1622 - Microsoft Intune supported attributes: iOS app protection policy

Modified on Wed, 6 Aug at 2:44 PM

Attribute

Description

Backed up

Restorable

allowedDataIngestionLocationsData storage locations where a user may store managed data. Inherited from managedAppProtectionYesYes
allowedDataStorageLocationsData storage locations where a user may store managed data. Inherited from managedAppProtectionYesYes
allowedInboundDataTransferSourcesSources from which data is allowed to be transferred. Inherited from managedAppProtectionYesYes
allowedIosDeviceModels
Semicolon-separated list of device models allowed, as a string, for the managed app to work. (iOS only)
YesYes
allowedOutboundClipboardSharingExceptionLengthNumber of characters that may be cut or copied from Org data and accounts to any application.YesYes
allowedOutboundClipboardSharingLevelThe level to which the clipboard may be shared between apps on the managed device. Inherited from managedAppProtection.YesYes
allowedOutboundDataTransferDestinationsDestinations to which data is allowed to be transferred. Inherited from managedAppProtection.YesYes
allowWidgetContentSync
Indicates if content sync for widgets is allowed for iOS on app protection policies.
YesYes
appActionIfAccountIsClockedOutDefines a managed app behavior, either block or warn, if the user is clocked out (non-working time).YesYes
appActionIfDeviceComplianceRequiredDefines a managed app behavior, either block or wipe, when the device is either rooted or jailbroken( if DeviceComplianceRequired is set to true).YesYes
appActionIfIosDeviceModelNotAllowed
Defines a managed app behavior, either block or wipe, if the specified device model is not allowed. (iOS only)
YesYes
appActionIfMaximumPinRetriesExceededDefines a managed app behavior, either block or wipe, based on maximum number of incorrect pin retry attempts. Inherited from managedAppProtection.YesYes
appActionIfUnableToAuthenticateUserSpecifies what action to take in the case where the user is unable to check in because their authentication token is invalidbecause the user has been deleted or disabled.YesYes
appDataEncryptionTypeType of encryption which should be used for data in a managed app. (iOS only)YesYes
appGroupTypePublic apps selection: group or individual . Inherited from targetedManagedAppProtectionYesYes
blockDataIngestionIntoOrganizationDocumentsIndicates whether a user can bring data into org documents. Inherited from managedAppProtectionYesYes
contactSyncBlockedIndicates whether contacts can be synced to the user's device. Inherited from managedAppProtectionYesYes
createdDateTimeThe date and time the policy was created. Inherited from managedAppPolicyYesYes
customBrowserProtocol
A custom browser protocol to open internet links on iOS. (iOS only)
Yes
Yes
customDialerAppProtocol
Protocol of a custom dialer app to click-to-open a phone number on iOS.
Yes
Yes
dataBackupBlockedIndicates whether the backup of a managed app's data is blocked. Inherited from managedAppProtectionYesYes
deployedAppCountNumber of apps to which the current policy is deployed.YesYes
descriptionDescription of the policy. Inherited from managedAppPolicyYesYes
deviceComplianceRequiredIndicates whether device compliance is required. Inherited from managedAppProtectionYesYes
deviceLockRequiredDefines if any kind of lock must be required on Android devices.YesYes
dialerRestrictionLevelLists the classes of dialer apps that are allowed to click-to-open a phone number. Inherited from managedAppProtection.YesYes
disableAppPinIfDevicePinIsSetIndicates whether use of the app pin is required if the device pin is set. Inherited from managedAppProtectionYesYes
disableProtectionOfManagedOutboundOpenInData
Disables protection of data transferred to other apps through IOS OpenIn option. (iOS Only)
Yes
Yes
displayNamePolicy display name. Inherited from managedAppPolicyYesYes
exemptedAppProtocols
Lists iOS apps that will be exempt from the policy and will be able to receive data from managed apps. (iOS only)
Yes
Yes
exemptedUniversalLinks
Lists custom URLs that are allowed to invoke an unmanaged app.
Yes
Yes
faceIdBlocked
Indicates whether the use of the FaceID is allowed in place of a pin if pinRequired is set to True.
Yes
Yes
filterOpenInToOnlyManagedApps
Defines if open-in operation is supported from the managed app to the file-sharing locations selected. (iOS only)
Yes
Yes
fingerprintBlockedIndicates whether use of the fingerprint reader is allowed in place of a pin if PinRequired is set to True. Inherited from managedAppProtectionYesYes
gracePeriodToBlockAppsDuringOffClockHoursSpecifies the grace period before app access is blocked during off clock hours. Inherited from managedAppProtectionYesYes
idKey of the entity. Inherited from managedAppPolicyYesNo
lastModifiedDateTimeLast time the policy was modified. Inherited from managedAppPolicyYesYes
managedBrowserIndicates in which managed browser(s) internet links should be opened.YesYes
managedBrowserToOpenLinksRequiredIndicates whether internet links should be opened in the managed browser app or any custom browser specified by CustomBrowserProtocol (for iOS) or CustomBrowserPackageId / CustomBrowserDisplayName (for Android) Inherited from managedAppProtectionYesYes
managedUniversalLinks
Lists custom URLs that are allowed to invoke a managed app.
Yes
Yes
maximumAllowedDeviceThreatLevelMaximum allowed device threat level, as reported by the MTD app Inherited from managedAppProtection.YesYes
maximumPinRetriesMaximum number of incorrect pin retry attempts before the managed app is either blocked or wiped. Inherited from managedAppProtectionYesYes
maximumRequiredOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
maximumWarningOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
maximumWipeOsVersionVersions higher than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
messagingRedirectAppUrlScheme
Defines the app URL redirect schemes which are allowed to be used when a redirection is enforced by protectedMessagingRedirectAppTyp.
Yes
Yes
minimumPinLengthMinimum pin length required for an app-level pin if PinRequired is set to True. Inherited from managedAppProtectionYesYes
minimumRequiredAppVersionVersions lower than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
minimumRequiredOsVersionVersions lower than the specified version will block the managed app from accessing company data. Inherited from managedAppProtectionYesYes
minimumRequiredSdkVersion
Versions lower than the specified version will block the managed app from accessing company data. (iOS only)
Yes
Yes
minimumWarningAppVersionVersions lower than the specified version will result in a warning message on the managed app. Inherited from managedAppProtectionYesYes
minimumWarningOsVersionVersions lower than the specified version will result in a warning message on the managed app. Inherited from managedAppProtectionYesYes
minimumWarningSdkVersion
Versions lower than the specified version will result in warning message on the managed app when accessing company data. (iOS only)
Yes
Yes
minimumWipeAppVersionVersions lower than or equal to the specified version will wipe the managed app and the associated company data. Inherited from managedAppProtectionYesYes
minimumWipeOsVersionVersions lower than or equal to the specified version will wipe the managed app and the associated company data. Inherited from managedAppProtectionYesYes
minimumWipeSdkVersion
Versions lower than the specified version will block the managed app from accessing company data.
Yes
Yes
mobileThreatDefensePartnerPriorityIndicates how to prioritise which mobile threat defense partner is enabled for a given platform, when more than one is enabled. YesYes
mobileThreatDefenseRemediationActionDetermines what action to take if the mobile threat defense threat threshold isn't met.YesYes
notificationRestrictionSpecifies the level of restriction for app notifications. Inherited from managedAppProtection.YesYes
organizationalCredentialsRequiredIndicates whether organisational credentials are required for app use. Inherited from managedAppProtectionYesYes
periodBeforePinResetSpecifies the time period before the all-level pin must be reset if PinRequired is set to True. Inherited from managedAppProtectionYesYes
periodOfflineBeforeAccessCheckSpecifies the time period after which access is checked when the device is not connected to the internet. Inherited from managedAppProtectionYesYes
periodOfflineBeforeWipeIsEnforcedSpecifies the time period an app is allowed to remain disconnected from the internet before all managed data is wiped. Inherited from managedAppProtectionYesYes
periodOnlineBeforeAccessCheckSpecifies the time period after which access is checked when the device is connected to the internet. Inherited from managedAppProtectionYesYes
pinCharacterSetCharacter set which may be used for an app-level pin if PinRequired is set to True. Inherited from managedAppProtection. YesYes
pinRequiredIndicates whether an app-level pin is required. Inherited from managedAppProtectionYesYes
pinRequiredInsteadOfBiometricTimeoutTimeout in minutes for an app pin when required instead of a non-biometric passcode. Inherited from managedAppProtectionYesYes
previousPinBlockCountRequires a pin to be unique from the number specified in this property. Inherited from managedAppProtectionYesYes
printBlockedIndicates whether printing is allowed from managed apps. Inherited from managedAppProtectionYesYes
protectedMessagingRedirectAppTypeDefines how app messaging redirection is protected by an app protection policy. Inherited from managedAppProtection.YesYes
protectInboundDataFromUnknownSources
Protects incoming data from unknown sources. (iOS only)
Yes
Yes
roleScopeTagIdsList of scope tags for this entity instance. Inherited from managedAppPolicyYesYes
saveAsBlockedIndicates whether users may use the "Save As" menu item to save a copy of protected files. Inherited from managedAppProtectionYesYes
simplePinBlockedIndicates whether simplePin is blocked. Inherited from managedAppProtectionYesYes
targetedAppManagementLevels
The intended app management levels for this policy. Inherited from targetedManagedAppProtection.Yes
Yes
thirdPartyKeyboardsBlockedDefines if third party keyboards are allowed while accessing a managed app. (iOS only)YesYes
versionVersion of the entity. Inherited from managedAppPolicyYesYes

Was this article helpful?

That’s Great!

Thank you for your feedback

Sorry! We couldn't be helpful

Thank you for your feedback

Let us know how can we improve this article!

Select at least one of the reasons
CAPTCHA verification is required.

Feedback sent

We appreciate your effort and will try to fix the article