1620 - Microsoft Intune supported attributes: Android app protection policy

Modified on Wed, 6 Aug at 12:15 PM

 

Attribute

Description

Backed up

Restorable

allowedAndroidDeviceManufacturersSemicolon-separated list of device manufacturers allowed, as a string, for the managed app to work.YesYes
allowedAndroidDeviceModelsList of device models allowed, as a string, for the managed app to work.YesYes
allowedDataIngestionLocationsData storage locations where a user may store managed data. Inherited from managedAppProtectionYesYes
allowedDataStorageLocationsData storage locations where a user may store managed data. Inherited from managedAppProtectionYesYes
allowedInboundDataTransferSourcesSources from which data is allowed to be transferred. Inherited from managedAppProtectionYesYes
allowedOutboundClipboardSharingExceptionLengthNumber of characters that may be cut or copied from company data and accounts to any application.YesYes
allowedOutboundClipboardSharingLevelThe level to which the clipboard may be shared between apps on the managed device. Inherited from managedAppProtection.YesYes
allowedOutboundDataTransferDestinationsDestinations to which data is allowed to be transferred. Inherited from managedAppProtection.YesYes
appActionIfAccountIsClockedOutDefines a managed app behavior, either block or warn, if the user is clocked out (non-working time).YesYes
appActionIfAndroidDeviceManufacturerNotAllowedDefines a managed app behavior, either block or wipe, if the specified device manufacturer is not allowed.YesYes
appActionIfAndroidDeviceModelNotAllowedDefines a managed app behavior, either block or wipe, if the specified device model is not allowed.YesYes
appActionIfAndroidSafetyNetAppsVerificationFailedDefines a managed app behavior, either warn or block, if the specified Android app verification requirement fails.YesYes
appActionIfAndroidSafetyNetDeviceAttestationFailedDefines a managed app behavior, either warn or block, if the specified Android SafetyNet Attestation requirement fails.YesYes
appActionIfDeviceComplianceRequiredDefines a managed app behavior, either block or wipe, when the device is either rooted or jailbroken (if deviceComplianceRequired is set to true).YesYes
appActionIfDeviceLockNotSetDefines a managed app behavior, either warn, block or wipe, if the screen lock is required on Android device but is not set. YesYes
appActionIfDevicePasscodeComplexityLessThanHighDefines the action to be triggered if the device does not have a passcode of high complexity or higher.YesYes
appActionIfDevicePasscodeComplexityLessThanLowDefines the action to be triggered if the device does not have a passcode of low complexity or higher.YesYes
appActionIfDevicePasscodeComplexityLessThanMediumDefines the action to be triggered if the device does not have a passcode of medium complexity or higher.YesYes
appActionIfMaximumPinRetriesExceededDefines a managed app behavior, either block or wipe, based on maximum number of incorrect pin retry attempts. Inherited from managedAppProtection.YesYes
appActionIfSamsungKnoxAttestationRequiredDefines the behavior of a managed app when Samsung Knox Attestation is required.YesYes
appActionIfUnableToAuthenticateUserSpecifies what action to take in the case where the user is unable to check in because their authentication token is invalid because the user has been deleted or disabled.YesYes
appGroupTypePublic apps selection: group or individual. Inherited from targetedManagedAppProtection.YesYes
approvedKeyboardsSpecified which keyboards are allowed if keyboardsRestricted is enabled.YesYes
biometricAuthenticationBlockedIndicates whether use of the biometric authentication is allowed in place of a pin if pinRequired is set to True.YesYes
blockAfterCompanyPortalUpdateDeferralInDaysMaximum number of days the Company Portal update can be deferred on the device before app access will be blocked.YesYes
blockDataIngestionIntoOrganizationDocumentsIndicates whether a user can bring data into org documents. Inherited from managedAppProtectionYesYes
connectToVpnOnLaunchIndicates whether the app should connect to the configured VPN on launch.YesYes
contactSyncBlockedIndicates whether contacts can be synced to the user's device. Inherited from managedAppProtectionYesYes
createdDateTimeThe date and time the policy was created. Inherited from managedAppPolicyYesYes
customBrowserDisplayNameFriendly name of the preferred custom browser to open weblink on Android.YesYes
customBrowserPackageIdUnique identifier of the preferred custom browser to open internet links on Android.YesYes
customDialerAppDisplayNameFriendly name of a custom dialer app to click-to-open a phone number on Android.YesYes
customDialerAppPackageIdPackageId of a custom dialer app to click-to-open a phone number on Android.YesYes
dataBackupBlockedIndicates whether the backup of a managed app's data is blocked. Inherited from managedAppProtectionYesYes
deployedAppCountNumber of apps to which the current policy is deployed.YesYes
descriptionDescription of the policy. Inherited from managedAppPolicyYesYes
deviceComplianceRequiredIndicates whether device compliance is required. Inherited from managedAppProtectionYesYes
deviceLockRequiredDefines if any kind of lock must be required on Android devices.YesYes
dialerRestrictionLevelLists the classes of dialer apps that are allowed to click-to-open a phone number. Inherited from managedAppProtection.YesYes
disableAppEncryptionIfDeviceEncryptionIsEnabledWhen this setting is enabled, app level encryption is disabled if device level encryption is enabled.YesYes
disableAppPinIfDevicePinIsSetIndicates whether use of the app pin is required if the device pin is set. Inherited from managedAppProtectionYesYes
displayNamePolicy display name. Inherited from managedAppPolicyYesYes
encryptAppDataIndicates whether application data for managed apps should be encrypted.YesYes
exemptedAppPackagesLists the app packages that are exempt from the policy and will be able to receive data from managed apps.YesYes
fingerprintAndBiometricEnabledIf null, this setting will be ignored. If false, both fingerprint and biometrics will be disabled. If true, both fingerprint and biometrics will be enabled.YesYes
fingerprintBlockedIndicates whether use of the fingerprint reader is allowed in place of a pin if pinRequired is set to True. Inherited from managedAppProtectionYesYes
gracePeriodToBlockAppsDuringOffClockHoursSpecifies the grace period before app access is blocked during off clock hours. Inherited from managedAppProtectionYesYes
idKey of the entity. Inherited from managedAppPolicyYesNo
isAssignedIndicates whether the policy is deployed to any inclusion groups. Inherited from targetedManagedAppProtectionYesYes
keyboardsRestrictedIndicates if keyboard restriction is enabled.YesYes
lastModifiedDateTimeLast time the policy was modified. Inherited from managedAppPolicyYesYes
managedBrowserIndicates in which managed browser(s) internet links should be opened.YesYes
managedBrowserToOpenLinksRequiredIndicates whether internet links should be opened in the managed browser app or any custom browser specified by CustomBrowserProtocol (for iOS) or CustomBrowserPackageId / CustomBrowserDisplayName (for Android) Inherited from managedAppProtectionYesYes
maximumAllowedDeviceThreatLevelMaximum allowed device threat level, as reported by the mobile threat defense app Inherited from managedAppProtection.YesYes
maximumPinRetriesMaximum number of incorrect pin retry attempts before the managed app is either blocked or wiped. Inherited from managedAppProtectionYesYes
maximumRequiredOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
maximumWarningOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
maximumWipeOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
messagingRedirectAppDisplayNameDefines the app that is allowed when a redirection is enforced by protectedMessagingRedirectAppType.YesYes
messagingRedirectAppPackageIdDefines the app package id that is allowed when a redirection is enforced by protectedMessagingRedirectAppType.YesYes
minimumPinLengthMinimum pin length required for an app-level pin if pinRequired is set to True. Inherited from managedAppProtectionYesYes
minimumRequiredAppVersionVersions lower than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
minimumRequiredCompanyPortalVersionMinimum version of the Company Portal that must be installed on the device or app.YesYes
minimumRequiredOsVersionVersions lower than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
minimumRequiredPatchVersionOldest required Android security patch level a user can have to gain secure access to the app.YesYes
minimumWarningAppVersionVersions lower than the specified version will result in a warning message on the managed app. Inherited from managedAppProtectionYesYes
minimumWarningCompanyPortalVersionMinimum version of the Company Portal that must be installed on the device.YesYes
minimumWarningOsVersionVersions lower than the specified version will result in a warning message on the managed app. Inherited from managedAppProtectionYesYes
minimumWarningPatchVersionOldest recommended Android security patch level a user can have for secure access to the app.YesYes
minimumWipeAppVersionVersions lower than or equal to the specified version will wipe the managed app and the associated company data. Inherited from managedAppProtectionYesYes
minimumWipeCompanyPortalVersionMinimum version of the Company Portal that must be installed on the device otherwise the company data on the app will be wiped.YesYes
minimumWipeOsVersionVersions lower than or equal to the specified version will wipe the managed app and the associated company data. Inherited from managedAppProtectionYesYes
minimumWipePatchVersionAndroid security patch level lower than or equal to the specified value will wipe the managed app and the associated company data.YesYes
mobileThreatDefensePartnerPriorityIndicates how to prioritise which mobile threat defense partner is enabled for a given platform, when more than one is enabled. YesYes
mobileThreatDefenseRemediationActionDetermines what action to take if the mobile threat defense threat threshold isn't met.YesYes
notificationRestrictionSpecifies the level of restriction for app notifications. Inherited from managedAppProtection.YesYes
organizationalCredentialsRequiredIndicates whether organisational credentials are required for app use. Inherited from managedAppProtectionYesYes
periodBeforePinResetSpecifies the time period before the all-level pin must be reset if pinRequired is set to True. Inherited from managedAppProtectionYesYes
periodOfflineBeforeAccessCheckSpecifies the time period after which access is checked when the device is not connected to the internet. Inherited from managedAppProtectionYesYes
periodOfflineBeforeWipeIsEnforcedSpecifies the time period an app is allowed to remain disconnected from the internet before all managed data is wiped. Inherited from managedAppProtectionYesYes
periodOnlineBeforeAccessCheckSpecifies the time period after which access is checked when the device is connected to the internet. Inherited from managedAppProtectionYesYes
pinCharacterSetCharacter set which may be used for an app-level pin if pinRequired is set to True. Inherited from managedAppProtection. YesYes
pinRequiredIndicates whether an app-level pin is required. Inherited from managedAppProtectionYesYes
pinRequiredInsteadOfBiometricTimeoutTimeout in minutes for an app pin when required instead of a non-biometric passcode. Inherited from managedAppProtectionYesYes
previousPinBlockCountRequires a pin to be unique from the number specified in this property. Inherited from managedAppProtectionYesYes
printBlockedIndicates whether printing is allowed from managed apps. Inherited from managedAppProtectionYesYes
protectedMessagingRedirectAppTypeDefines how app messaging redirection is protected by an app protection policy. Inherited from managedAppProtection.YesYes
requireClass3BiometricsRequires the user to apply Class 3 biometrics on their Android device.YesYes
requiredAndroidSafetyNetAppsVerificationTypeDefines the Android SafetyNet app verification requirement for a managed app to work.YesYes
requiredAndroidSafetyNetDeviceAttestationTypeDefines the Android SafetyNet Device Attestation requirement for a managed app to workYesYes
requiredAndroidSafetyNetEvaluationTypeDefines the Android SafetyNet evaluation type requirement for a managed app to work.YesYes
requirePinAfterBiometricChangeSpecifies that a PIN prompt will override biometric prompts if Class 3 biometrics are updated on the device.YesYes
roleScopeTagIdsList of scope tags for this entity instance. Inherited from managedAppPolicyYesYes
saveAsBlockedIndicates whether users may use the "Save As" menu item to save a copy of protected files. Inherited from managedAppProtectionYesYes
screenCaptureBlockedIndicates whether a managed user can take screen captures of managed apps.YesYes
simplePinBlockedIndicates whether simplePin is blocked. Inherited from managedAppProtectionYesYes
targetedAppManagementLevelsThe intended app management levels for this policy. Inherited from targetedManagedAppProtection.YesYes
versionVersion of the entity. Inherited from managedAppPolicyYesYes
warnAfterCompanyPortalUpdateDeferralInDaysMaximum number of days a Company Portal update can be deferred on the device before the user receives a warning.YesYes
wipeAfterCompanyPortalUpdateDeferralInDaysMaximum number of days a Company Portal update can be deferred on the device before company data on the app is wiped.YesYes

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article