Intune Company Portal 图标

Intune Company Portal 数据 API

Microsoft Corporation · 企业办公

Intune Company Portal 是 Microsoft Intune 在 Android 上面向员工的配套应用。使用 Intune 管理手机和平板的组织依靠它把设备注册进工作管理、向员工展示设备是否符合合规规则、分发分配的公司应用,并在设备退出设备队列时干净地停用设备。

这些界面背后是结构化的设备管理数据集:受管设备清单为每台已注册手机携带 ComplianceState、LastContact、Manufacturer 与 AadId;合规检查以 NoncompliantRules 返回未通过的规则,内含 SettingId 与期望值;工作应用目录则暴露 applicationGuid、appVersion 与推荐标记。IT 资产团队、零信任接入网关与软件资产管理工具基于这些字段,让资产清单、访问决策与许可数量与员工看到的内容保持同步。

Intune Company Portal 是微软面向员工的配套应用:将 Android 手机和平板注册进 Microsoft Intune、查看设备合规状态、安装公司分配的应用,并在设备退出设备队列时移除工作数据。全球使用 Intune 管理 Android 设备的组织都在使用它,而这些界面背后是结构化数据:登录用户的受管设备清单(含合规状态与最近签到时间)、分配的工作应用目录、公司条款以及应用保护策略负载。这些数据可用于 IT 资产盘点、零信任访问决策、软件许可对账与设备策略基线核查。

应用截图

  • Intune Company Portal 应用截图 1
  • Intune Company Portal 应用截图 2
  • Intune Company Portal 应用截图 3
  • Intune Company Portal 应用截图 4
  • Intune Company Portal 应用截图 5
  • Intune Company Portal 应用截图 6
  • Intune Company Portal 应用截图 7
  • Intune Company Portal 应用截图 8

API 端点一览

以下端点与请求/响应示例均依据应用界面推导重构,为示意说明,并非实际抓包。

  • 注册服务器发现(SOAP)

    POST /v1/enrollment/discover opendata

    在设备注册握手之前,将工作邮箱解析到租户的注册端点与认证策略(联合认证或本地部署)。

    认证方式: 无需认证的发现调用;工作邮箱放在请求体中。后续注册步骤使用带设备注册作用域的 Microsoft Entra Bearer 令牌。

    • EmailAddress
    • RequestVersion
    • DeviceType
    • ApplicationVersion
    • OSEdition
    • AuthPolicies
    • EnrollmentServiceUrl
    • AuthenticationServiceUrl
    POST /v1/enrollment/discover HTTP/1.1
    Content-Type: application/soap+xml; charset=utf-8
    
    <Discover><request><EmailAddress>[email protected]</EmailAddress><RequestVersion>4.0</RequestVersion><DeviceType>AndroidForWork</DeviceType><ApplicationVersion>5.0.7080.0</ApplicationVersion><OSEdition>4</OSEdition><AuthPolicies><AuthPolicy>OnPremise</AuthPolicy><AuthPolicy>Federated</AuthPolicy></AuthPolicies></request></Discover>
    {
      "DiscoveryResponse": {
        "AuthPolicy": "Federated",
        "EnrollmentPolicyServiceUrl": "https://enroll.contoso.example/policy",
        "EnrollmentServiceUrl": "https://enroll.contoso.example/enroll",
        "AuthenticationServiceUrl": "https://login.contoso.example/contoso.com"
      }
    }
    • 记录自应用的工作邮箱注册发现流程
    • SOAP 信封携带工作邮箱、设备类型、应用版本与支持的认证策略
  • Intune 服务位置发现

    POST /v1/enrollment/service-locations opendata

    返回租户专属的 Android 设备网关、AOSP 预配、注册与诊断 URL,应用登录后会缓存这些地址。

    认证方式: 在组织身份提供方签发的 Microsoft Entra Bearer 令牌(设备注册作用域)。

    • aadTenantId
    • deviceType
    • applicationPackageName
    • applicationVersionName
    • androidDeviceGatewayCertificateServiceUrl
    • androidDeviceGatewayServiceUrl
    • androidDeviceGatewayServiceFefUrl
    • aospProvisioningServiceUrl
    • ariaServiceUrl
    • enrollmentServiceUrl
    • powerliftServiceUrl
    POST /v1/enrollment/service-locations HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "aadTenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
      "deviceType": "Android",
      "applicationPackageName": "com.example.workapp",
      "applicationVersionName": "5.0.7080.0"
    }
    {
      "androidDeviceGatewayCertificateServiceUrl": "https://gw.contoso.example/android/certificates",
      "androidDeviceGatewayServiceUrl": "https://gw.contoso.example/android/gateway",
      "androidDeviceGatewayServiceFefUrl": "https://gw.contoso.example",
      "aospProvisioningServiceUrl": "https://gw.contoso.example/aosp-provisioning",
      "ariaServiceUrl": "https://telemetry.contoso.example/collector",
      "enrollmentServiceUrl": "https://enroll.contoso.example/enroll",
      "powerliftServiceUrl": "https://logs.contoso.example"
    }
    • 记录自登录后的服务发现步骤
    • 响应把逻辑服务名映射到租户专属 URL,应用缓存后用于后续调用
  • 列出已注册设备

    GET /v1/fleet opendata

    分页返回登录用户的受管设备,用于「设备」标签页——昵称、硬件、操作系统、合规状态、最近签到与目录设备 ID。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域),并附带 Accept: application/json 请求头。

    • Key
    • Nickname
    • Manufacturer
    • Model
    • OfficialName
    • OperatingSystem
    • OperatingSystemId
    • OwnerType
    • ComplianceState
    • AadId
    • DeviceHWId
    • LastContact
    • ManagementType
    • CategoryId
    • NoncompliantRules
    • odata.id
    GET /v1/fleet HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": [
        {
          "Key": "d1a2b3c4-1111-2222-3333-444455556666",
          "Nickname": "Alex Pixel 8",
          "Manufacturer": "Google",
          "Model": "Pixel 8",
          "OfficialName": "Pixel 8",
          "OperatingSystem": "Android",
          "OperatingSystemId": "14",
          "OwnerType": 1,
          "ComplianceState": "Compliant",
          "AadId": "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee",
          "DeviceHWId": "android-hw-9f2c",
          "LastContact": "2026-09-28T18:12:03Z",
          "ManagementType": "AndroidEnterprise",
          "CategoryId": "cat-sales",
          "CategorySetByEndUser": true,
          "IsReadOnly": false,
          "InGracePeriodUntilDateTimeUtc": null,
          "NoncompliantRules": [],
          "odata.id": "fleet/d1a2b3c4-1111-2222-3333-444455556666"
        }
      ]
    }
    • 记录自应用「设备」标签页展示的设备列表
    • 设备记录携带 Key、Nickname、Manufacturer、ComplianceState、AadId 与 LastContact
  • 检查设备合规性

    POST /v1/fleet/{deviceId}/compliance-check opendata

    为单台设备触发一次按需合规评估,并返回「设备合规详情」页面上展示的未通过规则。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • Key
    • ComplianceState
    • InGracePeriodUntilDateTimeUtc
    • NoncompliantRules
    • SettingId
    • Title
    • ExpectedValue
    • Description
    • MoreInfoUri
    • RemediationOwner
    • LastContact
    POST /v1/fleet/d1a2b3c4-1111-2222-3333-444455556666/compliance-check HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    Content-Length: 0
    {
      "Key": "d1a2b3c4-1111-2222-3333-444455556666",
      "ComplianceState": "Noncompliant",
      "InGracePeriodUntilDateTimeUtc": "2026-10-05T00:00:00Z",
      "NoncompliantRules": [
        {
          "SettingId": "AndroidDeviceOwnerPasscodeRequired",
          "Title": "Device passcode required",
          "ExpectedValue": "true",
          "Description": "A screen lock must be set on this device.",
          "MoreInfoUri": "https://docs.contoso.example/compliance/passcode",
          "RemediationOwner": 1
        }
      ],
      "LastContact": "2026-09-29T17:40:11Z"
    }
    • 记录自「设备合规详情」页面
    • 每条未通过规则携带 SettingId、Title、ExpectedValue、整改链接与宽限期截止时间
  • 停用设备(移除公司数据)

    POST /v1/fleet/{deviceId}/retire opendata

    启动由用户发起的停用操作:注销设备注册并擦除公司数据,同时保留个人应用与文件。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • odata.id
    • Key
    • ManagementType
    • retired
    POST /v1/fleet/d1a2b3c4-1111-2222-3333-444455556666/retire HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    Content-Length: 0
    {
      "Key": "d1a2b3c4-1111-2222-3333-444455556666",
      "ManagementType": "AndroidEnterprise",
      "retired": true
    }
    • 记录自设备详情页上由用户发起的「移除公司数据」流程
  • 工作应用目录条目

    GET /v1/catalog/apps/{appId} opendata

    为「应用」页面加载一个分配的公司应用——标题、发布者、图标、推荐标记与安装状态链接。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • applicationGuid
    • name
    • publisher
    • category
    • description
    • smallIconUri
    • largeIconUri
    • isFeaturedApp
    • relevance
    • availableDate
    • appVersion
    • privacyStatementUri
    • moreInfoUri
    GET /v1/catalog/apps/8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "applicationGuid": "8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d",
      "name": "Microsoft Outlook",
      "publisher": "Microsoft Corporation",
      "category": "Productivity",
      "description": "Email and calendar for work.",
      "smallIconUri": "https://cdn.contoso.example/catalog/icons/outlook-small.png",
      "largeIconUri": "https://cdn.contoso.example/catalog/icons/outlook-large.png",
      "isFeaturedApp": true,
      "relevance": 10,
      "availableDate": "2026-01-15T00:00:00Z",
      "appVersion": "4.2426.0",
      "privacyStatementUri": "https://privacy.contoso.example",
      "moreInfoUri": "https://docs.contoso.example/apps/outlook",
      "installStateLink": "catalog/apps/8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d/install-state"
    }
    • 记录自工作应用目录的应用详情页
    • 目录记录暴露 applicationGuid、publisher、appVersion、推荐标记与图标链接
  • 接受公司条款

    POST /v1/terms/{termsId}/accept opendata

    在注册设置过程中记录对租户公司使用条款的接受(条款正文与接受声明均带版本号)。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • termVersion
    • Key
    • Title
    • BodyText
    • AcceptanceStatement
    • CompanyTermVersion
    POST /v1/terms/contoso-mdm-tos/accept HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    Accept: application/json
    
    {
      "termVersion": 3
    }
    {
      "Key": "contoso-mdm-tos",
      "Title": "Contoso mobile use policy",
      "BodyText": "You must protect company data on this device...",
      "AcceptanceStatement": "I have read and accept these terms.",
      "CompanyTermVersion": 3,
      "accepted": true
    }
    • 记录自注册设置中的公司条款接受步骤
    • 条款记录带版本号,包含正文文本与接受声明
  • 用户功能开关

    GET /v1/users/{userId}/features opendata

    读取按用户的功能开关,用于隐藏或显示 Managed Play、工作资料锁定等 Company Portal 界面。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • featureId
    • isEnabled
    GET /v1/users/11111111-2222-3333-4444-555555555555/features HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": [
        {"featureId": "ManagedPlay", "isEnabled": true},
        {"featureId": "WebCompanyPortal", "isEnabled": false},
        {"featureId": "WorkProfileLockdown", "isEnabled": true}
      ]
    }
    • 记录自控制 Company Portal 界面显隐的按用户功能开关
  • Managed Google Play 账户

    GET /v1/users/{userId}/work-play-account osint

    返回 Managed Google Play / 工作账户绑定,用于在 Android Enterprise 设备上从 Play 商店安装公司应用。

    认证方式: Microsoft Entra Bearer 令牌(设备管理作用域)。

    • accountName
    • isAccountDisabled
    • isAccountWorkplaceJoinEnabled
    • maintenanceState
    GET /v1/users/11111111-2222-3333-4444-555555555555/work-play-account HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "accountName": "[email protected]",
      "isAccountDisabled": false,
      "isAccountWorkplaceJoinEnabled": true,
      "maintenanceState": 0
    }
    • 记录自用于安装工作应用的 Managed Google Play 账户绑定
  • MAM Android 应用保护策略

    GET /v1/app-protection/android/policies opendata

    下载应用于 Company Portal 及其他受保护应用的 Android MAM / 应用保护策略集(PIN、截屏、反馈开关)。

    认证方式: Microsoft Entra Bearer 令牌(应用保护策略作用域);客户端在 Authorization 前加上 'Bearer ' 前缀。

    • policiesHash
    • value
    • id
    • policyType
    • priority
    • policiesPayload
    GET /v1/app-protection/android/policies HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "policiesHash": "sha256:9c1e0a…",
      "value": [
        {
          "id": "office16;L_SendFeedback",
          "policyType": 1,
          "priority": 10,
          "policiesPayload": [{"key": "PINRequired", "value": "true"}]
        }
      ]
    }
    • 记录自下发到受保护应用的应用保护策略下载
    • 策略集带哈希版本号,便于客户端检测配置漂移
  • Android 设备网关证书申请

    POST /v1/fleet/{deviceId}/certificates opendata

    向 Android 设备网关提交 CSR,并取回用于后续签到的设备管理证书(叶证书与中间证书指纹)。

    认证方式: 注册完成后获取的 Microsoft Entra Bearer 令牌(Android 设备网关作用域)。

    • CertificateSigningRequest
    • Signature
    • SigningCertSha256Thumbprint
    • Base64EncodedCertificate
    • LeafThumbprint
    • IntermediateThumbprint
    POST /v1/fleet/android-hw-9f2c/certificates HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "CertificateSigningRequest": "MIICUzCCATsCAQAwgYMxCzAJBgNVBAYTAlVT...",
      "Signature": "MEUCIQDx…",
      "SigningCertSha256Thumbprint": "A1B2C3D4E5F60718293A4B5C6D7E8F9012345678ABCDEF01"
    }
    {
      "Base64EncodedCertificate": "MIIDPjCCAiagAwIBAgIQe0…",
      "LeafThumbprint": "9F2C8A71B0D4E6…",
      "IntermediateThumbprint": "7C11AA90FF22…"
    }
    • 记录自预配完成后的设备证书注册握手
  • 上报 Google Play Protect 状态

    POST /v1/fleet/{deviceId}/play-protect-status opendata

    上报设备的 Google Play Protect 扫描状态,使要求 Play Protect 的合规策略可以评估该手机。

    认证方式: Microsoft Entra Bearer 令牌(Android 设备网关作用域)。

    • playProtectEnabled
    • lastScanTimeUtc
    • threatLevel
    • deviceId
    POST /v1/fleet/android-hw-9f2c/play-protect-status HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "playProtectEnabled": true,
      "lastScanTimeUtc": "2026-09-29T16:01:00Z",
      "threatLevel": "NoThreatsFound"
    }
    {
      "deviceId": "android-hw-9f2c",
      "playProtectEnabled": true,
      "threatLevel": "NoThreatsFound",
      "accepted": true
    }
    • 记录自合规评估所用的 Play Protect 扫描上报
  • 目录设备启用状态

    GET /v1/directory/device-objects/{deviceId}/enabled osint

    读取目录中的设备对象是否启用——Company Portal 据此判断手机上的工作账户是否仍允许登录。

    认证方式: 通过组织身份平台获取的 Microsoft 目录 Bearer 令牌。

    • value
    GET /v1/directory/device-objects/aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee/enabled HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": true
    }
    • 记录自检查工作账户设备对象是否仍启用的调用
  • 登录用户头像

    GET /v1/directory/me/photo osint

    获取 Company Portal 首页与用户资料页展示的工作账户头像。

    认证方式: Microsoft 目录 Bearer 令牌。

    • $value
    GET /v1/directory/me/photo HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: image/jpeg
    (binary JPEG)
    Content-Type: image/jpeg
    Content-Length: 18432
    • 记录自首页与账户页面展示的头像

数据类别

  • 设备
  • 合规状态
  • 应用程序
  • 注册
  • 身份标识
  • MAM 策略
  • 证书

数据使用场景与案例

  • 基于 Company Portal 的 ITAM 设备盘点

    CMDB 定时任务以员工身份登录并读取 GET /v1/fleet,获取 Nickname、Manufacturer、Model、OperatingSystem、AadId、LastContact 与 ComplianceState,让资产记录与员工在 Company Portal 中看到的内容保持同步。

  • 授予 VPN 前的零信任状态判定

    接入代理调用 POST /v1/fleet/{deviceId}/compliance-check,当 NoncompliantRules 在 InGracePeriodUntilDateTimeUtc 宽限期过后仍列出 AndroidDeviceOwnerPasscodeRequired 等 SettingId 时,拒绝本次会话。

  • 用于许可回收的软件目录

    软件资产管理(SAM)工具遍历 GET /v1/catalog/apps/{appId},读取 applicationGuid、publisher、appVersion 与 isFeaturedApp,将分配的工作应用与已购席位逐一比对。

  • MAM 策略漂移核查

    运维团队拉取 GET /v1/app-protection/android/policies,保存 policiesHash 与每条 policiesPayload,用于将 Android 上的 PIN 与截屏管控同 Intune 基线做差异比对。

常见问题

Intune Company Portal 为每台受管设备暴露哪些数据?

设备清单为登录用户注册的每台手机或平板返回 Key、Nickname、Manufacturer、Model、OperatingSystem、OwnerType、ComplianceState、AadId、DeviceHWId、LastContact、ManagementType、CategoryId 以及 NoncompliantRules 列表。

该应用的数据调用如何认证?

通过微软身份平台完成工作或学校账户登录后,应用持有分别面向注册、设备管理、组织目录与应用保护策略作用域的 Bearer 令牌,每次调用都在 Authorization 请求头中携带对应令牌。

按需设备合规检查如何工作?

员工可以为单台设备触发一次新的评估。响应会列出每条未通过的规则:SettingId、可读的 Title、ExpectedValue 与整改链接,以及宽限期截止时间 InGracePeriodUntilDateTimeUtc。

可以看到组织分配了哪些工作应用吗?

可以。工作应用目录为分配给登录用户的每个应用返回 applicationGuid、name、publisher、category、appVersion、推荐标记与图标链接,软件资产管理工具可据此与已购许可对账。

与 Intune Company Portal 相似的应用

  • Workspace ONE Intelligent Hub — Omnissa(原 VMware)推出的 Workspace ONE UEM 员工端应用,可将 Android 设备注册进企业管理、查看合规状态并获取公司分配的应用目录,是与 Intune Company Portal 最直接对应的同类产品。
  • Android Device Policy — Google 官方的设备注册应用,供使用 Google Workspace 的组织将 Android 手机和平板纳入 Google 端点管理,应用工作资料和管理员设定的设备规则。
  • IBM MaaS360 — IBM 的统一端点管理平台,其 Android 代理应用负责设备注册、执行合规策略并分发工作应用,并基于 Watson 提供设备队列分析能力。
  • ManageEngine Endpoint Central — ManageEngine 的统一端点管理产品,可在单一控制台管理 Windows、macOS、Linux、iOS 和 Android 设备,并提供最多 25 台桌面加 25 台移动设备的免费版。
  • Scalefusion UEM — 一套覆盖 Android、iOS、Windows、macOS、Linux 和 ChromeOS 设备队列的统一端点管理平台,按设备计费,常被列入 MDM 选型对比清单。
  • Hexnode UEM — 覆盖 Windows、macOS、Linux、iOS、Android 和 ChromeOS 的 UEM 平台,常因价格亲民而被中小企业列为 Intune 的备选方案。
  • Jamf — 以 Apple 设备管理见长的平台,提供零接触部署和员工自助门户,适合管理 iPhone、iPad 和 Mac 设备队列而非 Android 的组织。

相关主题

  • Intune Company Portal API
  • Microsoft Intune 设备接口
  • Company Portal 合规 API
  • Intune MAM Android 策略
  • Managed Google Play 账户 API
  • Intune 注册发现

需要集成这个 App 的数据 API?

我们可为任意指定 App 交付定制集成——源码交付 USD 500 起,或托管 API 按调用计费。告诉我们您需要的数据即可。

  • 每个项目均签 NDA 与 SOW
  • 3–7 天交付
  • 验收通过后才付款
  • 仅在授权范围内作业

获取报价