Skip to content

IntuneMobileAppsLobAppWindows10

Parameters

Parameter Attribute DataType Description Allowed Values
DisplayName Key String The admin provided or imported title of the app.
Id Write String The unique identifier for an entity. Read-only.
FileName Write String The name of the main Lob application file. Required for creating the resource.
Description Write String The description of the app.
Developer Write String The developer of the app.
InformationUrl Write String The more information Url.
IsFeatured Write Boolean The value indicating whether the app is marked as featured by the admin.
LargeIcon Write MSFT_DeviceManagementMimeContent The large icon, to be displayed in the app details and used for upload of the icon.
Notes Write String Notes for the app.
Owner Write String The owner of the app.
PrivacyInformationUrl Write String The privacy statement Url.
Publisher Write String The publisher of the app.
RoleScopeTagIds Write String[] List of scope tag ids for this mobile app.
Categories Write MSFT_DeviceManagementMobileAppCategory[] The list of categories for this app.
MinimumSupportedOperatingSystem Write MSFT_MicrosoftGraphWindowsMinimumOperatingSystem The value for the minimum applicable Windows operating system.
Assignments Write MSFT_DeviceManagementAppxMobileAppAssignment[] Represents the assignment to the Intune policy.
Ensure Write String Present ensures the policy exists, absent ensures it is removed. Present, Absent
Credential Write PSCredential Credentials of the Admin
ApplicationId Write String Id of the Azure Active Directory application to authenticate with.
TenantId Write String Id of the Azure Active Directory tenant used for authentication.
ApplicationSecret Write PSCredential Secret of the Azure Active Directory tenant used for authentication.
CertificateThumbprint Write String Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
AccessTokens Write String[] Access token used for authentication.

Embedded Instances

MSFT_DeviceManagementMimeContent

Parameters

Parameter Attribute DataType Description Allowed Values
Type Write String Indicates the type of content mime.
Value Write String The Base64 encoded string content.

MSFT_DeviceManagementMobileAppCategory

Parameters

Parameter Attribute DataType Description Allowed Values
DisplayName Required String The name of the app category.
Id Write String The unique identifier for an entity. Read-only.

MSFT_MicrosoftGraphWindowsMinimumOperatingSystem

Parameters

Parameter Attribute DataType Description Allowed Values
V10_0 Write Boolean Windows version 10.0 or later.
V10_1607 Write Boolean Windows 10 1607 or later.
V10_1703 Write Boolean Windows 10 1703 or later.
V10_1709 Write Boolean Windows 10 1709 or later.
V10_1803 Write Boolean Windows 10 1803 or later.
V10_1809 Write Boolean Windows 10 1809 or later.
V10_1903 Write Boolean Windows 10 1903 or later.
V10_1909 Write Boolean Windows 10 1909 or later.
V10_2004 Write Boolean Windows 10 2004 or later.
V10_21H1 Write Boolean Windows 10 21H1 or later.
V10_2H20 Write Boolean Windows 10 2H20 or later.
V8_0 Write Boolean Windows version 8.0 or later.
V8_1 Write Boolean Windows version 8.1 or later.

MSFT_DeviceManagementAppxMobileAppAssignment

Parameters

Parameter Attribute DataType Description Allowed Values
dataType Write String The type of the target assignment. #microsoft.graph.groupAssignmentTarget, #microsoft.graph.allLicensedUsersAssignmentTarget, #microsoft.graph.allDevicesAssignmentTarget, #microsoft.graph.exclusionGroupAssignmentTarget, #microsoft.graph.mobileAppAssignment
deviceAndAppManagementAssignmentFilterId Write String The Id of the filter for the target assignment.
deviceAndAppManagementAssignmentFilterDisplayName Write String The display name of the filter for the target assignment.
deviceAndAppManagementAssignmentFilterType Write String The type of filter of the target assignment i.e. Exclude or Include. Possible values are: none, include, exclude. none, include, exclude
groupId Write String The group Id that is the target of the assignment.
groupDisplayName Write String The group Display Name that is the target of the assignment.
intent Write String Possible values for the install intent chosen by the admin. available, required, uninstall, availableWithoutEnrollment
assignmentSettings Write MSFT_DeviceManagementAppxMobileAppAssignmentSettings The settings of the assignment.

MSFT_DeviceManagementAppxMobileAppAssignmentSettings

Parameters

Parameter Attribute DataType Description Allowed Values
odataType Required String The odata type of the assignment type. #microsoft.graph.androidManagedStoreAppAssignmentSettings, #microsoft.graph.iosStoreAppAssignmentSettings, #microsoft.graph.iosLobAppAssignmentSettings, #microsoft.graph.macOsLobAppAssignmentSettings, #microsoft.graph.win32LobAppAssignmentSettings, #microsoft.graph.winGetAppAssignmentSettings, #microsoft.graph.windowsUniversalAppXAppAssignmentSettings
useDeviceContext Write Boolean If true, uses device execution context for Windows Universal AppX mobile app. Device-context install is not allowed when this type of app is targeted with Available intent. Defaults to false.

Description

Intune Mobile Apps Lob App for Windows10 for Appx, AppxBundle, Msix and MsixBundle applications.

Permissions

Graph

To authenticate with the Graph API, this resource requires the following permissions:

Delegated permissions

  • Read
  • DeviceManagementApps.Read.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • DeviceManagementApps.ReadWrite.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

Application permissions

  • Read
  • DeviceManagementApps.Read.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • DeviceManagementApps.ReadWrite.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsLobAppWindows10 "IntuneMobileAppsLobAppWindows10-Example"
        {
            Description                     = "Appx App Description";
            Developer                       = "Contoso";
            DisplayName                     = "Appx App";
            Ensure                          = "Present";
            FileName                        = "Contoso.Appx_1.0.0.0_x64__contoso.appx";
            InformationUrl                  = "";
            IsFeatured                      = $False;
            Notes                           = "";
            Owner                           = "";
            PrivacyInformationUrl           = "";
            Publisher                       = "Contoso";
            MinimumSupportedOperatingSystem = MSFT_MicrosoftGraphWindowsMinimumOperatingSystem{
                V8_0     = $False
                V8_1     = $False
                V10_0    = $False
                V10_1607 = $False
                V10_1703 = $False
                V10_1709 = $False
                V10_1803 = $False
                V10_1809 = $True
                V10_1903 = $False
                V10_1909 = $False
                V10_2004 = $False
                V10_2H20 = $False
                V10_21H1 = $False
            };
            Assignments                     = @(
                MSFT_DeviceManagementAppxMobileAppAssignment {
                    groupDisplayName                           = 'All devices'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    dataType                                   = '#microsoft.graph.allDevicesAssignmentTarget'
                    intent                                     = 'required'
                    assignmentSettings                         = MSFT_DeviceManagementAppxMobileAppAssignmentSettings{
                        useDeviceContext = $true
                        odataType        = "#microsoft.graph.windowsUniversalAppXAppAssignmentSettings"
                    }
                }
                MSFT_DeviceManagementAppxMobileAppAssignment{
                    dataType         = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    groupDisplayName = 'Policy Exclusions'
                }
            );
            Categories                      = @(
                MSFT_DeviceManagementMobileAppCategory{
                    Id          = "2185c6bf-1b3d-4daa-a0bc-79cb4fad9c87"
                    DisplayName = "App Category 1"
                }
            );
            ApplicationId                   = $ApplicationId;
            TenantId                        = $TenantId;
            CertificateThumbprint           = $CertificateThumbprint;
        }
    }
}

Example 2

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsLobAppWindows10 "IntuneMobileAppsLobAppWindows10-Example"
        {
            Description                     = "Appx App Description";
            Developer                       = "Contoso";
            DisplayName                     = "Appx App";
            Ensure                          = "Present";
            FileName                        = "Contoso.Appx_1.0.0.0_x64__contoso.appx";
            InformationUrl                  = "";
            IsFeatured                      = $True; # Updated Property
            Notes                           = "";
            Owner                           = "";
            PrivacyInformationUrl           = "";
            Publisher                       = "Contoso";
            MinimumSupportedOperatingSystem = MSFT_MicrosoftGraphWindowsMinimumOperatingSystem{
                V8_0     = $False
                V8_1     = $False
                V10_0    = $False
                V10_1607 = $False
                V10_1703 = $False
                V10_1709 = $False
                V10_1803 = $False
                V10_1809 = $True
                V10_1903 = $False
                V10_1909 = $False
                V10_2004 = $False
                V10_2H20 = $False
                V10_21H1 = $False
            };
            Assignments                     = @(
                MSFT_DeviceManagementAppxMobileAppAssignment {
                    groupDisplayName                           = 'All devices'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    dataType                                   = '#microsoft.graph.allDevicesAssignmentTarget'
                    intent                                     = 'required'
                    assignmentSettings                         = MSFT_DeviceManagementAppxMobileAppAssignmentSettings{
                        useDeviceContext = $true
                        odataType        = "#microsoft.graph.windowsUniversalAppXAppAssignmentSettings"
                    }
                }
                MSFT_DeviceManagementAppxMobileAppAssignment{
                    dataType         = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    groupDisplayName = 'Policy Exclusions'
                }
            );
            Categories                      = @(
                MSFT_DeviceManagementMobileAppCategory{
                    Id          = "2185c6bf-1b3d-4daa-a0bc-79cb4fad9c87"
                    DisplayName = "App Category 1"
                }
            );
            ApplicationId                   = $ApplicationId;
            TenantId                        = $TenantId;
            CertificateThumbprint           = $CertificateThumbprint;
        }
    }
}

Example 3

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsLobAppWindows10 "IntuneMobileAppsLobAppWindows10-Example"
        {
            DisplayName           = "Appx App";
            Ensure                = "Absent";
            ApplicationId         = $ApplicationId;
            TenantId              = $TenantId;
            CertificateThumbprint = $CertificateThumbprint;
        }
    }
}