{"_id":"@capawesome/capacitor-intune","_rev":"4-7050c4320b8282fc07d3843e6fd64e02","name":"@capawesome/capacitor-intune","dist-tags":{"latest":"0.1.2"},"versions":{"0.0.1":{"name":"@capawesome/capacitor-intune","version":"0.0.1","keywords":["capacitor","plugin","native","capacitor-plugin","intune","microsoft intune","mam","app protection","mobile application management","msal","enterprise","emm"],"author":{"name":"Robin Genz","email":"mail@robingenz.dev"},"license":"MIT","_id":"@capawesome/capacitor-intune@0.0.1","maintainers":[{"name":"robingenz","email":"mail@robingenz.dev"}],"homepage":"https://capawesome.io/docs/sdks/capacitor/intune/","bugs":{"url":"https://github.com/capawesome-team/capacitor-plugins/issues"},"dist":{"shasum":"0b046f1f1dbed2741db1fa8b91eddfa512bf5a8e","tarball":"https://registry.npmjs.org/@capawesome/capacitor-intune/-/capacitor-intune-0.0.1.tgz","fileCount":66,"integrity":"sha512-lEjIUautkxP6I2Z0LNBNqsiambQydSldRazWlw8zQgvm01Br/jGh0tbmrPKcXCvjrJVbXf/Ouct4+IUDr1I6Sg==","signatures":[{"sig":"MEYCIQCojreuee8mFXLSfKfyE1lQNG49xRypvKJ3uHah1Ps7lwIhAI25y0g81+qbigUPxu83g6NKYAdpobktxyOQH7LcrFwH","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":224685},"main":"dist/plugin.cjs.js","types":"dist/esm/index.d.ts","unpkg":"dist/plugin.js","module":"dist/esm/index.js","funding":[{"url":"https://github.com/sponsors/capawesome-team/","type":"github"},{"url":"https://opencollective.com/capawesome","type":"opencollective"}],"gitHead":"691c6a81b477efcb3ce937d7f80bb3d4fd1fe4a1","scripts":{"fmt":"npm run eslint -- --fix && npm run prettier -- --write && npm run swiftlint -- --fix --format","lint":"npm run eslint && npm run prettier -- --check && npm run swiftlint -- lint","build":"npm run clean && npm run docgen && tsc && rollup -c rollup.config.mjs","clean":"rimraf ./dist","watch":"tsc --watch","docgen":"docgen --api IntunePlugin --output-readme README.md --output-json dist/docs.json","eslint":"eslint . --ext ts","verify":"npm run verify:ios && npm run verify:android && npm run verify:web","prettier":"prettier \"**/*.{css,html,ts,js,java}\"","swiftlint":"node-swiftlint","verify:ios":"cd ios && pod install && xcodebuild -workspace Plugin.xcworkspace -scheme Plugin -destination generic/platform=iOS && cd ..","verify:web":"npm run build","prepublishOnly":"npm run build","verify:android":"cd android && ./gradlew clean build test && cd ..","ios:pod:install":"cd ios && pod install --repo-update && cd ..","ios:spm:install":"cd ios && swift package resolve && cd .."},"_npmUser":{"name":"robingenz","email":"mail@robingenz.dev"},"capacitor":{"ios":{"src":"ios"},"android":{"src":"android"}},"repository":{"url":"git+https://github.com/capawesome-team/capacitor-plugins.git","type":"git"},"_npmVersion":"11.13.0","description":"Unofficial Capacitor plugin for Microsoft Intune app protection policies (MAM) on Android and iOS.","directories":{},"_nodeVersion":"24.16.0","eslintConfig":{"extends":"@ionic/eslint-config/recommended"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","rimraf":"6.1.2","rollup":"4.53.3","swiftlint":"2.0.0","typescript":"5.9.3","@capacitor/cli":"8.0.0","@capacitor/ios":"8.0.0","@capacitor/core":"8.0.0","@capacitor/docgen":"0.3.1","@capacitor/android":"8.0.0","@ionic/eslint-config":"0.4.0","prettier-plugin-java":"2.6.7"},"peerDependencies":{"@capacitor/core":">=8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/capacitor-intune_0.0.1_1783839251498_0.5250696028879751","host":"s3://npm-registry-packages-npm-production"}},"0.1.0":{"name":"@capawesome/capacitor-intune","version":"0.1.0","keywords":["capacitor","plugin","native","capacitor-plugin","intune","microsoft intune","mam","app protection","mobile application management","msal","enterprise","emm"],"author":{"name":"Robin Genz","email":"mail@robingenz.dev"},"license":"MIT","_id":"@capawesome/capacitor-intune@0.1.0","maintainers":[{"name":"robingenz","email":"mail@robingenz.dev"}],"homepage":"https://capawesome.io/docs/sdks/capacitor/intune/","bugs":{"url":"https://github.com/capawesome-team/capacitor-plugins/issues"},"dist":{"shasum":"6fb6cd105ae62aa84476a8ab0dbaf86d2d368b62","tarball":"https://registry.npmjs.org/@capawesome/capacitor-intune/-/capacitor-intune-0.1.0.tgz","fileCount":66,"integrity":"sha512-GKh5qkieyXF/dc+y8ZTtcCkqhvQsXzI2L+hLanK0n/y2nGOUEaXUaR5RgxmM41qhRREJ7ELTQjDOUaS6kqE+ng==","signatures":[{"sig":"MEQCIGZl+Kf6u05oRaM8z3MHJiwN0esZA9QxgZroluij4f/+AiBQ9fCWEHQ/LWS3rfA7IiF081elPe3jJEHlLlX0f4qz1A==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@capawesome%2fcapacitor-intune@0.1.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":224685},"main":"dist/plugin.cjs.js","types":"dist/esm/index.d.ts","unpkg":"dist/plugin.js","module":"dist/esm/index.js","funding":[{"url":"https://github.com/sponsors/capawesome-team/","type":"github"},{"url":"https://opencollective.com/capawesome","type":"opencollective"}],"gitHead":"1ce17b1fd14c43b2f1d5d3c2da82221e1d1dca37","scripts":{"fmt":"npm run eslint -- --fix && npm run prettier -- --write && npm run swiftlint -- --fix --format","lint":"npm run eslint && npm run prettier -- --check && npm run swiftlint -- lint","build":"npm run clean && npm run docgen && tsc && rollup -c rollup.config.mjs","clean":"rimraf ./dist","watch":"tsc --watch","docgen":"docgen --api IntunePlugin --output-readme README.md --output-json dist/docs.json","eslint":"eslint . --ext ts","verify":"npm run verify:ios && npm run verify:android && npm run verify:web","prettier":"prettier \"**/*.{css,html,ts,js,java}\"","swiftlint":"node-swiftlint","verify:ios":"cd ios && pod install && xcodebuild -workspace Plugin.xcworkspace -scheme Plugin -destination generic/platform=iOS && cd ..","verify:web":"npm run build","prepublishOnly":"npm run build","verify:android":"cd android && ./gradlew clean build test && cd ..","ios:pod:install":"cd ios && pod install --repo-update && cd ..","ios:spm:install":"cd ios && swift package resolve && cd .."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ba9865f4-eb33-4eb5-8326-a93dc72c44bf"}},"capacitor":{"ios":{"src":"ios"},"android":{"src":"android"}},"repository":{"url":"git+https://github.com/capawesome-team/capacitor-plugins.git","type":"git"},"_npmVersion":"11.16.0","description":"Unofficial Capacitor plugin for Microsoft Intune app protection policies (MAM) on Android and iOS.","directories":{},"_nodeVersion":"24.18.0","eslintConfig":{"extends":"@ionic/eslint-config/recommended"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","rimraf":"6.1.2","rollup":"4.53.3","swiftlint":"2.0.0","typescript":"5.9.3","@capacitor/cli":"8.0.0","@capacitor/ios":"8.0.0","@capacitor/core":"8.0.0","@capacitor/docgen":"0.3.1","@capacitor/android":"8.0.0","@ionic/eslint-config":"0.4.0","prettier-plugin-java":"2.6.7"},"peerDependencies":{"@capacitor/core":">=8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/capacitor-intune_0.1.0_1784015546870_0.12107996334287563","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@capawesome/capacitor-intune","version":"0.1.1","keywords":["capacitor","plugin","native","capacitor-plugin","intune","microsoft intune","mam","app protection","mobile application management","msal","enterprise","emm"],"author":{"name":"Robin Genz","email":"mail@robingenz.dev"},"license":"MIT","_id":"@capawesome/capacitor-intune@0.1.1","maintainers":[{"name":"robingenz","email":"mail@robingenz.dev"}],"homepage":"https://capawesome.io/docs/sdks/capacitor/intune/","bugs":{"url":"https://github.com/capawesome-team/capacitor-plugins/issues"},"dist":{"shasum":"7d1f1ef23de6bbe264aa13847fdc7dede0db433a","tarball":"https://registry.npmjs.org/@capawesome/capacitor-intune/-/capacitor-intune-0.1.1.tgz","fileCount":76,"integrity":"sha512-TCjNknFTgUihg6Nadqd1ztdX0bpU2Iw7v7i+kyeZqs2+NP9qOSrYoce5kWSrdeLLPOFhUp4k7+LLfd+D4pcfPQ==","signatures":[{"sig":"MEUCIQCe9I3h1f8rwoVtQN/HcOGvHY946zgnoOLASMqGnohlzQIgLe4gG3w6EU/wtBNIHD3++sgCzEJgPM3VKJXccaDskKU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIBNaXWmzbz21exFpHnjiQNLtaAOXOJswGeZ3ijCO9m0DAiEA5a9HbgG2wamKeOxeWis0Meu44dzQmdXJz2OMOdmq7m0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@capawesome%2fcapacitor-intune@0.1.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":265387},"main":"dist/plugin.cjs.js","types":"dist/esm/index.d.ts","unpkg":"dist/plugin.js","module":"dist/esm/index.js","funding":[{"url":"https://github.com/sponsors/capawesome-team/","type":"github"},{"url":"https://opencollective.com/capawesome","type":"opencollective"}],"gitHead":"664ecb7850a9b34251e94be3ec6dd8faca69cec3","scripts":{"fmt":"npm run eslint -- --fix && npm run prettier -- --write && npm run swiftlint -- --fix --format","lint":"npm run eslint && npm run prettier -- --check && npm run swiftlint -- lint","build":"npm run clean && npm run docgen && tsc && rollup -c rollup.config.mjs","clean":"rimraf ./dist","watch":"tsc --watch","docgen":"docgen --api IntunePlugin --output-readme README.md --output-json dist/docs.json","eslint":"eslint . --ext ts","verify":"npm run verify:ios && npm run verify:android && npm run verify:web","prettier":"prettier \"**/*.{css,html,ts,js,java}\"","swiftlint":"node-swiftlint","verify:ios":"cd ios && pod install && xcodebuild -workspace Plugin.xcworkspace -scheme Plugin -destination generic/platform=iOS && cd ..","verify:web":"npm run build","prepublishOnly":"npm run build","verify:android":"cd android && ./gradlew clean build test && cd ..","ios:pod:install":"cd ios && pod install --repo-update && cd ..","ios:spm:install":"cd ios && swift package resolve && cd .."},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ba9865f4-eb33-4eb5-8326-a93dc72c44bf"}},"capacitor":{"ios":{"src":"ios"},"android":{"src":"android"}},"repository":{"url":"git+https://github.com/capawesome-team/capacitor-plugins.git","type":"git"},"_npmVersion":"11.19.0","description":"Unofficial Capacitor plugin for Microsoft Intune app protection policies (MAM) on Android and iOS.","directories":{},"_nodeVersion":"24.20.0","eslintConfig":{"extends":"@ionic/eslint-config/recommended"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","rimraf":"6.1.2","rollup":"4.62.3","swiftlint":"2.0.0","typescript":"5.9.3","@capacitor/cli":"8.4.2","@capacitor/ios":"8.0.0","@capacitor/core":"8.0.0","@capacitor/docgen":"0.3.1","@capacitor/android":"8.0.0","@ionic/eslint-config":"0.4.0","prettier-plugin-java":"2.9.7"},"peerDependencies":{"@capacitor/core":">=8.0.0"},"_npmOperationalInternal":{"tmp":"tmp/capacitor-intune_0.1.1_1789983563715_0.891631340354065","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"_id":"@capawesome/capacitor-intune@0.1.2","bugs":{"url":"https://github.com/capawesome-team/capacitor-plugins/issues"},"dist":{"shasum":"9a0bd6a932b3e94b5476489640d1874362b5f4a3","tarball":"https://registry.npmjs.org/@capawesome/capacitor-intune/-/capacitor-intune-0.1.2.tgz","fileCount":80,"integrity":"sha512-5PijvSTDZK+AOR6U0/w56dCZIpClibxJBvsLCklOxrjXx0vlEyLG/SmAb22bv+nssLPmQ1s7bMdwUn4Dr2pBOw==","signatures":[{"sig":"MEUCIHKJ1IQAH+CWBmfRCGBMk4ZsOBebYkHANUXNKThco0kMAiEA4EHKxcl/P7L2kOdv30uGoKOpV9mGRc5PBWPIWkIfxPc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIGrlXcRkQX6KJxQ2ZV2Hc3YdlzhK3UOMzDJhbAoRtvgEAiEAjHtR83HqWfmFf+SEkpzjncjX4RV6f8cs8M08XomdCxU="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@capawesome%2fcapacitor-intune@0.1.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":311272},"main":"dist/plugin.cjs.js","name":"@capawesome/capacitor-intune","types":"dist/esm/index.d.ts","unpkg":"dist/plugin.js","author":{"name":"Robin Genz","email":"mail@robingenz.dev"},"module":"dist/esm/index.js","funding":[{"url":"https://github.com/sponsors/capawesome-team/","type":"github"},{"url":"https://opencollective.com/capawesome","type":"opencollective"}],"gitHead":"f1561cfecf0c2ad417c5dac49b8556991dc5ab97","license":"MIT","scripts":{"fmt":"npm run eslint -- --fix && npm run prettier -- --write && npm run swiftlint -- --fix --format","lint":"npm run eslint && npm run prettier -- --check && npm run swiftlint -- lint","build":"npm run clean && npm run docgen && tsc && rollup -c rollup.config.mjs","clean":"rimraf ./dist","watch":"tsc --watch","docgen":"docgen --api IntunePlugin --output-readme README.md --output-json dist/docs.json","eslint":"eslint . --ext ts","verify":"npm run verify:ios && npm run verify:android && npm run verify:web","prettier":"prettier \"**/*.{css,html,ts,js,java}\"","swiftlint":"node-swiftlint","verify:ios":"cd ios && pod install && xcodebuild -workspace Plugin.xcworkspace -scheme Plugin -destination generic/platform=iOS && cd ..","verify:web":"npm run build","prepublishOnly":"npm run build","verify:android":"cd android && ./gradlew clean build test && cd ..","ios:pod:install":"cd ios && pod install --repo-update && cd ..","ios:spm:install":"cd ios && swift package resolve && cd .."},"version":"0.1.2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:ba9865f4-eb33-4eb5-8326-a93dc72c44bf"}},"homepage":"https://capawesome.io/docs/sdks/capacitor/intune/","keywords":["capacitor","plugin","native","capacitor-plugin","intune","microsoft intune","mam","app protection","mobile application management","msal","enterprise","emm"],"capacitor":{"ios":{"src":"ios"},"android":{"src":"android"}},"repository":{"url":"git+https://github.com/capawesome-team/capacitor-plugins.git","type":"git"},"_npmVersion":"11.19.0","description":"Unofficial Capacitor plugin for Microsoft Intune app protection policies (MAM) on Android and iOS.","directories":{},"maintainers":[{"name":"robingenz","email":"mail@robingenz.dev"}],"_nodeVersion":"24.21.0","eslintConfig":{"extends":"@ionic/eslint-config/recommended"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"eslint":"8.57.0","rimraf":"6.1.2","rollup":"4.62.3","swiftlint":"2.0.0","typescript":"5.9.3","@capacitor/cli":"8.4.2","@capacitor/ios":"8.0.0","@capacitor/core":"8.0.0","@capacitor/docgen":"0.3.1","@capacitor/android":"8.0.0","@ionic/eslint-config":"0.4.0","prettier-plugin-java":"2.9.7"},"peerDependencies":{"@capacitor/core":">=8.0.0"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/capacitor-intune_0.1.2_1790490651435_0.8525626006047267"}}},"time":{"created":"2026-07-12T06:54:11.405Z","modified":"2026-09-27T06:30:51.944Z","0.0.1":"2026-07-12T06:54:11.637Z","0.1.0":"2026-07-14T07:52:27.030Z","0.1.1":"2026-09-21T09:39:23.819Z","0.1.2":"2026-09-27T06:30:51.526Z"},"bugs":{"url":"https://github.com/capawesome-team/capacitor-plugins/issues"},"author":{"name":"Robin Genz","email":"mail@robingenz.dev"},"license":"MIT","homepage":"https://capawesome.io/docs/sdks/capacitor/intune/","keywords":["capacitor","plugin","native","capacitor-plugin","intune","microsoft intune","mam","app protection","mobile application management","msal","enterprise","emm"],"repository":{"url":"git+https://github.com/capawesome-team/capacitor-plugins.git","type":"git"},"description":"Unofficial Capacitor plugin for Microsoft Intune app protection policies (MAM) on Android and iOS.","maintainers":[{"name":"robingenz","email":"mail@robingenz.dev"}],"readme":"# Capacitor Intune Plugin\n\nUnofficial Capacitor plugin for [Microsoft Intune](https://www.microsoft.com/en-us/security/business/microsoft-intune).[^1]\n\n<div class=\"capawesome-z29o10a\">\n  <a href=\"https://cloud.capawesome.io/\" target=\"_blank\">\n    <img alt=\"Deliver Live Updates to your Capacitor app with Capawesome Cloud\" src=\"https://cloud.capawesome.io/assets/banners/cloud-build-and-deploy-capacitor-apps.png?t=1\" />\n  </a>\n</div>\n\n## Features\n\nThe Capacitor Intune plugin integrates the Microsoft Intune App SDK for Mobile Application Management (MAM) into Capacitor apps. Here are some of the key features:\n\n- 🖥️ **Cross-platform**: Supports Android and iOS.\n- 🛡️ **App Protection Policies**: Automatic enforcement of PIN, copy/paste and screenshot restrictions after the native integration.\n- 🔐 **File Protection**: Encrypt, inspect and decrypt files through the Intune App SDK to honor the \"Encrypt org data\" policy on iOS, where the SDK does not encrypt files on its own.\n- 🔑 **MSAL**: Acquire tokens interactively or silently via the Microsoft Authentication Library.\n- 🧾 **Enrollment**: Register and enroll accounts in Mobile Application Management (MAM) — without device enrollment.\n- 🚦 **App Protection Conditional Access**: Remediate compliance when Microsoft Entra ID requires an app protection policy before issuing tokens.\n- 📋 **Typed Policy Introspection**: Read the applied app protection policy as typed booleans to adapt your UI.\n- ⚙️ **App Configuration**: Read the application configuration deployed via the MAM channel, including conflict information.\n- 🧹 **Selective Wipe Events**: Get notified when the Intune service requests a wipe so you can purge the web layer storage (e.g. IndexedDB, Local Storage) that the SDK cannot wipe itself.\n- 🩺 **Diagnostics**: Show the Intune diagnostic console from JavaScript.\n- 📌 **Current SDK Pins**: Built against current Microsoft Intune App SDK and MSAL versions — Microsoft blocks apps that ship outdated SDKs.\n- 🤝 **Compatibility**: Works alongside the [Managed Configurations](https://capawesome.io/docs/sdks/capacitor/managed-configurations/) plugin, which covers the MDM channel (see [Choosing between the MAM and MDM channel](#choosing-between-the-mam-and-mdm-channel)).\n- 📦 **CocoaPods & SPM**: Supports CocoaPods and Swift Package Manager for iOS.\n- 🔁 **Up-to-date**: Always supports the latest Capacitor version.\n\nMissing a feature? Just [open an issue](https://github.com/capawesome-team/capacitor-plugins/issues) and we'll take a look!\n\n## Use Cases\n\nThe Intune plugin is typically used in line-of-business apps that are distributed to employees of organizations that manage corporate data with Microsoft Intune, for example:\n\n- **App protection without device enrollment**: Protect corporate data in your app on personal (BYOD) devices via Mobile Application Management (MAM).\n- **Conditional access**: Combine with Microsoft Entra conditional access policies that require an Intune-protected app (see [Handle App Protection Conditional Access](#handle-app-protection-conditional-access)).\n- **Policy-aware UI**: Read the applied app protection policy and hide or disable features (e.g. local export) that the policy does not allow.\n- **Encrypt organization data**: Protect recordings, downloads and exports on iOS when the app protection policy requires file encryption.\n- **Per-tenant configuration**: Read the application configuration that the organization's IT administrator has deployed for the signed-in account.\n- **Selective wipe**: Clean up the web layer storage of your app when the organization wipes its corporate data.\n- **Ionic enterprise migration**: Migrate from the discontinued Ionic enterprise Intune integration to a maintained, free plugin.\n\n## Compatibility\n\n| Plugin Version | Capacitor Version | Status         |\n| -------------- | ----------------- | -------------- |\n| 0.x.x          | >=8.x.x           | Active support |\n\n## Installation\n\nYou can use our **AI-Assisted Setup** to install the plugin.\nAdd the [Capawesome Skills](https://github.com/capawesome-team/skills) to your AI tool using the following command:\n\n```bash\nnpx skills add capawesome-team/skills --skill capacitor-plugins\n```\n\nThen use the following prompt:\n\n```\nUse the `capacitor-plugins` skill from `capawesome-team/skills` to install the `@capawesome/capacitor-intune` plugin in my project.\n```\n\nIf you prefer **Manual Setup**, install the plugin by running the following commands and follow the platform-specific instructions below:\n\n```bash\nnpm install @capawesome/capacitor-intune\nnpx cap sync\n```\n\nThis plugin requires a [Microsoft Intune](https://www.microsoft.com/en-us/security/business/microsoft-intune) tenant with Intune licenses and an app registration in [Microsoft Entra ID](https://entra.microsoft.com/). Create the app registration in the Microsoft Entra admin center, note its **Application (client) ID** and configure the platform-specific redirect URIs (see below). The `acquireToken(...)` scopes you request must be exposed or granted on this app registration.\n\n> [!IMPORTANT]\n> The Intune App SDKs are developed and licensed by Microsoft (see [Third-Party Notices](#third-party-notices)). This plugin declares them as dependencies and downloads them from Microsoft's official repositories at build or install time. It does not bundle or modify them.\n\n### Android\n\nThe Microsoft Intune App SDK for Android is downloaded automatically from [Microsoft's official GitHub repository](https://github.com/microsoftconnect/ms-intune-app-sdk-android) during the Gradle build. However, the Intune App SDK requires several changes to your app project that no plugin can make for you. Follow the steps below or use [Trapeze](#automated-setup-with-trapeze) to automate them.\n\n#### Variables\n\nThis plugin will use the following project variables (defined in your app's `variables.gradle` file):\n\n- `$intuneMamSdkVersion` version of the [Microsoft Intune App SDK for Android](https://github.com/microsoftconnect/ms-intune-app-sdk-android) (default: `12.4.0`)\n- `$msalVersion` version of `com.microsoft.identity.client:msal` (default: `8.4.0`)\n\n#### MAM Build Plugin\n\nThe Intune App SDK relies on a Gradle build plugin that rewrites the Android base classes of your app **and all Capacitor plugins** to their MAM equivalents. Only the app module can apply this plugin — it cannot be applied by a library. Add the following to the `buildscript` block of your `android/build.gradle` file:\n\n```diff\n buildscript {\n     repositories {\n         google()\n         mavenCentral()\n+        ivy {\n+            url 'https://raw.githubusercontent.com/microsoftconnect/ms-intune-app-sdk-android'\n+            patternLayout { artifact '[revision]/GradlePlugin/[artifact].[ext]' }\n+            metadataSources { artifact() }\n+            content { includeGroup 'com.microsoft.intune.mam.build' }\n+        }\n     }\n     dependencies {\n         classpath 'com.android.tools.build:gradle:8.13.0'\n+        classpath 'org.javassist:javassist:3.29.2-GA'\n+        classpath 'com.microsoft.intune.mam.build:com.microsoft.intune.mam.build:12.4.0@jar'\n     }\n }\n```\n\nThen apply the plugin in your `android/app/build.gradle` file:\n\n```diff\n apply plugin: 'com.android.application'\n+apply plugin: 'com.microsoft.intune.mam'\n```\n\n#### Application Class\n\nThe Intune App SDK requires an `Application` class that registers the MAM components before any other code runs. Set the ready-made class provided by this plugin in the `application` tag of your `android/app/src/main/AndroidManifest.xml` file:\n\n```xml\n<application\n    android:name=\"io.capawesome.capacitorjs.plugins.intune.IntuneApplication\"\n    ...>\n```\n\nIf your app already uses a custom `Application` class, call the initializer yourself instead:\n\n```java\nimport io.capawesome.capacitorjs.plugins.intune.Intune;\n\npublic class MyApplication extends Application {\n\n    @Override\n    public void onCreate() {\n        super.onCreate();\n        Intune.initialize(this);\n    }\n}\n```\n\nIt's also recommended to disable predictive back gestures in the `application` tag since the Intune App SDK does not support them yet:\n\n```xml\n<application\n    android:enableOnBackInvokedCallback=\"false\"\n    ...>\n```\n\n#### MSAL Configuration\n\nCreate the file `android/app/src/main/res/raw/auth_config.json` with your MSAL configuration:\n\n```json\n{\n  \"client_id\": \"YOUR_CLIENT_ID\",\n  \"authorization_user_agent\": \"DEFAULT\",\n  \"redirect_uri\": \"msauth://YOUR_PACKAGE_NAME/YOUR_BASE64_URL_ENCODED_PACKAGE_SIGNATURE\",\n  \"account_mode\": \"MULTIPLE\",\n  \"broker_redirect_uri_registered\": true,\n  \"client_capabilities\": \"protapp\",\n  \"authorities\": [\n    {\n      \"type\": \"AAD\",\n      \"audience\": {\n        \"type\": \"AzureADMultipleOrgs\"\n      }\n    }\n  ]\n}\n```\n\nThe `client_capabilities` entry declares that your app supports [App Protection Conditional Access](#handle-app-protection-conditional-access). On iOS, the plugin declares it automatically.\n\nYou can generate the base64-encoded signature hash of your signing key with:\n\n```bash\nkeytool -exportcert -alias YOUR_KEY_ALIAS -keystore YOUR_KEYSTORE | openssl sha1 -binary | openssl base64\n```\n\nMake sure the same redirect URI (`msauth://YOUR_PACKAGE_NAME/YOUR_BASE64_URL_ENCODED_PACKAGE_SIGNATURE`) is registered as an **Android** platform redirect URI on your app registration in the Microsoft Entra admin center.\n\nNext, add the following activity to the `application` tag of your `android/app/src/main/AndroidManifest.xml` file so that MSAL can receive the redirect from the Microsoft sign-in flow:\n\n```xml\n<activity android:name=\"com.microsoft.identity.client.BrowserTabActivity\" android:exported=\"true\">\n    <intent-filter>\n        <action android:name=\"android.intent.action.VIEW\" />\n        <category android:name=\"android.intent.category.DEFAULT\" />\n        <category android:name=\"android.intent.category.BROWSABLE\" />\n        <data android:scheme=\"msauth\" android:host=\"YOUR_PACKAGE_NAME\" android:path=\"/YOUR_BASE64_ENCODED_PACKAGE_SIGNATURE\" />\n    </intent-filter>\n</activity>\n```\n\n#### Gradle Properties\n\nAdd the following to your `android/gradle.properties` file. Without it, release builds may report `MAM Enabled: No` in the diagnostic console:\n\n```properties\nandroid.enableResourceOptimizations=false\n```\n\n#### Company Portal\n\nApp protection policies are only applied when the [Company Portal](https://play.google.com/store/apps/details?id=com.microsoft.windowsintune.companyportal) app is installed on the device. The user does **not** need to sign in to the Company Portal. Without it, your app behaves as unmanaged.\n\n### iOS\n\nThe Microsoft Intune App SDK for iOS requires **iOS 17+** as deployment target and a current Xcode version. This deviates from the usual iOS 15 minimum of the Capawesome plugin collection. Make sure the deployment target of your app is set to iOS 17.0 or later (in `ios/App/App.xcodeproj` and, if you use Swift Package Manager, in `ios/App/CapApp-SPM/Package.swift`).\n\nThe SDK is consumed from [Microsoft's official GitHub repository](https://github.com/msintuneappsdk/ms-intune-app-sdk-ios): via Swift Package Manager it is resolved like any other package; via CocoaPods it is downloaded automatically during `pod install` (Microsoft does not publish a CocoaPods pod).\n\n#### Info.plist\n\nAdd the `IntuneMAMSettings` dictionary to your `ios/App/App/Info.plist` file (the keys keep their legacy `ADAL` names for historical reasons):\n\n```xml\n<key>IntuneMAMSettings</key>\n<dict>\n    <key>ADALAuthority</key>\n    <string>https://login.microsoftonline.com/YOUR_TENANT_ID</string>\n    <key>ADALClientId</key>\n    <string>YOUR_CLIENT_ID</string>\n    <key>ADALRedirectUri</key>\n    <string>msauth.YOUR_BUNDLE_ID://auth</string>\n</dict>\n```\n\nThis plugin also uses these values to configure MSAL, so no separate MSAL configuration is needed.\n\nNext, register the MSAL redirect URL scheme and the query schemes in the same file:\n\n```xml\n<key>CFBundleURLTypes</key>\n<array>\n    <dict>\n        <key>CFBundleURLName</key>\n        <string>MSAL</string>\n        <key>CFBundleURLSchemes</key>\n        <array>\n            <string>msauth.YOUR_BUNDLE_ID</string>\n        </array>\n    </dict>\n</array>\n<key>LSApplicationQueriesSchemes</key>\n<array>\n    <string>msauthv2</string>\n    <string>msauthv3</string>\n    <string>http-intunemam</string>\n    <string>https-intunemam</string>\n</array>\n```\n\nMake sure the redirect URI (`msauth.YOUR_BUNDLE_ID://auth`) is registered as an **iOS/macOS** platform redirect URI on your app registration in the Microsoft Entra admin center. The plugin handles the MSAL redirect automatically — no `AppDelegate` changes are required.\n\nFinally, add a Face ID usage description if your app does not have one yet, since app protection policies may require biometric unlock:\n\n```xml\n<key>NSFaceIDUsageDescription</key>\n<string>This app uses Face ID to secure corporate data.</string>\n```\n\n#### Keychain Sharing\n\nEnable the **Keychain Sharing** capability for your app target in Xcode and add the following keychain groups (in this order):\n\n1. `com.example.app` (your bundle ID, usually already present)\n2. `com.microsoft.intune.mam`\n3. `com.microsoft.adalcache`\n\n#### IntuneMAMConfigurator\n\nMicrosoft ships the `IntuneMAMConfigurator` tool with the [SDK repository](https://github.com/msintuneappsdk/ms-intune-app-sdk-ios). It applies the minimum required `Info.plist` changes for Intune management (including the `-intunemam` query scheme variants for every scheme your app queries) and is idempotent:\n\n```bash\nIntuneMAMConfigurator -i ios/App/App/Info.plist -e ios/App/App/App.entitlements\n```\n\nRunning it is recommended before you ship, especially if your app passes additional URL schemes to `canOpenURL`.\n\n### Automated Setup with Trapeze\n\nMost of the host app changes above can be automated with [Trapeze](https://trapeze.dev/), which is also used by [Capawesome Cloud](https://capawesome.io/cloud/). Save the following configuration as `trapeze.yaml` and run `npx @trapezedev/configure run trapeze.yaml` with the `CLIENT_ID`, `TENANT_ID`, `PACKAGE_NAME`, `BUNDLE_ID` and `SIGNATURE_HASH` variables set:\n\n```yaml\nvars:\n  CLIENT_ID:\n  TENANT_ID:\n  PACKAGE_NAME:\n  BUNDLE_ID:\n  SIGNATURE_HASH:\n\nplatforms:\n  android:\n    gradle:\n      - file: build.gradle\n        target:\n          buildscript:\n            dependencies:\n        insert: |\n          classpath 'org.javassist:javassist:3.29.2-GA'\n          classpath 'com.microsoft.intune.mam.build:com.microsoft.intune.mam.build:12.4.0@jar'\n      - file: build.gradle\n        target:\n          buildscript:\n            repositories:\n        insert: |\n          ivy {\n              url 'https://raw.githubusercontent.com/microsoftconnect/ms-intune-app-sdk-android'\n              patternLayout { artifact '[revision]/GradlePlugin/[artifact].[ext]' }\n              metadataSources { artifact() }\n              content { includeGroup 'com.microsoft.intune.mam.build' }\n          }\n      - file: app/build.gradle\n        target:\n        insert: |\n          apply plugin: 'com.microsoft.intune.mam'\n    manifest:\n      - file: AndroidManifest.xml\n        target: manifest/application\n        attrs:\n          android:name: io.capawesome.capacitorjs.plugins.intune.IntuneApplication\n          android:enableOnBackInvokedCallback: 'false'\n      - file: AndroidManifest.xml\n        target: manifest/application\n        inject: |\n          <activity android:name=\"com.microsoft.identity.client.BrowserTabActivity\" android:exported=\"true\">\n            <intent-filter>\n              <action android:name=\"android.intent.action.VIEW\" />\n              <category android:name=\"android.intent.category.DEFAULT\" />\n              <category android:name=\"android.intent.category.BROWSABLE\" />\n              <data android:scheme=\"msauth\" android:host=\"$PACKAGE_NAME\" android:path=\"/$SIGNATURE_HASH\" />\n            </intent-filter>\n          </activity>\n    res:\n      - path: raw\n        file: auth_config.json\n        text: |\n          {\n            \"client_id\": \"$CLIENT_ID\",\n            \"authorization_user_agent\": \"DEFAULT\",\n            \"redirect_uri\": \"msauth://$PACKAGE_NAME/$SIGNATURE_HASH\",\n            \"account_mode\": \"MULTIPLE\",\n            \"broker_redirect_uri_registered\": true,\n            \"client_capabilities\": \"protapp\",\n            \"authorities\": [\n              {\n                \"type\": \"AAD\",\n                \"audience\": {\n                  \"type\": \"AzureADMultipleOrgs\"\n                }\n              }\n            ]\n          }\n  ios:\n    targets:\n      App:\n        buildSettings:\n          IPHONEOS_DEPLOYMENT_TARGET: '17.0'\n        entitlements:\n          - keychain-access-groups:\n              [\n                '$BUNDLE_ID',\n                'com.microsoft.intune.mam',\n                'com.microsoft.adalcache',\n              ]\n        plist:\n          - entries:\n              - IntuneMAMSettings:\n                  ADALAuthority: https://login.microsoftonline.com/$TENANT_ID\n                  ADALClientId: $CLIENT_ID\n                  ADALRedirectUri: msauth.$BUNDLE_ID://auth\n              - CFBundleURLTypes:\n                  - CFBundleURLName: MSAL\n                    CFBundleURLSchemes:\n                      - msauth.$BUNDLE_ID\n              - LSApplicationQueriesSchemes:\n                  - msauthv2\n                  - msauthv3\n                  - http-intunemam\n                  - https-intunemam\n              - NSFaceIDUsageDescription: This app uses Face ID to secure corporate data.\n```\n\n> [!NOTE]\n> Trapeze cannot edit `gradle.properties`, so the [Gradle Properties](#gradle-properties) step must still be done manually. Review the result after running Trapeze: some list-valued Info.plist entries may be merged rather than replaced, and the Gradle insertions are not idempotent — run them only once.\n\n### Web\n\nThis plugin does not provide a web implementation. All methods reject with an `unimplemented` error on the web platform.\n\n## Configuration\n\nNo configuration required for this plugin.\n\n## Usage\n\nThe following examples show how to use the plugin.\n\n### Sign in and enroll an account\n\nAcquire a token via MSAL and enroll the returned account in Mobile Application Management (MAM). The enrollment itself is asynchronous — listen for the `enrollmentChange` event to get the result:\n\n```typescript\nimport { Intune } from '@capawesome/capacitor-intune';\n\nconst signInAndEnroll = async () => {\n  await Intune.addListener('enrollmentChange', event => {\n    console.log('Enrollment status:', event.status);\n  });\n  const { accountId } = await Intune.acquireToken({\n    scopes: ['https://graph.microsoft.com/.default'],\n  });\n  await Intune.registerAndEnrollAccount({ accountId });\n};\n```\n\n### Handle App Protection Conditional Access\n\nIf your organization requires an app protection policy via Conditional Access, Microsoft Entra ID only issues tokens once Intune manages the app. In this case, the token acquisition is rejected with the `PROTECTION_POLICY_REQUIRED` error code. Remediate the compliance and retry the token acquisition:\n\n```typescript\nimport { ErrorCode, Intune } from '@capawesome/capacitor-intune';\n\nconst acquireToken = async (scopes: string[]) => {\n  try {\n    return await Intune.acquireToken({ scopes });\n  } catch (error) {\n    if (error.code !== ErrorCode.ProtectionPolicyRequired) {\n      throw error;\n    }\n    const { status } = await Intune.remediateCompliance(error.data);\n    if (status !== 'compliant') {\n      throw error;\n    }\n    return Intune.acquireTokenSilent({ accountId: error.data.accountId, scopes });\n  }\n};\n```\n\n### Read the app protection policy\n\nAdapt your UI to the applied app protection policy:\n\n```typescript\nimport { Intune } from '@capawesome/capacitor-intune';\n\nconst applyPolicy = async () => {\n  const { account } = await Intune.getEnrolledAccount();\n  if (!account) {\n    return;\n  }\n  const policy = await Intune.getPolicy({ accountId: account.accountId });\n  if (!policy.saveToPersonalStorageAllowed) {\n    // Hide your export/download buttons.\n  }\n};\n```\n\n### Protect files\n\nOn iOS, the Intune App SDK does not encrypt files on its own. Protect every file that contains organization data, and decrypt it before handing it to other plugins or native components:\n\n```typescript\nimport { Intune } from '@capawesome/capacitor-intune';\n\nconst protectFile = async (path: string) => {\n  const { account } = await Intune.getEnrolledAccount();\n  if (!account) {\n    return;\n  }\n  await Intune.protectFile({ path, accountId: account.accountId });\n};\n\nconst decryptFile = async (path: string, destination: string) => {\n  const { encrypted } = await Intune.isFileEncrypted({ path });\n  if (encrypted) {\n    await Intune.decryptFile({ path, destination });\n  }\n};\n```\n\n### Read the app configuration\n\nRead the configuration values that the organization's IT administrator has deployed:\n\n```typescript\nimport { Intune } from '@capawesome/capacitor-intune';\n\nconst readAppConfig = async () => {\n  const { account } = await Intune.getEnrolledAccount();\n  if (!account) {\n    return;\n  }\n  const { values } = await Intune.getAppConfig({ accountId: account.accountId });\n  console.log('Server URL:', values['com.example.serverUrl']);\n};\n```\n\n### Handle selective wipe\n\nThe Intune App SDK wipes the data it manages, but it does **not** wipe the web layer storage of your Capacitor app. Register the `wipeRequested` listener as early as possible and purge your web storage when it fires:\n\n```typescript\nimport { Intune } from '@capawesome/capacitor-intune';\n\nconst registerWipeListener = async () => {\n  await Intune.addListener('wipeRequested', async () => {\n    localStorage.clear();\n    sessionStorage.clear();\n    const databases = await indexedDB.databases();\n    for (const database of databases) {\n      if (database.name) {\n        indexedDB.deleteDatabase(database.name);\n      }\n    }\n  });\n};\n```\n\n## API\n\n<docgen-index>\n\n* [`acquireToken(...)`](#acquiretoken)\n* [`acquireTokenSilent(...)`](#acquiretokensilent)\n* [`decryptFile(...)`](#decryptfile)\n* [`getAppConfig(...)`](#getappconfig)\n* [`getEnrolledAccount()`](#getenrolledaccount)\n* [`getPolicy(...)`](#getpolicy)\n* [`getSdkVersion()`](#getsdkversion)\n* [`isFileEncrypted(...)`](#isfileencrypted)\n* [`loginAndEnrollAccount()`](#loginandenrollaccount)\n* [`protectFile(...)`](#protectfile)\n* [`registerAndEnrollAccount(...)`](#registerandenrollaccount)\n* [`remediateCompliance(...)`](#remediatecompliance)\n* [`showDiagnosticConsole()`](#showdiagnosticconsole)\n* [`unenrollAccount(...)`](#unenrollaccount)\n* [`addListener('appConfigChange', ...)`](#addlistenerappconfigchange-)\n* [`addListener('enrollmentChange', ...)`](#addlistenerenrollmentchange-)\n* [`addListener('policyChange', ...)`](#addlistenerpolicychange-)\n* [`addListener('wipeRequested', ...)`](#addlistenerwiperequested-)\n* [`removeAllListeners()`](#removealllisteners)\n* [Interfaces](#interfaces)\n* [Type Aliases](#type-aliases)\n\n</docgen-index>\n\n<docgen-api>\n<!--Update the source file JSDoc comments and rerun docgen to update the docs below-->\n\n### acquireToken(...)\n\n```typescript\nacquireToken(options: AcquireTokenOptions) => Promise<AcquireTokenResult>\n```\n\nAcquire an access token interactively via the Microsoft Authentication\nLibrary (MSAL).\n\nThis presents the Microsoft sign-in UI if necessary. Use the returned\n`accountId` to enroll the account via `registerAndEnrollAccount(...)`.\n\nIf the tenant requires an app protection policy, the call is rejected\nwith the `PROTECTION_POLICY_REQUIRED` error code. Use\n`remediateCompliance(...)` in this case.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                |\n| ------------- | ------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#acquiretokenoptions\">AcquireTokenOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#acquiretokenresult\">AcquireTokenResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### acquireTokenSilent(...)\n\n```typescript\nacquireTokenSilent(options: AcquireTokenSilentOptions) => Promise<AcquireTokenResult>\n```\n\nAcquire an access token silently via the Microsoft Authentication\nLibrary (MSAL) for an already signed-in account.\n\nIf the tenant requires an app protection policy, the call is rejected\nwith the `PROTECTION_POLICY_REQUIRED` error code. Use\n`remediateCompliance(...)` in this case.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                            |\n| ------------- | ------------------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#acquiretokensilentoptions\">AcquireTokenSilentOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#acquiretokenresult\">AcquireTokenResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### decryptFile(...)\n\n```typescript\ndecryptFile(options: DecryptFileOptions) => Promise<void>\n```\n\nDecrypt a file that was encrypted by the Intune App SDK.\n\nOn iOS, encrypted files can only be read through the Intune App SDK.\nCall this method before handing a file to other consumers such as the\nFilesystem plugin, a media player or an uploader.\n\nOn Android, the app reads encrypted files transparently, so this method\nis rarely needed. The file is tagged with the unmanaged identity, which\nremoves the encryption and takes the file out of the scope of a\nselective wipe.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                              |\n| ------------- | ----------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#decryptfileoptions\">DecryptFileOptions</a></code> |\n\n**Since:** 0.1.1\n\n--------------------\n\n\n### getAppConfig(...)\n\n```typescript\ngetAppConfig(options: GetAppConfigOptions) => Promise<GetAppConfigResult>\n```\n\nGet the application configuration values that the organization's IT\nadministrator has deployed for the given account via the MAM channel.\n\nFor configuration deployed via the MDM channel (device enrollment), use\nthe Managed Configurations plugin instead.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                |\n| ------------- | ------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#getappconfigoptions\">GetAppConfigOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#getappconfigresult\">GetAppConfigResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### getEnrolledAccount()\n\n```typescript\ngetEnrolledAccount() => Promise<GetEnrolledAccountResult>\n```\n\nGet the account that is currently enrolled in Mobile Application\nManagement (MAM).\n\nOnly available on Android and iOS.\n\n**Returns:** <code>Promise&lt;<a href=\"#getenrolledaccountresult\">GetEnrolledAccountResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### getPolicy(...)\n\n```typescript\ngetPolicy(options: GetPolicyOptions) => Promise<GetPolicyResult>\n```\n\nGet the app protection policy that is currently applied for the given\naccount.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                          |\n| ------------- | ------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#getpolicyoptions\">GetPolicyOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#getpolicyresult\">GetPolicyResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### getSdkVersion()\n\n```typescript\ngetSdkVersion() => Promise<GetSdkVersionResult>\n```\n\nGet the versions of the Intune App SDK and the Microsoft Authentication\nLibrary (MSAL) that the plugin was built with.\n\nOnly available on Android and iOS.\n\n**Returns:** <code>Promise&lt;<a href=\"#getsdkversionresult\">GetSdkVersionResult</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### isFileEncrypted(...)\n\n```typescript\nisFileEncrypted(options: IsFileEncryptedOptions) => Promise<IsFileEncryptedResult>\n```\n\nCheck whether a file is encrypted by the Intune App SDK.\n\nOn Android, this reflects whether the file is tagged with a managed\nidentity whose app protection policy uses file encryption, since the\nIntune App SDK for Android does not expose the encryption state of a\nsingle file.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                      |\n| ------------- | ------------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#isfileencryptedoptions\">IsFileEncryptedOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#isfileencryptedresult\">IsFileEncryptedResult</a>&gt;</code>\n\n**Since:** 0.1.1\n\n--------------------\n\n\n### loginAndEnrollAccount()\n\n```typescript\nloginAndEnrollAccount() => Promise<void>\n```\n\nSign in and enroll an account using the login UI provided by the Intune\nApp SDK.\n\nOn Android, use `acquireToken(...)` followed by\n`registerAndEnrollAccount(...)` instead.\n\nOnly available on iOS.\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### protectFile(...)\n\n```typescript\nprotectFile(options: ProtectFileOptions) => Promise<void>\n```\n\nProtect a file or directory for the given account.\n\nOn iOS, the Intune App SDK does not encrypt files on its own. Call this\nmethod for every file that contains organization data if the app\nprotection policy requires file encryption (see\n`GetPolicyResult.fileEncryptionRequired`). The file is encrypted in\nplace if the policy requires it. For a directory, all files it currently\ncontains are protected; files added later must be protected separately.\nEncrypted files can only be read through the Intune App SDK, so use\n`decryptFile(...)` before reading them with other plugins.\n\nOn Android, the Intune App SDK encrypts files automatically and the app\nreads them transparently. This method tags the file or directory with\nthe account so that it is in the scope of a selective wipe. Files added\nto a protected directory later inherit the protection.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                              |\n| ------------- | ----------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#protectfileoptions\">ProtectFileOptions</a></code> |\n\n**Since:** 0.1.1\n\n--------------------\n\n\n### registerAndEnrollAccount(...)\n\n```typescript\nregisterAndEnrollAccount(options: RegisterAndEnrollAccountOptions) => Promise<void>\n```\n\nRegister an account for Mobile Application Management (MAM) and enroll\nit in the Intune service.\n\nCall this after a successful `acquireToken(...)` call. The enrollment\nitself is asynchronous; listen for the `enrollmentChange` event to get\nthe enrollment result.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                                        |\n| ------------- | ------------------------------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#registerandenrollaccountoptions\">RegisterAndEnrollAccountOptions</a></code> |\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### remediateCompliance(...)\n\n```typescript\nremediateCompliance(options: RemediateComplianceOptions) => Promise<RemediateComplianceResult>\n```\n\nBring the app into compliance with the app protection policy of an\naccount so that Microsoft Entra ID grants tokens for it.\n\nCall this when `acquireToken(...)` or `acquireTokenSilent(...)` is\nrejected with the `PROTECTION_POLICY_REQUIRED` error code, passing the\n`data` of the error as options. The Intune App SDK registers and\nenrolls the account as needed. If the returned status is `compliant`,\nretry the token acquisition.\n\nOn iOS, the Intune App SDK may restart the app during the remediation if\nthe account was not enrolled before. In that case, the promise is never\nsettled and the app should retry the sign-in after the restart.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                              |\n| ------------- | --------------------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#remediatecomplianceoptions\">RemediateComplianceOptions</a></code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#remediatecomplianceresult\">RemediateComplianceResult</a>&gt;</code>\n\n**Since:** 0.1.2\n\n--------------------\n\n\n### showDiagnosticConsole()\n\n```typescript\nshowDiagnosticConsole() => Promise<void>\n```\n\nShow the diagnostic console of the Intune App SDK.\n\nThe console allows the user to inspect the SDK state and collect logs\nfor support requests.\n\nOnly available on Android and iOS.\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### unenrollAccount(...)\n\n```typescript\nunenrollAccount(options: UnenrollAccountOptions) => Promise<void>\n```\n\nUnenroll an account from Mobile Application Management (MAM) and\nunregister it from the Intune service.\n\nOnly available on Android and iOS.\n\n| Param         | Type                                                                      |\n| ------------- | ------------------------------------------------------------------------- |\n| **`options`** | <code><a href=\"#unenrollaccountoptions\">UnenrollAccountOptions</a></code> |\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### addListener('appConfigChange', ...)\n\n```typescript\naddListener(eventName: 'appConfigChange', listenerFunc: (event: AppConfigChangeEvent) => void) => Promise<PluginListenerHandle>\n```\n\nCalled when the application configuration changes.\n\nUse `getAppConfig(...)` to read the new configuration values.\n\nOnly available on Android and iOS.\n\n| Param              | Type                                                                                      |\n| ------------------ | ----------------------------------------------------------------------------------------- |\n| **`eventName`**    | <code>'appConfigChange'</code>                                                            |\n| **`listenerFunc`** | <code>(event: <a href=\"#appconfigchangeevent\">AppConfigChangeEvent</a>) =&gt; void</code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#pluginlistenerhandle\">PluginListenerHandle</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### addListener('enrollmentChange', ...)\n\n```typescript\naddListener(eventName: 'enrollmentChange', listenerFunc: (event: EnrollmentChangeEvent) => void) => Promise<PluginListenerHandle>\n```\n\nCalled when the enrollment state of an account changes, for example\nwhen an enrollment attempt succeeds or fails.\n\nOnly available on Android and iOS.\n\n| Param              | Type                                                                                        |\n| ------------------ | ------------------------------------------------------------------------------------------- |\n| **`eventName`**    | <code>'enrollmentChange'</code>                                                             |\n| **`listenerFunc`** | <code>(event: <a href=\"#enrollmentchangeevent\">EnrollmentChangeEvent</a>) =&gt; void</code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#pluginlistenerhandle\">PluginListenerHandle</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### addListener('policyChange', ...)\n\n```typescript\naddListener(eventName: 'policyChange', listenerFunc: (event: PolicyChangeEvent) => void) => Promise<PluginListenerHandle>\n```\n\nCalled when the app protection policy changes.\n\nUse `getPolicy(...)` to read the new policy values.\n\nOnly available on Android and iOS.\n\n| Param              | Type                                                                                |\n| ------------------ | ----------------------------------------------------------------------------------- |\n| **`eventName`**    | <code>'policyChange'</code>                                                         |\n| **`listenerFunc`** | <code>(event: <a href=\"#policychangeevent\">PolicyChangeEvent</a>) =&gt; void</code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#pluginlistenerhandle\">PluginListenerHandle</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### addListener('wipeRequested', ...)\n\n```typescript\naddListener(eventName: 'wipeRequested', listenerFunc: (event: WipeRequestedEvent) => void) => Promise<PluginListenerHandle>\n```\n\nCalled when the Intune service requests a selective wipe of the\naccount's data.\n\nThe Intune App SDK wipes the data it manages, but it does **not** wipe\nthe web layer storage of your Capacitor app (e.g. IndexedDB, Local\nStorage). Use this event to clean up any data your web code has\npersisted.\n\nThe event is delivered even if the wipe was requested while your app\nwas not running (see the documentation for details).\n\nOnly available on Android and iOS.\n\n| Param              | Type                                                                                  |\n| ------------------ | ------------------------------------------------------------------------------------- |\n| **`eventName`**    | <code>'wipeRequested'</code>                                                          |\n| **`listenerFunc`** | <code>(event: <a href=\"#wiperequestedevent\">WipeRequestedEvent</a>) =&gt; void</code> |\n\n**Returns:** <code>Promise&lt;<a href=\"#pluginlistenerhandle\">PluginListenerHandle</a>&gt;</code>\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### removeAllListeners()\n\n```typescript\nremoveAllListeners() => Promise<void>\n```\n\nRemove all listeners for this plugin.\n\n**Since:** 0.1.0\n\n--------------------\n\n\n### Interfaces\n\n\n#### AcquireTokenResult\n\n| Prop              | Type                        | Description                                                                                                             | Since |\n| ----------------- | --------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----- |\n| **`accessToken`** | <code>string</code>         | The acquired access token.                                                                                              | 0.1.0 |\n| **`accountId`**   | <code>string</code>         | The Microsoft Entra object ID (OID) of the signed-in account. Use this identifier for all other methods of this plugin. | 0.1.0 |\n| **`idToken`**     | <code>string \\| null</code> | The raw ID token of the signed-in account, if available.                                                                | 0.1.0 |\n| **`tenantId`**    | <code>string \\| null</code> | The Microsoft Entra tenant ID of the signed-in account, if available.                                                   | 0.1.0 |\n| **`username`**    | <code>string \\| null</code> | The username (usually the UPN) of the signed-in account, if available.                                                  | 0.1.0 |\n\n\n#### AcquireTokenOptions\n\n| Prop              | Type                  | Description                                                                                            | Default            | Since |\n| ----------------- | --------------------- | ------------------------------------------------------------------------------------------------------ | ------------------ | ----- |\n| **`forcePrompt`** | <code>boolean</code>  | Whether or not to force the account selection prompt to be shown, even if a user is already signed in. | <code>false</code> | 0.1.0 |\n| **`loginHint`**   | <code>string</code>   | The username to pre-fill in the sign-in UI.                                                            |                    | 0.1.0 |\n| **`scopes`**      | <code>string[]</code> | The scopes to request the access token for.                                                            |                    | 0.1.0 |\n\n\n#### AcquireTokenSilentOptions\n\n| Prop               | Type                  | Description                                                                  | Default            | Since |\n| ------------------ | --------------------- | ---------------------------------------------------------------------------- | ------------------ | ----- |\n| **`accountId`**    | <code>string</code>   | The Microsoft Entra object ID (OID) of the account to acquire the token for. |                    | 0.1.0 |\n| **`forceRefresh`** | <code>boolean</code>  | Whether or not to ignore any cached token and force a token refresh.         | <code>false</code> | 0.1.0 |\n| **`scopes`**       | <code>string[]</code> | The scopes to request the access token for.                                  |                    | 0.1.0 |\n\n\n#### DecryptFileOptions\n\n| Prop              | Type                | Description                                                                                                                                                             | Since |\n| ----------------- | ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----- |\n| **`destination`** | <code>string</code> | The absolute path or `file://` URI to write the decrypted copy to. If not provided, the file is decrypted in place. An existing file at the destination is overwritten. | 0.1.1 |\n| **`path`**        | <code>string</code> | The absolute path or `file://` URI of the encrypted file.                                                                                                               | 0.1.1 |\n\n\n#### GetAppConfigResult\n\n| Prop            | Type                                      | Description                                                                                                                             | Since |\n| --------------- | ----------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------- | ----- |\n| **`conflicts`** | <code>AppConfigConflict[]</code>          | The configuration keys for which multiple conflicting values have been deployed.                                                        | 0.1.0 |\n| **`values`**    | <code>Record&lt;string, string&gt;</code> | The merged application configuration values. For keys with conflicting values, the value that the Intune App SDK returns first is used. | 0.1.0 |\n\n\n#### AppConfigConflict\n\n| Prop         | Type                  | Description                                                   | Since |\n| ------------ | --------------------- | ------------------------------------------------------------- | ----- |\n| **`key`**    | <code>string</code>   | The configuration key for which conflicting values exist.     | 0.1.0 |\n| **`values`** | <code>string[]</code> | All values that have been deployed for the configuration key. | 0.1.0 |\n\n\n#### GetAppConfigOptions\n\n| Prop            | Type                | Description                                                                                  | Since |\n| --------------- | ------------------- | -------------------------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string</code> | The Microsoft Entra object ID (OID) of the account to get the application configuration for. | 0.1.0 |\n\n\n#### GetEnrolledAccountResult\n\n| Prop          | Type                                                                | Description                                               | Since |\n| ------------- | ------------------------------------------------------------------- | --------------------------------------------------------- | ----- |\n| **`account`** | <code><a href=\"#enrolledaccount\">EnrolledAccount</a> \\| null</code> | The enrolled account or `null` if no account is enrolled. | 0.1.0 |\n\n\n#### EnrolledAccount\n\n| Prop            | Type                        | Description                                                           | Since |\n| --------------- | --------------------------- | --------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string</code>         | The Microsoft Entra object ID (OID) of the enrolled account.          | 0.1.0 |\n| **`username`**  | <code>string \\| null</code> | The username (usually the UPN) of the enrolled account, if available. | 0.1.0 |\n\n\n#### GetPolicyResult\n\n| Prop                               | Type                 | Description                                                                                                                      | Since |\n| ---------------------------------- | -------------------- | -------------------------------------------------------------------------------------------------------------------------------- | ----- |\n| **`contactSyncAllowed`**           | <code>boolean</code> | Whether or not the policy allows syncing contacts to the device.                                                                 | 0.1.0 |\n| **`fileEncryptionRequired`**       | <code>boolean</code> | Whether or not the policy requires files to be encrypted. On Android, this reflects whether file encryption is currently in use. | 0.1.0 |\n| **`managedBrowserRequired`**       | <code>boolean</code> | Whether or not the policy requires links to be opened in a managed browser (e.g. Microsoft Edge).                                | 0.1.0 |\n| **`pinRequired`**                  | <code>boolean</code> | Whether or not the policy requires a PIN to access the app.                                                                      | 0.1.0 |\n| **`saveToPersonalStorageAllowed`** | <code>boolean</code> | Whether or not the policy allows saving files to personal (local) storage.                                                       | 0.1.0 |\n| **`screenCaptureAllowed`**         | <code>boolean</code> | Whether or not the policy allows taking screenshots.                                                                             | 0.1.0 |\n\n\n#### GetPolicyOptions\n\n| Prop            | Type                | Description                                                                              | Since |\n| --------------- | ------------------- | ---------------------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string</code> | The Microsoft Entra object ID (OID) of the account to get the app protection policy for. | 0.1.0 |\n\n\n#### GetSdkVersionResult\n\n| Prop                   | Type                        | Description                                                               | Since |\n| ---------------------- | --------------------------- | ------------------------------------------------------------------------- | ----- |\n| **`intuneSdkVersion`** | <code>string</code>         | The version of the Intune App SDK.                                        | 0.1.0 |\n| **`msalVersion`**      | <code>string \\| null</code> | The version of the Microsoft Authentication Library (MSAL), if available. | 0.1.0 |\n\n\n#### IsFileEncryptedResult\n\n| Prop            | Type                 | Description                                                 | Since |\n| --------------- | -------------------- | ----------------------------------------------------------- | ----- |\n| **`encrypted`** | <code>boolean</code> | Whether or not the file is encrypted by the Intune App SDK. | 0.1.1 |\n\n\n#### IsFileEncryptedOptions\n\n| Prop       | Type                | Description                                              | Since |\n| ---------- | ------------------- | -------------------------------------------------------- | ----- |\n| **`path`** | <code>string</code> | The absolute path or `file://` URI of the file to check. | 0.1.1 |\n\n\n#### ProtectFileOptions\n\n| Prop            | Type                | Description                                                             | Since |\n| --------------- | ------------------- | ----------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string</code> | The Microsoft Entra object ID (OID) of the account that owns the file.  | 0.1.1 |\n| **`path`**      | <code>string</code> | The absolute path or `file://` URI of the file or directory to protect. | 0.1.1 |\n\n\n#### RegisterAndEnrollAccountOptions\n\n| Prop            | Type                | Description                                                                                                    | Since |\n| --------------- | ------------------- | -------------------------------------------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string</code> | The Microsoft Entra object ID (OID) of the account to register and enroll, as returned by `acquireToken(...)`. | 0.1.0 |\n\n\n#### RemediateComplianceResult\n\n| Prop               | Type                                                          | Description                                                                                                | Since |\n| ------------------ | ------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ----- |\n| **`errorMessage`** | <code>string \\| null</code>                                   | A localized error message that can be displayed to the user if the account is not compliant, if available. | 0.1.2 |\n| **`errorTitle`**   | <code>string \\| null</code>                                   | A localized error title that can be displayed to the user if the account is not compliant, if available.   | 0.1.2 |\n| **`status`**       | <code><a href=\"#compliancestatus\">ComplianceStatus</a></code> | The compliance status of the account after the remediation.                                                | 0.1.2 |\n\n\n#### RemediateComplianceOptions\n\n| Prop            | Type                 | Description                                                                                                                                                                                     | Default            | Since |\n| --------------- | -------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------ | ----- |\n| **`accountId`** | <code>string</code>  | The Microsoft Entra object ID (OID) of the account to remediate.                                                                                                                                |                    | 0.1.2 |\n| **`authority`** | <code>string</code>  | The authority URL of the account. Only available on Android. Required on Android.                                                                                                               |                    | 0.1.2 |\n| **`silent`**    | <code>boolean</code> | Whether or not to remediate without showing any UI of the Intune App SDK. On iOS, the status `interactionRequired` is returned if the remediation cannot be completed without user interaction. | <code>false</code> | 0.1.2 |\n| **`tenantId`**  | <code>string</code>  | The Microsoft Entra tenant ID of the account. Only available on Android. Required on Android.                                                                                                   |                    | 0.1.2 |\n| **`username`**  | <code>string</code>  | The username (usually the UPN) of the account. Only available on Android. Required on Android.                                                                                                  |                    | 0.1.2 |\n\n\n#### UnenrollAccountOptions\n\n| Prop            | Type                 | Description                                                                                           | Default            | Since |\n| --------------- | -------------------- | ----------------------------------------------------------------------------------------------------- | ------------------ | ----- |\n| **`accountId`** | <code>string</code>  | The Microsoft Entra object ID (OID) of the account to unenroll.                                       |                    | 0.1.0 |\n| **`wipe`**      | <code>boolean</code> | Whether or not the account's data should be wiped as part of the unenrollment. Only available on iOS. | <code>false</code> | 0.1.0 |\n\n\n#### PluginListenerHandle\n\n| Prop         | Type                                      |\n| ------------ | ----------------------------------------- |\n| **`remove`** | <code>() =&gt; Promise&lt;void&gt;</code> |\n\n\n#### AppConfigChangeEvent\n\n| Prop            | Type                        | Description                                                                | Since |\n| --------------- | --------------------------- | -------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string \\| null</code> | The Microsoft Entra object ID (OID) of the affected account, if available. | 0.1.0 |\n\n\n#### EnrollmentChangeEvent\n\n| Prop            | Type                                                          | Description                                                                | Since |\n| --------------- | ------------------------------------------------------------- | -------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string \\| null</code>                                   | The Microsoft Entra object ID (OID) of the affected account, if available. | 0.1.0 |\n| **`status`**    | <code><a href=\"#enrollmentstatus\">EnrollmentStatus</a></code> | The new enrollment status of the account.                                  | 0.1.0 |\n\n\n#### PolicyChangeEvent\n\n| Prop            | Type                        | Description                                                                | Since |\n| --------------- | --------------------------- | -------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string \\| null</code> | The Microsoft Entra object ID (OID) of the affected account, if available. | 0.1.0 |\n\n\n#### WipeRequestedEvent\n\n| Prop            | Type                        | Description                                                                | Since |\n| --------------- | --------------------------- | -------------------------------------------------------------------------- | ----- |\n| **`accountId`** | <code>string \\| null</code> | The Microsoft Entra object ID (OID) of the affected account, if available. | 0.1.0 |\n\n\n### Type Aliases\n\n\n#### ComplianceStatus\n\nThe compliance status of an account.\n\n- `canceled`: The user canceled the remediation. Only available on iOS.\n- `clientError`: The remediation failed due to a client issue, such as a\n  missing or invalid token. Only available on Android.\n- `companyPortalRequired`: The Company Portal app must be installed. If it\n  is already installed, the app must be restarted. Only available on\n  Android.\n- `compliant`: The account is compliant. Retry the token acquisition.\n- `interactionRequired`: The remediation requires user interaction. Call\n  `remediateCompliance(...)` again with `silent` set to `false`. Only\n  available on iOS.\n- `networkFailure`: The Intune service could not be reached. Retry when\n  the network connection is restored.\n- `notCompliant`: The account is not compliant.\n- `pending`: The Intune service did not respond in time. Retry later.\n  Only available on Android.\n- `serviceFailure`: The compliance data could not be retrieved from the\n  Intune service. Retry later.\n- `unknown`: The status is unknown. Only available on Android.\n\n<code>'canceled' | 'clientError' | 'companyPortalRequired' | 'compliant' | 'interactionRequired' | 'networkFailure' | 'notCompliant' | 'pending' | 'serviceFailure' | 'unknown'</code>\n\n\n#### EnrollmentStatus\n\nThe enrollment status of an account.\n\n<code>'enrolled' | 'failed' | 'pending' | 'unenrolled'</code>\n\n</docgen-api>\n\n## Platform Support\n\nNot every feature is available on all platforms. The following table lists the notable per-platform differences of the plugin's API:\n\n| Method / Option                       | Android | iOS | Web |\n| ------------------------------------- | :-----: | :-: | :-: |\n| `loginAndEnrollAccount()`              |   ❌    | ✅  | ❌  |\n| `unenrollAccount(...)` (`wipe` option) |   ❌    | ✅  | ❌  |\n\nAdditional notes:\n\n- On Android, use `acquireToken(...)` followed by `registerAndEnrollAccount(...)` instead of `loginAndEnrollAccount()`. The Intune App SDK for Android does not provide its own login UI.\n- On Android, `remediateCompliance(...)` requires the `authority`, `tenantId` and `username` options. All of them are included in the `data` of the `PROTECTION_POLICY_REQUIRED` error.\n- On Android, `fileEncryptionRequired` reflects whether file encryption is currently **in use** by the Intune App SDK, which is the closest equivalent the SDK exposes.\n- The `wipeRequested` event is persisted and replayed on the next app launch if no listener was registered when the wipe arrived. In rare cases the event may be delivered more than once, so make sure your wipe handler is idempotent.\n- On iOS, the Intune App SDK does not encrypt files on its own. Call `protectFile(...)` for every file that contains organization data. On Android, file encryption is automatic and `protectFile(...)` only tags the file with the account so that it is in the scope of a selective wipe.\n- On iOS, encrypted files can only be read through the Intune App SDK. Reading them with the Filesystem plugin or handing them to other native plugins (e.g. media players or uploaders) yields the encrypted content. Call `decryptFile(...)` first. On Android, the app reads encrypted files transparently, so `decryptFile(...)` is rarely needed.\n- On Android, `isFileEncrypted(...)` reflects whether the file is tagged with a managed identity whose policy uses file encryption, since the Intune App SDK does not expose the encryption state of a single file.\n- Policy **enforcement** (PIN, copy/paste and screenshot restrictions, etc.) is performed automatically by the Intune App SDK once the native integration is in place. The JavaScript API exists for the parts that enforcement cannot do: enrolling accounts, reading configuration, adapting your UI to the policy, protecting files on iOS, and cleaning up web storage on selective wipe.\n\n## Choosing between the MAM and MDM channel\n\nOrganizations can deliver app configuration through two different channels, and administrators frequently mix them up. This plugin covers the **MAM channel**; the [Managed Configurations](https://capawesome.io/docs/sdks/capacitor/managed-configurations/) plugin covers the **MDM channel**:\n\n|                            | MAM channel (this plugin)                       | MDM channel ([Managed Configurations](https://capawesome.io/docs/sdks/capacitor/managed-configurations/)) |\n| -------------------------- | ----------------------------------------------- | --------------------------------------------------------- |\n| Device enrollment required | No                                              | Yes                                                        |\n| Delivered via              | Intune App SDK (Intune service)                 | `RestrictionsManager` / `com.apple.configuration.managed`  |\n| Targeted at                | The signed-in account (identity)                | The device                                                 |\n| EMM vendor                 | Microsoft Intune only                           | Any EMM/MDM vendor                                         |\n| Typical scenario           | BYOD / app protection without device management | Corporate-owned, fully managed devices                     |\n\nIf your organization deploys the app configuration policy with **\"Managed apps\"** as the delivery channel in the Intune admin center, use this plugin. If it is deployed with **\"Managed devices\"**, use the Managed Configurations plugin. Apps that must support both scenarios should read both channels.\n\n## Testing\n\nExercising Mobile Application Management (MAM) requires infrastructure that cannot be simulated locally:\n\n- A **Microsoft Intune tenant** with **Intune licenses** and a **licensed test user**.\n- An **app protection policy** and (optionally) an **app configuration policy** targeted at the test user and your app.\n- On Android, the **Company Portal** app installed on the test device.\n\nWithout a tenant, the plugin compiles and loads, but enrollment fails with `AccountNotLicensed`-style errors and no policy is applied. Building this plugin (e.g. via `npm run verify`) only proves that the code compiles — it does not exercise any MAM functionality.\n\n## FAQ\n\n### How is this plugin different from other similar plugins?\n\nIt integrates the Microsoft Intune App SDK for Mobile Application Management on Android and iOS through a fully typed API, enforcing app protection policies and exposing them as typed booleans so you can adapt your UI, acquiring tokens via MSAL, and enrolling accounts without device enrollment. It emits selective-wipe events so you can purge the web-layer storage (such as IndexedDB and Local Storage) that the SDK cannot reach itself, and it is built against current Intune and MSAL versions, which matters because Microsoft blocks apps that ship outdated SDKs. It is a free, actively maintained plugin that stays current with the latest Capacitor version.\n\n### Do I need a Microsoft Intune tenant to use this plugin?\n\nYes. This plugin wraps the Microsoft Intune App SDK, which requires a Microsoft Intune tenant, Intune licenses, and an app registration in Microsoft Entra ID (see [Testing](#testing)).\n\n### Why does the plugin require iOS 17?\n\nThe current Microsoft Intune App SDK for iOS requires iOS 17 or later. Microsoft actively blocks apps built with outdated Intune App SDK versions, so this plugin always tracks Microsoft's current SDK line instead of pinning an older one.\n\n### Does this plugin enforce the app protection policies?\n\nMostly, yes. Once the native integration (MAM build plugin on Android, SDK integration on iOS) is in place, the Intune App SDK enforces PIN, data transfer and screenshot restrictions itself. File encryption is automatic on Android, but on iOS the app must protect its files via `protectFile(...)`. The JavaScript API of this plugin is for the parts enforcement cannot do: enrollment, introspection, file protection on iOS, and cleaning up web storage on selective wipe.\n\n### What is the difference between this plugin and the Managed Configurations plugin?\n\nThis plugin reads the MAM channel (Intune App SDK, no device enrollment required). The [Managed Configurations](https://capawesome.io/docs/sdks/capacitor/managed-configurations/) plugin reads the MDM channel (device enrollment required, works with any EMM vendor). See [Choosing between the MAM and MDM channel](#choosing-between-the-mam-and-mdm-channel).\n\n### Can I use this plugin with Ionic, React, Vue or Angular?\n\nYes, the plugin is framework-agnostic. It works in any Capacitor app regardless of the web framework, including Ionic with Angular, React, or Vue, as well as plain JavaScript projects.\n\n## Related Plugins\n\n- [App Integrity](https://capawesome.io/docs/sdks/capacitor/app-integrity/): Verify app and device integrity using the Play Integrity API and App Attest.\n- [Managed Configurations](https://capawesome.io/docs/sdks/capacitor/managed-configurations/): Access managed configuration settings deployed by an MDM channel, the counterpart to Intune's MAM channel.\n- [Root Detection](https://capawesome.io/docs/sdks/capacitor/root-detection/): Detect rooted and jailbroken devices.\n\n## Newsletter\n\nStay up to date with the latest news and updates about the Capawesome, Capacitor, and Ionic ecosystem by subscribing to our [Capawesome Newsletter](https://cloud.capawesome.io/newsletter/).\n\n## Changelog\n\nSee [CHANGELOG.md](https://github.com/capawesome-team/capacitor-plugins/blob/main/packages/intune/CHANGELOG.md).\n\n## License\n\nSee [LICENSE](https://github.com/capawesome-team/capacitor-plugins/blob/main/packages/intune/LICENSE).\n\n## Third-Party Notices\n\nThe Microsoft Intune App SDKs for Android and iOS are proprietary software, licensed by Microsoft under the [Microsoft License Terms Intune App SDK](https://github.com/msintuneappsdk/ms-intune-app-sdk-ios/blob/master/Microsoft%20License%20Terms%20Intune%20App%20SDK%20for%20iOS.pdf). This plugin does **not** bundle or modify the Intune App SDKs — it declares them as dependencies and downloads them from Microsoft's official repositories at build or install time. By building an app with this plugin, you accept Microsoft's license terms for the Intune App SDK. The Microsoft Authentication Library (MSAL) is licensed under the MIT license. Using the plugin requires a Microsoft Intune tenant with appropriate licenses. The MIT license of this plugin covers the wrapper code only, not the Microsoft SDKs.\n\nNote that Microsoft's license terms also place obligations on **your app** as the distributor of the Intune App SDK binaries — among other things regarding your app's own functionality and copyright notice, license compatibility, and indemnification. Review the license terms linked above before shipping your app.\n\n[^1]: This project is not affiliated with, endorsed by, sponsored by, or approved by Microsoft Corporation or any of its","readmeFilename":"README.md"}