b3c4d5e6f'
                }
                MSFT_DeviceManagementConfigurationPolicyAssignments{
                    dataType                                   = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    groupDisplayName                           = 'Mobile Application Management Exclusions'
                    groupId                                    = '9c4b1e07-52da-4f83-a6d1-7e8f9a0b1c2d'
                }
            )
            BiometricAuthenticationBlocked                     = $false
            BlockAfterCompanyPortalUpdateDeferralInDays        = 60
            BlockDataIngestionIntoOrganizationDocuments        = $true
            ConnectToVpnOnLaunch                               = $false
            ContactSyncBlocked                                 = $true # Updated Property
            CustomBrowserDisplayName                           = 'Contoso Secure Browser'
            CustomBrowserPackageId                             = 'com.contoso.securebrowser'
            CustomDialerAppDisplayName                         = 'Contoso Softphone'
            CustomDialerAppPackageId                           = 'com.contoso.softphone'
            DataBackupBlocked                                  = $true
            Description                                        = 'Protects company data in the Android apps used by field technicians'
            DeviceComplianceRequired                           = $true
            DeviceLockRequired                                 = $true
            DialerRestrictionLevel                             = 'customApp'
            DisableAppEncryptionIfDeviceEncryptionIsEnabled    = $false
            DisableAppPinIfDevicePinIsSet                      = $false
            EncryptAppData                                     = $true
            ExemptedAppPackages                                = @('com.android.chrome|Google Chrome', 'com.google.android.apps.maps|Google Maps')
            FingerprintAndBiometricEnabled                     = $true
            FingerprintBlocked                                 = $false
            GracePeriodToBlockAppsDuringOffClockHours          = 'PT1H'
            KeyboardsRestricted                                = $true
            ManagedBrowser                                     = 'notConfigured'
            ManagedBrowserToOpenLinksRequired                  = $true
            MaximumAllowedDeviceThreatLevel                    = 'medium'
            MaximumPinRetries                                  = 5
            MaximumRequiredOsVersion                           = '15.0'
            MaximumWarningOsVersion                            = '15.0'
            MaximumWipeOsVersion                               = '16.0'
            MessagingRedirectAppDisplayName                    = 'Contoso Secure Messenger'
            MessagingRedirectAppPackageId                      = 'com.contoso.securemessenger'
            MinimumPinLength                                   = 6
            MinimumRequiredAppVersion                          = '16.0'
            MinimumRequiredCompanyPortalVersion                = '5.0.5484.0'
            MinimumRequiredOSVersion                           = '11.0'
            MinimumRequiredPatchVersion                        = '2023-01-01'
            MinimumWarningAppVersion                           = '16.5'
            MinimumWarningCompanyPortalVersion                 = '5.0.5545.0'
            MinimumWarningOSVersion                            = '12.0'
            MinimumWarningPatchVersion                         = '2024-01-01'
            MinimumWipeAppVersion                              = '15.0'
            MinimumWipeCompanyPortalVersion                    = '5.0.5333.0'
            MinimumWipeOsVersion                               = '10.0'
            MinimumWipePatchVersion                            = '2022-01-01'
            MobileThreatDefensePartnerPriority                 = 'defenderOverThirdPartyPartner'
            MobileThreatDefenseRemediationAction               = 'block'
            NotificationRestriction                            = 'blockOrganizationalData'
            OrganizationalCredentialsRequired                  = $false
            PeriodBeforePinReset                               = 'P90D'
            PeriodOfflineBeforeAccessCheck                     = 'PT12H'
            PeriodOfflineBeforeWipeIsEnforced                  = 'P90D'
            PeriodOnlineBeforeAccessCheck                      = 'PT30M'
            PinCharacterSet                                    = 'numeric'
            PinRequired                                        = $true
            PinRequiredInsteadOfBiometricTimeout               = 'PT30M'
            PreviousPinBlockCount                              = 5
            PrintBlocked                                       = $true
            ProtectedMessagingRedirectAppType                  = 'specificApps'
            PurviewContentEvaluationRequired                   = 'requiredWhenOnline'
            RequireClass3Biometrics                            = $true
            RequiredAndroidSafetyNetAppsVerificationType       = 'enabled'
            RequiredAndroidSafetyNetDeviceAttestationType      = 'basicIntegrityAndDeviceCertification'
            RequiredAndroidSafetyNetEvaluationType             = 'hardwareBacked'
            RequirePinAfterBiometricChange                     = $true
            RoleScopeTagIds                                    = @('0')
            SaveAsBlocked                                      = $true
            ScreenCaptureBlocked                               = $true
            SimplePinBlocked                                   = $true
            TargetedAppManagementLevels                        = 'unspecified'
            WarnAfterCompanyPortalUpdateDeferralInDays         = 30
            WipeAfterCompanyPortalUpdateDeferralInDays         = 90
            Ensure                                             = 'Present'
            ApplicationId                                      = $ApplicationId;
            TenantId                                           = $TenantId;
            CertificateThumbprint                              = $CertificateThumbprint;
        }
    }
}

Example 3

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneAppProtectionPolicyAndroid 'IntuneAppProtectionPolicyAndroid-Example'
        {
            DisplayName           = 'Android App Protection - Corporate'
            Ensure                = 'Absent'
            ApplicationId         = $ApplicationId;
            TenantId              = $TenantId;
            CertificateThumbprint = $CertificateThumbprint;
        }
    }
}