Intune Company Portal icon

Intune Company Portal Data API

Microsoft Corporation · Business

Intune Company Portal is the employee-facing companion to Microsoft Intune on Android. Organizations that manage phones and tablets with Intune rely on it to enroll devices into work management, show employees whether their device meets compliance rules, distribute assigned company apps, and retire a device cleanly when it leaves the fleet.

Behind those screens sits a structured device-management dataset: the managed-device inventory carries ComplianceState, LastContact, Manufacturer and AadId for every enrolled phone, compliance checks return failing rules as NoncompliantRules with a SettingId and expected value, and the work-app catalog exposes applicationGuid, appVersion and featured flags. IT asset teams, zero-trust access gateways and software-asset-management tools build on these fields to keep inventory, access decisions and license counts in sync with what the employee sees.

Intune Company Portal is Microsoft's employee app for enrolling Android phones and tablets into Microsoft Intune, checking device compliance, installing company apps, and removing work data when a device leaves the fleet. Used by organizations worldwide that manage Android devices with Intune, it exposes the data behind those screens: the signed-in user's managed-device inventory with compliance state and last check-in, the assigned work-app catalog, company terms, and app-protection policy payloads. That data serves IT asset inventory, zero-trust access decisions, software license reconciliation, and security policy audits.

Screenshots

  • Intune Company Portal screenshot 1
  • Intune Company Portal screenshot 2
  • Intune Company Portal screenshot 3
  • Intune Company Portal screenshot 4
  • Intune Company Portal screenshot 5
  • Intune Company Portal screenshot 6
  • Intune Company Portal screenshot 7
  • Intune Company Portal screenshot 8

API surface

The endpoints and request/response examples below are reconstructed from the app's interface — illustrative, not a live capture.

  • Enrollment server discovery (SOAP)

    POST /v1/enrollment/discover opendata

    Resolves the work email to the tenant's enrollment endpoints and auth policy (federated vs on-prem) before the device enrollment handshake.

    Auth: Unauthenticated discovery call; the work email goes in the request body. Later enrollment steps use a Microsoft Entra Bearer token scoped for device enrollment.

    • EmailAddress
    • RequestVersion
    • DeviceType
    • ApplicationVersion
    • OSEdition
    • AuthPolicies
    • EnrollmentServiceUrl
    • AuthenticationServiceUrl
    POST /v1/enrollment/discover HTTP/1.1
    Content-Type: application/soap+xml; charset=utf-8
    
    <Discover><request><EmailAddress>[email protected]</EmailAddress><RequestVersion>4.0</RequestVersion><DeviceType>AndroidForWork</DeviceType><ApplicationVersion>5.0.7080.0</ApplicationVersion><OSEdition>4</OSEdition><AuthPolicies><AuthPolicy>OnPremise</AuthPolicy><AuthPolicy>Federated</AuthPolicy></AuthPolicies></request></Discover>
    {
      "DiscoveryResponse": {
        "AuthPolicy": "Federated",
        "EnrollmentPolicyServiceUrl": "https://enroll.contoso.example/policy",
        "EnrollmentServiceUrl": "https://enroll.contoso.example/enroll",
        "AuthenticationServiceUrl": "https://login.contoso.example/contoso.com"
      }
    }
    • Reconstructed from the app's work-email enrollment discovery flow
    • The SOAP envelope carries the work email, device type, app version and supported auth policies
  • Intune service-location discovery

    POST /v1/enrollment/service-locations opendata

    Returns the tenant-specific Android device-gateway, AOSP provisioning, enrollment and diagnostics URLs the app caches after sign-in.

    Auth: Microsoft Entra Bearer token (device-enrollment scope) issued at the organization's identity provider.

    • aadTenantId
    • deviceType
    • applicationPackageName
    • applicationVersionName
    • androidDeviceGatewayCertificateServiceUrl
    • androidDeviceGatewayServiceUrl
    • androidDeviceGatewayServiceFefUrl
    • aospProvisioningServiceUrl
    • ariaServiceUrl
    • enrollmentServiceUrl
    • powerliftServiceUrl
    POST /v1/enrollment/service-locations HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "aadTenantId": "72f988bf-86f1-41af-91ab-2d7cd011db47",
      "deviceType": "Android",
      "applicationPackageName": "com.example.workapp",
      "applicationVersionName": "5.0.7080.0"
    }
    {
      "androidDeviceGatewayCertificateServiceUrl": "https://gw.contoso.example/android/certificates",
      "androidDeviceGatewayServiceUrl": "https://gw.contoso.example/android/gateway",
      "androidDeviceGatewayServiceFefUrl": "https://gw.contoso.example",
      "aospProvisioningServiceUrl": "https://gw.contoso.example/aosp-provisioning",
      "ariaServiceUrl": "https://telemetry.contoso.example/collector",
      "enrollmentServiceUrl": "https://enroll.contoso.example/enroll",
      "powerliftServiceUrl": "https://logs.contoso.example"
    }
    • Reconstructed from the post-sign-in service discovery step
    • The response maps logical service names to tenant-specific URLs the app caches for later calls
  • List enrolled devices

    GET /v1/fleet opendata

    Pages the signed-in user's managed devices for the Devices tab — nickname, hardware, OS, compliance, last check-in and directory device id.

    Auth: Microsoft Entra Bearer token (device-management scope) with an Accept: application/json header.

    • Key
    • Nickname
    • Manufacturer
    • Model
    • OfficialName
    • OperatingSystem
    • OperatingSystemId
    • OwnerType
    • ComplianceState
    • AadId
    • DeviceHWId
    • LastContact
    • ManagementType
    • CategoryId
    • NoncompliantRules
    • odata.id
    GET /v1/fleet HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": [
        {
          "Key": "d1a2b3c4-1111-2222-3333-444455556666",
          "Nickname": "Alex Pixel 8",
          "Manufacturer": "Google",
          "Model": "Pixel 8",
          "OfficialName": "Pixel 8",
          "OperatingSystem": "Android",
          "OperatingSystemId": "14",
          "OwnerType": 1,
          "ComplianceState": "Compliant",
          "AadId": "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee",
          "DeviceHWId": "android-hw-9f2c",
          "LastContact": "2026-09-28T18:12:03Z",
          "ManagementType": "AndroidEnterprise",
          "CategoryId": "cat-sales",
          "CategorySetByEndUser": true,
          "IsReadOnly": false,
          "InGracePeriodUntilDateTimeUtc": null,
          "NoncompliantRules": [],
          "odata.id": "fleet/d1a2b3c4-1111-2222-3333-444455556666"
        }
      ]
    }
    • Reconstructed from the device list shown on the app's Devices tab
    • Device records carry Key, Nickname, Manufacturer, ComplianceState, AadId and LastContact
  • Check device compliance

    POST /v1/fleet/{deviceId}/compliance-check opendata

    Triggers an on-demand compliance evaluation for one device and returns the failing rules shown on the Device compliance details screen.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • Key
    • ComplianceState
    • InGracePeriodUntilDateTimeUtc
    • NoncompliantRules
    • SettingId
    • Title
    • ExpectedValue
    • Description
    • MoreInfoUri
    • RemediationOwner
    • LastContact
    POST /v1/fleet/d1a2b3c4-1111-2222-3333-444455556666/compliance-check HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    Content-Length: 0
    {
      "Key": "d1a2b3c4-1111-2222-3333-444455556666",
      "ComplianceState": "Noncompliant",
      "InGracePeriodUntilDateTimeUtc": "2026-10-05T00:00:00Z",
      "NoncompliantRules": [
        {
          "SettingId": "AndroidDeviceOwnerPasscodeRequired",
          "Title": "Device passcode required",
          "ExpectedValue": "true",
          "Description": "A screen lock must be set on this device.",
          "MoreInfoUri": "https://docs.contoso.example/compliance/passcode",
          "RemediationOwner": 1
        }
      ],
      "LastContact": "2026-09-29T17:40:11Z"
    }
    • Reconstructed from the Device compliance details screen
    • Each failing rule carries SettingId, Title, ExpectedValue, a remediation link and a grace-period deadline
  • Retire device (remove company data)

    POST /v1/fleet/{deviceId}/retire opendata

    Starts the user-initiated retire action that unenrolls the device and wipes company data while leaving personal apps and files.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • odata.id
    • Key
    • ManagementType
    • retired
    POST /v1/fleet/d1a2b3c4-1111-2222-3333-444455556666/retire HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    Content-Length: 0
    {
      "Key": "d1a2b3c4-1111-2222-3333-444455556666",
      "ManagementType": "AndroidEnterprise",
      "retired": true
    }
    • Reconstructed from the user-initiated remove-company-data flow on the device details screen
  • Work-app catalog item

    GET /v1/catalog/apps/{appId} opendata

    Loads one assigned company app for the Apps screen — title, publisher, icons, featured flag and the install-state link.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • applicationGuid
    • name
    • publisher
    • category
    • description
    • smallIconUri
    • largeIconUri
    • isFeaturedApp
    • relevance
    • availableDate
    • appVersion
    • privacyStatementUri
    • moreInfoUri
    GET /v1/catalog/apps/8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "applicationGuid": "8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d",
      "name": "Microsoft Outlook",
      "publisher": "Microsoft Corporation",
      "category": "Productivity",
      "description": "Email and calendar for work.",
      "smallIconUri": "https://cdn.contoso.example/catalog/icons/outlook-small.png",
      "largeIconUri": "https://cdn.contoso.example/catalog/icons/outlook-large.png",
      "isFeaturedApp": true,
      "relevance": 10,
      "availableDate": "2026-01-15T00:00:00Z",
      "appVersion": "4.2426.0",
      "privacyStatementUri": "https://privacy.contoso.example",
      "moreInfoUri": "https://docs.contoso.example/apps/outlook",
      "installStateLink": "catalog/apps/8e2c1a90-77ab-4d21-9c0e-0b6d1f2a3c4d/install-state"
    }
    • Reconstructed from the app details screen of the work-app catalog
    • Catalog records expose applicationGuid, publisher, appVersion, a featured flag and icon links
  • Accept company terms

    POST /v1/terms/{termsId}/accept opendata

    Records acceptance of the tenant's company terms of use (versioned body and acceptance statement) during enrollment setup.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • termVersion
    • Key
    • Title
    • BodyText
    • AcceptanceStatement
    • CompanyTermVersion
    POST /v1/terms/contoso-mdm-tos/accept HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    Accept: application/json
    
    {
      "termVersion": 3
    }
    {
      "Key": "contoso-mdm-tos",
      "Title": "Contoso mobile use policy",
      "BodyText": "You must protect company data on this device...",
      "AcceptanceStatement": "I have read and accept these terms.",
      "CompanyTermVersion": 3,
      "accepted": true
    }
    • Reconstructed from the company terms acceptance step during enrollment setup
    • Terms records are versioned and carry the body text plus the acceptance statement
  • Feature flags for user

    GET /v1/users/{userId}/features opendata

    Reads per-user feature gates that hide or show Company Portal screens such as Managed Play and work-profile lockdown.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • featureId
    • isEnabled
    GET /v1/users/11111111-2222-3333-4444-555555555555/features HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": [
        {"featureId": "ManagedPlay", "isEnabled": true},
        {"featureId": "WebCompanyPortal", "isEnabled": false},
        {"featureId": "WorkProfileLockdown", "isEnabled": true}
      ]
    }
    • Reconstructed from the per-user feature gates that toggle Company Portal screens
  • Managed Google Play account

    GET /v1/users/{userId}/work-play-account osint

    Returns the Managed Google Play / work account binding used to install company apps from the Play Store on an Android Enterprise device.

    Auth: Microsoft Entra Bearer token (device-management scope).

    • accountName
    • isAccountDisabled
    • isAccountWorkplaceJoinEnabled
    • maintenanceState
    GET /v1/users/11111111-2222-3333-4444-555555555555/work-play-account HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "accountName": "[email protected]",
      "isAccountDisabled": false,
      "isAccountWorkplaceJoinEnabled": true,
      "maintenanceState": 0
    }
    • Reconstructed from the Managed Google Play account binding used for work app installs
  • MAM Android app-protection policies

    GET /v1/app-protection/android/policies opendata

    Downloads the Android MAM / app-protection policy set (PIN, screenshot, feedback gates) applied to Company Portal and other protected apps.

    Auth: Microsoft Entra Bearer token (app-protection policy scope); the client prefixes Authorization with 'Bearer '.

    • policiesHash
    • value
    • id
    • policyType
    • priority
    • policiesPayload
    GET /v1/app-protection/android/policies HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "policiesHash": "sha256:9c1e0a…",
      "value": [
        {
          "id": "office16;L_SendFeedback",
          "policyType": 1,
          "priority": 10,
          "policiesPayload": [{"key": "PINRequired", "value": "true"}]
        }
      ]
    }
    • Reconstructed from the app-protection policy download applied to protected apps
    • The policy set is versioned with a hash so clients can detect drift
  • Android device-gateway certificate request

    POST /v1/fleet/{deviceId}/certificates opendata

    Submits a CSR to the Android device gateway and receives the device management certificate (leaf + intermediate thumbprints) used for subsequent check-ins.

    Auth: Microsoft Entra Bearer token (Android device-gateway scope) obtained after enrollment.

    • CertificateSigningRequest
    • Signature
    • SigningCertSha256Thumbprint
    • Base64EncodedCertificate
    • LeafThumbprint
    • IntermediateThumbprint
    POST /v1/fleet/android-hw-9f2c/certificates HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "CertificateSigningRequest": "MIICUzCCATsCAQAwgYMxCzAJBgNVBAYTAlVT...",
      "Signature": "MEUCIQDx…",
      "SigningCertSha256Thumbprint": "A1B2C3D4E5F60718293A4B5C6D7E8F9012345678ABCDEF01"
    }
    {
      "Base64EncodedCertificate": "MIIDPjCCAiagAwIBAgIQe0…",
      "LeafThumbprint": "9F2C8A71B0D4E6…",
      "IntermediateThumbprint": "7C11AA90FF22…"
    }
    • Reconstructed from the device certificate enrollment handshake after provisioning
  • Update Google Play Protect status

    POST /v1/fleet/{deviceId}/play-protect-status opendata

    Reports the device's Google Play Protect scan state so compliance policies that require Play Protect can evaluate the phone.

    Auth: Microsoft Entra Bearer token (Android device-gateway scope).

    • playProtectEnabled
    • lastScanTimeUtc
    • threatLevel
    • deviceId
    POST /v1/fleet/android-hw-9f2c/play-protect-status HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Content-Type: application/json
    
    {
      "playProtectEnabled": true,
      "lastScanTimeUtc": "2026-09-29T16:01:00Z",
      "threatLevel": "NoThreatsFound"
    }
    {
      "deviceId": "android-hw-9f2c",
      "playProtectEnabled": true,
      "threatLevel": "NoThreatsFound",
      "accepted": true
    }
    • Reconstructed from the Play Protect scan reporting used by compliance evaluation
  • Directory device enabled state

    GET /v1/directory/device-objects/{deviceId}/enabled osint

    Reads whether the directory device object is enabled — Company Portal uses this to decide if the work account on the phone is still allowed to sign in.

    Auth: Microsoft directory Bearer token acquired through the organization's identity platform.

    • value
    GET /v1/directory/device-objects/aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee/enabled HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: application/json
    {
      "value": true
    }
    • Reconstructed from the check that the work account's device object is still enabled
  • Signed-in user photo

    GET /v1/directory/me/photo osint

    Fetches the work-account profile photo shown on the Company Portal home and user-profile screens.

    Auth: Microsoft directory Bearer token.

    • $value
    GET /v1/directory/me/photo HTTP/1.1
    Authorization: Bearer eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIs...
    Accept: image/jpeg
    (binary JPEG)
    Content-Type: image/jpeg
    Content-Length: 18432
    • Reconstructed from the profile photo shown on the home and account screens

Data categories

  • devices
  • compliance
  • applications
  • enrollment
  • identity
  • mam-policies
  • certificates

Where teams use this data

  • ITAM device inventory from Company Portal

    A CMDB job signs in as the employee and reads GET /v1/fleet for Nickname, Manufacturer, Model, OperatingSystem, AadId, LastContact and ComplianceState so asset records stay in sync with what the user sees in Company Portal.

  • Zero-trust posture before granting VPN

    An access proxy calls POST /v1/fleet/{deviceId}/compliance-check and blocks the session when NoncompliantRules still list SettingId values such as AndroidDeviceOwnerPasscodeRequired past InGracePeriodUntilDateTimeUtc.

  • Software catalog for license reclaim

    SAM tooling walks GET /v1/catalog/apps/{appId} for applicationGuid, publisher, appVersion and isFeaturedApp to compare assigned work apps against purchased seats.

  • MAM policy drift audit

    Security ops pull GET /v1/app-protection/android/policies and store policiesHash plus each policiesPayload so PIN and screenshot controls on Android can be diffed against the Intune baseline.

Frequently asked questions

What data does Intune Company Portal expose for each managed device?

The device inventory returns a Key, Nickname, Manufacturer, Model, OperatingSystem, OwnerType, ComplianceState, AadId, DeviceHWId, LastContact, ManagementType, CategoryId and a list of NoncompliantRules for every phone or tablet the signed-in user has enrolled.

How does the app authenticate its data calls?

After a work or school sign-in through Microsoft's identity platform, the app holds Bearer tokens scoped for enrollment, device management, the organization's directory, and app-protection policy. Each call sends the matching token in the Authorization header.

How does an on-demand device compliance check work?

The employee can trigger a fresh evaluation for one device. The response lists each failing rule with a SettingId, a human-readable Title, the ExpectedValue and a remediation link, plus the grace-period deadline InGracePeriodUntilDateTimeUtc.

Can I see which work apps an organization assigned?

Yes. The work-app catalog returns applicationGuid, name, publisher, category, appVersion, a featured flag and icon links for every app assigned to the signed-in user, which software-asset-management tools can reconcile against purchased licenses.

Apps similar to Intune Company Portal

  • Workspace ONE Intelligent Hub — Omnissa's (formerly VMware) employee app for Workspace ONE UEM, enrolling Android devices into management, showing compliance status, and delivering the company's assigned app catalog — the most direct counterpart to Intune Company Portal.
  • Android Device Policy — Google's own enrollment app that registers Android phones and tablets into Google endpoint management for organizations using Google Workspace, applying work profiles and admin-set device rules.
  • IBM MaaS360 — IBM's unified endpoint management platform whose Android agent enrolls devices, enforces compliance policies, and distributes work apps, with Watson-based analytics on the managed fleet.
  • ManageEngine Endpoint Central — ManageEngine's UEM console manages Windows, macOS, Linux, iOS and Android endpoints from one place, including a free tier covering up to 25 desktops and 25 mobile devices.
  • Scalefusion UEM — A unified endpoint management platform for Android, iOS, Windows, macOS, Linux and ChromeOS fleets with per-device pricing aimed at organizations comparing MDM suites.
  • Hexnode UEM — A UEM platform covering Windows, macOS, Linux, iOS, Android and ChromeOS that is frequently shortlisted as a budget-friendly Intune alternative for small and mid-sized businesses.
  • Jamf — The leading Apple-focused device management platform, offering zero-touch deployment and its own self-service portal for organizations managing iPhone, iPad and Mac fleets instead of Android.

Topics

  • intune company portal api
  • microsoft intune devices endpoint
  • company portal compliance api
  • intune mam android policies
  • managed google play account api
  • intune enrollment discovery

Need this app's data API integrated?

We deliver scoped integrations for any named app — from USD 500 with source-code handoff, or hosted access billed per call. Tell us the data you need.

  • NDA + SOW on every engagement
  • Delivery in 3–7 days
  • Payment only after acceptance
  • Work scoped to authorized use

Get a quote