為受控的 iOS 裝置新增應用程式設定原則Add app configuration policies for managed iOS devices

使用 Microsoft Intune 中的應用程式設定原則,提供 iOS 應用程式的自訂組態設定。Use app configuration policies in Microsoft Intune to provide custom configuration settings for an iOS app. 這些組態設定可讓您根據供應商指示來自訂應用程式。These configuration settings allow an app to be customized based on the suppliers direction. 您必須從應用程式的供應商取得這些組態設定 (金鑰和值)。You must get these configuration settings (keys and values) from the supplier of the app. 若要設定應用程式,請以金鑰和值的形式,或以包含金鑰和值的 XML 形式來指定設定。To configure the app, you specify the settings as keys and values, or as XML containing the keys and values. 此外,您不會直接將這些設定原則指派給使用者與裝置。Also, you do not assign these configuration policies directly to users and devices. 而是建立設定原則與應用程式的關聯,然後指派應用程式。Instead, you associate a configuration policy with an app, and then assign the app. 每當應用程式檢查是否有設定原則設定時 (通常是第一次執行時),便會使用這些設定。The configuration policy settings are used when the app checks for them, typically the first time it is run.

新增應用程式設定原則後,就可以設定指派應用程式設定原則。Once you add an app configuration policy, you can set the assignments for the app configuration policy. 當您設定原則指派時,您可以選擇包含與排除要套用原則的使用者群組。When you set the assignments for the policy, you can choose to include and exclude the groups of users for which the policy applies. 當您選擇要包含一或多個群組時,您可以選擇選取要包含特定群組或選取內建群組。When you choose to include one or more groups, you can choose to select specific groups to include or select built-in groups. 內建群組包括 [所有使用者]、[所有裝置] 和 [所有使用者及所有裝置]。Built-in groups include All Users, All Devices, and All Users + All Devices.

注意

Intune 會在主控台中提供預先建立的 [所有使用者] 和 [所有裝置] 群組,附有內建的最佳化方便您使用。Intune provides pre-created All Users and All Devices groups in the console with built-in optimizations for your convenience. 強烈建議您使用這些群組針對所有使用者和所有裝置,而不是您自行建立的任何「所有使用者」或「所有裝置」群組。It is highly recommended that you use these groups to target all users and all devices instead of any ‘All users’ or ’All devices’ groups you may have created yourself.

選取應用程式設定原則包含的群組後,您也可以選擇要排除的特定群組。Once you have selected the included groups for your application configuration policy, you can also choose the specific groups to exclude. 如需詳細資訊,請參閱 Microsoft Intune 的包含與排除應用程式指派For more information, see Include and exclude app assignments in Microsoft Intune.

提示

此原則類型目前僅針對執行 iOS 8.0 和更新版本的裝置提供。This policy type is currently available only for devices running iOS 8.0 and later. 它支援下列應用程式安裝類型︰It supports the following app installation types:

  • App Store 中的受管理 iOS 應用程式Managed iOS app from the app store
  • iOS 應用程式套件App package for iOS

如需應用程式安裝類型的詳細資訊,請參閱如何將應用程式新增至 Microsoft IntuneFor more information about app installation types, see How to add an app to Microsoft Intune.

建立應用程式設定原則Create an app configuration policy

  1. 登入 Azure 入口網站Sign into the Azure portal.

  2. 選擇 [All services] (所有服務) > [Intune]。Choose All services > Intune. Intune 位於 [監視 + 管理] 區段。Intune is located in the Monitoring + Management section.

  3. 選擇 [Mobile Apps] 工作負載。Choose the Mobile apps workload.

  4. 選擇 [管理] 群組中的 [應用程式設定原則],然後選擇 [新增]。Choose App configuration policies in the Manage group, and then choose Add.

  5. 使用下列詳細資料:Set the following details:

    • 名稱 - 在 Azure 入口網站中顯示的設定檔名稱。Name - The name of the profile that appears in the Azure portal.
    • 描述 - 在 Azure 入口網站中顯示的設定檔描述。Description - The description of the profile that appears in the Azure portal.
    • 裝置註冊類型 - 選擇 [受控裝置]。Device enrollment type - Choose Managed devices.
  6. 為 [平台] 選取 [iOS]。Select iOS for Platform.

  7. 選擇 [相關聯的應用程式]。Choose Associated app. 然後,在 [相關聯的應用程式] 窗格上,選擇要套用設定的受控應用程式,然後選取 [確定]。Then, on the Associated app pane, choose the managed app to which you want to apply the configuration and select OK.

  8. 在 [新增設定原則] 窗格上,選擇 [組態設定]。On the Add configuration policy pane, choose Configuration settings.

  9. 選取 [組態設定格式]。Select Configuration settings format. 選取下列其中一項以新增 XML 資訊:Select one of the following to add XML information:

  10. 新增 XML 資訊之後,請選擇 [確定],然後選擇 [新增] 新增設定原則。Once you have added your XML information, choose OK, and then choose Add to add the configuration policy. 即會顯示設定原則的概觀窗格。The overview pane for the configuration policy is displayed.

  11. 選取 [指派] 來顯示包含與排除選項。Select Assignments to display the include and exclude options.

    [原則指派] [包含] 索引標籤的螢幕擷取畫面

  12. 選取 [包含] 索引標籤的 [所有使用者]。Select All Users on the Include tab.

    [原則指派 - 所有使用者] 下拉式選項的螢幕擷取畫面

  13. 選取 [排除] 索引標籤。Select the Exclude tab.

  14. 按一下 [選取要排除的群組] 以顯示相關的窗格。Click Select groups to exclude to display the related pane.

    [原則指派 - 選取要排除的群組] 刀鋒視窗的螢幕擷取畫面

  15. 選擇您要排除的群組,然後按一下 [選取]。Choose the groups you want to exclude and then click Select.

    注意

    新增群組時,如已包含任何其他群組用於指定的指派類型,就會預先選取且無法針對其他包含指派類型進行變更。When adding a group, if any other group has already been included for a given assignment type, it is pre-selected and unchangeable for other include assignment types. 因此,已使用的該群組,不能用為排除的群組。Therefore, that group that has been used, cannot be used as an excluded group.

  16. 按一下 [儲存]Click Save.

使用設定設計工具Use configuration designer

Microsoft Intune 提供應用程式專屬的組態設定。Microsoft Intune provides configuration settings that are unique to an app. 您可在 Microsoft Intune 中已註冊或未註冊的裝置上,針對應用程式使用設定設計工具。You can use the configuration designer for apps on devices that are enrolled or not enrolled in Microsoft Intune. 設計工具可讓您設定特定的設定金鑰和值,以協助您建立基礎 XML。The designer lets you configure specific configuration keys and values that helps you create the underlying XML. 您也必須指定每個值的資料類型。You must also specify the data type for each value. 安裝應用程式時,會自動將這些設定提供給應用程式。These settings are supplied to apps automatically when the apps are installed.

新增設定Add a setting

  1. 對於設定中的每個金鑰和值,請設定:For each key and value in the configuration, set:
    • 設定金鑰 - 唯一識別特定設定組態的金鑰。Configuration key - The key that uniquely identifies the specific setting configuration.
    • 實值型別 - 設定值的資料類型。Value type - The data type of the configuration value. 類型包括整數、實數、字串或布林值。Types include Integer, Real, String, or Boolean.
    • 設定值 - 設定的值。Configuration value - The value for the configuration.
  2. 選擇 [確定] 來設定您的組態設定。Choose OK to set your configuration settings.

刪除設定Delete a setting

  1. 選擇設定旁邊的省略符號 (...)。Choose the ellipsis (...) next to the setting.
  2. 選取 [刪除]。Select Delete.

{{ 和 }} 字元僅供權杖類型使用,絕不能用於其他用途。The {{ and }} characters are used by token types only and must not be used for other purposes.

輸入 XML 資料Enter XML data

您可以輸入或貼上 XML 屬性清單,其中包含 Intune 中所註冊裝置的應用程式組態設定。You can type or paste an XML property list that contains the app configuration settings for devices enrolled in Intune. XML 屬性清單的格式會依您所設定的應用程式而有所不同。The format of the XML property list varies depending on the app that you are configuring. 如需所要使用之確切格式的詳細資訊,請連絡應用程式供應商。For details about the exact format to use, contact the supplier of the app.

Intune 會驗證 XML 格式。Intune validates the XML format. 但 Intune 不會檢查 XML 屬性清單 (PList) 是否適用於目標應用程式。However, Intune does not check that the XML property list (PList) works with the target app.

若要深入了解 XML 屬性清單:To learn more about XML property lists:

應用程式設定 XML 檔案的範例格式Example format for an app configuration XML file

當您建立應用程式設定檔時,可以使用下列格式指定下列一或多個值︰When you create an app configuration file, you can specify one or more of the following values by using this format:

<dict>
  <key>userprincipalname</key>
  <string>{{userprincipalname}}</string>
  <key>mail</key>
  <string>{{mail}}</string>
  <key>partialupn</key>
  <string>{{partialupn}}</string>
  <key>accountid</key>
  <string>{{accountid}}</string>
  <key>deviceid</key>
  <string>{{deviceid}}</string>
  <key>userid</key>
  <string>{{userid}}</string>
  <key>username</key>
  <string>{{username}}</string>
  <key>serialnumber</key>
  <string>{{serialnumber}}</string>
  <key>serialnumberlast4digits</key>
  <string>{{serialnumberlast4digits}}</string>
  <key>udidlast4digits</key>
  <string>{{udidlast4digits}}</string>
</dict>

支援的 XML PList 資料類型Supported XML PList data types

Intune 支援屬性清單中的下列資料類型:Intune supports the following data types in a property list:

  • <integer><integer>
  • <real><real>
  • <string><string>
  • <array><array>
  • <dict><dict>
  • <true /> 或 <false /><true /> or <false />

屬性清單中使用的權杖Tokens used in the property list

此外,Intune 支援屬性清單中的下列權杖類型︰Additionally, Intune supports the following token types in the property list:

  • {{userprincipalname}}—例如,**John@contoso.com**{{userprincipalname}}—for example, **John@contoso.com**
  • {{mail}}—例如,**John@contoso.com**{{mail}}—for example, **John@contoso.com**
  • {{partialupn}}—例如,John{{partialupn}}—for example, John
  • {{accountid}}—例如,fc0dc142-71d8-4b12-bbea-bae2a8514c81{{accountid}}—for example, fc0dc142-71d8-4b12-bbea-bae2a8514c81
  • {{deviceid}}—例如,b9841cd9-9843-405f-be28-b2265c59ef97{{deviceid}}—for example, b9841cd9-9843-405f-be28-b2265c59ef97
  • {{userid}}—例如,3ec2c00f-b125-4519-acf0-302ac3761822{{userid}}—for example, 3ec2c00f-b125-4519-acf0-302ac3761822
  • {{username}}—例如,John Doe{{username}}—for example, John Doe
  • {{serialnumber}}—例如,F4KN99ZUG5V2 (適用於 iOS 裝置){{serialnumber}}—for example, F4KN99ZUG5V2 (for iOS devices)
  • {{serialnumberlast4digits}}—例如,G5V2 (適用於 iOS 裝置){{serialnumberlast4digits}}—for example, G5V2 (for iOS devices)

監視每個裝置的 iOS 應用程式設定狀態Monitor iOS app configuration status per device

一旦指派設定原則,您可以監視每個受控裝置的 iOS 應用程式設定狀態。Once a configuration policy has been assigned, you can monitor iOS app configuration status for each managed device. 從 Azure 入口網站的 [Microsoft Intune] 中,選取 [裝置] > [所有裝置]。From Microsoft Intune in the Azure portal, select Devices > All devices. 從受控裝置清單中,選取特定的裝置以顯示裝置的刀鋒視窗。From the list of managed devices, select a specific device to display a blade for the device. 在裝置的刀鋒視窗中,選取 [應用程式設定]。On the device blade, select App configuration.

接下來的步驟Next steps

繼續指派監視應用程式。Continue to assign and monitor the app.