Skip to content

IntuneMobileAppsSystemAppAndroid

Parameters

Parameter Attribute DataType Description Allowed Values
AppIdentifier Required String The app identifier. Cannot be changed after creation.
DisplayName Key String The admin provided or imported title of the app.
Publisher Required String The publisher of the app.
Description Write String The description of the app.
Developer Write String The developer of the app.
InformationUrl Write String The more information Url.
IsFeatured Write Boolean The value indicating whether the app is marked as featured by the admin.
LargeIcon Write MSFT_DeviceManagementMimeContent The large icon, to be displayed in the app details and used for upload of the icon.
Notes Write String Notes for the app.
Owner Write String The owner of the app.
PrivacyInformationUrl Write String The privacy statement Url.
RoleScopeTagIds Write String[] List of scope tag ids for this mobile app.
Id Write String The unique identifier for an entity. Read-only.
Assignments Write MSFT_DeviceManagementSystemMobileAppAssignment[] Represents the assignment to the Intune policy.
Ensure Write String Present ensures the policy exists, absent ensures it is removed. Present, Absent
Credential Write PSCredential Credentials of the Admin
ApplicationId Write String Id of the Azure Active Directory application to authenticate with.
TenantId Write String Id of the Azure Active Directory tenant used for authentication.
ApplicationSecret Write PSCredential Secret of the Azure Active Directory tenant used for authentication.
CertificateThumbprint Write String Thumbprint of the Azure Active Directory application's authentication certificate to use for authentication.
CertificatePassword Write PSCredential Username can be made up to anything but password will be used for CertificatePassword
CertificatePath Write String Path to certificate used in service principal usually a PFX file.
ManagedIdentity Write Boolean Managed ID being used for authentication.
AccessTokens Write String[] Access token used for authentication.

Embedded Instances

MSFT_DeviceManagementMimeContent

Parameters

Parameter Attribute DataType Description Allowed Values
Type Write String Indicates the type of content mime.
Value Write String The Base64 encoded string content.

MSFT_DeviceManagementSystemMobileAppAssignment

Parameters

Parameter Attribute DataType Description Allowed Values
dataType Write String The type of the target assignment. #microsoft.graph.groupAssignmentTarget, #microsoft.graph.allLicensedUsersAssignmentTarget, #microsoft.graph.allDevicesAssignmentTarget, #microsoft.graph.exclusionGroupAssignmentTarget, #microsoft.graph.mobileAppAssignment
deviceAndAppManagementAssignmentFilterId Write String The Id of the filter for the target assignment.
deviceAndAppManagementAssignmentFilterDisplayName Write String The display name of the filter for the target assignment.
deviceAndAppManagementAssignmentFilterType Write String The type of filter of the target assignment i.e. Exclude or Include. Possible values are: none, include, exclude. none, include, exclude
groupId Write String The group Id that is the target of the assignment.
groupDisplayName Write String The group Display Name that is the target of the assignment.
intent Write String Possible values for the install intent chosen by the admin. available, required, uninstall, availableWithoutEnrollment
assignmentSettings Write MSFT_DeviceManagementSystemMobileAppAssignmentSettings The settings of the assignment.

MSFT_DeviceManagementSystemMobileAppAssignmentSettings

Parameters

Parameter Attribute DataType Description Allowed Values
odataType Required String The odata type of the assignment type. #microsoft.graph.androidManagedStoreAppAssignmentSettings, #microsoft.graph.iosStoreAppAssignmentSettings, #microsoft.graph.iosLobAppAssignmentSettings, #microsoft.graph.macOsLobAppAssignmentSettings, #microsoft.graph.win32LobAppAssignmentSettings, #microsoft.graph.winGetAppAssignmentSettings, #microsoft.graph.windowsUniversalAppXAppAssignmentSettings
androidManagedStoreAppTrackIds Write String[] The track IDs to enable for this app assignment.
autoUpdateMode Write String The prioritization of automatic updates for this app assignment. The possible values are: default, postponed, priority, unknownFutureValue. default, postponed, priority

Description

Intune Mobile Apps System App for Android

Permissions

Graph

To authenticate with the Graph API, this resource requires the following permissions:

Delegated permissions

  • Read
  • DeviceManagementApps.Read.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • DeviceManagementApps.ReadWrite.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

Application permissions

  • Read
  • DeviceManagementApps.Read.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

  • Update

  • DeviceManagementApps.ReadWrite.All, GroupMember.Read.All, DeviceManagementRBAC.Read.All

Examples

Example 1

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsSystemAppAndroid "IntuneMobileAppsSystemAppAndroid-Example"
        {
            DisplayName           = "Office";
            Ensure                = "Present";
            AppIdentifier         = "com.microsoft.office";
            Publisher             = "Microsoft";
            Description           = "Microsoft Office system app preinstalled on corporate-owned Android devices";
            Developer             = "Microsoft Corporation";
            InformationUrl        = "https://intranet.contoso.com/apps/office-android";
            IsFeatured            = $true;
            LargeIcon             = MSFT_DeviceManagementMimeContent{
                Type  = "image/png"
                Value = "<base64-encoded-app-icon>"
            };
            Notes                 = "Reviewed annually by the mobility team";
            Owner                 = "Endpoint Management Team";
            PrivacyInformationUrl = "https://www.contoso.com/privacy";
            RoleScopeTagIds       = @("0")
            Assignments           = @(
                MSFT_DeviceManagementSystemMobileAppAssignment {
                    groupDisplayName                           = 'All devices'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    dataType                                   = '#microsoft.graph.allDevicesAssignmentTarget'
                    intent                                     = 'required'
                    assignmentSettings                         = MSFT_DeviceManagementSystemMobileAppAssignmentSettings{
                        odataType                      = "#microsoft.graph.androidManagedStoreAppAssignmentSettings"
                        androidManagedStoreAppTrackIds = @()
                        autoUpdateMode                 = "default"
                    }
                }
                MSFT_DeviceManagementSystemMobileAppAssignment{
                    dataType         = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    groupDisplayName = 'Policy Exclusions'
                }
            );
            ApplicationId         = $ApplicationId;
            TenantId              = $TenantId;
            CertificateThumbprint = $CertificateThumbprint;
        }
    }
}

Example 2

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsSystemAppAndroid "IntuneMobileAppsSystemAppAndroid-Example"
        {
            DisplayName           = "Office";
            Ensure                = "Present";
            AppIdentifier         = "com.microsoft.office";
            Publisher             = "Company"; # Updated Property
            Description           = "Microsoft Office system app preinstalled on corporate-owned Android devices";
            Developer             = "Microsoft Corporation";
            InformationUrl        = "https://intranet.contoso.com/apps/office-android";
            IsFeatured            = $true;
            LargeIcon             = MSFT_DeviceManagementMimeContent{
                Type  = "image/png"
                Value = "<base64-encoded-app-icon>"
            };
            Notes                 = "Reviewed annually by the mobility team";
            Owner                 = "Endpoint Management Team";
            PrivacyInformationUrl = "https://www.contoso.com/privacy";
            RoleScopeTagIds       = @("0")
            Assignments           = @(
                MSFT_DeviceManagementSystemMobileAppAssignment {
                    groupDisplayName                           = 'All devices'
                    deviceAndAppManagementAssignmentFilterType = 'none'
                    dataType                                   = '#microsoft.graph.allDevicesAssignmentTarget'
                    intent                                     = 'required'
                    assignmentSettings                         = MSFT_DeviceManagementSystemMobileAppAssignmentSettings{
                        odataType                      = "#microsoft.graph.androidManagedStoreAppAssignmentSettings"
                        androidManagedStoreAppTrackIds = @()
                        autoUpdateMode                 = "default"
                    }
                }
                MSFT_DeviceManagementSystemMobileAppAssignment{
                    dataType         = '#microsoft.graph.exclusionGroupAssignmentTarget'
                    groupDisplayName = 'Policy Exclusions'
                }
            );
            ApplicationId         = $ApplicationId;
            TenantId              = $TenantId;
            CertificateThumbprint = $CertificateThumbprint;
        }
    }
}

Example 3

This example is used to test new resources and showcase the usage of new resources being worked on. It is not meant to use as a production baseline.

Configuration Example
{
    param
    (
        [Parameter()]
        [System.String]
        $ApplicationId,

        [Parameter()]
        [System.String]
        $TenantId,

        [Parameter()]
        [System.String]
        $CertificateThumbprint
    )

    Import-DscResource -ModuleName Microsoft365DSC

    Node localhost
    {
        IntuneMobileAppsSystemAppAndroid "IntuneMobileAppsSystemAppAndroid-Example"
        {
            DisplayName           = "Office";
            AppIdentifier         = "com.microsoft.office";
            Publisher             = "Microsoft";
            Ensure                = "Absent";
            ApplicationId         = $ApplicationId;
            TenantId              = $TenantId;
            CertificateThumbprint = $CertificateThumbprint;
        }
    }
}