Microsoft Intune Device Compliance Policies API

Operations for managing device compliance policies. Compliance policies define rules and settings that a device must comply with to be considered compliant.

OpenAPI Specification

microsoft-intune-device-compliance-policies-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Microsoft Intune Graph Device Compliance Policies API
  description: The Microsoft Graph API for Intune enables programmatic access to Intune information and actions for your tenant. The API performs the same Intune operations as those available through the Microsoft Intune admin center, including managed device management, device configuration, and compliance policy enforcement. Requires an active Intune license for the tenant.
  version: 1.0.0
  termsOfService: https://www.microsoft.com/en-us/legal/terms-of-use
  contact:
    name: Microsoft Graph Support
    url: https://developer.microsoft.com/graph/support
  license:
    name: Microsoft API License
    url: https://learn.microsoft.com/en-us/legal/microsoft-apis/terms-of-use
servers:
- url: https://graph.microsoft.com/v1.0
  description: Microsoft Graph v1.0 production endpoint
security:
- oauth2:
  - DeviceManagementManagedDevices.Read.All
  - DeviceManagementConfiguration.Read.All
tags:
- name: Device Compliance Policies
  description: Operations for managing device compliance policies. Compliance policies define rules and settings that a device must comply with to be considered compliant.
  externalDocs:
    url: https://learn.microsoft.com/en-us/graph/api/resources/intune-deviceconfig-devicecompliancepolicy?view=graph-rest-1.0
paths:
  /deviceManagement/deviceCompliancePolicies:
    get:
      operationId: listDeviceCompliancePolicies
      summary: Microsoft Intune List device compliance policies
      description: List properties and relationships of the deviceCompliancePolicy objects. Returns all compliance policies defined in the tenant. Compliance policies are platform specific and individual per-platform policies inherit from this base class.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/top'
      - $ref: '#/components/parameters/skip'
      - $ref: '#/components/parameters/search'
      - $ref: '#/components/parameters/filter'
      - $ref: '#/components/parameters/count'
      - $ref: '#/components/parameters/orderby'
      - $ref: '#/components/parameters/select'
      - $ref: '#/components/parameters/expand'
      responses:
        '200':
          description: A collection of deviceCompliancePolicy objects.
          content:
            application/json:
              schema:
                type: object
                properties:
                  '@odata.context':
                    type: string
                  '@odata.count':
                    type: integer
                  '@odata.nextLink':
                    type: string
                    format: uri
                  value:
                    type: array
                    items:
                      $ref: '#/components/schemas/deviceCompliancePolicy'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.Read.All
        - DeviceManagementConfiguration.ReadWrite.All
  /deviceManagement/deviceCompliancePolicies/{deviceCompliancePolicyId}:
    get:
      operationId: getDeviceCompliancePolicy
      summary: Microsoft Intune Get device compliance policy
      description: Read properties and relationships of a deviceCompliancePolicy object.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/deviceCompliancePolicyId'
      - $ref: '#/components/parameters/select'
      - $ref: '#/components/parameters/expand'
      responses:
        '200':
          description: The requested deviceCompliancePolicy object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/deviceCompliancePolicy'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.Read.All
        - DeviceManagementConfiguration.ReadWrite.All
    patch:
      operationId: updateDeviceCompliancePolicy
      summary: Microsoft Intune Update device compliance policy
      description: Update the properties of a deviceCompliancePolicy object.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/deviceCompliancePolicyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/deviceCompliancePolicy'
      responses:
        '200':
          description: The updated deviceCompliancePolicy object.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/deviceCompliancePolicy'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.ReadWrite.All
    delete:
      operationId: deleteDeviceCompliancePolicy
      summary: Microsoft Intune Delete device compliance policy
      description: Deletes a deviceCompliancePolicy.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/deviceCompliancePolicyId'
      responses:
        '204':
          description: No content. The deviceCompliancePolicy was successfully deleted.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.ReadWrite.All
  /deviceManagement/deviceCompliancePolicies/{deviceCompliancePolicyId}/assign:
    post:
      operationId: assignDeviceCompliancePolicy
      summary: Microsoft Intune Assign device compliance policy
      description: Assign a device compliance policy to groups of users or devices.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/deviceCompliancePolicyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                assignments:
                  type: array
                  items:
                    $ref: '#/components/schemas/deviceCompliancePolicyAssignment'
      responses:
        '200':
          description: The list of assignments for the compliance policy.
          content:
            application/json:
              schema:
                type: object
                properties:
                  value:
                    type: array
                    items:
                      $ref: '#/components/schemas/deviceCompliancePolicyAssignment'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.ReadWrite.All
  /deviceManagement/deviceCompliancePolicies/{deviceCompliancePolicyId}/scheduleActionsForRules:
    post:
      operationId: scheduleActionsForRules
      summary: Microsoft Intune Schedule actions for compliance rules
      description: Schedule actions for rules associated with a device compliance policy, such as marking a device as noncompliant or sending notification emails.
      tags:
      - Device Compliance Policies
      parameters:
      - $ref: '#/components/parameters/deviceCompliancePolicyId'
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                deviceComplianceScheduledActionForRules:
                  type: array
                  items:
                    $ref: '#/components/schemas/deviceComplianceScheduledActionForRule'
      responses:
        '204':
          description: No content. The scheduled actions were successfully set.
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '404':
          $ref: '#/components/responses/NotFound'
        default:
          $ref: '#/components/responses/ODataError'
      security:
      - oauth2:
        - DeviceManagementConfiguration.ReadWrite.All
components:
  schemas:
    deviceComplianceActionItem:
      type: object
      description: Scheduled action configuration.
      properties:
        '@odata.type':
          type: string
          default: '#microsoft.graph.deviceComplianceActionItem'
        id:
          type: string
          description: Key of the entity.
        gracePeriodHours:
          type: integer
          format: int32
          description: Number of hours to wait till the action will be enforced.
        actionType:
          type: string
          description: What action to take.
          enum:
          - noAction
          - notification
          - block
          - retire
          - wipe
          - removeResourceAccessProfiles
          - pushNotification
        notificationTemplateId:
          type: string
          description: What notification message template to use.
        notificationMessageCCList:
          type: array
          items:
            type: string
          description: A list of group IDs to specify who to CC this notification message to.
    deviceCompliancePolicyAssignment:
      type: object
      description: Device compliance policy assignment.
      properties:
        '@odata.type':
          type: string
          default: '#microsoft.graph.deviceCompliancePolicyAssignment'
        id:
          type: string
          description: Key of the entity.
        target:
          $ref: '#/components/schemas/deviceAndAppManagementAssignmentTarget'
    deviceComplianceScheduledActionForRule:
      type: object
      description: Scheduled action for a compliance rule.
      properties:
        '@odata.type':
          type: string
          default: '#microsoft.graph.deviceComplianceScheduledActionForRule'
        id:
          type: string
          description: Key of the entity.
        ruleName:
          type: string
          description: Name of the rule which this scheduled action applies to.
        scheduledActionConfigurations:
          type: array
          items:
            $ref: '#/components/schemas/deviceComplianceActionItem'
          description: The list of scheduled action configurations for this compliance policy.
    deviceCompliancePolicy:
      type: object
      description: This is the base class for Compliance policy. Compliance policies are platform specific and individual per-platform compliance policies inherit from here.
      properties:
        '@odata.type':
          type: string
          default: '#microsoft.graph.deviceCompliancePolicy'
        id:
          type: string
          description: Key of the entity.
        createdDateTime:
          type: string
          format: date-time
          description: DateTime the object was created.
          readOnly: true
        description:
          type: string
          description: Admin provided description of the Device Configuration.
        lastModifiedDateTime:
          type: string
          format: date-time
          description: DateTime the object was last modified.
          readOnly: true
        displayName:
          type: string
          description: Admin provided name of the device configuration.
        version:
          type: integer
          format: int32
          description: Version of the device configuration.
          readOnly: true
    odataError:
      type: object
      description: OData error response.
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              description: Error code.
            message:
              type: string
              description: Error message.
            innerError:
              type: object
              properties:
                request-id:
                  type: string
                  description: Request ID for tracing.
                date:
                  type: string
                  format: date-time
                  description: Date and time of the error.
    deviceAndAppManagementAssignmentTarget:
      type: object
      description: Base type for assignment targets.
      properties:
        '@odata.type':
          type: string
          description: The OData type of the assignment target.
  parameters:
    select:
      name: $select
      in: query
      description: Comma-separated list of properties to include in the response.
      schema:
        type: string
    top:
      name: $top
      in: query
      description: Number of items to return in a result set.
      schema:
        type: integer
        minimum: 0
    search:
      name: $search
      in: query
      description: Search string for filtering results.
      schema:
        type: string
    skip:
      name: $skip
      in: query
      description: Number of items to skip in the result set.
      schema:
        type: integer
        minimum: 0
    count:
      name: $count
      in: query
      description: Include count of items in the result set.
      schema:
        type: boolean
    expand:
      name: $expand
      in: query
      description: Comma-separated list of relationships to expand and include in the response.
      schema:
        type: string
    filter:
      name: $filter
      in: query
      description: OData filter expression for filtering results.
      schema:
        type: string
    deviceCompliancePolicyId:
      name: deviceCompliancePolicyId
      in: path
      required: true
      description: The unique identifier of the device compliance policy.
      schema:
        type: string
    orderby:
      name: $orderby
      in: query
      description: Comma-separated list of properties to sort the result set by.
      schema:
        type: string
  responses:
    NotFound:
      description: Not found. The requested resource does not exist.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/odataError'
    ODataError:
      description: An unexpected error occurred.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/odataError'
    Forbidden:
      description: Forbidden. The caller does not have the required permissions.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/odataError'
    Unauthorized:
      description: Unauthorized. The request requires valid authentication credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/odataError'
  securitySchemes:
    oauth2:
      type: oauth2
      description: OAuth 2.0 authorization using Azure Active Directory. Requires an active Intune license for the tenant.
      flows:
        authorizationCode:
          authorizationUrl: https://login.microsoftonline.com/common/oauth2/v2.0/authorize
          tokenUrl: https://login.microsoftonline.com/common/oauth2/v2.0/token
          scopes:
            DeviceManagementManagedDevices.Read.All: Read Microsoft Intune managed devices
            DeviceManagementManagedDevices.ReadWrite.All: Read and write Microsoft Intune managed devices
            DeviceManagementConfiguration.Read.All: Read Microsoft Intune device configuration and policies
            DeviceManagementConfiguration.ReadWrite.All: Read and write Microsoft Intune device configuration and policies
externalDocs:
  description: Microsoft Graph Intune API Overview
  url: https://learn.microsoft.com/en-us/graph/api/resources/intune-graph-overview?view=graph-rest-1.0