macOSEndpointProtectionConfiguration リソースの種類

名前空間: microsoft.graph

重要:Microsoft は Intune /beta API をサポートしていますが、より頻繁に変更される可能性があります。 可能な場合は、バージョン v1.0 を使用することをお勧めします。 バージョン セレクターを使用して、バージョン v1.0 で API が使用できるかどうかを確認します。

注:Intune 用 Microsoft Graph API には、テナントの有効な Intune ライセンスが必要です。

MacOS エンドポイント保護構成プロファイル。

deviceConfiguration から継承します

メソッド

メソッド 戻り値の型 説明
macOSEndpointProtectionConfigurations の一覧表示 macOSEndpointProtectionConfiguration コレクション macOSEndpointProtectionConfiguration オブジェクトのプロパティと関係を一覧表示します。
macOSEndpointProtectionConfiguration の取得 macOSEndpointProtectionConfiguration macOSEndpointProtectionConfiguration オブジェクトのプロパティと関係を読み取ります。
macOSEndpointProtectionConfiguration を作成する macOSEndpointProtectionConfiguration 新しい macOSEndpointProtectionConfiguration オブジェクトを作成します。
macOSEndpointProtectionConfiguration を削除する なし macOSEndpointProtectionConfiguration を削除します。
macOSEndpointProtectionConfiguration を更新する macOSEndpointProtectionConfiguration macOSEndpointProtectionConfiguration オブジェクトのプロパティを更新します。

プロパティ

プロパティ 説明
id String エンティティのキー。 deviceConfiguration から継承します
lastModifiedDateTime DateTimeOffset オブジェクトの最終更新の DateTime。 deviceConfiguration から継承します
roleScopeTagIds String collection このエンティティ インスタンスのスコープ タグの一覧。 deviceConfiguration から継承します
supportsScopeTags ブール型 基になるデバイス構成がスコープ タグの割り当てをサポートしているかどうかを示します。 この値が false の場合、ScopeTags プロパティへの割り当ては許可されず、スコープを指定されたユーザーにエンティティが表示されません。 これは、Silverlight で作成されたレガシ ポリシーで発生し、Azure Portal でポリシーを削除して再作成することで解決できます。 このプロパティは読み取り専用です。 deviceConfiguration から継承します
deviceManagementApplicabilityRuleOsEdition deviceManagementApplicabilityRuleOsEdition このポリシーの OS エディションの適用範囲。 deviceConfiguration から継承します
deviceManagementApplicabilityRuleOsVersion deviceManagementApplicabilityRuleOsVersion このポリシーの OS バージョン適用性ルール。 deviceConfiguration から継承します
deviceManagementApplicabilityRuleDeviceMode deviceManagementApplicabilityRuleDeviceMode このポリシーのデバイス モード適用性ルール。 deviceConfiguration から継承します
createdDateTime DateTimeOffset オブジェクトが作成された DateTime。 deviceConfiguration から継承します
description String 管理者が指定した、デバイス構成についての説明。 deviceConfiguration から継承します
displayName String 管理者が指定した、デバイス構成の名前。 deviceConfiguration から継承します
version Int32 デバイス構成のバージョン。 deviceConfiguration から継承します
gatekeeperAllowedAppSource macOSGatekeeperAppSources macOS デバイスでアプリを実行できるダウンロード場所を決定するシステムとプライバシーの設定。 使用可能な値: notConfiguredmacAppStoremacAppStoreAndIdentifiedDevelopersanywhere
gatekeeperBlockOverride ブール型 true に設定すると、Gatekeeper のユーザー オーバーライドが無効になります。
firewallEnabled ブール型 ファイアウォールを有効にする必要があるかどうか。
firewallBlockAllIncoming ブール型 [すべての着信接続をブロックする] オプションに対応します。
firewallEnableStealthMode ブール型 「ステルス モードを有効にする」に相当します。
firewallApplications macOSFirewallApplication コレクション ファイアウォール設定のあるアプリケーションの一覧。 この一覧に記載されていないアプリケーションのファイアウォール設定は、ユーザーが決定します。 このコレクションには、最大で 500 個の要素を含めることができます。
fileVaultEnabled ブール型 FileVault を有効にするかどうか。
fileVaultSelectedRecoveryKeyTypes macOSFileVaultRecoveryKeyTypes FileVault が有効になっている場合は必須。使用する回復キーの種類を決定します。 . 可能な値は notConfiguredinstitutionalRecoveryKeypersonalRecoveryKey です。
fileVaultInstitutionalRecoveryKeyCertificate Binary 選択した回復キーの種類に InstitutionalRecoveryKey が含まれる場合は必須。 教育機関の回復キーを設定するために使用される DER エンコードされた証明書ファイル。
fileVaultInstitutionalRecoveryKeyCertificateFileName 文字列 UI に表示する教育機関の回復キー証明書のファイル名。 (*.der) です。
fileVaultPersonalRecoveryKeyHelpMessage 文字列 選択した回復キーの種類に PersonalRecoveryKey が含まれている場合は必須。 個人用回復キーを取得する方法を説明する短いメッセージがユーザーに表示されます。
fileVaultAllowDeferralUntilSignOut ブール値 省略可能。 true に設定すると、ユーザーはサインアウトするまで FileVault の有効化を延期できます。
fileVaultNumberOfTimesUserCanIgnore Int32 省略可能。 [延期] オプションを使用する場合、これは、ユーザーがサインインするために FileVault が必要になる前に、FileVault を有効にするためのプロンプトをユーザーが無視できる最大回数です。 -1 に設定すると、FileVault が有効になるまで、常に FileVault を有効にするように求められますが、ユーザーは FileVault を有効にすることをバイパスできます。 これを 0 に設定すると、機能が無効になります。
fileVaultDisablePromptAtSignOut ブール値 省略可能。 [延期] オプションを使用する場合、true に設定すると、ユーザーはサインアウト時に FileVault を有効にするように求められません。
fileVaultPersonalRecoveryKeyRotationInMonths Int32 省略可能。 選択した回復キーの種類に、そのキーをローテーションする頻度 (月単位) である PersonalRecoveryKey が含まれます。
fileVaultHidePersonalRecoveryKey ブール値 省略可能。 FileVault の暗号化中、非表示の個人用回復キーはユーザーの画面に表示されないため、悪者の手に渡るリスクが軽減されます。
advancedThreatProtectionRealTime 有効化 macOS で Microsoft Defender Advanced Threat Protection のリアルタイム保護を有効にするかどうかを決定します。 可能な値は notConfiguredenableddisabled です。
advancedThreatProtectionCloudDelivered 有効化 macOS で Microsoft Defender Advanced Threat Protection のクラウドによる保護を有効にするかどうかを決定します。 可能な値は notConfiguredenableddisabled です。
advancedThreatProtectionAutomaticSampleSubmission 有効化 macOS で Microsoft Defender Advanced Threat Protection のファイル サンプルの自動送信を有効にするかどうかを決定します。 可能な値は notConfiguredenableddisabled です。
advancedThreatProtectionDiagnosticDataCollection 有効化 macOS で Microsoft Defender Advanced Threat Protection の診断および使用状況データの収集を有効にするかどうかを決定します。 可能な値は notConfiguredenableddisabled です。
advancedThreatProtectionExcludedFolders String collection macOS の Microsoft Defender Advanced Threat Protection のウイルス対策スキャンから除外するフォルダーへのパスの一覧。
advancedThreatProtectionExcludedFiles String collection macOS の Microsoft Defender Advanced Threat Protection のウイルス対策スキャンから除外するファイルへのパスの一覧。
advancedThreatProtectionExcludedExtensions String collection macOS の Microsoft Defender Advanced Threat Protection のウイルス対策スキャンから除外するファイル拡張子の一覧。
advancedThreatProtectionExcludedProcesses String collection macOS の Microsoft Defender Advanced Threat Protection のウイルス対策スキャンから除外するプロセス名の一覧。

リレーションシップ

リレーションシップ 説明
groupAssignments deviceConfigurationGroupAssignment コレクション デバイスの構成プロファイルのグループ割り当てのリストです。 deviceConfiguration から継承します
assignments deviceConfigurationAssignment コレクション デバイスの構成プロファイルの割り当てのリスト。 deviceConfiguration から継承します
deviceStatuses deviceConfigurationDeviceStatus コレクション デバイスごとのデバイス構成のインストール状況。 deviceConfiguration から継承します
userStatuses deviceConfigurationUserStatus コレクション ユーザー別のデバイス構成のインストールの状態。 deviceConfiguration から継承します
deviceStatusOverview deviceConfigurationDeviceOverview デバイス構成のデバイス状態の概要 (deviceConfiguration から継承)
userStatusOverview deviceConfigurationUserOverview デバイス構成のユーザー状態の概要 (deviceConfiguration から継承)
deviceSettingStateSummaries settingStateDeviceSummary コレクション デバイス構成設定状態のデバイスの要約 (deviceConfiguration から継承)

JSON 表記

以下は、リソースの JSON 表記です。

{
  "@odata.type": "#microsoft.graph.macOSEndpointProtectionConfiguration",
  "id": "String (identifier)",
  "lastModifiedDateTime": "String (timestamp)",
  "roleScopeTagIds": [
    "String"
  ],
  "supportsScopeTags": true,
  "deviceManagementApplicabilityRuleOsEdition": {
    "@odata.type": "microsoft.graph.deviceManagementApplicabilityRuleOsEdition",
    "osEditionTypes": [
      "String"
    ],
    "name": "String",
    "ruleType": "String"
  },
  "deviceManagementApplicabilityRuleOsVersion": {
    "@odata.type": "microsoft.graph.deviceManagementApplicabilityRuleOsVersion",
    "minOSVersion": "String",
    "maxOSVersion": "String",
    "name": "String",
    "ruleType": "String"
  },
  "deviceManagementApplicabilityRuleDeviceMode": {
    "@odata.type": "microsoft.graph.deviceManagementApplicabilityRuleDeviceMode",
    "deviceMode": "String",
    "name": "String",
    "ruleType": "String"
  },
  "createdDateTime": "String (timestamp)",
  "description": "String",
  "displayName": "String",
  "version": 1024,
  "gatekeeperAllowedAppSource": "String",
  "gatekeeperBlockOverride": true,
  "firewallEnabled": true,
  "firewallBlockAllIncoming": true,
  "firewallEnableStealthMode": true,
  "firewallApplications": [
    {
      "@odata.type": "microsoft.graph.macOSFirewallApplication",
      "bundleId": "String",
      "allowsIncomingConnections": true
    }
  ],
  "fileVaultEnabled": true,
  "fileVaultSelectedRecoveryKeyTypes": "String",
  "fileVaultInstitutionalRecoveryKeyCertificate": "binary",
  "fileVaultInstitutionalRecoveryKeyCertificateFileName": "String",
  "fileVaultPersonalRecoveryKeyHelpMessage": "String",
  "fileVaultAllowDeferralUntilSignOut": true,
  "fileVaultNumberOfTimesUserCanIgnore": 1024,
  "fileVaultDisablePromptAtSignOut": true,
  "fileVaultPersonalRecoveryKeyRotationInMonths": 1024,
  "fileVaultHidePersonalRecoveryKey": true,
  "advancedThreatProtectionRealTime": "String",
  "advancedThreatProtectionCloudDelivered": "String",
  "advancedThreatProtectionAutomaticSampleSubmission": "String",
  "advancedThreatProtectionDiagnosticDataCollection": "String",
  "advancedThreatProtectionExcludedFolders": [
    "String"
  ],
  "advancedThreatProtectionExcludedFiles": [
    "String"
  ],
  "advancedThreatProtectionExcludedExtensions": [
    "String"
  ],
  "advancedThreatProtectionExcludedProcesses": [
    "String"
  ]
}