Export (0) Print
Expand All

Configure security policy for mobile devices in Microsoft Intune

Updated: December 12, 2014

Applies To: Microsoft Intune

Use Microsoft Intune mobile device security policies to configure a wide range of settings that you can deploy to managed devices in your organization. These settings can be used to control the functionality and security of your devices.

You can create and deploy mobile device security policies for the following device types:

  • Windows RT 8.1 and enrolled Windows 8.1 devices

  • Windows RT

  • Windows Phone 8 and Windows Phone 8.1

  • iOS

  • Android and Samsung KNOX

noteNote
Some settings are not applicable to some devices. See the Policy settings for mobile devices section in this topic for a full list of settings you can configure.

  1. In the Microsoft Intune administration console, click Policy > Add Policy.

  2. Click Common Mobile Device Settings > Mobile Device Security Policy.

  3. Choose whether you want to create a policy that contains recommended settings, or whether you want to create a custom policy, and then click Create Policy.

    For more information about how to create and deploy policies, see the Use policies to manage computers and mobile devices with Microsoft Intune topic.

  4. See the Policy settings for mobile devices section in this topic for information about the settings you can configure.

  5. When you are finished, click Save Policy.

The new policy displays in the Configuration Policies node of the Policy workspace.

  1. Deploy the mobile device security policy to one or more groups of users or devices in your organization.

For more information about how to deploy policies, see Use policies to manage computers and mobile devices with Microsoft Intune.

A status summary and alerts on the Overview page of the Policy workspace identify issues with the policy that require your attention. Additionally, a status summary appears in the Dashboard workspace.

ImportantImportant
It might take up to 24 hours for status information to appear in the Intune admin console.

The following sections list the Intune policy settings you can use to help manage mobile devices.

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Require a password to unlock mobile devices

No

No

Yes

Yes

Yes

Required password type

Yes

Yes

Yes

Yes

No

Required password type – Minimum number of character sets

Yes2

Yes

Yes

Yes

No

Minimum password length

Yes

Yes

Yes

Yes

Yes

Allow simple passwords

No

No

Yes

Yes

No

Number of repeated sign-in failures to allow before the device is wiped

Yes

Yes

Yes

Yes

Yes

Minutes of inactivity before screen turns off1

Yes

Yes

Yes

Yes

Yes

Password expiration (days)

Yes

Yes

Yes

Yes

Yes

Remember password history

Yes

Yes

Yes

Yes

Yes

Password quality

No

No

No

No

Yes

Allow picture password and PIN

Yes

Yes

No

No

No

Minutes of inactivity before password is required1

No

No

No

Yes

No

Allow fingerprint unlock

No

No

No

iOS 7 and later

No

1 For iOS devices, when you configure the settings Minutes of inactivity before screen turns off and Minutes of inactivity before password is required, they are applied in sequence. For example, if you set the value for both settings to 5 minutes, the screen will turn off automatically after 5 minutes, and the device will be locked after an additional 5 minutes. However, if the user turns off the screen manually, the second setting is immediately applied. In the same example, after the user turns off the screen, the device will lock 5 minutes later.

2 When you set deploy a password length policy to devices that run Windows RT, users will be forced to reset their password, even if their current password complies with the policy requirements.

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Require encryption on mobile device

Yes

No

Yes

No

Yes

Require encryption on storage cards 1

n/a

n/a

n/a (apps and associated data are automatically encrypted)

n/a

Yes

1 Applies to devices that are managed by Exchange ActiveSync only.

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Require network firewall

Yes

No

No

No

No

Enable SmartScreen

Yes

No

No

No

No

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Require automatic updates

Yes

No

No

No

No

Allow screen capture

No

No

Windows Phone 8.1 only

Yes

Yes (Samsung KNOX only)

Allow control center in lock screen

No

No

No

iOS 7 and later

No

Allow notification view in lock screen

No

No

No

iOS 7 and later

No

Allow today view in lock screen

No

No

No

iOS 7 and later

No

User Account Control

Yes

No

No

No

No

Allow diagnostic data submission

Yes

No

Windows Phone 8.1 only

Yes

Yes (Samsung KNOX only)

Allow untrusted TLS certificates

No

No

No

Yes

No

Allow personal wallet software while locked

No

No

No

Yes

No

Allow factory reset

No

No

No

No

Yes (Samsung KNOX only)

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow backup to iCloud

No

No

No

Yes

No

Allow document sync to iCloud

No

No

No

Yes

No

Allow Photo Stream sync to iCloud

No

No

No

Yes

No

Require encrypted backup

No

No

No

Yes

No

Work Folders URL

Yes

No

No

No

No

Allow Google backup

No

No

No

No

Yes (Samsung KNOX only)

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow Microsoft account

No

No

Windows Phone 8.1 only

No

No

Allow Google account auto sync

No

No

No

No

Yes (Samsung KNOX only)

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow users to download email attachments1

n/a

n/a

n/a

n/a

n/a

Email synchronization period1

n/a

n/a

n/a

n/a

n/a

Allow mobile devices that don’t fully support these settings to synchronize with Exchange (Exchange ActiveSync) 1

n/a

n/a

n/a

n/a

n/a

Make Microsoft account optional in Windows Mail application

Yes

No

No

No

No

Allow custom email accounts

No

No

Windows Phone 8.1 only

No

No

1 Applies to devices that are managed by Exchange ActiveSync only.

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow web browser

No

No

Windows Phone 8.1 only

Yes

Yes (Samsung KNOX only)

Allow autofill

Yes

No

No

Yes

Yes (Samsung KNOX only)

Allow pop-up blocker

Yes

No

No

Yes

Yes (Samsung KNOX only)

Allow cookies

No

No

No

Yes

Yes (Samsung KNOX only)

Allow plug-ins

Yes

No

No

No

No

Allow active scripting

Yes

No

No

Yes

Yes (Samsung KNOX only)

Allow fraud warning

Yes

No

No

Yes

No

Allow intranet site for single word entry

Yes

No

No

No

No

Allow automatic detection of intranet network

Yes

No

No

No

No

Security level for Internet

Yes

No

No

No

No

Security level for intranet

Yes

No

No

No

No

Security level for trusted sites

Yes

No

No

No

No

Security level for restricted sites

Yes

No

No

No

No

Send Do Not Track header

Yes

No

No

No

No

Allow Enterprise Mode menu access

Yes

No

No

No

No

Enterprise Mode site list location

Yes

No

No

No

No

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow application store

No

No

Windows Phone 8.1 only

Yes

Yes (Samsung KNOX only)

Require a password to access application store

No

No

No

Yes

No

Allow in-app purchases

No

No

No

Yes

No

Allow managed documents in other unmanaged apps

No

No

No

iOS 7 and later

No

Allow unmanaged documents in other managed apps

No

No

No

iOS 7 and later

No

Allow video conferencing

No

No

No

Yes

No

Allow adult content in media store

No

No

No

Yes

No

Allow app installation

No

No

No

iOS 6 and later

No

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow Game Center friends

No

No

No

Yes

No

Allow multiplayer gaming

No

No

No

Yes

No

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow camera

No

No

Windows Phone 8.1 only

Yes

Yes

Allow removable storage

No

No

Yes

No

Yes (Samsung KNOX only)

Allow Wi-Fi

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow Wi-Fi tethering

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow automatic connection to free Wi-Fi hotspots

No

No

Windows Phone 8.1 only

No

No

Allow Wi-Fi hotspot reporting

No

No

Windows Phone 8.1 only

No

No

Allow geolocation

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow NFC

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow Bluetooth

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow power off1

No

No

No

No

Yes (Samsung KNOX only)

1 If this setting is disabled, the setting Number of repeated sign in failures to allow before the device is wiped for Samsung KNOX devices does not function.

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow voice roaming

No

No

No

Yes

Yes (Samsung KNOX only)

Allow data roaming

Yes

No

No

Yes

Yes (Samsung KNOX only)

Allow automatic synchronization while roaming

No

No

No

Yes

No

Allow SMS/MMS messaging

No

No

No

No

Yes (Samsung KNOX only)

 

Setting name Windows 8.1 and Windows RT 8.1 Windows RT Windows Phone 8 and Windows Phone 8.1 iOS Android and Samsung KNOX

Allow voice assistant

No

No

No

Yes

Yes (Samsung KNOX only)

Allow voice assistant while device is locked

No

No

No

Yes

No

Allow voice dialing

No

No

No

Yes

Yes (Samsung KNOX only)

Allow copy and paste

No

No

Windows Phone 8.1 only

No

Yes (Samsung KNOX only)

Allow clipboard share between applications

No

No

No

No

Yes (Samsung KNOX only)

Allow YouTube

No

No

No

No

Yes (Samsung KNOX only)

See Also

 
Was this page helpful?
(1500 characters remaining)
Thank you for your feedback
Show:
© 2014 Microsoft