Guide
How to use Persona in Capacitor
Using @capgo/capacitor-intune
Capacitor plugin for Microsoft Intune MAM enrollment, app protection policies, app config, and MSAL authentication.
Install
bun add @capgo/capacitor-intune
bunx cap sync
bunx cap sync copies the plugin's native code into your native projects. Run it again after every plugin upgrade.
Import
import { IntuneMAM } from '@capgo/capacitor-intune';
API at a glance
| Method | Description |
|---|---|
acquireToken |
Present the Microsoft sign-in flow and return an access token plus the account metadata. |
acquireTokenSilent |
Acquire a token from the MSAL cache for a previously signed-in user. |
registerAndEnrollAccount |
Register a previously authenticated account with Intune and start enrollment. |
loginAndEnrollAccount |
Ask Intune to authenticate and enroll a user without first requesting an app token. |
enrolledAccount |
Return the currently enrolled Intune account, if one is available. |
deRegisterAndUnenrollAccount |
Deregister the account from Intune and trigger selective wipe when applicable. |
logoutOfAccount |
Sign the user out of MSAL without unenrolling the Intune account. |
appConfig |
Fetch the remote Intune app configuration for a managed account. |
getPolicy |
Fetch the currently effective Intune app protection policy for a managed account. |
groupName |
Convenience helper that resolves the GroupName app configuration value when present. |
sdkVersion |
Return the native Intune and MSAL SDK versions bundled by this plugin. |
displayDiagnosticConsole |
Show the native Intune diagnostics UI. |
Examples
acquireToken()
Present the Microsoft sign-in flow and return an access token plus the account metadata.
import { IntuneMAM } from '@capgo/capacitor-intune';
const result = await IntuneMAM.acquireToken({ scopes: ['openid'] });
// The result holds sensitive values: use it without logging it.
acquireTokenSilent()
Acquire a token from the MSAL cache for a previously signed-in user.
import { IntuneMAM } from '@capgo/capacitor-intune';
const result = await IntuneMAM.acquireTokenSilent({
scopes: ['openid'],
accountId: 'acquireToken',
});
// The result holds sensitive values: use it without logging it.
registerAndEnrollAccount()
Register a previously authenticated account with Intune and start enrollment.
import { IntuneMAM } from '@capgo/capacitor-intune';
await IntuneMAM.registerAndEnrollAccount({ accountId: 'account-id-123' });
loginAndEnrollAccount()
Ask Intune to authenticate and enroll a user without first requesting an app token.
import { IntuneMAM } from '@capgo/capacitor-intune';
await IntuneMAM.loginAndEnrollAccount();
enrolledAccount()
Return the currently enrolled Intune account, if one is available.
import { IntuneMAM } from '@capgo/capacitor-intune';
const result = await IntuneMAM.enrolledAccount();
console.log(result);
deRegisterAndUnenrollAccount()
Deregister the account from Intune and trigger selective wipe when applicable.
import { IntuneMAM } from '@capgo/capacitor-intune';
await IntuneMAM.deRegisterAndUnenrollAccount({ accountId: 'account-id-123' });
The table above lists the 12 core methods. Listener and version helpers, and the full contract of each method, are documented in the GitHub repository.
Listen to events
addListener returns a handle. Call handle.remove() when the screen unmounts, or IntuneMAM.removeAllListeners() to clear every listener.
Full reference
Keep going from Using @capgo/capacitor-intune
If you are using Using @capgo/capacitor-intune to plan authentication and account flows, connect it with @capgo/capacitor-intune for the implementation detail in @capgo/capacitor-intune, Getting Started for the implementation detail in Getting Started, @capgo/capacitor-social-login for the implementation detail in @capgo/capacitor-social-login, @capgo/capacitor-passkey for the implementation detail in @capgo/capacitor-passkey, and @capgo/capacitor-native-biometric for the implementation detail in @capgo/capacitor-native-biometric.