1592 - Microsoft Intune supported attributes: Windows 10+

Modified on Mon, 21 Jul at 1:03 PM

Supported attributes: Windows 10+

AttributeDescriptionBacked upRestorable
activeFirewallRequiredRequire active firewall on Windows devices.YesYes
antiSpywareRequiredRequire any antispyware solution registered with Windows Security Center to be on and monitoring.YesYes
antivirusRequiredRequire any antivirus solution registered with Windows Security Center to be on and monitoring.YesYes
bitLockerEnabledRequire devices to be reported healthy by Windows Device Health Attestation - Bitlocker is enabledYesYes
codeIntegrityEnabledRequire devices to be reported as healthy by Windows Device Health Attestation.YesYes
configurationManagerComplianceRequiredRequire taking SCCM compliance state into consideration for Intune compliance stateYesYes
createdDateTimeDateTime the object was created. Inherited from deviceCompliancePolicyYesYes
defenderEnabledRequire Windows Defender Antimalware on Windows devices.YesYes
defenderVersionRequire Windows Defender Antimalware minimum version on Windows devices.YesYes
descriptionAdmin-provided description of the device configuration. Inherited from deviceCompliancePolicyYesYes
deviceCompliancePolicyScript>deviceComplianceScriptIdDevice compliance script Id.YesYes
deviceCompliancePolicyScript>RulesContentJSON file of the rules, encoded binaryYesYes
deviceThreatProtectionEnabledRequire devices to have device threat protection enabled.YesYes
deviceThreatProtectionRequiredSecurityLevelRequire device threat protection minimum risk level to report noncompliance.YesYes
displayNameAdmin-provided name of the device configuration. Inherited from deviceCompliancePolicyYesYes
earlyLaunchAntiMalwareDriverEnabledRequire devices to be reported as healthy by Windows Device Health Attestation - early launch antimalware driver is enabled.YesYes
firmwareProtectionEnabledWhen TRUE, indicates that Firmware protection is required to be reported as healthy. Default value is FALSE.YesYes
idKey of the entity. Inherited from deviceCompliancePolicyYes No
kernelDmaProtectionEnabledWhen TRUE, indicates that Kernel Direct Memory Access (DMA) protection is required to be reported as healthy  Default value is FALSE.YesYes
lastModifiedDateTimeDateTime the object was last modified. Inherited from deviceCompliancePolicyYesYes
memoryIntegrityEnabledWhen TRUE, indicates that Memory Integrity is required to be reported as healthy. Default value is FALSE.YesYes
mobileOsMaximumVersionMaximum Windows Phone version.YesYes
mobileOsMinimumVersionMinimum Windows Phone version.YesYes
osMaximumVersionMaximum Windows 10 version.YesYes
osMinimumVersionMinimum Windows 10 version.YesYes
passwordBlockSimpleIndicates whether or not to block simple passwords.YesYes
passwordExpirationDaysPassword expiration in days.YesYes
passwordMinimumCharacterSetCountNumber of character sets required in the password.YesYes
passwordMinimumLengthMinimum password length.YesYes
passwordMinutesOfInactivityBeforeLockMinutes of inactivity before a password is required.YesYes
passwordPreviousPasswordBlockCountNumber of previous passwords to prevent re-use of.YesYes
passwordRequiredRequire a password to unlock Windows devices.YesYes
passwordRequiredToUnlockFromIdleRequire a password to unlock an idle device.YesYes
passwordRequiredTypeRequired password type. YesYes
requireHealthyDeviceReportRequire devices to be reported as healthy by Windows Device Health Attestation.YesYes
roleScopeTagIdsList of scope tags for this entity instance. Inherited from deviceCompliancePolicyYesYes
rtpEnabledRequire Windows Defender Antimalware Real-Time Protection on Windows devices.YesYes
secureBootEnabledRequire devices to be reported as healthy by Windows Device Health Attestation - secure boot is enabled.YesYes
signatureOutOfDateRequire Windows Defender Antimalware Signature to be up to date on Windows devices.YesYes
storageRequireEncryptionRequire encryption on Windows devices.YesYes
tpmRequiredRequire Trusted Platform Module(TPM) to be present.YesYes
validOperatingSystemBuildRangesValid operating system build ranges on Windows devices. YesYes
validOperatingSystemBuildRanges>descriptionThe description of valid operating system build range.YesYes
validOperatingSystemBuildRanges>highestVersionHighest inclusive versionin valid operating system build range.YesYes
validOperatingSystemBuildRanges>lowestVersionLowest inclusive version in valid operating system build range.YesYes
versionVersion of the device configuration. Inherited from deviceCompliancePolicyYesYes
virtualizationBasedSecurityEnabledWhen TRUE, indicates that Virtualization-based Security is required to be reported as healthy. Default value is FALSE.YesYes
wslDistributionsSettings relating to Linux distributions installed on managed Windows devices.YesYes
wslDistributions>distributionLinux distributions e.g. Debian, Fedora, Ubuntu.YesYes
wslDistributions>maximumOSVersionMaximum supported Linux operating system version.YesYes
wslDistributions>minimumOSVersionMinimum supported Linux operating system version.YesYes

 

 

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article