# Secure Contacts App (SCA)

Welcome to the Secure Contacts Documentation

Welcome to the official documentation for **Secure Contacts App**. This resource provides comprehensive guidance for administrators and end-users to effectively deploy, configure, and use Secure Contacts within your organization.

{% hint style="success" %}
**Secure Contacts App - available in** [**AppStore**](https://apps.apple.com/de/app/secure-contacts/id1617596880) **/** [**PlayStore**](https://play.google.com/store/apps/details?id=de.provectus.securecontacts.droid)
{% endhint %}

* Security through **GDPR-Compliant** contact management
* **No unintentional outflow** of confidential data to third-party apps, \
  such as Whatsapp and Google
* **No unintentional synchronisation** with rental cars and carsharings
* Ideal for **BYOD** and **COPE** devices
* **iOS Contact Provider**: Securely share managed contacts to the native iOS Contacts app, making them available for Siri, CarPlay, and other system features, all under IT control via App Configuration.
* **Contact Creation, Editing, and Deletion**: Users can create, edit, and delete their personal Outlook contacts directly in the app, including adding new contacts by scanning vCard QR codes.
* **Modern User Interface**: A modern look and improved navigation for a smoother experience.

### Documentation Overview

To help you get the most out of Secure Contacts, the documentation is organized as follows:

* [**Quick Facts**](/introduction/quick-facts) – A concise summary of the key improvements and features.
* [**Technical Security Overview**](/introduction/technical-security-overview) – Explore the security architecture and safeguards that protect your data.
* [**Data Protection and GDPR Compliance**](/introduction/data-protection-and-gdpr-compliance) – Understand how Secure Contacts ensures privacy and regulatory compliance.
* [**Editions**](/introduction/editions) – Compare the available Secure Contacts editions and their features to determine which best fits your organization.
* [**Quick Start Guides**](/quickstart-guide/requirements) – Step-by-step instructions to get up and running quickly with Secure Contacts.

### Getting Started

For new users, start with the **Quick Start Guides** and **Quick Facts** to understand the main capabilities.\
Administrators and developers should refer to the **Technical Security Overview**, **App Configuration Policies**, and **Editions** page to select and configure the appropriate version for your organization.

### **All Contacts in one App** <a href="#securecontactsapp-sca-safe-and-gdprcompliant-allcontactsinoneapp" id="securecontactsapp-sca-safe-and-gdprcompliant-allcontactsinoneapp"></a>

* **Pool all** your Business Contacts
* **Automatic integration** of all Contacts without **manual data maintenance**
* Simple **Caller ID** including for contacts from the CRM system
* **Anonymized calls** can be placed directly from the app without displaying the caller\`s number
* **Single sign on**
* **Easy quick search**
* **Out-of-office function**
* Display of Out of Office Status Messages

  • Display of Addresses (open address in maps app)

  • Display of Organizational Chart (show manager)

### **DATA PRIVACY AT RISK: BUSINESS CONTACTS** <a href="#securecontactsapp-sca-safe-and-gdprcompliant-dataprivacyatrisk-businesscontacts" id="securecontactsapp-sca-safe-and-gdprcompliant-dataprivacyatrisk-businesscontacts"></a>

The GDPR limits the extent to which business contacts may be stored in the smartphone’s address, because

* a phone’s contact data **automatically syncs with commercial platforms such as those belonging to Apple, Facebook/WhatsApp or Google**
* a phone’s contact data can **synchronize** unintentionally **with rental cars and carsharings**


# Secure Contacts App (SCA) (2025) new 3.0 release

Welcome to the Secure Contacts Documentation

Welcome to the official documentation for **Secure Contacts App**. This resource provides comprehensive guidance for administrators and end-users to effectively deploy, configure, and use Secure Contacts within your organization.

{% hint style="success" %}
**Secure Contacts App 3.0 is here** 🎉 Released on **18 September 2025 - available in** [**AppStore**](https://apps.apple.com/de/app/secure-contacts/id1617596880) **/** [**PlayStore**](https://play.google.com/store/apps/details?id=de.provectus.securecontacts.droid)
{% endhint %}

Secure Contacts App 3.0 represents a major release with enhanced security, improved usability, and robust compliance with data protection regulations.

### What’s New in Version 3.0

This release introduces important enhancements in security, privacy, and user experience. While detailed features are covered in dedicated sections, some of the key highlights include:

* **iOS Contact Provider**: Securely share managed contacts to the native iOS Contacts app, making them available for Siri, CarPlay, and other system features, all under IT control via App Configuration.
* **Contact Creation, Editing, and Deletion**: Users can create, edit, and delete their personal Outlook contacts directly in the app, including adding new contacts by scanning vCard QR codes.
* **Redesigned User Interface**: A modern look and improved navigation for a smoother experience.

For a full overview of all new features, please see [**What’s New in SCA 3.0**](/sca-3.0-public-beta/whats-new-in-sca-3.0).

**Update from SCA 2.0 to SCA 3.0**: [**Important Information for Administrators and End Users**](/introduction/update-sca-2.0-to-3.0) ⚠️

### Documentation Overview

To help you get the most out of Secure Contacts 3.0, the documentation is organized as follows:

* [**Quick Facts – Version 3.0**](/introduction/quick-facts) – A concise summary of the key improvements and features.
* [**Technical Security Overview**](/introduction/technical-security-overview) – Explore the security architecture and safeguards that protect your data.
* [**Data Protection and GDPR Compliance**](/introduction/data-protection-and-gdpr-compliance) – Understand how Secure Contacts ensures privacy and regulatory compliance.
* [**Editions**](/introduction/editions) – Compare the available Secure Contacts editions and their features to determine which best fits your organization.
* [**Quick Start Guides**](/quickstart-guide/requirements) – Step-by-step instructions to get up and running quickly with Secure Contacts 3.0.

### Getting Started

For new users, start with the **Quick Start Guides** and **Quick Facts** to understand the main capabilities.\
Administrators and developers should refer to the **Technical Security Overview**, **App Configuration Policies**, and **Editions** page to select and configure the appropriate version for your organization.


# Secure Contacts App (SCA) - Safe & GDPR Compliant (2022-2024)

* Security through **GDPR-Compliant** contact management
* **No unintentional outflow** of confidential data to third-party apps, \
  such as Whatsapp and Google
* **No unintentional synchronisation** with rental cars and carsharings
* Ideal for **BYOD** and **COPE** devices

### **DATA PRIVACY AT RISK: BUSINESS CONTACTS** <a href="#securecontactsapp-sca-safe-and-gdprcompliant-dataprivacyatrisk-businesscontacts" id="securecontactsapp-sca-safe-and-gdprcompliant-dataprivacyatrisk-businesscontacts"></a>

The GDPR limits the extent to which business contacts may be stored in the smartphone’s address, because

* a phone’s contact data **automatically syncs with commercial platforms such as those belonging to Apple, Facebook/WhatsApp or Google**
* a phone’s contact data can **synchronize** unintentionally **with rental cars and carsharings**

### **All Contacts in one App** <a href="#securecontactsapp-sca-safe-and-gdprcompliant-allcontactsinoneapp" id="securecontactsapp-sca-safe-and-gdprcompliant-allcontactsinoneapp"></a>

* **Pool all** your Business Contacts
* **Automatic integration** of all Contacts without **manual data maintenance**
* Simple **Caller ID** including for contacts from the CRM system
* **Anonymized calls** can be placed directly from the app without displaying the caller\`s number
* **Single sign on**
* **Easy quick search**
* **Out-of-office function**
* Display of Out of Office Status Messages

  • Display of Addresses (open address in maps app)

  • Display of Organizational Chart (show manager)

## Requirements <a href="#securecontactsapp-sca-safe-and-gdprcompliant-requirements" id="securecontactsapp-sca-safe-and-gdprcompliant-requirements"></a>

For this guide, you download SCA from the [App Store (apple.com)](https://apps.apple.com/de/app/secure-contacts/id1617596880?uo=4) \
only works in **demo-mode**, without a valid license provided.\
\
In order to install apps through the App Store you would need an iCloud-account to install apps from App Store.

An **activation** by Provectus Software GmbH **with a valid license** is required.

To use the Secure Contacts app (SCA) in your **Microsoft Entra** tenant,\
the following functions must be present and activated:

* Azure Active Directory Premium P1 (or higher)
* Exchange Online P1 (or higher)
* Microsoft Intune
* Dataverse

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-cover data-type="files"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td></td><td></td><td></td><td><a href="/files/Uqs3q1TXor66dQxOlMBi">/files/Uqs3q1TXor66dQxOlMBi</a></td><td><a href="https://secure-contacts.com/kontakt-testlizenz/">https://secure-contacts.com/kontakt-testlizenz/</a></td></tr><tr><td></td><td></td><td></td><td><a href="/files/mlDaxWiB4Q62I00VX76c">/files/mlDaxWiB4Q62I00VX76c</a></td><td><a href="https://secure-contacts.com/kontakt/">https://secure-contacts.com/kontakt/</a></td></tr></tbody></table>


# Quick Facts

SCA - Quick Facts

<table data-header-hidden><thead><tr><th width="273.999755859375"></th><th></th></tr></thead><tbody><tr><td>Platform</td><td>iOS / Android</td></tr><tr><td>Minimum Requirements</td><td>Microsoft Entra ID (formerly Azure AD) for user management and any MDM system (Intune preferred) to manage mobile devices.</td></tr><tr><td>Architecture</td><td>Fully embedded in Microsoft 365: Entra ID, MSAL and Intune SDK integration ensure security and compliance by design.</td></tr><tr><td>Single Sign-On (SSO)</td><td>Single Sign-On (SSO) with Microsoft Entra ID, allowing users to log in securely with their existing corporate credentials. This ensures seamless access while meeting enterprise security and compliance requirements.</td></tr><tr><td>Intune SDK integration</td><td>With Intune SDK integration, SCA enforces corporate policies and app protection (full app encryption, Face ID/Touch ID/PIN, copy/paste restrictions, org data protection, Conditional Access), allowing access only for registered, compliant devices.</td></tr><tr><td>Access to contact sources</td><td>Azure Active Directory &#x26; Groups, Org Contacts (GAL), Exchange Online (EXO) Personal Contacts &#x26; Shared MailBox Contacts, Dynamics 365, MS Dataverse, Azure Blob Storage. Granularly configurable via AppConfig.</td></tr><tr><td>Other contact sources</td><td>Exported contacts (CSV/JSON) from any source (cloud or on-prem) are automatically encrypted &#x26; uploaded to your Azure Blob Storage using the SCA-ABS-Connector (CMD tool) for SCA to synchronize.</td></tr><tr><td>No dedicated backend</td><td>Contacts stay yours: SCA reads contact data directly from your Azure tenant in the context of the signed-in user. Your Azure tenant is the backend - no foreign data processing.</td></tr><tr><td>Secure Storage</td><td>Stores all contact data locally in its secure container database, fully protected with AES-256 encryption.</td></tr><tr><td>Contact Features</td><td>Full name, title, company &#x26; department, phone &#x26; email, postal/business addresses, notes, and profile image.</td></tr><tr><td>Duplicate Contact Merge</td><td>Automatically detects and merges duplicate contacts into a single entry, preserving all associated information and features.</td></tr><tr><td>Incoming Caller Identification</td><td>Instantly see who’s calling, even if the number is not in your local contacts, with full company context.</td></tr><tr><td>Siri / CarPlay integration</td><td>Through CPE (Contact Provider Extension), SCA can share its contacts system-wide on iOS, with granular control over which contact sources and properties are shared.</td></tr><tr><td>Android Auto integration</td><td>Through AWP (Android Work Profile), SCA can share its contacts system-wide on Android.</td></tr><tr><td>Create, Edit &#x26; Delete Contacts</td><td>Manage your (EXO) personal contacts in SCA - create, edit, delete, or add new contacts instantly via QR code.</td></tr><tr><td>vCard integration</td><td>Auto-generated vCard (digital business card) for the signed-in user - optionally editable, multiple vCards and your company logo in the QR code for easy sharing. Fully configurable via AppConfig.</td></tr><tr><td>Core communication options</td><td>Phone, Email, SMS/iMessage, FaceTime</td></tr><tr><td>Optional Messenger</td><td>Support for WhatsApp, Signal, Telegram, WebEx via AppConfig; additional messengers upon request.</td></tr><tr><td>MS Teams integration</td><td>Start a Chat, Call &#x26; VideoCall</td></tr><tr><td>MS Teams Status Display</td><td>Real-time Microsoft Teams status display (Teams presence indicator) for the corresponding contact.</td></tr><tr><td>Out-of-Office Display</td><td>Real-time display of the Outlook/Teams Out-of-Office message for the corresponding contact.</td></tr><tr><td>Organizational Chart</td><td>Real-time interactive organizational chart: quickly see reporting relationships and team hierarchy.</td></tr><tr><td>Export/Share a Contact</td><td>Safely share individual contacts from SCA with trusted apps (e.g., Outlook, Microsoft Teams).</td></tr><tr><td>Vacation Mode</td><td>All contacts except favorites are blocked and redirected to voicemail during vacation mode.</td></tr><tr><td>Anonymous Mode</td><td>Place calls without revealing your number.</td></tr><tr><td>Offline Mode</td><td>All features, including caller identification, work without an active internet connection - except real-time feature like MS Teams Status, Out of Office messages, and similar.</td></tr><tr><td>CI customization / WhiteLabel</td><td>Button colors, switches, UI accents, and the company logo (shown in multiple places within the SCA) can be customized via AppConfig.</td></tr><tr><td>Granular control over everything</td><td>Every feature, switch, and contact source is configurable via AppConfig, with the option to create different AppConfigs for different user groups.</td></tr></tbody></table>


# Quick Facts (Desktop)

SCA Desktop - Quick Facts

<table data-header-hidden><thead><tr><th width="273.999755859375"></th><th></th></tr></thead><tbody><tr><td>Platform</td><td>Windows / MacOS</td></tr><tr><td>Minimum Requirements</td><td>Microsoft Entra ID for authentication and a device management solution (e.g., Intune, SCCM, Jamf) for centralized deployment and configuration.</td></tr><tr><td>Architecture</td><td>Fully embedded in Microsoft 365: Entra ID, MSAL ensure security and compliance by design.</td></tr><tr><td>Single Sign-On (SSO)</td><td>Single Sign-On (SSO) with Microsoft Entra ID, allowing users to log in securely with their existing corporate credentials. This ensures seamless access while meeting enterprise security and compliance requirements.</td></tr><tr><td>Access to contact sources</td><td>Azure Active Directory &#x26; Groups, Org Contacts (GAL), Exchange Online (EXO) Personal Contacts &#x26; Shared MailBox Contacts, Dynamics 365, MS Dataverse, Azure Blob Storage. Granularly configurable via AppConfig.</td></tr><tr><td>CRM Connectors</td><td>Access customer and business contacts from Salesforce, HubSpot, SAP, and other connected CRM systems.</td></tr><tr><td>Other contact sources</td><td>Exported contacts (CSV/JSON) from any source (cloud or on-prem) are automatically encrypted &#x26; uploaded to your Azure Blob Storage using the SCA-ABS-Connector (CMD tool) for SCA to synchronize.</td></tr><tr><td>No dedicated backend</td><td>Contacts stay yours: SCA reads contact data directly from your Azure tenant in the context of the signed-in user. Your Azure tenant is the backend - no foreign data processing.</td></tr><tr><td>Secure Storage</td><td>Stores all contact data locally in its secure container database, fully protected with AES-256 encryption.</td></tr><tr><td>Contact Features</td><td>Full name, title, company &#x26; department, phone &#x26; email, postal/business addresses, notes, and profile image.</td></tr><tr><td>Duplicate Contact Merge</td><td>Automatically detects and merges duplicate contacts into a single entry, preserving all associated information and features.</td></tr><tr><td>One-Click Calling</td><td>Start calls directly from SCA using Microsoft Teams, your preferred softphone, or native platform calling services.</td></tr><tr><td>Incoming Caller Identification (MS Teams)</td><td>Displays an enhanced caller popup with enriched contact details and company context for incoming Microsoft Teams and PSTN calls.</td></tr><tr><td>Create, Edit &#x26; Delete Contacts</td><td>Manage your (EXO) personal contacts in SCA - create, edit or, delete.</td></tr><tr><td>vCard integration</td><td>Auto-generated vCard (digital business card) for the signed-in user - optionally editable, multiple vCards. Fully configurable via AppConfig.</td></tr><tr><td>Core communication options</td><td>Phone, Email, MS Teams</td></tr><tr><td>Optional Messenger</td><td>Support for WhatsApp, Signal, Telegram, WebEx via AppConfig; additional messengers upon request.</td></tr><tr><td>MS Teams integration</td><td>Start a Chat, Call &#x26; VideoCall</td></tr><tr><td>MS Teams Status Display</td><td>Real-time Microsoft Teams status display (Teams presence indicator) for the corresponding contact.</td></tr><tr><td>Out-of-Office Display</td><td>Real-time display of the Outlook/Teams Out-of-Office message for the corresponding contact.</td></tr><tr><td>Organizational Chart</td><td>Real-time interactive organizational chart: quickly see reporting relationships and team hierarchy.</td></tr><tr><td>Sponsors Chart</td><td>Real-time interactive sponsors chart: quickly identify sponsor relationships and responsibilities.</td></tr><tr><td>Export/Share a Contact</td><td>Safely share individual contacts from SCA with trusted apps (e.g., Outlook, Microsoft Teams).</td></tr><tr><td>Dashboard &#x26; Widgets</td><td>Customizable dashboard with favorites, saved searches, team overview, calendar insights, recent activity, and company resources.</td></tr><tr><td>Offline Mode</td><td>All features, including caller identification, work without an active internet connection - except real-time feature like MS Teams Status, Out of Office messages, and similar.</td></tr><tr><td>CI customization / WhiteLabel</td><td>Button colors, switches, UI accents, and the company logo (shown in multiple places within the SCA) can be customized via AppConfig.</td></tr><tr><td>Granular control over everything</td><td>Every feature, switch, and contact source is configurable via AppConfig, with the option to create different AppConfigs for different user groups.</td></tr></tbody></table>


# Technical / Security Overview

The **Secure Contacts App (SCA)** provides enterprise-grade security for managing business contacts on mobile devices. Its architecture balances strong data protection, GDPR compliance, and seamless integration with Microsoft Intune and Azure Active Directory (AAD).\ <br>

<figure><img src="/files/vnlAyRzi6zM6UJ1QSNuQ" alt=""><figcaption></figcaption></figure>

### **Security Concept**

* **Encrypted Container:** The app functions as a protected and encrypted container, preventing uncontrolled data leakage to third-party apps or services.
* **Data Ownership:** All personal and business contact data remains under the control of the customer organization.
* **No Telemetry or External Connections:** SCA does **not collect any telemetry data** and only connects to Microsoft Azure Cloud endpoints. No data is sent to the app provider or any other third-party services.

### **Data Sources**

SCA consolidates contact information from [trusted organizational sources](/documentation/data-sources):

* **Azure Active Directory (AAD):** Central directory for organizational contacts.
* **Global Address List (GAL):** Complete organizational contact list.
* **Personal Outlook Contacts (APC):** User-specific contacts from Exchange Online.

**Optional sources** (if enabled by the organization):

* Microsoft Dynamics 365 (D365)
* Microsoft Dataverse (DVRS) – for contacts stored by apps built on Microsoft Dataverse
* Azure Blob Storage (ABS) – for contacts exported from **any** app (including on-premises) via CSV/JSON using the SCA Blob Storage connector
* Shared Mailbox Contacts (SMC) – part of Exchange Online

SCA accesses only backend services within the customer’s Azure tenant, including Microsoft Graph API and optionally Dataverse and Blob Storage. There are **no external backend servers, remote monitoring, analytics, or data collection** by Secure Contacts.

> **Azure Enterprise App Registration:** [SCA is registered as an Azure Enterprise Application](/documentation/authentication/enterprise-application). Access to organizational data requires **admin consent**, ensuring that all permissions are granted and controlled by the organization.

### **Requirements**

To deploy and use SCA:

* **Microsoft 365 Tenant (Worldwide)** – required for identity and organizational management.
* **Azure Active Directory Premium P1 (or higher)** – required for Conditional Access, MFA, and identity management.
* **Exchange Online Plan 1 (or higher)** – optional; needed only if accessing personal Outlook contacts (APC) or shared mailbox contacts (SMC).
* **Mobile Device Management (MDM) System** – mandatory; allows management and enforcement of security policies on mobile devices.
  * **Microsoft Intune** is preferred for full integration with SCA.
  * Other MDM systems may be used

> These requirements ensure proper security, management, and integration of SCA with Microsoft cloud services and enterprise device policies

### **Data in Transit**

* **Secure Communication:** All API calls and data transactions are encrypted using **HTTPS with TLS 1.2 or higher**.
* After SSL handshake negotiation, SCA and Azure API endpoints use the strongest encryption algorithm available on both sides.
* This ensures contact data is protected against interception during synchronization or API calls.

### **Data at Rest**

* Contacts are stored locally within the app container in a **local encrypted database**.
* Encryption keys are securely generated and stored in the **iOS Keychain** or **Android Keystore**, inaccessible to other apps or users without proper authentication.
* **Microsoft Intune App Protection Policies (APP)** provide an additional layer of container-level security.
* **Data Deletion:** When the app is uninstalled, all locally stored contact data is removed.

### **Data Processed**

SCA processes and stores the following contact information locally:

* First and last name
* Company name
* Position / job title
* Email addresses and phone numbers
* Profile photo
* Contact GUID (internal identifier)
* Data source name / ID / priority (e.g., GAL, APC, D365)
* Hash ID (for internal matching and lookup)

All data remains within the app container; **there is no external storage or monitoring** by Secure Contacts. Synchronization occurs only through trusted backend services such as Microsoft Graph API, Dataverse, or Blob Storage.

### **How Data is Processed by the App**

* When the app is launched for the first time, or the user performs a pull-to-update gesture, a **resync process** is started.
* SCA queries all configured data sources for which the user has been authorized.
* Each received contact is analyzed to:
  * Remove duplicates
  * Combine contacts from different sources where possible
  * Normalize and verify each phone number according to the international standard **ITU-T E.164**
* After processing, contact data is stored in a **local encrypted database**.
* On subsequent app launches, the contact data is loaded directly from the encrypted database.

### **Authentication**

* **PIN:** User-defined personal identifier
* **Biometric Authentication:** Touch ID or Face ID
* **Azure AD Conditional Access:** Enforces security based on device compliance and app protection status

These mechanisms ensure that only **authorized users** can access sensitive contact data.

### **Microsoft Intune Integration**

SCA integrates with **Microsoft Intune**, allowing enforcement of **App Protection Policies (APP)** and **Conditional Access Policies (CAP)**. Centralized management ensures compliance with organizational security requirements.

### **Data Flow Control**

* **Open-In Control:** Prevents opening contact data in unauthorized apps
* **Copy/Paste Control:** Limits copying and pasting from the app
* **Third-Party Keyboard Restrictions:** Disables third-party keyboards to prevent data interception
* **iCloud and Backup Restrictions:** Ensures data remains within the secure app container
* **No Unintentional Synchronization:** Prevents data from syncing with third-party apps such as WhatsApp or Google services

### **Incoming Call Identification**

* **Instant Caller Recognition**: Displays the caller’s full name and company on the device’s native incoming call screen **without syncing with the device’s local contacts**, ensuring privacy. Works even when the app is not running or offline.
* **Full Contact Details (Inside App):** Position, profile photo, contact source, and presence or Out-of-Office status are visible in the contact’s detail card within the app.
* **Presence & Out-of-Office:** Displays **Microsoft Teams presence** and Outlook/Microsoft Teams Out-of-Office messages in the contact card. These are retrieved securely via **Microsoft Graph API**.
* **Cross-Platform Support:** [Works on both **iOS and Android**](/documentation/ios-and-android-version-of-sca-in-comparison) with enterprise-grade security and privacy protections.

All data used for caller identification remains **within approved services or the secure app container**, with no external sharing outside the organization.

### **Compliance and Data Protection**

* **GDPR Compliance:** SCA is designed in accordance with GDPR, ensuring all personal data remains under the control of the customer organization.
* **End-to-End Security:** Combines encrypted storage, secure transit, containerization, and controlled authentication to protect sensitive information.

### **Deployment Scenarios**

* **Private Use / BYOD (Bring Your Own Device):**\
  SCA can be installed on personal devices while maintaining enterprise-grade security and data protection. Intune App Protection Policies enforce containerization and prevent data leakage, even on personal devices.
* **Corporate-Owned / Private-Enabled Devices (COPE):**\
  On corporate-owned devices that allow private use, SCA can be deployed with full Intune management and Conditional Access policies, ensuring data is secure while enabling personal use.

### **Logging & Monitoring**

* **Local Logfile**: SCA maintains a daily rotating logfile for app events and diagnostics.
* **Customer-Controlled Export**: Customers may manually export logfiles for support purposes, with the ability to review and remove sensitive information before sharing.
* **No Automatic Transfer**: There is no online or automated mechanism that transfers logs to the app provider. Logfiles remain entirely under the customer’s control unless explicitly exported.

> Logs **do not contain contact content**, ensuring troubleshooting while maintaining data privacy.


# Technical / Security Overview (2024)

* 1 [Intro](#scatechnicaloverview-intro)
* 2 [Function overview](#scatechnicaloverview-functionoverview)
* 3 [Architecture](#scatechnicaloverview-architecture)
* 4 [Security concept](#scatechnicaloverview-securityconcept)
  * 4.1 [Data sources](#scatechnicaloverview-datasources)
  * 4.2 [App Data in Transit](#scatechnicaloverview-appdataintransit)
  * 4.3 [App Data in Rest](#scatechnicaloverview-appdatainrest)
  * 4.4 [Microsoft Intune](#scatechnicaloverview-microsoftintune)
  * 4.5 [Authentication](#scatechnicaloverview-authentication)
* 5 [Data model](#scatechnicaloverview-datamodel)
  * 5.1 [What data is processed](#scatechnicaloverview-whatdataisprocessed)
  * 5.2 [How data is processed by the app](#scatechnicaloverview-howdataisprocessedbytheapp)
* 6 [Incoming caller identification](#scatechnicaloverview-incomingcalleridentification)
* 7 [MS Teams Status display](#scatechnicaloverview-msteamsstatusdisplay)
* 8 [Requirements](#scatechnicaloverview-requirements)
* 9 [Deployment Scenarios](#scatechnicaloverview-deploymentscenarios)

## Intro <a href="#scatechnicaloverview-intro" id="scatechnicaloverview-intro"></a>

Secure Contacts app enables the end-to-end privacy-compliant use of business contacts on the iPhone. Personal data is protected through full integration with Microsoft Intune, and synchronization with third-party apps such as Whatsapp, Google, etc. is prevented. Users do not have to store and maintain a single contact on their own device.

All business data from the company address book, personal Outlook address book, and customer data from any CRM system or other sources are made available in the app and managed centrally.

The app acts as a protected and encrypted container that prevents uncontrolled data leakage to third-party app providers.

## Function overview <a href="#scatechnicaloverview-functionoverview" id="scatechnicaloverview-functionoverview"></a>

| Data protection and information security                 |                                                                                                                                       |
| -------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| **DSGVO/GDPR Compliant**                                 | DSGVO/GDPR compliant storage of data                                                                                                  |
|                                                          | Prevention of uncontrolled outflow of contact data by apps with access to the device phonebook (such as Whatsapp).                    |
| **Encryption**                                           | 256-Bit-AES-Encryption                                                                                                                |
| **Control over the data**                                | <p>Deletion of all data at</p><ul><li>loss of the device</li><li>quits company</li><li>suspicious behavior</li></ul>                  |
|                                                          | Prevent data from being stored in the iCloud or local backups                                                                         |
| **Control over data flow**                               | <p>Open-In Control</p><ul><li>Control of the usable messenger and telephony apps</li><li>Deactivation of local data storage</li></ul> |
|                                                          | <p></p><p>Copy/Paste Control</p><ul><li>Control in from and to which apps data can be copied</li></ul>                                |
|                                                          | Disable 3rd party keyboards                                                                                                           |
| **Access protection**                                    | PIN, TouchID or FaceID before using the app                                                                                           |
|                                                          | Azure AD Conditional Access based on device status (= Compliant Device)                                                               |
|                                                          | Azure AD Conditional Access based on App-Status (= Require App protection policy)                                                     |
|                                                          |                                                                                                                                       |
| Usability                                                |                                                                                                                                       |
| **Outgoing calls: Telephony**                            | Contacts from Outlook address book                                                                                                    |
|                                                          | Contacts from the company address book (Global Address List)                                                                          |
|                                                          | Contacts from other sources such as CRM system                                                                                        |
|                                                          | simple, anonymized calls                                                                                                              |
| **Caller identification of incoming calls**              | Contacts from Outlook address book                                                                                                    |
|                                                          | Contacts from the company address book (Global Address List)                                                                          |
|                                                          | Contacts from other sources such as CRM system                                                                                        |
|                                                          | Vacation and idle mode (diverting business calls to voicemail)                                                                        |
| **Microsoft Teams status display**                       | Display of Microsoft Teams status for contacts from the company address book                                                          |
| **Integratable telephony and messenger apps**            | Cell phone                                                                                                                            |
|                                                          | Microsoft Teams                                                                                                                       |
|                                                          | Other services such as Cisco Jabber                                                                                                   |
| **More functions**                                       | Merging duplicate contacts                                                                                                            |
|                                                          | Simple search                                                                                                                         |
| **Management**                                           |                                                                                                                                       |
| **Central management of the app (via Microsoft Intune)** | <p>App-based configuration</p><ul><li>App protection policies</li><li>App configuration policies</li></ul>                            |
|                                                          | Global filter rules for contacts                                                                                                      |
|                                                          | CI-customization                                                                                                                      |

## Architecture <a href="#scatechnicaloverview-architecture" id="scatechnicaloverview-architecture"></a>

<figure><img src="/files/5hJrZeeZuOn89TVS8cLd" alt=""><figcaption></figcaption></figure>

## Security concept <a href="#scatechnicaloverview-securityconcept" id="scatechnicaloverview-securityconcept"></a>

The app's security concept is based on two components. First, the data is encrypted within the app. In addition, a security configuration is applied to the app via the Microsoft UEM System Endpoint Manager (Intune).

### Data sources <a href="#scatechnicaloverview-datasources" id="scatechnicaloverview-datasources"></a>

SCA is a cloud nativ App, so it gets all contact information from the client Azure Tenant. Primary data sources are the Azure Active Directory \[AAD] and the Global Address List \[GAL]. Furthermore, it gets contact information from the users personal Outlook Contacts \[APC] (Exchange Online only). Optional data sources are Dynamics 365 \[D365], MS Dataverse \[DVRS] and Azure Blob Storage \[ABS], which need additional configuration at clients Azure Tenant.

### App Data in Transit <a href="#scatechnicaloverview-appdataintransit" id="scatechnicaloverview-appdataintransit"></a>

SCA communicates with MS Azure Cloud only. Primarily with Graph API and the Azure Authentication Endpoint, optionally with Azure Blob Storage and Azure Dataverse. Any API call or transaction take place over HTTPS using Transport Layer Security (TLS). After SSL handshake negotiation, SCA and Azure API Endpoints will utilize the strongest encryption algorithm which is available on both sides. SCA does NOT collect any telemetry data, nor does it connect to endpoints other than MS Azure Cloud.

### App Data in Rest <a href="#scatechnicaloverview-appdatainrest" id="scatechnicaloverview-appdatainrest"></a>

SCA stores any data in an encrypted SQLite database using an AES-256 Cipher. The cryptography key is randomly generated at the very first start of the App using RNGCryptoServiceProvider from Microsoft. The Key is then stored securely in the local iOS Key Chain of the device.  The SCA App Container itself is secured by MS Intune App Protection.  That way no other App nor the OS itself can see or alter the stored data.

### Microsoft Intune <a href="#scatechnicaloverview-microsoftintune" id="scatechnicaloverview-microsoftintune"></a>

In addition to the security features built into the app, SCA also integrates the Microsoft Intune SDK. (<https://learn.microsoft.com/en-us/mem/intune/developer/app-sdk>). The Intune SDK allows control of the app's security features via Microsoft App Protection Policies. <https://learn.microsoft.com/de-de/mem/intune/apps/app-protection-policy>\
This includes the following function, among others:

* Securing access via app PIN, or biometric factors
* Enforce app data encryption
* Data flow control
  * Control of OpenIn function - definition with which apps OpenIn is allowed
  * Control of Copy/Paste - definition with which apps Copy/Paste is allowed
  * Control of links - definition in which apps calls, mails, chats can be started and which web browser is used
  * Control if printing of data is allowed
* Selective wipe of app data, e.g. in case of loss of the device

The configuration of the Microsoft app protection policies is done by the customer. The customer decides which of these functions are enabled/disabled. We only make recommendations in this regard.

### Authentication <a href="#scatechnicaloverview-authentication" id="scatechnicaloverview-authentication"></a>

Authentication is based on Microsoft Authentication Library (<https://learn.microsoft.com/en-us/azure/active-directory/develop/msal-overview>) This is used to log in to the app against the Microsoft Azure AD Enterprise app “Secure Contacts App” using a business, school or university account. (<https://learn.microsoft.com/en-us/azure/active-directory/manage-apps/what-is-application-management>) The App ID of “Secure Contacts App” is 20429334-d869-476e-8a65-ea300a327985.

The user IDs used for login are always located in the customer's tenant.

The configuration of Azure AD user account security (password, login factors, etc.) is done by the customer. The customer decides which account security configuration is to be made.

Microsoft Conditional Access is used to control which devices can use the app. (<https://learn.microsoft.com/de-de/azure/active-directory/conditional-access/overview>) This makes it possible to decide, for example, that the app may only be used on company-owned devices, devices managed via MDM, or private devices.

The configuration of the Microsoft Conditional Access Policies is done by the customer. The customer decides which accesses are allowed or not allowed. We only make recommendations in this regard.

## Data model <a href="#scatechnicaloverview-datamodel" id="scatechnicaloverview-datamodel"></a>

The SCA’s data model consists of a list of contact objects stored in a SQLite Cipher database.&#x20;

### What data is processed <a href="#scatechnicaloverview-whatdataisprocessed" id="scatechnicaloverview-whatdataisprocessed"></a>

SCA processes the following contact information:

1. First and last name
2. Company name
3. Position / job title
4. All email addresses saved
5. All telephone numbers saved
6. Profile photos
7. Contact GUID
8. Data source Name / ID / Priority
9. Hash id

### How data is processed by the app <a href="#scatechnicaloverview-howdataisprocessedbytheapp" id="scatechnicaloverview-howdataisprocessedbytheapp"></a>

When the app is launched for the first time or the user performs the pull-to-update gesture, the resync process is started. During that resync process, SCA queries all configured data sources for which the user has been authorized. Then it analyzes each received contact, removes duplicates, combines contacts from different data sources if possible, normalizes and verifies each phone number against the international standard (ITU-T E. 164). After that, the contact data is stored encrypted in the local SQLite Cipher database. Next time the App restarts, it will load the contact data from the database.

## Incoming caller identification <a href="#scatechnicaloverview-incomingcalleridentification" id="scatechnicaloverview-incomingcalleridentification"></a>

The SCA uses Apple's iOS CallKit Blocking & Identification feature. The phone numbers to be identified or blocked are loaded by the SCA’s Call Directory extension before an incoming call and stored by the operating system hidden from all other apps on the phone. When the phone receives an incoming call, the system first consults the user's local contacts to find a matching phone number. If no match is found, the system then consults SCA’s Call Directory extension to find a matching entry to identify the phone number.

## MS Teams Status display <a href="#scatechnicaloverview-msteamsstatusdisplay" id="scatechnicaloverview-msteamsstatusdisplay"></a>

If configured and licensed, the SCA periodically polls the MS Teams Status via Graph API. For this purpose, it sends the GUID of each contact originating from the data source Azure Active Directory \[AAD] to the Graph API and then receives the corresponding status information. This information is then inserted into the current view of the application. Depending on the current view, the query interval is between 20 to 60 seconds. When the app is pushed to the background, it stops polling the MS Teams Status.

## Requirements <a href="#scatechnicaloverview-requirements" id="scatechnicaloverview-requirements"></a>

**Microsoft Tenant**

* Microsoft 365 (worlwide) Tenant
* Licenses
  * Azure Active Directory Premium P1 (or higher)
  * Exchange Online P1 (or higher)
  * Microsoft Intune

**Devices**

* iPhone with iOS 15 or newer
* iPad with iPadOS 15 or newer
* Android-devices with Android 12 or newer

## Deployment Scenarios <a href="#scatechnicaloverview-deploymentscenarios" id="scatechnicaloverview-deploymentscenarios"></a>

* For private use of the service smartphone BYOD
* For use Corporate Owned, Private enabled Devices (COPE)


# Data Protection & GDPR Compliance

Secure Contacts App (SCA) is a mobile-only solution for iOS and Android that enables organizations to manage corporate contact data securely. Data is retrieved directly from the customer’s Azure tenant and is protected according to Intune or MDM/MAM policies.

Provectus provides the application only and does not access, store, or process personal data. The customer organization remains the data controller, while Microsoft acts as the data processor for cloud-based synchronization. No Data Processing Agreement (DPA) with Provectus is required under Article 28 GDPR.

All personal data is processed locally on the device or through Microsoft services under the customer’s agreements, ensuring GDPR compliance and corporate data protection.

### Data Processing

* **Local processing (on device)**
  * Contact data is stored and cached only on the end user’s mobile device.
  * Data is encrypted at rest using the device’s native security mechanisms (iOS/Android).
  * When the app is uninstalled, stored data is removed.
* **Cloud processing (via Microsoft services)**
  * Synchronization occurs through services such as Microsoft Graph API.
  * All communication is encrypted in transit (TLS).
  * Data residency, compliance, and security are governed by Microsoft’s contractual commitments with the customer organization.

### Roles and Responsibilities

* **Provectus (App Provider)**
  * Does not access, store, or process contact data.
  * Is neither a controller nor a processor under GDPR definitions.
* **Customer Organization**
  * Acts as the data controller.
  * Responsible for configuring Intune policies or other device/app protection settings, governing access, and handling data subject requests (DSRs).

### Typical Scenarios

<table><thead><tr><th width="223.71435546875">Scenario</th><th>Handling</th></tr></thead><tbody><tr><td>Lost or stolen device</td><td>Contact data remains protected through device encryption and can be wiped remotely via Intune or MDM.</td></tr><tr><td>Policy change</td><td>SCA applies updates at the next sync or upon re-login/re-enrollment.</td></tr><tr><td>Offline use</td><td>Contacts remain available in the local cache until the next synchronization.</td></tr><tr><td>Data subject request</td><td>The customer organization responds directly, as Provectus has no access to personal data.</td></tr></tbody></table>

### Key Takeaways

* SCA ensures that all personal data remains under the control of the customer organization.
* Data is processed only locally on the device or via Microsoft services governed by the customer’s agreements with Microsoft.
* Provectus does not act as a controller or processor under GDPR.

### Additional Resources

* [Microsoft Compliance Center](https://www.microsoft.com/en-us/trust-center)
* [Intune App Protection documentation](https://learn.microsoft.com/en-us/intune/intune-service/apps/app-protection-policy)
* [GDPR overview (EU Commission)](https://commission.europa.eu/law/law-topic/data-protection_en)

### Final Note

Under the GDPR, a Data Processing Agreement (DPA) pursuant to Article 28 is required only where a processor handles personal data on behalf of a controller. In the case of the Secure Contacts App (SCA):

* **Customer organization** acts as the data controller.
* **Microsoft** acts as the data processor for cloud-based synchronization services (e.g., Microsoft Graph), governed by the customer’s existing agreements with Microsoft.
* **Provectus** provides only the application software and is contractually and technically excluded from accessing, storing, processing, or transmitting personal data.

Accordingly, Provectus is neither a controller nor a processor within the meaning of Article 4 GDPR, and no Data Processing Agreement with Provectus under Article 28 GDPR is required.


# Editions

Overview: Standard vs. Enterprise Editions of Secure Contacts App (SCA)

### Standard Edition

* **GDPR-compliant** handling of business contacts
* Integration with:
  * **Exchange Online** (EXO) - Personal Contacts
  * **Azure Active Directory -** Company Address Book
  * **Organizational contacts** - GAL
* **Central configuration** via Microsoft Intune or other MDM-System
* **Telephony and messenger integration** with:
  * Telephony, SMS, iMessage
  * Microsoft Teams
  * Microsoft Outlook
* **Optional integrations**:
  * WhatsApp
  * Signal
  * Telegram
  * WebEx

### Enterprise Edition

Includes **all features of the Standard Edition**, plus:

* **Integration of additional data sources**:
  * Shared Mailbox Contacts (EXO)
  * Microsoft Dynamics 365 - Contacts stored in Microsoft Dynamics 365
  * Microsoft Dataverse - Contacts stored by apps built on Microsoft Dataverse
  * Azure Blob Storage - Contacts exported from any app (incl. on-premises) via CSV/JSON
* **Contact enhancements**:
  * Display Microsoft Teams presence/status
  * Display Out-of-Office messages
  * Show organizational chart (reporting relationships)
  * Address fields with direct link to Maps app
* **Advanced functionality**:
  * Create, edit, and delete personal contacts within SCA
  * Safe contact export/sharing
  * Vacation Mode
  * Anonymized calling
* **Customization options**:
  * App CI (corporate identity/branding)
  * Additional messenger/telephony apps available on request
* **Extended platform support**:
  * Secure iOS / Siri / CarPlay integration via CPE (Contact Provider Extension)


# Update SCA 2.0 to 3.0

## After the Release of SCA 3.0

With the public release of [**Secure Contacts App (SCA) 3.0**](/sca-3.0-public-beta/whats-new-in-sca-3.0), here’s what administrators and end users need to know.

### Updates & Compatibility

* **Automatic Update**: Devices running SCA 2.0 are upgraded to 3.0 through the App Store/Google Play. No manual uninstall is required.
* **Seamless Transition**: After the update, users only need to **sign in again**. A full re-enrollment is **not required**.
* **Contacts & Settings**: Contacts and configurations remain unaffected during the update. Favorites need to be reconfigured.
* **Configuration Compatibility**: All settings from SCA 2.0 continue to work in 3.0, **including the license key.** [New options are available](/sca-3.0-public-beta/app-config-policy-name-values-for-sca-3.0), and some new features require updated configuration.
* **Managed Apps**: On iOS and Android, auto-updates apply as with any managed app, though timing may depend on MDM/MAM policies.

### New Features

* [Most new capabilities in 3.0](/sca-3.0-public-beta/whats-new-in-sca-3.0) are **opt-in** and must be explicitly enabled by administrators via App Configuration.
* [**Personal Outlook Contacts**](https://docs.secure-contacts.com/introduction/pages/6SFaCpH5zzgdT7Q8fct1#create-and-edit-personal-outlook-contacts-in-sca-3.0) **(special case)**: To allow users to create, edit, and delete personal Outlook contacts directly in SCA, admins **must grant the** [`Contacts.ReadWrite`](https://docs.secure-contacts.com/introduction/pages/6SFaCpH5zzgdT7Q8fct1#create-and-edit-personal-outlook-contacts-in-sca-3.0) **permission** in the Secure Contacts App - Azure AD enterprise app. ⚠️

{% hint style="success" %}
If you do not want users to edit their own personal Outlook contacts in SCA, disable the feature by setting:\
`APCeditor_Enabled = false`
{% endhint %}

For a complete overview of all new features and improvements, see [What’s New in SCA 3.0](/sca-3.0-public-beta/whats-new-in-sca-3.0).

### What This Means

**For Administrators**

* Verify that the SCA enterprise app is registered and consented.
* Review App Configuration and enable new features as needed.
* Grant `Contacts.ReadWrite` if Outlook contact editing should be allowed.
* Check MDM/MAM policies to ensure app updates flow correctly.

**For End Users**

* SCA will update automatically to 3.0 when store updates are allowed.
* Existing settings remain in place, favorites need to be reconfigured.
* New features become available only if enabled by your administrator.


# Requirements

For the full range of functions, an activation by Provectus Software GmbH is required.

The app only works in demo-mode, without a valid license provided.

To use the Secure Contacts app Microsoft Azure tennant must be present and activated with following functions:

* Azure Active Directory Premium P1 (or higher)
* Exchange Online P1 (or higher)
* Microsoft Intune (M365 E3 or M365 E5)
* Dataverse

In order to use the Microsoft Teams integration, the Microsoft Teams function must be activated.

### Testgroup <a href="#testgroup" id="testgroup"></a>

In Azure Active Directory a Security Group is required and all test-users must be member of this group for this guide.

### Requirements for all Implementations of SCA in this guide: <a href="#requirements-for-implementation-of-sca-in-this-guide" id="requirements-for-implementation-of-sca-in-this-guide"></a>

1. M365 E3 or M365 E5 License for admin and test-users
2. Administrative Azure account with sufficient permissions

{% hint style="info" %}

* **AAD-role for Enterprise App Registration:**

Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator

* **AAD-role for Endpoint Manager implementation:**

Global Administrator, Intune Service Administrator

* **AAD-role for Conditional Access:**

Global Administrator, Conditional Access Administrator
{% endhint %}

&#x20;&#x20;

Additional requirements are necessary depending on your Endpoint Manager Environment.

* Microsoft Exchange Online mailbox must be activated for the Test-User. (optional)
* Microsoft Authenticator must be configured for your test-user on the Test-Device.
* The Test-Device (iOS or Android) must be “freshly” enrolled in Endpoint Manager after implementing all policies in this guide, in case you want to test SCA for your devices.
* Apple VPP-Connector connected to Intune, in case you want to automatically push our iOS app via Intune.
* Managed Google Play connected to Intune, in case you want to automatically push our Android app via Intune.

### Guides:

<table data-view="cards"><thead><tr><th data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/LM4TfAnghg8UkjKL0Sts">/pages/LM4TfAnghg8UkjKL0Sts</a></td></tr><tr><td><a href="/pages/IHrYQ7jLEuGP0nexnYWM">/pages/IHrYQ7jLEuGP0nexnYWM</a></td></tr></tbody></table>

<table data-view="cards"><thead><tr><th data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/EHjIfMZECnJBem1Ua4UT">/pages/EHjIfMZECnJBem1Ua4UT</a></td></tr><tr><td><a href="/pages/Xsna2sRNTkamdhteA8c7">/pages/Xsna2sRNTkamdhteA8c7</a></td></tr></tbody></table>


# iOS (MAM) - Steps to activate SCA in your Entra Tenant

This guide shows you all required steps to onboard SCA in your environment.\
This configuration uses SCA with [Mobile Application Management (MAM)](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe) within Microsoft Intune.\
\
SCA can be downloaded from the App Store directly and installed on any iOS/iPadOS device.

## Preconditions <a href="#id-5stepstoactivatescainyourazuretenant-preconditions" id="id-5stepstoactivatescainyourazuretenant-preconditions"></a>

For this Quick Guide, the AAD-Role “Global Administrator” or a comparable Administrator role in Microsoft Intune is required, depending on your RBAC-Concept.

You need an Entra-User with a proper license assigned. The test-device for SCA should have the latest OS-version and Microsoft Authenticator installed.

You need additionally an Entra-Security Group with your test user as Member.

<table data-view="cards"><thead><tr><th></th><th></th><th data-type="content-ref"></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/FSMgDhsMghWcV1YVS0zU">Step 1 -MAM- Register Enterprise App</a></td><td>Register Enterprise App with your tenant-ID from our website.</td><td></td><td><a href="/pages/FSMgDhsMghWcV1YVS0zU">/pages/FSMgDhsMghWcV1YVS0zU</a></td></tr><tr><td><a href="/pages/zzIPpXJUUmsJSXbHlXXY">Step 2 -MAM- Add App Protection Policy</a></td><td>Create an App Protection Policy or add SCA to existing policy.</td><td></td><td><a href="/pages/zzIPpXJUUmsJSXbHlXXY">/pages/zzIPpXJUUmsJSXbHlXXY</a></td></tr><tr><td><a href="/pages/WF02kzY07bxb3uaEOin5">Step 3 -MAM- Add Conditional Access Policy</a></td><td>Create a Conditional Access Policy for SCA.</td><td></td><td><a href="/pages/WF02kzY07bxb3uaEOin5">/pages/WF02kzY07bxb3uaEOin5</a></td></tr><tr><td><a href="/pages/vjzpCLM61hCvMgMfO75K">Step 4 -MAM- Add App Configuration Policy</a></td><td>Create an App Configuration Policy for licensing.</td><td></td><td><a href="/pages/vjzpCLM61hCvMgMfO75K">/pages/vjzpCLM61hCvMgMfO75K</a></td></tr></tbody></table>

{% hint style="info" %}
In this Guide you can also find the Features of SCA and the difference \
in between [Standard vs. Enterprise Editon](https://docs.secure-contacts.com/introduction/editions).
{% endhint %}

{% hint style="success" %}
In case you have further questions see our [Frequently Asked Questions (FAQ)](/additional-information/frequently-asked-questions-faq).\
Your question is missing in the FAQ? Do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/)!
{% endhint %}


# Step 1 -iMAM- Register Enterprise App

{% hint style="info" %}

### Find tenant ID through the Azure portal <a href="#step1-registerenterpriseapp-findtenantidthroughtheazureportal" id="step1-registerenterpriseapp-findtenantidthroughtheazureportal"></a>

1. Sign in to the Azure portal.
2. Select Azure Active Directory.
3. Select Properties.
4. Scroll down to the tenant ID field. Your tenant ID will be in the box.

&#x20;\
For more information or alternative ways to find your tenant ID go to:\
[How to find your tenant ID | Microsoft Docs](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-how-to-find-tenant#find-tenant-id-through-the-azure-portal)
{% endhint %}

## Enterprise App Registration from the SCA homepage <a href="#step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage" id="step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage"></a>

\
The first step is to register SCA as Enterprise Application in your Entra tenant.\
You can register SCA from your homepage and must grant tenant-wide Admin Consent.

For more information, see [Enterprise App](/documentation/authentication/enterprise-application).\ <br>

1.1 - Go to the SCA homepage: [Secure Contacts App | provectus.de](https://secure-contacts.com/en/secure-contacts-app-azure-lp/)

1.2 - Scroll down till the "Admin-Consent" section

<figure><img src="/files/wsWrhqGBZoQD5dti6Sho" alt=""><figcaption></figcaption></figure>

1.3 - Enter your tenant ID on our website and click “Add”, this will open a new tab.

{% hint style="info" %}
This will automatically register SCA as Enterprise App in your Azure tenant.
{% endhint %}

1.4 - Log in with your Azure admin account&#x20;

{% hint style="info" %}
The following privileged AAD roles are necessary:

Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
{% endhint %}

1.5 - Confirm the Admin Consent for the SCA accordingly.

{% hint style="success" %}
Once SCA is registered as Enterprise App in your tenant, you need to configure\
App Protection Policies in Microsoft Intune.
{% endhint %}

{% hint style="danger" %}
The consent of the admin-page may stuck a in loop, you won't get a feedback from the admin consent page. \
Verify if the [enterprise app](https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null) "Secure Contacts App" is registered in Azure-AD.\
If you have any issues with the Registration of SCA in Azure. \
[contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}

{% content-ref url="/pages/HvqNqkZDTQoVlxagE2ry" %}
[Enterprise Application](/documentation/authentication/enterprise-application)
{% endcontent-ref %}

\ <br>


# Step 2 -iMAM- Add App Protection Policy

SCA supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy and App Configuration Policy settings.

{% hint style="success" %}
For more information about App Protection policies, you can check out Microsoft Docs.\
[App protection policies overview | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy)
{% endhint %}

\
2.1 - Create an App Protection Policy in Microsoft Intune.

2.2 - Add Secure Contacts to App Protection Policies

2.3 - Configure the setting for *Send org data to other apps at least* with the restrictive option e.g.\
*Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/FMo2f2luNiqa0BUOHent" alt=""><figcaption></figcaption></figure>

2.4 - Add for the setting “Select apps to exempt” the following Name/Value

| **Name**  | **Value**   |
| --------- | ----------- |
| `Default` | `app-prefs` |

{% hint style="info" %}
This option is needed for SCA to open phone-settings on your iOS/iPadOS device.
{% endhint %}

\
Proceed with the any other setting in this policy according to your best practice for App Protection Policies and assign the test group to this policy.

After you created the App Protection Policies and configured them in Endpoint Manager,\
in the next step, you need to enforce this policy with Conditional Access.

{% hint style="success" %}
If you have any questions regards the implementation of App Protection Policies, \
do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Step 3 -iMAM- Add Conditional Access Policy

The next step in this quick guide is to create a Conditional Access Policy in Microsoft Intune.\
It is possible to add SCA to your existing Conditional Access Policies for Office 365.<br>

{% hint style="success" %}
For more information about Conditional Access, you can check Microsoft Docs\
[What is Conditional Access in Azure Active Directory? | Microsoft Docs](https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview)
{% endhint %}

\
The following steps are required to implement Conditional Access for our App:

&#x20;3.1 - *Include* your SCA-Testgroup to **Users and Groups**<br>

<div align="left"><figure><img src="/files/9bzTpuci6UrN4D8gc1Jw" alt=""><figcaption></figcaption></figure></div>

*3.2 - Include the apps* **Office 365** and **Provectus - Secure Contacts** as **Cloud Apps**

<div align="left"><figure><img src="/files/jBHsdSl6JUEjflQUY0iI" alt=""><figcaption></figcaption></figure></div>

3.3 - Set **Require app protection policy** as *Grant* in the *Access controls* pane\
\
![](/files/kkwiSmKHNignIlLXBZoe)<br>

3.4 - Turn your Conditional Access Policy **ON**<br>

{% hint style="warning" %}
**Office 365** as Cloud App will affect other Apps on your Mobile device, like Outlook, OneDrive & Teams etc.

According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using its data source.<br>

Be aware: You cannot exclude these Cloud Apps or separate them in different Conditional Access policies!
{% endhint %}

Once *Conditional Access* enforces *App Protection Policies*, the next step is to create an \
*App Configuration Policy* in Endpoint Manager in order to add a license for SCA.<br>

{% hint style="success" %}
If you have any questions regarding Conditional Access and how this will affect your Azure environment, do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Step 4 -iMAM- Add App Configuration Policy

You can already use our App in Demo-Mode. \
You can only use our features and onboard our app in your environment, \
with a valid license assigned.

It is required to get a valid license through Provectus GmbH.

{% hint style="success" %}

#### [Contact us](https://secure-contacts.com/en/kontakt-beratung/) for a trial license key.

{% endhint %}

The license-key and features for SCA will be applied to the app through *App configuration policy* in Microsoft Intune.

{% hint style="info" %}
For more information about App configuration policies, you can check Microsoft Docs.

[App configuration policies for Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview)
{% endhint %}

4.1 - Create an App Configuration Policy *for Managed App* in Microsoft Intune<br>

4.2 - Add the following Name/Value pairs to your App Configuration Policy

<table><thead><tr><th width="255">Name</th><th width="641">Value</th></tr></thead><tbody><tr><td><code>SecContacts.Licenses</code></td><td><code>[{"name":"license name", "key":"license key"}]</code></td></tr></tbody></table>

{% hint style="info" %}
Depending on the Editon you choose, different features are available in SCA.

In [Standard vs. Enterprise Editon](/introduction/editions) you will find the differences between these licenses.
{% endhint %}

4.3 - Assign App Configuration Policy to your test group

{% hint style="success" %}
This was the last policy you need to configure in Microsoft Intune.\
In the next step you onboard the test device in your environment.
{% endhint %}


# iOS (MDM) - Steps to activate SCA in your Entra Tenant

This guide shows you all required steps to onboard SCA in your environment.\
This configuration uses SCA with [Mobile Device Management (MDM)](https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/deployment-guide-platform-ios-ipados) within Microsoft Intune.\
\
SCA can be downloaded from the App Store directly and installed on any iOS/iPadOS device.

## Preconditions <a href="#id-5stepstoactivatescainyourazuretenant-preconditions" id="id-5stepstoactivatescainyourazuretenant-preconditions"></a>

For this Quick Guide, the AAD-Role “Global Administrator” or a comparable Administrator role in Microsoft Intune is required, depending on your RBAC-Concept.

You need an Entra-User with a proper license assigned. The test-device for SCA should be deployed to Intune and have the latest OS-version and Microsoft Authenticator installed.

You need additionally an Entra-Security Group with your test user as Member.

<table data-view="cards"><thead><tr><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/Y6QPwD41aiXQv7t8iBO7">Step 1 -MDM- Register Enterprise App</a></td><td>Register Enterprise App with your tenant-ID from our website.</td><td><a href="/pages/fJXjz3cIucAnw5FArh2B">/pages/fJXjz3cIucAnw5FArh2B</a></td></tr><tr><td><a href="/pages/fJXjz3cIucAnw5FArh2B">Step 2 -MDM- Add App Protection Policy</a></td><td>Create an App Protection Policy or add SCA to existing policy.</td><td><a href="/pages/fJXjz3cIucAnw5FArh2B">/pages/fJXjz3cIucAnw5FArh2B</a></td></tr><tr><td><a href="/pages/x2oCz7i1eecViCW7zrbM">Step 3 -MDM- Add Conditional Access Policy</a></td><td>Create a Conditional Access Policy for SCA.</td><td><a href="/pages/x2oCz7i1eecViCW7zrbM">/pages/x2oCz7i1eecViCW7zrbM</a></td></tr><tr><td><a href="/pages/5kPFzglvX3fw7ryjHZsn">Step 4 -MDM- Add App Configuration Policy</a></td><td>Create an App Configuration Policy for licensing.</td><td><a href="/pages/5kPFzglvX3fw7ryjHZsn">/pages/5kPFzglvX3fw7ryjHZsn</a></td></tr></tbody></table>

{% hint style="info" %}
In this Guide you can also find the Features of SCA and the difference \
in between [Standard vs. Enterprise Editon](/introduction/editions).
{% endhint %}

{% hint style="success" %}
In case you have further questions see our [Frequently Asked Questions (FAQ)](/additional-information/frequently-asked-questions-faq).\
Your question is missing in the FAQ? Do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/)!
{% endhint %}


# Step 1 -iMDM- Register Enterprise App

{% hint style="info" %}

### Find tenant ID through the Azure portal <a href="#step1-registerenterpriseapp-findtenantidthroughtheazureportal" id="step1-registerenterpriseapp-findtenantidthroughtheazureportal"></a>

1. Sign in to the Azure portal.
2. Select Azure Active Directory.
3. Select Properties.
4. Scroll down to the tenant ID field. Your tenant ID will be in the box.

&#x20;\
For more information or alternative ways to find your tenant ID go to:\
[How to find your tenant ID | Microsoft Docs](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-how-to-find-tenant#find-tenant-id-through-the-azure-portal)
{% endhint %}

## Enterprise App Registration from the SCA homepage <a href="#step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage" id="step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage"></a>

\
The first step is to register SCA as Enterprise Application in your Azure tenant.\
You can register SCA from your homepage and must grant tenant-wide Admin Consent.

For more information, see [Enterprise App](/documentation/authentication/enterprise-application).\ <br>

1.1 - Go to the SCA homepage: [Secure Contacts App | provectus.de](https://secure-contacts.com/en/secure-contacts-app-azure-lp/)

1.2 - Scroll down till the "Admin-Consent" section

<figure><img src="/files/wsWrhqGBZoQD5dti6Sho" alt=""><figcaption></figcaption></figure>

1.3 - Enter your tenant ID on our website and click “Add”, this will open a new tab.

{% hint style="info" %}
This will automatically register SCA as Enterprise App in your Azure tenant.
{% endhint %}

1.4 - Log in with your Azure admin account&#x20;

{% hint style="info" %}
The following privileged AAD roles are necessary:

Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
{% endhint %}

1.5 - Confirm the Admin Consent for the SCA accordingly.

{% hint style="success" %}
Once SCA is registered as Enterprise App in your tenant, you need to configure\
App Protection Policies in Microsoft Intune.
{% endhint %}

{% hint style="danger" %}
The consent of the admin-page may stuck a in loop, you won't get a feedback from the admin consent page. Verify if the [enterprise app](https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null) "Secure Contacts App" is registered in Azure-AD. If you have any issues with the Registration of SCA in Azure. \
[contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}

{% content-ref url="/pages/HvqNqkZDTQoVlxagE2ry" %}
[Enterprise Application](/documentation/authentication/enterprise-application)
{% endcontent-ref %}

\ <br>


# Step 2 -iMDM- Add App Protection Policy

SCA supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy and App Configuration Policy settings.

{% hint style="success" %}
For more information about App Protection policies, you can check out Microsoft Docs.\
[App protection policies overview | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy)
{% endhint %}

\
2.1 - Create an App Protection Policy in Microsoft Intune.

2.2 - Add Secure Contacts to App Protection Policies

2.3 - Configure the setting for *Send org data to other apps at least* with the restrictive option e.g.\
*Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/FMo2f2luNiqa0BUOHent" alt=""><figcaption></figcaption></figure>

2.4 - Add for the setting “Select apps to exempt” the following Name/Value

| **Name**  | **Value**   |
| --------- | ----------- |
| `Default` | `app-prefs` |

{% hint style="info" %}
This option is needed for SCA to open phone-settings on your iOS/iPadOS device.
{% endhint %}

\
Proceed with the any other setting in this policy according to your best practice for App Protection Policies and assign the test group to this policy.

After you created the App Protection Policies and configured them in Endpoint Manager,\
in the next step, you need to enforce this policy with Conditional Access.

{% hint style="success" %}
If you have any questions regards the implementation of App Protection Policies, \
do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Step 3 -iMDM- Add Conditional Access Policy

The next step in this quick guide is to create a Conditional Access Policy in Microsoft Intune.\
It is possible to add SCA to your existing Conditional Access Policies for Office 365.<br>

{% hint style="success" %}
For more information about Conditional Access, you can check Microsoft Docs\
[What is Conditional Access in Azure Active Directory? | Microsoft Docs](https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview)
{% endhint %}

\
The following steps are required to implement Conditional Access for our App:

&#x20;3.1 - *Include* your SCA-Testgroup to **Users and Groups**<br>

<div align="left"><figure><img src="/files/9bzTpuci6UrN4D8gc1Jw" alt=""><figcaption></figcaption></figure></div>

*3.2 - Include the apps* **Office 365** and **Provectus - Secure Contacts** as **Cloud Apps**

<div align="left"><figure><img src="/files/jBHsdSl6JUEjflQUY0iI" alt=""><figcaption></figcaption></figure></div>

3.3 - Set **Require app protection policy** as *Grant* in the *Access controls* pane\
\
![](/files/kkwiSmKHNignIlLXBZoe)<br>

3.4 - Turn your Conditional Access Policy **ON**<br>

{% hint style="warning" %}
**Office 365** as Cloud App will affect other Apps on your Mobile device, like Outlook, OneDrive & Teams etc.

According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using its data source.<br>

Be aware: You cannot exclude these Cloud Apps or separate them in different Conditional Access policies!
{% endhint %}

Once *Conditional Access* enforces *App Protection Policies*, the next step is to create an \
*App Configuration Policy* in Endpoint Manager in order to add a license for SCA.<br>

{% hint style="success" %}
If you have any questions regarding Conditional Access and how this will affect your Azure environment, do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Step 4 -iMDM- Add App Configuration Policy

You can already use our App in Demo-Mode. \
You need to onboard our app in your environment, \
with a valid license assigned.

It is required to get a valid license through Provectus GmbH.

{% hint style="success" %}

#### [Contact us](https://secure-contacts.com/en/kontakt-beratung/) for a trial license key.

{% endhint %}

The license-key and features for SCA will be applied to the app through *App configuration policy* in Microsoft Intune.

{% hint style="info" %}
For more information about App configuration policies, you can check Microsoft Docs.

[App configuration policies for Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview)
{% endhint %}

4.1 - Create an App Configuration Policy *for Managed Devices* in Microsoft Intune<br>

4.2 - Add the following Name/Value pairs to your App Configuration Policy

<table><thead><tr><th>Configuration key</th><th>Value type</th><th>Configuration vale</th><th data-hidden>Value</th></tr></thead><tbody><tr><td><code>IntuneMAMUPN</code></td><td><code>String</code></td><td><code>{{userprincipalname}}</code></td><td><code>SecContacts</code></td></tr><tr><td><code>SecContacts.Licenses</code></td><td><code>String</code></td><td><code>[{"name":"license name", "key":"license key"}]</code></td><td><code>[{"name":"&#x3C;license name>", "key":"&#x3C;license key>"}]</code></td></tr></tbody></table>

{% hint style="info" %}
Depending on the Editon you choose, different features are available in SCA.

In [Standard vs. Enterprise Editon](/introduction/editions) you will find the differences between these licenses.
{% endhint %}

4.3 - Assign App Configuration Policy to your test group

{% hint style="success" %}
This was the last policy you need to configure in Microsoft Intune.\
In the next step you onboard the test device in your environment.
{% endhint %}


# Android (Android Enterprise) - Steps to activate SCA in your Entra Tenant

This guide shows you all required steps to onboard SCA in your environment.\
This configuration uses SCA with [Android Enterprise Workprofile](https://learn.microsoft.com/en-us/intune/intune-service/fundamentals/deployment-guide-platform-android) within Microsoft Intune.\
\
SCA can be downloaded from the Play Store directly and installed on any Android device.\
It is mandatory to deploy our App via Managed Google Play Store in Intune.

## Preconditions <a href="#id-5stepstoactivatescainyourazuretenant-preconditions" id="id-5stepstoactivatescainyourazuretenant-preconditions"></a>

For this Quick Guide, the AAD-Role “Global Administrator” or a comparable Administrator role in Microsoft Intune is required, depending on your RBAC-Concept.

You need an Entra-User with a proper license assigned. The test-device for SCA should have the latest OS-version and Microsoft Authenticator installed.

You need additionally an Entra-Security Group with your test user as Member.

You need a test-device with SCA deployed via Intune and Managed Google Play Store.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/O1xSN4LCr3uMspFBpmLg">Step 1 -AE- Register Enterprise App</a></td><td>Register Enterprise App with your tenant-ID from our website.</td><td></td><td><a href="/pages/O1xSN4LCr3uMspFBpmLg">/pages/O1xSN4LCr3uMspFBpmLg</a></td></tr><tr><td><a href="/pages/VNTKt4JaAtVqy3ojSEvA">Step 2 -AE- Add App Configuration Policy</a></td><td>Create an App Configuration Policy for licensing.</td><td></td><td><a href="/pages/VNTKt4JaAtVqy3ojSEvA">/pages/VNTKt4JaAtVqy3ojSEvA</a></td></tr></tbody></table>

{% hint style="info" %}
In this Guide you can also find the Features of SCA and the difference \
in between [Standard vs. Enterprise Editon](/introduction/editions).
{% endhint %}

{% hint style="success" %}
In case you have further questions see our [Frequently Asked Questions (FAQ)](/additional-information/frequently-asked-questions-faq).\
Your question is missing in the FAQ? Do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/)!
{% endhint %}


# Step 1 -AE- Register Enterprise App

{% hint style="info" %}

### Find tenant ID through the Azure portal <a href="#step1-registerenterpriseapp-findtenantidthroughtheazureportal" id="step1-registerenterpriseapp-findtenantidthroughtheazureportal"></a>

1. Sign in to the Entra portal.
2. Select Azure Active Directory.
3. Select Properties.
4. Scroll down to the tenant ID field. Your tenant ID will be in the box.

&#x20;\
For more information or alternative ways to find your tenant ID go to:\
[How to find your tenant ID | Microsoft Docs](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-how-to-find-tenant#find-tenant-id-through-the-azure-portal)
{% endhint %}

## Enterprise App Registration from the SCA homepage <a href="#step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage" id="step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage"></a>

\
The first step is to register SCA as Enterprise Application in your Azure tenant.\
You can register SCA from your homepage and must grant tenant-wide Admin Consent.

For more information, see [Enterprise App](/documentation/authentication/enterprise-application).\ <br>

1.1 - Go to the SCA homepage: [Secure Contacts App | provectus.de](https://secure-contacts.com/en/secure-contacts-app-azure-lp/)

1.2 - Scroll down till the "Admin-Consent" section

<figure><img src="/files/wsWrhqGBZoQD5dti6Sho" alt=""><figcaption></figcaption></figure>

1.3 - Enter your tenant ID on our website and click “Add”, this will open a new tab.

{% hint style="info" %}
This will automatically register SCA as Enterprise App in your Azure tenant.
{% endhint %}

1.4 - Log in with your Azure admin account&#x20;

{% hint style="info" %}
The following privileged AAD roles are necessary:

Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
{% endhint %}

1.5 - Confirm the Admin Consent for the SCA accordingly.

{% hint style="success" %}
Once SCA is registered as Enterprise App in your tenant, you need to configure Policies in Microsoft Intune.
{% endhint %}

{% hint style="danger" %}
The consent of the admin-page may stuck a in loop, you won't get a feedback from the admin consent page. Verify if the [enterprise app](https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null) "Secure Contacts App" is registered in Azure-AD. If you have any issues with the Registration of SCA in Azure. \
[contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}

\ <br>


# Step 2 -AE- Add App Configuration Policy

You can already use our App in Demo-Mode. \
You need to onboard our app in your environment, \
with a valid license assigned.

It is required to get a valid license through Provectus GmbH.

{% hint style="success" %}

#### [Contact us](https://secure-contacts.com/en/kontakt-beratung/) for a trial license key.

{% endhint %}

The license-key and features for SCA will be applied to the app through *App configuration policy* in Microsoft Intune.

{% hint style="info" %}
For more information about App configuration policies, you can check Microsoft Docs.

[App configuration policies for Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview)
{% endhint %}

{% hint style="warning" %}
For this quickstart guide, SCA has to be deployed via Managed Google Play Store as discribed [here](/documentation/deployment-sca/android-app-installation)
{% endhint %}

2.1 - Create an App Configuration Policy *for Managed Devices* in Microsoft Intune<br>

2.2 - Add the following Name/Value pairs to your App Configuration Policy

<table><thead><tr><th>Configuration key</th><th width="145">Value type</th><th>Configuration value</th><th data-hidden>Value</th></tr></thead><tbody><tr><td><code>SecContacts.Licenses</code></td><td><code>String</code></td><td><code>[{"name":"license name", "key":"license key"}]</code></td><td><code>[{"name":"&#x3C;license name>", "key":"&#x3C;license key>"}]</code></td></tr></tbody></table>

{% hint style="info" %}
A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](#app-configuration-policy)
{% endhint %}

2.3 - Assign App Configuration Policy to your test group

{% hint style="info" %}
Depending on the Editon you choose, different features are available in SCA.

In [Standard vs. Enterprise Editon](/introduction/editions) you will find the differences between these licenses.
{% endhint %}

{% hint style="success" %}
This was the last policy you need to configure in Microsoft Intune.\
In the next step you onboard the test device in your environment.
{% endhint %}


# Android (aMAM) - Steps to activate SCA in your Entra Tenant

This guide shows you all required steps to onboard SCA in your environment.\
This configuration uses SCA with [Mobile Application Management (MAM)](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe) within Microsoft Intune.\
\
SCA can be downloaded from the Play Store directly and installed on any Android device.

## Preconditions <a href="#id-5stepstoactivatescainyourazuretenant-preconditions" id="id-5stepstoactivatescainyourazuretenant-preconditions"></a>

For this Quick Guide, the AAD-Role “Global Administrator” or a comparable Administrator role in Microsoft Intune is required, depending on your RBAC-Concept.

You need an Entra-User with a proper license assigned. The test-device for SCA should have the latest OS-version and Microsoft Authenticator installed.

You need additionally an Entra-Security Group with your test user as Member.

You need a test-device with SCA deployed via Intune and Managed Google Play Store.

<table data-view="cards"><thead><tr><th></th><th></th><th></th><th data-hidden data-card-target data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/QEDcK6mSM6m52B940txQ">Step 1 -aMAM- Register Enterprise App</a></td><td><br>Register Enterprise App with your tenant-ID from our website.</td><td></td><td><a href="/pages/O1xSN4LCr3uMspFBpmLg">/pages/O1xSN4LCr3uMspFBpmLg</a></td></tr><tr><td><a href="/pages/1p6IyzNgdjZGbv6uG1sD">Step 2 -aMAM- Add App Configuration Policy</a></td><td><br>Create an App Configuration Policy for licensing.</td><td></td><td><a href="/pages/VNTKt4JaAtVqy3ojSEvA">/pages/VNTKt4JaAtVqy3ojSEvA</a></td></tr><tr><td><a href="/pages/dyLAwiIjV0GXH7NZ8dCg">Step 3 -aMAM- Add App Protection Policy</a><br><br>Create an App Protection Policy in Intune<br><br></td><td></td><td></td><td></td></tr><tr><td><a href="/pages/qMpVX2AXEZDizep2ceNK">Step 4 -aMAM- Add Conditional Access Policy</a></td><td></td><td>Create a Conditional Access Policy for SCA.</td><td></td></tr></tbody></table>

{% hint style="info" %}
In this Guide you can also find the Features of SCA and the difference \
in between [Standard vs. Enterprise Editon](/introduction/editions).
{% endhint %}

{% hint style="success" %}
In case you have further questions see our [Frequently Asked Questions (FAQ)](/additional-information/frequently-asked-questions-faq).\
Your question is missing in the FAQ? Do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/)!
{% endhint %}


# Step 1 -aMAM- Register Enterprise App

{% hint style="info" %}

### Find tenant ID through the Azure portal <a href="#step1-registerenterpriseapp-findtenantidthroughtheazureportal" id="step1-registerenterpriseapp-findtenantidthroughtheazureportal"></a>

1. Sign in to the Azure portal.
2. Select Azure Active Directory.
3. Select Properties.
4. Scroll down to the tenant ID field. Your tenant ID will be in the box.

&#x20;\
For more information or alternative ways to find your tenant ID go to:\
[How to find your tenant ID | Microsoft Docs](https://docs.microsoft.com/en-us/azure/active-directory/fundamentals/active-directory-how-to-find-tenant#find-tenant-id-through-the-azure-portal)
{% endhint %}

## Enterprise App Registration from the SCA homepage <a href="#step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage" id="step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage"></a>

\
The first step is to register SCA as Enterprise Application in your Azure tenant.\
You can register SCA from your homepage and must grant tenant-wide Admin Consent.

For more information, see [Enterprise App](/documentation/authentication/enterprise-application).\ <br>

1.1 - Go to the SCA homepage: [Secure Contacts App | provectus.de](https://secure-contacts.com/en/secure-contacts-app-azure-lp/)

1.2 - Scroll down till the "Admin-Consent" section

<figure><img src="/files/wsWrhqGBZoQD5dti6Sho" alt=""><figcaption></figcaption></figure>

1.3 - Enter your tenant ID on our website and click “Add”, this will open a new tab.

{% hint style="info" %}
This will automatically register SCA as Enterprise App in your Azure tenant.
{% endhint %}

1.4 - Log in with your Azure admin account&#x20;

{% hint style="info" %}
The following privileged AAD roles are necessary:

Global Administrator, Privileged Role Administrator, Cloud Application Administrator, or Application Administrator.
{% endhint %}

1.5 - Confirm the Admin Consent for the SCA accordingly.

{% hint style="success" %}
Once SCA is registered as Enterprise App in your tenant, you need to configure Policies in Microsoft Intune.
{% endhint %}

{% hint style="danger" %}
The consent of the admin-page may stuck a in loop, you won't get a feedback from the admin consent page. Verify if the [enterprise app](https://portal.azure.com/#view/Microsoft_AAD_IAM/StartboardApplicationsMenuBlade/~/AppAppsPreview/menuId~/null) "Secure Contacts App" is registered in Azure-AD. If you have any issues with the Registration of SCA in Azure. \
[contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}

\ <br>


# Step 2 -aMAM- Add App Configuration Policy

You can already use our App in Demo-Mode. \
You need to onboard our app in your environment, \
with a valid license assigned.

It is required to get a valid license through Provectus GmbH.

{% hint style="success" %}

#### [Contact us](https://secure-contacts.com/en/kontakt-beratung/) for a trial license key.

{% endhint %}

The license-key and features for SCA will be applied to the app through *App configuration policy* in Microsoft Intune.

{% hint style="info" %}
For more information about App configuration policies, you can check Microsoft Docs.

[App configuration policies for Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview)
{% endhint %}

{% hint style="warning" %}
For this quickstart guide, SCA has to be deployed via Managed Google Play Store as discribed [here](/documentation/deployment-sca/android-app-installation)
{% endhint %}

2.1 - Create an App Configuration Policy *for Managed Apps* in Microsoft Intune\
\
2.2 - Add **`de.provectus.securecontacts.droid`** as Custom App to your App Configuration Policy\
\
2.3 - Add the following Name/Value pairs as configuration for the app

<table><thead><tr><th>Configuration key</th><th width="145">Value type</th><th>Configuration value</th><th data-hidden>Value</th></tr></thead><tbody><tr><td><code>SecContacts.Licenses</code></td><td><code>String</code></td><td><code>[{"name":"license name", "key":"license key"}]</code></td><td><code>[{"name":"&#x3C;license name>", "key":"&#x3C;license key>"}]</code></td></tr></tbody></table>

{% hint style="info" %}
A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](/documentation/app-configuration-policy-name-values-for-sca)
{% endhint %}

2.4 - Assign App Configuration Policy to your test group

{% hint style="info" %}
Depending on the Editon you choose, different features are available in SCA.

In [Standard vs. Enterprise Editon](/introduction/editions) you will find the differences between these licenses.
{% endhint %}

{% hint style="success" %}
This was the last policy you need to configure in Microsoft Intune.\
In the next step you onboard the test device in your environment.
{% endhint %}


# Step 3 -aMAM- Add App Protection Policy

SCA supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy and App Configuration Policy settings.

{% hint style="success" %}
For more information about App Protection policies, you can check out Microsoft Docs.\
[App protection policies overview | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy)
{% endhint %}

\
2.1 - Create an App Protection Policy in Microsoft Intune.

2.2 - Add `de.provectus.securecontacts.droid` as Custom App to your App Protection Policies

2.3 - Configure the setting for *Send org data to other apps at least* with the restrictive option e.g.\
*Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/FMo2f2luNiqa0BUOHent" alt=""><figcaption></figcaption></figure>

2.4 - Add for the setting “Select apps to exempt” we recommend the following Name/Values for testing.

<table data-header-hidden><thead><tr><th width="286"></th><th></th></tr></thead><tbody><tr><td><strong>Name</strong></td><td><strong>Value</strong></td></tr><tr><td>phonecall</td><td><code>tel</code></td></tr><tr><td>sms</td><td><code>smsto</code></td></tr><tr><td>email</td><td><code>mailto</code></td></tr><tr><td>PermissionController</td><td><code>com.google.android.permissioncontroller</code></td></tr><tr><td>Optional:</td><td></td></tr><tr><td>CallSimulator</td><td><code>com.android.server.telecom</code></td></tr><tr><td>LocalContactsSync</td><td><code>com.google.android.dialer</code></td></tr></tbody></table>

{% hint style="danger" %}
App Protection Policy blocks all comunication. \
\
**SCA needs this mandatory settings to work:**\
\
phonecall - App requires this to open your phone-app\
sms - App requires this to open your message-app\
email - App requires this to open your mail-app\
PermissionController - App requires this to add permissions in Android\
\
**optional:**\
Call Simulator - Required for testing with Call Simulator\
LocalContactsSync - Required to sync contacts to work-profile\
Proceed with the any other setting in this policy according to your best practice for App Protection Policies and assign the test group to this policy.
{% endhint %}

After you created the App Protection Policies and configured them in Endpoint Manager,\
in the next step, you need to enforce this policy with Conditional Access.

{% hint style="success" %}
If you have any questions regards the implementation of App Protection Policies, \
do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Step 4 -aMAM- Add Conditional Access Policy

The next step in this quick guide is to create a Conditional Access Policy in Microsoft Intune.\
It is possible to add SCA to your existing Conditional Access Policies for Office 365.<br>

{% hint style="success" %}
For more information about Conditional Access, you can check Microsoft Docs\
[What is Conditional Access in Azure Active Directory? | Microsoft Docs](https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/overview)
{% endhint %}

\
The following steps are required to implement Conditional Access for our App:

&#x20;3.1 - *Include* your SCA-Testgroup to **Users and Groups**<br>

<div align="left"><figure><img src="/files/9bzTpuci6UrN4D8gc1Jw" alt=""><figcaption></figcaption></figure></div>

*3.2 - Include the apps* **Office 365** and **Provectus - Secure Contacts** as **Cloud Apps**

<div align="left"><figure><img src="/files/jBHsdSl6JUEjflQUY0iI" alt=""><figcaption></figcaption></figure></div>

3.3 - Set **Require app protection policy** as *Grant* in the *Access controls* pane\
\
![](/files/kkwiSmKHNignIlLXBZoe)<br>

3.4 - Turn your Conditional Access Policy **ON**<br>

{% hint style="warning" %}
**Office 365** as Cloud App will affect other Apps on your Mobile device, like Outlook, OneDrive & Teams etc.

According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using its data source.<br>

Be aware: You cannot exclude these Cloud Apps or separate them in different Conditional Access policies!
{% endhint %}

Once *Conditional Access* enforces *App Protection Policies*, the next step is to create an \
*App Configuration Policy* in Endpoint Manager in order to add a license for SCA.<br>

{% hint style="success" %}
If you have any questions regarding Conditional Access and how this will affect your Azure environment, do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/) for support.
{% endhint %}


# Additional Datasource for SCA

You can connect several types of DataSource to SCA, in order to provide contacts \
to your employees.

Depending on your environment all different kind of data can be imported \
to our app via your Entra tenant.<br>

<figure><img src="/files/9EiuHWIz6xuzshXDYOZN" alt=""><figcaption></figcaption></figure>

Supported types of DataSource:

1. [Azure Active Directory](/documentation/data-sources/aad-azure-active-directory) (By default this DataSource is `on`)
2. [Personal Outlook Contacts](/documentation/data-sources/apc-personal-outlook-contacts) (By default this DataSource is `on`)
3. [Global Address List](/documentation/data-sources/gal-global-address-list) (by default this DataSource is `on`)
4. [Dynamics 365](/documentation/data-sources/d365-dynamics-365) (Enterprise License required and by default this DataSource is `off`)
5. [Dataverse](/documentation/data-sources/dvrs-dataverse) (Enterprise License required and by default this DataSource is `off`)
6. [Shared Mailbox Contacts](/documentation/data-sources/smc-shared-mailbox-contacts) (Enterprise License required and by default this DataSource is `off`)
7. [Azure Blob Storage](/documentation/data-sources/abs-azure-blob-storage) (Enterprise License required and by default this DataSource is `off`)

{% hint style="info" %}
[Azure Blob Storage](/documentation/data-sources/abs-azure-blob-storage) is particularly suitable for contacts that are stored in onprem systems which supports an export of data, e.g. SAP and many more.
{% endhint %}

{% hint style="success" %}
In case you want to add a different CRM to SCA, we will find a solution for you!\
Do not hesitate to [contact us](https://secure-contacts.com/en/kontakt-beratung/).
{% endhint %}


# Best-Practice Guide for SCA

This guide provides administrators with recommended practices for configuring and managing the Secure Contacts App (SCA) to ensure optimal performance and user experience.

### 1. Data Sources Hint

SCA can integrate contacts from multiple sources, each with different capabilities. Administrators should consider which sources are relevant for their organization.

**Available data sources include:**

* **Azure Active Directory (AAD)** – Primary source for company-wide contacts.
* **Global Address List / OrgContacts (GAL)** – External contacts integrated into the directory.
* **Personal Outlook Contacts (APC)** – User-managed personal contacts.
* **Dynamics 365 (D365)** – Contacts stored in Dynamics 365 entities.
* **Dataverse (DVRS)** – Contacts from apps built on Microsoft Dataverse.
* **Azure Blob Storage (ABS)** – Contacts exported via CSV/JSON from any app.
* **Shared Mailbox Contacts (SMC)** – Contacts from Exchange Online shared mailboxes.

**Tip:** Administrators can **rename, hide, or customize** any data source using App Config parameters. For details, see the [Data Sources documentation](/documentation/data-sources).

### 2. Phone Number Formatting

Ensure all phone numbers are stored in **international format** to enable accurate caller identification and cross-region compatibility.

#### Optional Configuration Parameters

SCA provides several optional configuration parameters to manage phone number handling:

* **`PhoneNumberParseCountryCode_Option`** → Automatically parse and add missing country codes.
* **`PhoneNumberIgnoreInvalid_Option`** → Filter out invalid phone numbers.
* **`PhoneNumberExtensionInfix_Option`** → Customize the extension marker to match your organization’s format.

For more details, see the [Valid Phone Numbers documentation](/documentation/valid-phone-numbers-for-sca).

### 3. Group-Based Assignment (Data Sources & Features)

Do you need to assign different data sources and SCA features to user groups?

* Use **multiple App Configuration Policies** and assign them to different Azure AD user groups.
* Each policy can provide **different SCA features and different data sources**, tailored to the needs of that group.

**Example:**

* The **Sales group** can be assigned Dynamics 365 contacts.
* The **Support group** can be assigned Shared Mailbox Contacts.
* The **Management group** can be assigned all available data sources and advanced features.

**Hint:** Group-based assignments let you control both **which data sources** and **which features** are available to each group, ensuring users only see what’s relevant to their role.

### 4. Customization and Branding

For Enterprise Edition users, customize the app’s appearance to align with corporate branding:

* [**Whitelabel / Customize the CI**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-ci-customization) → Modify highlight/button colors and the flyout menu to match your corporate identity.

### 5. Service Menu Access

For security, [change the **default PIN**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.defaults#service-menu-access) for accessing the hidden Service Menu.


# How to - Troubleshoot SCA


# How to - Verify Configuation for SCA

How to Verify Config | Secure Contacts App (SCA)

Verifying the application configuration is a critical step after deployment or any policy change to ensure that the Secure Contacts App (SCA) is receiving and correctly interpreting the intended settings from the Unified Endpoint Management (UEM) solution (e.g., Microsoft Intune/Entra ID).

1. Using the Configuration Viewer

The most reliable method for verifying the applied configuration is through the hidden Service Menu in the SCA application. This menu includes a dedicated Configuration Viewer that displays the raw and parsed settings.

• Access Service Menu: Follow the procedure to enter the Service Menu.

• Navigate: In the Service Menu, locate and select the Configuration Viewer or App Config Status option.

• Review Policy: The viewer will display the active App Configuration Policy assigned to the user, including all key-value pairs.

Tip: Pay close attention to the Source of the configuration (e.g., "Intune Policy," "Default Settings"). This confirms that the UEM policy has successfully reached the device.

2. Key Configuration Parameters to Check

While the Configuration Viewer shows all parameters, certain keys are fundamental to SCA's operation and should be prioritized during verification.

Parameter Category Key Parameter Example Verification Check Data Sources DataSource\_AAD\_Enabled Must be set to True if Azure AD contacts are expected. Phone Formatting PhoneNumberParseCountryCode\_Option Verify the country code is correct (e.g., DE for Germany) to ensure proper caller ID matching. Features Feature\_CallerID\_Enabled Must be set to True for iOS Caller Identification to function. Branding App\_Title\_Custom Check if the custom title is correctly displayed, confirming the policy is applied.

Hint: If a parameter is missing or shows an unexpected value, it indicates an issue with the UEM policy assignment or the parameter key name. Ensure the key name in the UEM console exactly matches the required SCA parameter name (case-sensitive).

3. Verifying End-User Experience

The final verification step is to confirm that the applied configuration translates into the correct end-user experience.

• Contact Count: Check the number of contacts displayed in the SCA. Does it match the expected count based on the enabled data sources and the user's group membership?

• Feature Availability: If a feature like Shared Mailbox Contacts was enabled, verify that the option to view or search these contacts is now visible to the user.

• Functionality Test: Perform a simple test, such as calling the device from a synced contact number, to verify that the Caller Identification feature is working as configured.

Caution: UEM policy propagation can take time (up to several hours). If the configuration is not immediately visible in the Configuration Viewer, force a device check-in via the UEM client or wait for the next scheduled sync interval before concluding there is an error. If the issue persists, check the UEM console for any policy deployment errors.


# How to - Troubleshoot iOS Contact Provider Extention (CPE)


# SCA Contacts provided via CPE have white text on white background in iOS Contacts

**Reason**: In **iOS Contacts**, the **background color** of a **contact card** is determined by the most prominent color in the contact photo. Previously, SCA used a logo on a white background, which caused the card to adopt a white theme and made the text difficult to read.

**Solution:**\
To apply the fix:

1. Open **SCA**.
2. Navigate to **More > Settings > Share contacts with iOS**.
3. Disable **CPE** using the primary switch.
4. Re-enable **CPE** using the same switch.

This refreshes the contact photo and ensures proper contrast in iOS Contacts.


# How to - Enter Service Menu

Secure Contacts App (SCA) includes a hidden Service Menu designed for administrators and technical support. \
This menu provides deep insights into the current application state and the configurations pushed via Mobile Device Management (MDM).

### Accessing the Service Menu

The Service Menu is hidden from standard users to prevent accidental configuration changes. To access it, follow these steps:

1. Navigate to the **More** tab in the main navigation bar.
2. Perform a **long tap** on the **Settings button**. (press and hold for approx. 5 seconds)
3. A PIN prompt will appear. Enter the default administrative PIN: **`1234`**

{% hint style="info" %}
The Service Menu is primarily used for troubleshooting and verifying that MDM policies have been correctly applied to the device.
{% endhint %}

### Key Functions

Once unlocked, the Service Menu provides access to critical diagnostic data:

#### 1. Applied AppConfig

This view displays the raw AppConfig data currently received by the app.

* Purpose: Verify if the Key-Value pairs defined in your MDM (e.g., Microsoft Intune, Ivanti, Jamf) are reaching the device.
* Usage: Use this to troubleshoot why certain features (like "Allow Export") might not be behaving as expected despite being set in the MDM console.

#### 2. Inspect App Settings

This section allows you to browse all internal application settings currently in effect.

* Purpose: Check the active state of the app, including local database statuses and environment variables.
* Usage: Essential for identifying discrepancies between the intended policy and the actual local app behavior.

### Security and PIN Protection

To maintain a high level of security, the Service Menu is protected by a Personal Identification Number (PIN).

* Default PIN: `1234`
* Enterprise Deployments: In large-scale environments, the ability to access this menu or the PIN itself may be managed or restricted via specific AppConfig keys to prevent unauthorized tampering.

### Troubleshooting Access

* Menu does not appear: Ensure you are on the More tab. \
  The long tap must be performed directly on the text/area of the Settings button, not on other menu items.
* PIN rejected: If the default PIN `1234` does not work, check your organization's internal documentation, as the PIN might have been customized via an administrative policy.


# How to - Sync Contacts


# How to - Share a Contact

The Share Contact feature in the Secure Contacts App (SCA) lets users securely share individual contacts with colleagues. Administrators control its availability through App Configuration settings and ensure data security using Intune Application Protection, which restricts sharing to trusted apps only.

### Sharing an Contact

When users tap the **Share Contact** button, a dialog appears showing the contact’s details. Users can then select which properties to include before exporting the Contact, giving them control over what information is shared.

<div align="left"><figure><img src="/files/icL2GuzCoFdWlUdg4rmI" alt="" width="375"><figcaption></figcaption></figure></div>

### Enabling the Share Contact Option

To use the Share Contact feature in the SCA, the administrator must first enable it in the App Configuration policy. Once configured, users can share contacts through other apps, such as Outlook or Microsoft Teams, ensuring that the feature is only available in environments approved by administrators.

**`ShareContacts_Enabled`** : Enables or disables the Share Contact feature entirely.\
If set to `"true"`, the Share Contact option becomes available in SCA.\
**Default value**: `"false"`

{% hint style="info" %}
Instructions on how to apply SCA **App Configuration** settings are available [here](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.defaults)
{% endhint %}

{% hint style="danger" %}
By enabling the Share Contact option, contact information may leave the protected SCA environment. This can increase the risk of data exposure.
{% endhint %}

### Intune App Protection - managed apps only

By enabling Intune App Protection with the **Send org data to: Policy managed apps with Open-In/Share filtering** setting on iOS (or the **Send org data to: Policy managed apps** setting on Android), contact sharing is restricted exclusively to managed apps. This means that SCA contacts can only be shared with other Intune-protected or approved applications, such as Outlook, Teams, or other trusted corporate apps.

This ensures that sensitive corporate contact data cannot be transferred to personal or unmanaged apps, even on devices that are not fully enrolled in device management. By combining App Protection policies with share restrictions, organizations can maintain control over corporate information while still enabling secure collaboration within approved applications.

<div align="left"><figure><img src="/files/6WksiDsw6swzmEwtgjHe" alt="" width="375"><figcaption></figcaption></figure></div>

{% hint style="info" %}
Some apps can be exempted to allow sharing corporate data with critical or third-party apps that aren’t Intune-managed. Only exempt trusted apps, as doing so reduces data protection.
{% endhint %}

{% hint style="success" %}
The Share Contact feature is only available with an **SCA Enterprise license**.
{% endhint %}


# How to - Create and Edit personal outlook contacts in SCA

With Secure Contacts App, users can create, edit, and delete their personal Outlook contacts directly in the app.

To enable this feature, an administrator must grant consent for the newly added permission **`Contacts.ReadWrite`** to the [SCA Enterprise App](/documentation/authentication/enterprise-application). ⚠️

{% hint style="success" %}
If the [**SCA Enterprise App**](/documentation/authentication/enterprise-application) is being registered for the first time, no further action is required - all current permissions, including Contacts.ReadWrite, will be included automatically.
{% endhint %}

{% hint style="warning" %}
**Note:** This action is only required if the [**SCA Enterprise App**](/documentation/authentication/enterprise-application) has already been registered before September 2025 and used in your Azure tenant.<br>
{% endhint %}

1\) Go to <https://entra.microsoft.com> and sign in with a **Global Administrator** or **Privileged Role Administrator** account. \
2\) In the left menu, select **Enterprise Applications**, then find and select **Secure Contacts App**. \
3\) Open **Permissions**, click **Refresh**, and then click on **Grant admin consent for …**. \
4\) Wait a few seconds, then verify that the permission with the claim values **`Contacts.ReadWrite`** appears in the list and is marked as granted. \
5\) Done.


# How to - Troubleshoot Conditional Access with SCA

Here you can find tips and known issues we solved in the past on customer side.<br>

#### **Troubleshooting - Conditional Access “Cloud Apps”**

Unable to exclude SCA in Conditional Access during your Tests

{% hint style="danger" %}
Be aware - It is not possible to exclude SCA and Office as Cloud Apps for your Conditional Access Policies.\
You will need to use another “exclude” in Conditional Access, if it is required.
{% endhint %}


# How to - Troubleshoot Enterprise App Registration

#### Troubleshooting - Enterprise App Registration <a href="#troubleshooting-enterprise-app-registration" id="troubleshooting-enterprise-app-registration"></a>

Re-Register Enterprise Permissions due Permission-Changes or in case you cannot grant admin consent due missing permissions.\
\
You can grant admin consent in your azure-tenant manually in the Enterpise applications for Secure Contacts&#x20;

&#x20;

<figure><img src="/files/hDNjiQR1S3ygSnGKIQNP" alt=""><figcaption></figcaption></figure>

#### Troubleshooting - URL-Registration Enterprise App <a href="#troubleshooting-url-registration-enterprise-app" id="troubleshooting-url-registration-enterprise-app"></a>

In Case you cannot register our Enterprise App in your tennant, please make sure you set the region for your Dataverse.

{% hint style="info" %}
You can check if you set a region for your tennant, if you go to [![](https://make.powerautomate.com/favicon.ico)Microsoft Power Automate](https://make.powerautomate.com/) for example.
{% endhint %}


# How to - Manage Contact Visibiltity for Contact Provider Extention with MDM

##

This article only applies if you have configured App Configuration for iOS and CPE activated.

## **Controlling Contact Visibility via MDM**

When SCA is deployed on **MDM-managed devices** (via e.g., Intune or Jamf), and SCA is installed as a **managed app**, iOS treats the contacts from its Contact Provider Extension (CPE) as *managed*. This allows administrators to restrict access to CPE contacts from unmanaged apps.

**User Experience**

* Users will still see **CPE contacts** in the native iOS Contacts and Phone apps, including when using **CarPlay**.
* These contacts behave like standard contacts but remain protected from unmanaged third-party apps.

**Administrative Control**

* Administrators can block **unmanaged apps** (such as WhatsApp, Messenger, or social media apps) from accessing CPE contacts, reducing the risk of data leakage.
* This control applies **only to MDM-enrolled devices** with SCA deployed as a managed app.
* **It does not apply when using Intune App Protection Policies (MAM) alone**

### **Configuring Contact Restrictions on MDM-Managed Devices**

&#x20;To successfully block unmanaged apps from accessing SCA contacts, you must configure these as **Device Restriction policies** on MDM-enrolled devices. First, establish the **Global Data Boundary**, then configure the specific **Contact Restrictions**.

&#x20;**Step 1: The “Master Switch” – Global Data Boundary**

Establish the boundary between managed apps (SCA) and unmanaged apps (personal) on the device.

* **Purpose:** Enables the global *Managed Open In* restriction. On many MDMs (like Intune), specific contact settings are ignored or disabled unless this boundary is active.
* **Apple MDM Key:** `allowOpenFromManagedToUnmanaged`
  * **Value:** `false` (Do not allow)
* **Intune Setting:** **Block viewing corporate documents in unmanaged apps**
  * **Value:** Yes

**Step 2: The “Contacts Switch” – Specific Read Restriction**

Once the global boundary is established, explicitly enforce the rule for reading contacts.

* **Purpose:** Prevents unmanaged apps (like WhatsApp) from accessing, syncing, or importing SCA contacts.
* **Apple MDM Key:** `allowUnmanagedToReadManagedContacts`
  * **Value:** `false` (Do not allow)
* **Intune Setting:** **Allow unmanaged apps to read from managed contacts accounts**
  * **Value:** Not configured

<div align="left"><figure><img src="/files/dd4UkoXBRyYmIVI51RrH" alt="" width="375"><figcaption></figcaption></figure></div>

{% hint style="success" %}
These settings apply only to **MDM-enrolled devices** with SCA deployed as a **managed app**, and affect only contacts provided via the **Contact Provider Extension (CPE)**.
{% endhint %}

## Mandatory Intune-App Protection settings for CPE&#x20;

If your organization applies **Microsoft Intune App Protection Policies (APP)** to the Secure Contacts App (SCA), certain settings **must** be enabled to ensure the Contact Provider Extension (CPE) works correctly.

These APP settings are required *only when an Intune App Protection Policy is enforced*, and they enable SCA to securely expose contact data to the native iOS environment:

• **Policy managed apps with Open-In/Share filtering** – Required to allow secure data sharing between managed apps and ensure contact data can be used outside the SCA container.

<div data-with-frame="true"><figure><img src="/files/EenjAl3HAvgacwem6EYM" alt=""><figcaption></figcaption></figure></div>

• **Sync app data with native apps** – Enables synchronization of managed app data with native iOS apps like Contacts and Phone, which is necessary for contact visibility and call functionality.

<div data-with-frame="true"><figure><img src="/files/Uc76PTqDqBn4J7P5jSAd" alt=""><figcaption></figcaption></figure></div>

{% hint style="warning" %}
If these App Protection Policy settings aren’t enabled, the CPE won’t be able to share contact data with iOS, which may prevent features such as native contact lookup, caller ID, CarPlay, and similar integrations from working properly.
{% endhint %}


# How to - 3rd Party Visibility for Contact Provider Extention with MDM

<figure><img src="/files/MHU3ZWnzaLa92L6uuqrH" alt=""><figcaption></figcaption></figure>


# iOS - Userguide & Onboarding

The following steps show you, how to onboard SCA on your device with MAM-WE Policies enabled.\
We recommend using an iPhone with the latest iOS version.

{% hint style="success" %}
Find Secure Contacts App in the App store, if you search for “Provectus Secure Contacts”
{% endhint %}

{% hint style="success" %}
Microsoft Authenticator needs to be installed on the test-device
{% endhint %}

{% hint style="info" %}
Authenticator enforces the app protection policy on the device.\
You need to login through Authenticator in SCA.
{% endhint %}

1\) Download Microsoft Authenticator and Secure Contacts App to your device\
![](/files/TdSpHkHljkeF2xyWwshR)

2\) Skip the "First Steps"-part\
![](/files/1Y9m2sVXddZisuZKLDRy)\
\
3\) Next step to select ***Login***\
![](/files/IUWjXZ5IW7vHue43jYkX)

5\) Authenticator-App opens\
\- Select your already logged on account or login with your Account\
![](/files/JKVU6jDwiq2dwPSAOMKX)

6\) App-Protection will apply and prompt will show up\
\- Select OK (App will close)\
![](/files/sXuZnGpDC0C4CLR01LAk)

7\) Open Secure Contacts App again\
![](/files/ryMxsRKqdx0OMGRrkmKS)

8\) Screen to activate Caller identification will show. \
\- Select Activate to switch to settings-menu\
![](/files/clOgoiGt30VGS48qNCSX)

9\) Activate SecContacts in the Call Blocking & Identifation - menu \
\- switch back to Secure Contacts App  in the left corner\
![](/files/KRCBJ20nvxEwED4XaRq8)

10\) SCA is fully onboarded now!\
![](/files/oLj3E9zs7PKxrQCWuoyE)


# Android - Userguide & Onboarding


# iOS - activate Caller Identification

<figure><img src="/files/mCxTOrDhgPPHxN9zxO5V" alt=""><figcaption></figcaption></figure>

\
Description how to activate Caller Identification on iOS manually:

1\) Go to Settings and Navigate to **Apps**\
2\) Search in Apps for **Phone**\
3\) In Phone menu, navigate to **Call Blocking & identification**\
4\) Activate **SecContacts**


# Android - activate Caller Identification


# iOS - Dual-Sim with SCA

**Third-party apps like the SCA can’t actively control which SIM card is used for outgoing calls.** \
\
SCA tells the operating system to dial a number. \
iOS then decides which SIM to use based on device settings\
—in this case it would be the default line for outgoing calls.\
\
Usually, the business SIM is set as the default.<br>

**The only way to influence this is:**

* When creating a private contact, manually set the preferred SIM.
* Or, during the first call to a new contact, choose the desired SIM (e.g. “Private”) in the pop-up.

The iOS typically remembers this choice and uses it for future calls to that contact.

**We recommend, the following:**

* The business SIM should be set as the default for outgoing calls in device settings.
* All private contacts should be saved with the private SIM assigned for outgoing calls.\ <br>

**How to set Default Voice Line:**

* Go to *Settings*
* Go to *Mobile Service*
* You can set your *Default Voice Line* to Business or Primary.<br>

Underneath, both SIM lines (Primary and Business) are visible with their numbers.\
This setting defines which SIM line will be used first by default when you dial a number.\ <br>

**How to assign Prefered Line for Contacts:**

* Open the contact you want to change Preferred line.
* Tap the area between the profile picture and the name to edit the line setting.
* You can set the ***Preferred Line*** to **Last Used**, or choose to always use **Business** or **Primary**.

<br>

<figure><img src="/files/IUBZ3Vc41CkZmur79QTj" alt=""><figcaption></figcaption></figure>


# Android - Dual-Sim with SCA

Third-party apps like the SCA can’t actively control which SIM card is used for outgoing calls. \
\
SCA tells the operating system to dial a number. \
\
Which Caller-App or SIM card will be used is part of Android \
and depends on the OS-Settings of the device.\ <br>

We recommend, the following:

* The **business SIM** should be set as the default for outgoing calls in device settings.
* All private contacts should be saved with the private SIM assigned for outgoing calls.

<br>


# iOS - activate Caller Identification

### Guide to activate Caller Identification on the device

<figure><img src="/files/Ho5xexIGzujKXLWEaHBc" alt=""><figcaption></figcaption></figure>

### Caller Identification, when a call enters on the device

<figure><img src="/files/VEXEvqYQiiBYY0EKn9b8" alt=""><figcaption></figcaption></figure>

### **SCA identifies callers on your device and is integrated with CarPlay.**&#x20;

Caller Identification does work in a car with CarPlay, once your phone is connected to it. \
Caller Identification maybe works in modern cars with Bluetooth-Connection.


# iOS - Userguide

The following steps show you, how to onboard SCA on your device.\
We recommend using an iPhone with the latest iOS version.

{% hint style="warning" %}
Microsoft Authenticator needs to be installed on the test-device
{% endhint %}

{% hint style="info" %}
Authenticator enforces the app protection policy on the device.\
You need to login through Authenticator in SCA.
{% endhint %}

5.1 - Download & open the app directly from the app store

![](/files/37OFYHc0ipaFdrco46mQ)

{% hint style="info" %}
Search in the App store for “Provectus Secure Contacts”
{% endhint %}

5.2 - Accept terms and conditions and ***Continue***<br>

<div align="left"><figure><img src="/files/sScH5Lw1qhXqmVfGvNA9" alt=""><figcaption></figcaption></figure></div>

5.3 - Next step to select ***Login***<br>

<div align="left"><figure><img src="/files/TXVARk89Mh2DenNVHYjL" alt=""><figcaption></figcaption></figure></div>

5.4 - Select ***Open*** - this will open Microsoft Authenticator<br>

<div align="left"><figure><img src="/files/3twtqL9ltfGLbv25hKFw" alt=""><figcaption></figcaption></figure></div>

5.5 - In the Authenticator-App, sign in with your Azure-Account and password

<div align="left"><figure><img src="/files/FUKTSSkLPGvZzPqsM9O1" alt=""><figcaption></figcaption></figure></div>

5.6 - You are now successfully logged on with your Azure-Account.<br>

\
5.7 - Select Register in order to activate App Protection Policy for SCA.

<div align="left"><figure><img src="/files/9EwKxXklibNaOUAz61dx" alt=""><figcaption></figcaption></figure></div>

5.8 - Your phone will switch several times in between Authenticator and SCA for login.<br>

<div align="left"><figure><img src="/files/k8d2MabaiGjXyJxRFmA1" alt=""><figcaption></figcaption></figure></div>

5.9 - When you see this message, click on OK.

<div align="left"><figure><img src="/files/U65OBIgA3btFOuijZPks" alt=""><figcaption></figcaption></figure></div>

\
5.10 - SCA will close - This indicates that App Protection Policy gets active

5.11 - Open the app again and choose “activate now”.

<div align="left"><figure><img src="/files/p1VHQYU59zSBHsa7u7L6" alt=""><figcaption></figcaption></figure></div>

5.12 - At this screen, select phone settings\
→ This will open phone in settings-menu on your device

<div align="left"><figure><img src="/files/DqQNKeZGgrKJ63IePDDg" alt=""><figcaption></figcaption></figure></div>

5.13 - Once you selected phone settings, the phone-settings page of your phone opens directly!

5.14 -  Select “Call Blocking & Identifying”

<div align="left"><figure><img src="/files/yyoJ7CQKui3bYqKU9hum" alt=""><figcaption></figcaption></figure></div>

{% hint style="info" %}
This setting can be found on your phone in the menu:\
***Settings → Phone → Call Blocking & Identification***
{% endhint %}

5.15 - Activate **SecContacts** in “Call Identification apps”

→ This setting is mandatory to activate and provides the Call-Identification for SCA.

<div align="left"><figure><img src="/files/OpxjOY5CoRi7k8vQlgWO" alt=""><figcaption></figcaption></figure></div>

5.16 - Now SCA is fully onboarded!

<figure><img src="/files/9X1univgdVNVphUX5eQk" alt=""><figcaption></figcaption></figure>


# iOS - App Manual

<figure><img src="/files/PQRDxI2SC7hTkmIXK7pM" alt=""><figcaption></figcaption></figure>

{% content-ref url="/pages/vbkuDsdUvyA7yj7gyuVT" %}
[Contacts page](/enduser-guide/app-manual/contacts-page)
{% endcontent-ref %}

{% content-ref url="/pages/DaX9wBf8HXyA4vr3lOes" %}
[Contact information](/enduser-guide/app-manual/contact-information)
{% endcontent-ref %}

{% content-ref url="/pages/HTUytPo0bjsDcKdyodbd" %}
[Contact settings menu](/enduser-guide/app-manual/contact-settings-menu)
{% endcontent-ref %}

{% content-ref url="/pages/m99dzgzuBoseiRgax07W" %}
[Side menu](/enduser-guide/app-manual/side-menu)
{% endcontent-ref %}

{% content-ref url="/pages/BgyhrGs9jrRQc7R6TPSy" %}
[Logviewer](/enduser-guide/app-manual/logviewer)
{% endcontent-ref %}

{% content-ref url="/pages/xVaLI0IaA80YasM3uOHq" %}
[Help menu](/enduser-guide/app-manual/help-menu)
{% endcontent-ref %}

{% content-ref url="/pages/2TBH8p2G7hHMI9QEyFYg" %}
[vCard](/enduser-guide/app-manual/vcard)
{% endcontent-ref %}


# Contacts page

<figure><img src="/files/6VTuHY9ARKojycRir2vU" alt=""><figcaption></figcaption></figure>

###


# Contacts Sync

<figure><img src="/files/AyBtSeJopIDhwJWsGTmz" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
SCA generates a reminder notification for the next re-sync after each successful re-sync and schedules it 30 days in the future.

The notification is an automatic “reminder” for the contacts resynchronization, which utilizies the local notification service. \
After you tip on the notification the app opens and syncs automatically contacts.
{% endhint %}


# Contact information

<figure><img src="/files/h7tlBILWAZWutpZAHtvP" alt=""><figcaption></figcaption></figure>


# Contact settings menu

<figure><img src="/files/2id6GZ1QZHypuuMVazFa" alt=""><figcaption></figcaption></figure>


# Side menu

<figure><img src="/files/vP8StvOWn6157qWuLPW9" alt=""><figcaption></figcaption></figure>


# Logviewer

<figure><img src="/files/POLnEHRslp7WaBxvWhCN" alt=""><figcaption></figcaption></figure>


# Help menu

<figure><img src="/files/ZDaCpQ7dINUsQRdsBSpo" alt=""><figcaption></figcaption></figure>


# vCard

<figure><img src="/files/c25AQwhkpC05af8MKTH6" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
SCA gets it's information from the AAD-UserObject.\
In Azure the Contact Information for your user needs to have information filled out.\
In Case there is no adress in the Userobject then the adress,\
&#x20;you configured in your tenant is the fallback.
{% endhint %}


# Android Enterprise - Userguide

The following steps show you, how to onboard SCA on your device.\
We recommend using an Android with the latest OS version.

{% hint style="success" %}
SCA needs to be deployed via Intune and present on your device as discribed [here](/documentation/deployment-sca/android-app-installation)
{% endhint %}

3.1 - Open "SecContacts" with workprofile on your Android test-device

![](/files/YE9QUAxdbrPGM5Vgpwjn)

3.2 - Accept terms and conditions and ***Continue***\
![](/files/qv4U1U0G1hhsi0dnFlB8)

3.3 - Next step to select ***Login***\
![](/files/XXENWoqCZCU5QnM2d1nY)

3.4 - Select your Account\
![](/files/5VTX4MPXOBeEnUsLPUwJ)<br>

3.10 - SCA will login to Contacts

3.12 - At this screen, select **activate now**

\
![](/files/gAAIPA87pRiUOS7dxk3j)

\
3.14 -  Select **ENABLE CALLER IDENTIFICATION**

![](/files/XBUxywkTEcH0vdG9S3qY)

3.14 -  Choose *SecContacts* and confirm with **Set as default**

![](/files/UR97hTxJSJSILsPLlWjI)

3.14 -  Choose **Allow** for this prompt

![](/files/BaZs6EHMhgtBVLqD9clM)

3.15 - This indicated that Caller Identification is <mark style="color:green;">enabled</mark>

![](/files/LjKUbTGFd5PjjK5aEEQC)

3.16 - Now SCA is fully onboarded!

<figure><img src="/files/eCbn95uBHNAdQp5cIbsw" alt=""><figcaption></figcaption></figure>


# iOS - Onboarding SCA

These Steps to onboard SCA on your Test device, once it is fully activated in your Azure Tenant.

<figure><img src="/files/tg7JKUIm06tbJJggO7nn" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/nZ00yVmrimkW9RJKjlIR" alt=""><figcaption></figcaption></figure>


# iOS - vCard sharing and editing


# Authentication

## Authentication in Secure Contacts App (SCA)

Secure Contacts App (SCA) utilizes **Microsoft Authentication Library (MSAL)** to securely authenticate users via **Azure Active Directory (AAD)**. This authentication framework ensures that only authorized users can access the app, safeguarding both personal and organizational contact data.

#### Enterprise Application in Your Tenant

SCA is **registered and consented as an enterprise application in your Azure AD tenant**. This configuration enables your organization to:

* Control which users have access to the app
* Manage permissions and access centrally
* Enforce organizational security and compliance policies

Once the application is consented, user authentication is handled through your tenant, ensuring secure and controlled access.

For detailed guidance on registering and consenting the enterprise application, refer to the [Enterprise Application documentation](/documentation/authentication/enterprise-application).

{% hint style="info" %}
SCA App ID: “Provectus - Secure Contacts” is 20429334-d869-476e-8a65-ea300a327985.
{% endhint %}

#### User Authentication

Authenticated users gain access to both personal and organizational contacts. MSAL facilitates secure communication between the app and Azure AD, providing a consistent login experience across platforms.

#### Security Enhancements

* **Conditional Access**: Enforces requirements such as compliant devices or multi-factor authentication for secure access.
* **App Protection Policies (MAM)**: Protects organizational data on both managed and BYOD devices.

#### Platform Consistency

SCA employs the same authentication flow for **iOS** and **Android**, ensuring uniform security and functionality across devices.

### Best Practices

* Ensure the [SCA enterprise application](/documentation/authentication/enterprise-application) is properly **registered and consented** in your tenant.
* Align [Conditional Access](/documentation/authentication/conditional-access) and App Protection Policies with your organization’s security requirements.
* Maintain consistent authentication configurations across all devices.
* Monitor authentication logs to detect and address potential issues promptly.

### Summary

Authentication in SCA combines the security of Azure AD, MSAL, and enterprise controls to protect access and data. Utilizing a **registered and consented enterprise application** ensures that your organization retains control over access, permissions, and compliance policies.

The following chapters will cover:

1. [How to import and consent the SCA enterprise application](/documentation/authentication/enterprise-application)
2. [How to configure Conditional Access policies](/documentation/authentication/conditional-access)


# Enterprise Application

### About Enterprise Application Registration

An **Enterprise Application** in Azure Active Directory (Azure AD) is an app registered in your organization’s directory.

The **Secure Contacts App (SCA)** needs to be registered as an Enterprise Application to:

* **Authenticate users securely** via Azure AD.
* **Access organizational data** such as contacts, groups, and directory information.
* **Enable centralized management and compliance** of app permissions within your tenant.

Registering SCA ensures that administrators can control access and grant only the permissions necessary for the app to operate safely in the organization.

### How to Register the SCA Enterprise Application

There are **two ways** to register SCA as an Enterprise Application:

#### 1. Via the SCA Homepage

1. Go to the [Secure Contacts App homepage](/quickstart-guide/ios-mam-steps-to-activate-sca-in-your-azure-tenant/step-1-register-enterprise-app#step1-registerenterpriseapp-enterpriseappregistrationfromthescahomepage).
2. In the **Admin-Consent** section, enter your **Azure AD tenant ID** and click **Add**.
3. Sign in with an account that has the **Global Administrator** role.
4. Grant **tenant-wide admin consent** to complete the registration.

#### 2. Manual Registration via URL

1. Construct the following URL, replacing `{tenant-id}` with your Azure AD tenant ID:

```
https://login.microsoftonline.com/{tenant-id}/adminconsent?client_id=20429334-d869-476e-8a65-ea300a327985
```

2. Open the URL in your browser.
3. Sign in with an account that has the **Global Administrator** role.
4. Review and grant **tenant-wide admin consent**.

{% hint style="success" %}
Example:\
[https://login.microsoftonline.com/**XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX**/adminconsent?client\_id=20429334-d869-476e-8a65-ea300a327985](https://login.microsoftonline.com/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX/adminconsent?client_id=20429334-d869-476e-8a65-ea300a327985)

XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX = Replace this with **your own** Tenant-ID\
**20429334-d869-476e-8a65-ea300a327985** = Enterprise-App-ID of **Secure Contacts App**
{% endhint %}

{% hint style="danger" %}
The admin consent page may sometimes get stuck in a loop and not provide feedback. \
To verify the registration:

* Check if the Enterprise Application **"Secure Contacts App"** appears in your Azure AD.
* If you encounter any issues with registering SCA in Azure AD, **contact our support team** for assistance
  {% endhint %}

<div align="left"><figure><img src="/files/SI2sJZe0n2uqIi6ZKoOK" alt="" width="218"><figcaption></figcaption></figure></div>

### Permissions for SCA Enterprise app <a href="#permissions-for-sca-enterprise-app" id="permissions-for-sca-enterprise-app"></a>

In this table you will find all mandatory permissions

<table><thead><tr><th>Graph-Value</th><th>Permission</th><th>Function in SCA</th><th data-hidden></th><th data-hidden></th><th data-hidden></th></tr></thead><tbody><tr><td>Contacts.Read</td><td>Read user contacts</td><td>Personal contacts (APC)</td><td>1</td><td> </td><td> </td></tr><tr><td>Contacts.Read.Shared</td><td>Read user and shared contacts</td><td>Shared Mailbox contacts (SMC)</td><td></td><td></td><td></td></tr><tr><td>Contacts.ReadWrite</td><td>Read and write user contact</td><td>Allows users to create, edit and delete their own personal contacts (APC)</td><td></td><td></td><td></td></tr><tr><td>Directory.Read.All</td><td>Read directory</td><td>List all AD user / contacts (AAD)</td><td>2</td><td> </td><td> </td></tr><tr><td>offline_access</td><td>Maintain access to data you have given it access to</td><td>Default-Requirement for Enterprise App</td><td>3</td><td> </td><td> </td></tr><tr><td>openid</td><td>Sign users in</td><td>Default-Requirement for Enterprise App</td><td>4</td><td> </td><td> </td></tr><tr><td><p>Presence.Read.All</p><p> </p></td><td>Read presence information of all users in your organization</td><td>Teams Status</td><td>6</td><td> </td><td> </td></tr><tr><td><p>User.Read.All</p><p> </p></td><td>View full user profile info</td><td>get UPN of all users and users profile photos (AAD)</td><td>9</td><td> </td><td> </td></tr></tbody></table>

| Dynamics CRM        | Permission                                       | Function in SCA                                             |
| ------------------- | ------------------------------------------------ | ----------------------------------------------------------- |
| user\_impersonation | Access Common Data Service as organization users | Contacts from Dynamic 365  (D365) and from Dataverse (DVRS) |

<table><thead><tr><th width="254.1424560546875">MS Mobile Application Management </th><th>Permission</th><th>Function in SCA</th></tr></thead><tbody><tr><td><a href="/pages/U6gwEH8ABEuTRilX2uE3">DeviceManagementManagedApps.ReadWrite</a></td><td>(Read and Write the User's App Management data / allow app <a href="/pages/U6gwEH8ABEuTRilX2uE3">access to the Intune app protection service</a>)</td><td>Allows SCA to interact with the Intune App Protection service: checking and applying protection policies, reporting compliance status, and enforcing conditional access.</td></tr></tbody></table>

{% hint style="success" %}
SCA permissions are all **Delegated** — the app acts only for the signed-in user.
{% endhint %}


# Understanding the DeviceManagementManagedApps.ReadWrite Permission

### Introduction

When reviewing application permissions in Microsoft Entra ID (Azure AD), administrators may notice that Secure Contacts App (SCA) requests the **`DeviceManagementManagedApps.ReadWrite`** permission. At first glance, this can look concerning — it resembles the powerful Microsoft Graph permission **`DeviceManagementApps.ReadWrite`**, which grants tenant-wide access to Intune app configurations.

However, these two permissions belong to **entirely different contexts** and have **very different scopes and security implications**. This article explains what each permission does, why SCA needs `DeviceManagementManagedApps.ReadWrite`, and how it remains safely limited to app-specific operations.

### Summary of the Two Permissions

| Permission                                | Context / Source               | Scope                                                                                                                                       | Typical Use Case                                                                                                   |
| ----------------------------------------- | ------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| **DeviceManagementApps.ReadWrite**        | Microsoft Graph API            | Broad, tenant-wide read/write access to all Intune app management data (e.g. add, modify, assign managed apps and app protection policies). | Used by backend or admin apps that manage Intune applications or policies at the organization level.               |
| **DeviceManagementManagedApps.ReadWrite** | Microsoft Intune SDK (MAM SDK) | Narrow, app-level access for Intune-enlightened (MAM-enabled) apps to manage **their own protected data** for the signed-in user.           | Used by mobile apps that integrate the Intune SDK to enforce Mobile Application Management (MAM) policies locally. |

### Key Difference

The **DeviceManagementApps.ReadWrite** permission belongs to **Microsoft Graph**, and is intended for **administrative control** of Intune apps across the tenant. It can create, delete, and assign apps and policies — making it a **high-privilege permission**.

By contrast, **DeviceManagementManagedApps.ReadWrite** belongs to the **Intune Mobile Application Management (MAM) SDK**.\
It allows the managed app itself to read or write its **own app management state** (e.g. applying data protection, responding to wipe requests, or syncing MAM policy data).\
It **does not** provide access to other apps, Intune configurations, or any tenant-wide data.

In short:

> 🔒 `DeviceManagementManagedApps.ReadWrite` = App-local, user-specific\
> ⚙️ `DeviceManagementApps.ReadWrite` = Tenant-wide, admin-level

### Why SCA Needs `DeviceManagementManagedApps.ReadWrite`

SCA integrates the **Microsoft Intune App SDK** to provide secure, policy-driven behavior when used in an Intune-managed environment.\
The SDK requires `DeviceManagementManagedApps.ReadWrite` to:

* Retrieve and apply the user’s MAM policy (e.g. data protection, cut/copy/paste settings)
* Synchronize compliance state and encryption data
* Respond to selective wipe or policy refresh commands from Intune

These operations are **restricted to the app itself** and **do not grant visibility or access to other devices, users, or configurations** in the organization.

### Security Note

* The `DeviceManagementManagedApps.ReadWrite` permission **does not** enable tenant-wide device or app management.
* It is enforced by the Intune MAM service and scoped to **the current user and the app instance**.
* Admins can safely approve this permission knowing it only enables secure MAM functionality, not global Intune control.

### References

* **Microsoft Graph permissions reference** – [DeviceManagementApps.ReadWrite.All](https://learn.microsoft.com/en-us/graph/permissions-reference)
* **Microsoft Intune App SDK documentation** – [Get started with the Microsoft Intune App SDK](https://learn.microsoft.com/en-us/intune/intune-service/developer/app-sdk-get-started#give-your-app-access-to-the-intune-mobile-app-management-service)
* **Intune Graph API overview** – [Use the Intune Graph APIs](https://learn.microsoft.com/en-us/intune/intune-service/developer/intune-graph-apis)


# Conditional Access

Conditional Access consolidates signals to make decisions, and enforces organizational policies like in case of SCA, require a complaint device or App Protection Policies.

Use Conditional Access policies to apply the right access controls when needed to keep your organization secure. \
Azure AD Conditional Access is at the heart of the new identity-driven control plane.\ <br>

<figure><img src="/files/rNLIjxJBDG75IlQ5SUNL" alt=""><figcaption></figcaption></figure>

{% hint style="danger" %}
Conditional Access policies are enforced after first-factor authentication is completed. Conditional Access isn't intended to be an organization's first line of defense for scenarios like denial-of-service (DoS) attacks, but it can use signals from these events to determine access.
{% endhint %}

<table data-view="cards"><thead><tr><th data-type="content-ref"></th></tr></thead><tbody><tr><td><a href="/pages/aYO2HmogoiOQEP7Z65CX">/pages/aYO2HmogoiOQEP7Z65CX</a></td></tr><tr><td><a href="/pages/YHI4KwbtqqS5yXWU4yoV">/pages/YHI4KwbtqqS5yXWU4yoV</a></td></tr></tbody></table>


# CA - Require Complaint Device

### **Required AAD-role for Conditional Access Policy:**

Global Administrator, Conditional Access Administrator

### Conditional Access Policy

{% hint style="danger" %}
You must have [Compliance Policies](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesIosMenu/~/compliancePolicies) configured for your Devices, before you configure this Conditional Access Policy, else lock yourself out and access will be blocked.
{% endhint %}

1. Login to Endpoint Manager with your Admin-Account
2. Go to Endpoint security → Conditional access or follow this link:\
   [Conditional Access - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies)
3. Click on **New policy** to create a new Conditional Access policy
4. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
5. Go to ***Users or workload identities*** in *Assignments*
6. *Include* your SCA-Testgroup to **Users and Groups**\
   \
   ![](/files/KrMkyRkx28qjCZJxOpfD)<br>
7. Go to ***Cloud apps or actions*** in *Assignments*
8. *Include as Cloud Apps the apps* **Office 365** and **Provectus - Secure Contacts**<br>

   <div align="left"><figure><img src="/files/Xt5kYYsG2yM6awLb7lzT" alt=""><figcaption></figcaption></figure></div>
9. Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value *Mobile apps and desktop clients*
10. Go to *Grant* in the *Access controls* pane
11. Set **Require compliant device**

<div align="left"><figure><img src="/files/VlwpY0roksbQpI8MXwPv" alt=""><figcaption></figcaption></figure></div>

1. Set *Enable Policy* to **On**
2. Click on **Create**


# CA - Require App Protection Policy

### **Required AAD-role for Conditional Access Policy:**

Global Administrator, Conditional Access Administrator

### Conditional Access Policy

{% hint style="danger" %}
You must have [App Protection Policy](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appProtection) for your Devices configured, before you configure this Conditional Access Policy, else access will be blocked. \
See [App Protection Policy - Integration in Microsoft Intune](https://app.gitbook.com/o/ppfQqpWS3ym5iPtSC6tM/s/4v109br9tFl1Rxk2qP0x/~/changes/CR4vmE9IJ0wzV3FIur6m/documentation/deployment-sca/app-protection-policy-integration-in-microsoft-intune)
{% endhint %}

1. Login to Endpoint Manager with your Admin-Account
2. Go to Endpoint security → Conditional access or follow this link:\
   [Conditional Access - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies)
3. Click on **New policy** to create a new Conditional Access policy
4. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
5. Go to ***Users or workload identities*** in *Assignments*
6. *Include* your SCA-Testgroup to **Users and Groups**\
   \
   ![](/files/OtPAaM4ktLjTNFBHNvaN)
7. Go to ***Cloud apps or actions*** in *Assignments*
8. *Include as Cloud Apps the apps* **Office 365** and **Secure Contacts**\
   \
   ![](/files/RtXMlXvsFHsdO2SrQ6qX)
9. Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value *Mobile apps and desktop clients*
10. Go to *Grant* in the *Access controls* pane
11. Set **Require app protection policy**<br>

    ![](/files/0rNmi09fpdSIk7XVXRxk)

    &#x20;
12. Set *Enable Policy* to **On**
13. Click on **Create**


# Deployment SCA

There are 3 ways to get SCA on your device. You can download the app directly from the AppStore or you can deploy the App through Microsoft Intune via iOS Store App or Volume Purchase Program-App.\
\
You can use SCA with any EMM provider (e.g. Microsoft Intune, MobileIron, Jamf, Airwatch, XenMobile....), cause the App uses a standard protocol, the [Mobile Device Management (MDM) protocol](https://developer.apple.com/business/documentation/MDM-Protocol-Reference.pdf) from Apple.\
\
SCA dedicated for Microsoft Intune supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy, see [Microsoft Intune protected apps](https://learn.microsoft.com/en-us/mem/intune/apps/apps-supported-intune-apps#partner-productivity-apps) and App Configuration Policy settings, see [App configuration policies for Microsoft Intune](https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-policies-overview).<br>


# iOS - App Installation

There are 3 ways to get SCA on your device. You can download the app directly from the AppStore or you can deploy the App through Microsoft Intune via iOS Store App or Volume Purchase Program-App.

### Public App  <a href="#public-app" id="public-app"></a>

It is possible to download SCA directly from the [App Store - Apple (DE)](https://apps.apple.com/de/app/secure-contacts/id1617596880), like any other app on your private iOS/iPadOS device.

An Apple-ID is required to download apps from the AppStore.

### iOS Store App <a href="#ios-store-app" id="ios-store-app"></a>

You can deploy SCA through Microsoft Intune as iOS Store App.\
In this case your Users have to login with an Apple-ID to the App Store on the device, before the are able to download SCA.

#### **Implementation Microsoft Intune** <a href="#implementation-endpoint-manager" id="implementation-endpoint-manager"></a>

1. Login to Microsoft Intune with your Admin-Account
2. Go to Apps → iOS/iPadOS or follow this link:\
   [iOS/iPadOS apps - Microsoft Intune admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsIosMenu/~/iosApps)
3. Click on **Add**
4. **Select** iOS store app
5. Search for “Secure Contacts Provectus” and **Select** the app

<figure><img src="/files/KXSohOev3mj3LShAGdOb" alt=""><figcaption></figcaption></figure>

6\. Click **Next** on the App information pane

7\. On the Assignments tab, choose whether the app will be **Required** or **Available for enrolled devices**

8\. Choose **Add group** under the assignment type you've selected and add your SCA test-group

9\. Click on **Next** and then **Create**

&#x20;

### VPP-App (Volume Purchase Program) <a href="#vpp-app-volume-purchase-program" id="vpp-app-volume-purchase-program"></a>

SCA is available for [Apple Business Manager](http://business.apple.com/).

You can deploy SCA through Microsoft Intune as VPP-App, in this case the users get SCA automatically on the device without a Apple-ID required.

#### **Implementation Apple Business Manager** <a href="#implementation-apple-business-manager" id="implementation-apple-business-manager"></a>

1. Go to your [Apple Business Manager](http://business.apple.com/)
2. Login with your credentials
3. Go to **Apps and Books**
4. Search for “Secure Contacts Provectus”
5. ***Assign to*** your Intune tenant and choose quantity of licences

<figure><img src="/files/Gs065rwtMQYNw1H6XjbE" alt=""><figcaption></figcaption></figure>

#### **Implementation Microsoft Intune** <a href="#implementation-endpoint-manager.1" id="implementation-endpoint-manager.1"></a>

1. Change to [iOS/iPadOS apps - Microsoft Intune admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsIosMenu/~/iosApps)
2. On the list of apps pane, **Secure Contacts** appears as a Apple Volume Purchase Program (VPP) app, select the app

{% hint style="danger" %}
Make sure you **sync** your [VPP-Connector](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/TenantAdminConnectorsMenu/~/appleVpp) in Intune to see updated Apps in the apps-menu in Microsoft Intune
{% endhint %}

3\. Choose **Properties**. Go to Assignments and click on **Edit**&#x20;

4\. On the Assignments tab, choose whether the app will be **Required** or **Available for enrolled devices**

5\. Choose **Add group** under the assignment type you've selected and add your SCA test-group

6\. Click on **Review + save** and on the next pane **Save**

{% hint style="info" %}
When you create a new assignment for an Apple Volume Purchase Program (VPP) app, the default license type must be "device".
{% endhint %}


# Android - App Installation

There are 2 ways to get SCA on your Android device. You can download the app directly from the Play Store or you can deploy it through Managed Google Play. Managed Google Play is the preferred option for organizations as it provides a more secure and controlled distribution of apps.

### &#x20;<a href="#public-app" id="public-app"></a>

### Public App  <a href="#public-app" id="public-app"></a>

It is possible to download SCA directly from the public [Google Play Store](https://play.google.com/store/apps/details?id=de.provectus.securecontacts.droid), like any other app on your Android device with Google Services.

A Google Account is required to download apps from the Play Store.

### Managed Google Play Store App <a href="#vpp-app-volume-purchase-program" id="vpp-app-volume-purchase-program"></a>

SCA is available for Managed Google Play Store.

You can deploy SCA through Microsoft Intune to your Android Enterprise devices via Managed Google Play Store.\
\
&#x20;

Managed Google Play, organizations can create and manage their own app catalog, set access controls and permissions, and enforce security policies for the apps they distribute.&#x20;

Your third-party MDM solution, must have a Google Account to access the Managed Google Play console, in order to deploy SCA to your managed devices.

1. Login to Microsoft Intune with your Admin-Account
2. Go to Apps → Android
3. In the Select app type pane, under the available Store app types, select Managed Google Play app.
4. Click Select. The Managed Google Play app store is displayed.

Hint: Alternatively use this link to go directly to [Managed Google Play Console](https://endpoint.microsoft.com/#view/Microsoft_Intune_Apps/ManagedGoogleAppApprovalConsole) in Intune.

5. Search for "Provectus Secure Contacts" in your Google Play Console.
6. Click **Approve.**

<div align="left"><figure><img src="/files/l5zToZW9u9EM9FzlBFBl" alt="" width="563"><figcaption></figcaption></figure></div>

7. Click **Approve**, in order to accept app-permissions for SCA.

<div align="left"><figure><img src="/files/DYpiUeXCHU6gLLRvKeVs" alt="" width="339"><figcaption></figcaption></figure></div>

8. Click on Done, to finish the setup the setup in Managed Google Play.

<div align="left"><figure><img src="/files/C58XW4BV7QSLSqrxBhXf" alt="" width="375"><figcaption></figcaption></figure></div>

9. Next step, you need to sync Managed Google Play:\
   \
   Select **Tenant administration** > **Connectors and tokens** > **Managed Google Play**.<br>
10. In the **Managed Google Play** pane, choose **Sync**. The page updates the time and status of the last sync.
11. Change to Apps > Android&#x20;
12. On the list of apps pane, **Secure Contacts** appears as Managed Google Play store app, select the app.
13. Choose **Properties**. Go to Assignments and click on **Edit**&#x20;
14. On the Assignments tab, choose **Required** or **Available for enrolled devices**
15. Choose **Add group** under the assignment type you've selected and add your SCA test-group
16. Click on **Review + save** and on the next pane **Save**


# App Configuration

Configuration Policies for Apps, can be used with any EMM provider (e.g. Microsoft Intune, MobileIron, Jamf, Airwatch, XenMobile...).\
SCA uses a standard protocol, the [Mobile Device Management (MDM) protocol](https://developer.apple.com/business/documentation/MDM-Protocol-Reference.pdf) from Apple, which provides a way to tell a device to execute certain management commands remotely.\
\
\
In this chapters you can read about how you can use App Configurations for SCA:

{% content-ref url="/pages/RYTAzCKLQBnrrVVMFRKb" %}
[iOS - MobileDeviceManagement (MDM) protocol](/documentation/deployment-sca/app-configuration/ios-mobiledevicemanagement-mdm-protocol)
{% endcontent-ref %}

{% content-ref url="/pages/zDXDqSpl2kH1llomdljw" %}
[AppConfigurationPolicies](/documentation/deployment-sca/app-configuration/appconfigurationpolicies)
{% endcontent-ref %}

\
In this chapter you can find a full list of all possible Name/Values for SCA:

{% content-ref url="/pages/moAw51NoJWxNcLEFA6z7" %}
[App Configuration Policy -Name/Values for SCA](/documentation/app-configuration-policy-name-values-for-sca)
{% endcontent-ref %}

<br>


# iOS - MobileDeviceManagement (MDM) protocol

SCA uses a standard protocol, the [Mobile Device Management (MDM) protocol](https://developer.apple.com/business/documentation/MDM-Protocol-Reference.pdf) from Apple. \
You can use any EMM provider for our app (e.g. Microsoft Intune, MobileIron, Jamf, Airwatch, XenMobile...).\
\
To cause the device to poll the MDM server for commands, the MDM server sends a notification through the APNS gateway to the device. This message gets sent via the push notification service.

Configuring the user UPN setting is **required** for devices that are managed by Intune or a third-party EMM solution to identify the enrolled user account for the sending *policy managed app* when transferring data to an iOS managed app. The UPN configuration works with the app protection policies you deploy from Intune.<br>

### How to manage data transfer between SCA and iOS Apps

In case you have managed Devices in Intune (not MAM-WE), it is mandatory to use the IntuneMAMUPN ConfigurationKey in App Configuration Policy for Intune, for App Protection Policy.

The exact syntax of the key/value pair for SCA may differ based on your third-party MDM provider. The following table shows examples of third-party MDM providers and the exact values you should enter for the key/value pair.

<table><thead><tr><th>Third-party MDM provider</th><th>Configuration Key</th><th width="123">Value Type</th><th>Configuration Value</th></tr></thead><tbody><tr><td>Microsoft Intune</td><td>IntuneMAMUPN</td><td>String</td><td>{{userprincipalname}}</td></tr><tr><td>Microsoft Intune</td><td>IntuneMAMOID</td><td>String</td><td>{{userid}}</td></tr><tr><td>VMware AirWatch</td><td>IntuneMAMUPN</td><td>String</td><td>{UserPrincipalName}</td></tr><tr><td>MobileIron</td><td>IntuneMAMUPN</td><td>String</td><td>${userUPN} <strong>or</strong> ${userEmailAddress}</td></tr><tr><td>Citrix Endpoint Management</td><td>IntuneMAMUPN</td><td>String</td><td>${user.userprincipalname}</td></tr><tr><td>ManageEngine Mobile Device Manager</td><td>IntuneMAMUPN</td><td>String</td><td>%upn%</td></tr></tbody></table>

{% hint style="info" %}
For more information about [How to manage data transfer between iOS apps in Microsoft Intune](https://learn.microsoft.com/en-us/mem/intune/apps/data-transfer-between-apps-manage-ios)
{% endhint %}


# Android - App Restrictions

SCA was developed with a focus on adherence to the guidelines and restrictions of the Android platform, including implementing necessary security measures, extensive compatibility testing, and integrating advanced APIs for enhanced functionality. We followed Google Play Store policies and guidelines to ensure successful publication.

As a result, SCA offering security and advanced features. It is also designed to be compatible with Intune or any other MDM provider.


# AppConfigurationPolicies

To help protect company data, restrict file transfers to only the apps that you manage. \
You can manage iOS apps in the following ways:

* Protect Org data for work or school accounts with SCA by configuring an app protection policy for the apps. which Microsoft calls *policy managed apps*. See [Microsoft Intune protected apps](https://learn.microsoft.com/en-us/mem/intune/apps/apps-supported-intune-apps).
* Deploy and manage SCA through iOS device management, which requires your device to be enrolled in a Mobile Device Management (MDM) solution. The apps you deploy can be *policy managed apps* or other iOS managed apps.


# iOS - App Configuration Policies - MAM Integration in Microsoft Intune

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App configuration policies or follow this link:\
   [App configuration policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appConfig)
3. Click on **Add** -> **Managed Apps**<br>

   <div align="left"><figure><img src="/files/Dynkz0KwCuP7JYcyAxsE" alt=""><figcaption></figcaption></figure></div>
4. Enter a **Name** for App configuration policy e.g. “Secure Contacts App Configuration”
5. Add “Secure Contacts” as Public app, by clicking on **+ Select public apps (1)**
6. Search for Secure Contacts and select App (2) and click on Select (3)

   &#x20;

   <div align="left"><figure><img src="/files/eARvvqgPMSj5wJUMk7GQ" alt=""><figcaption></figcaption></figure></div>
7. Click on **Next**
8. Add the Name and Value under “General configuration settings” for licensing SCA<br>

   <figure><img src="/files/XvIngvpcwIQ8fpy36piK" alt=""><figcaption></figcaption></figure>
9. Click on **Next**
10. **Add group** at *Included groups* in the Assignments-pane, choose your SCA test-group with **Select**.\ <br>

    <div align="left"><figure><img src="/files/WxSjKhPVtjOcvVgtQyOv" alt=""><figcaption></figcaption></figure></div>
11. Click on **Next** after adding SCA test-group
12. In the *Review + create* pane click on **Create**

<div align="left"><figure><img src="/files/wNAIG7Am3RyfK9bXDWKL" alt=""><figcaption></figcaption></figure></div>

<br>


# Android - App Configuration Policies - MDM Integration in Microsoft Intune

{% hint style="info" %}
Please follow [Android - App Installation](/documentation/deployment-sca/android-app-installation) and deploy SCA first via Intune before you configure App Configuration Policy.
{% endhint %}

### App Configuration Policy <a href="#app-configuration-policy" id="app-configuration-policy"></a>

It is mandatory to configure an App Configuration Policy for SCA to your managed devices

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App configuration policies or follow this link:\
   [App configuration policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appConfig)
3. Click on **Add** -> **Managed** **devices**<br>

   <div align="left"><figure><img src="/files/sBfbjSEdvmyYtIneeEk7" alt=""><figcaption></figcaption></figure></div>
4. Enter a **Name** for App configuration policy e.g. “Secure Contacts App Android Managed”
5. Add “Secure Contacts” by clicking *Targeted app -* **Select app** **(1)** and search for “Secure Contacts” and select the app **(2)** and click on **OK (3)**
6. Click on **Next**
7. In the Settings pane, choose for *Configuration settings format* - **Use configuration designer**
8. A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](#app-configuration-policy)
9. Click on **Next**
10. **Add group** at *Included groups* in the Assignments-pane, choose your SCA test-group with **Select**.
11. Click on **Next** after adding SCA test-group
12. In the *Review + create* pane click on **Create**


# App Protection Policy - Integration in Microsoft Intune

App protection policies (APP) are rules that ensure an organization's data remains safe or contained in a managed app. A policy can be a rule that is enforced when the user attempts to access or move "corporate" data, or a set of actions that are prohibited or monitored when the user is inside the app.

It is possible to implement SCA with as [Mobile Application Management (MAM) App](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe) within Microsoft Intune. \
\
Our App can be downloaded from the App Store directly and installed on any device.\
The moment a user connects with the AAD-account, Access control via Azure AD Conditional Access enforces our App to require a App Protection Policy for the SCA.\
\
SCA dedicated for Microsoft Intune supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy, we recommend to use App Configuration Policy and App Protection Policy, additionally enforce your Configuration via Conditional Access.&#x20;


# APP - unmanaged Devices

Implement SCA as [Mobile Application Management (MAM) App](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe) within Microsoft Endpoint Manager.\
Our App can be downloaded from the App Store directly and installed on any iOS/iPadOS device.\
The moment a user connects with the AAD-account Access control via Azure AD, Conditional Access enforces our App to require an App Protection Policy for the SCA.

SCA supports the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy and App Configuration Policy settings.

* Add Secure Contacts to App Protection Policies for unmanaged Devices

<figure><img src="/files/1XGgCGz7Rzn89mXLgCHJ" alt=""><figcaption></figcaption></figure>

* Configure the setting for *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name**  | **Value**   |
| --------- | ----------- |
| `Default` | `app-prefs` |

\
This option is needed for SCA to open phone-settings on the iOS/iPadOS device.

{% hint style="success" %}
Proceed with the other settings according to your best practice for App Protection Policy&#x20;
{% endhint %}

{% hint style="info" %}
For more information about App Protection policies, you can check Microsoft Docs .\
[App protection policies overview - Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy)
{% endhint %}

&#x20;


# APP - managed Devices

Implement SCA for your devices managed with Microsoft Endpoint Manager.\
Our App can be deployed automatically as iOS Store App or Volume Purchase Program App.

SCA support the core Intune App Protection Policy settings and is capable of supporting advanced App Protection Policy and App Configuration Policy settings.\
\
The moment a user connects with the AAD-account Access control via Azure AD, Conditional Access enforces our App to require an App Protection Policy for the SCA.

* Add Secure Contacts to App Protection Policies for managed Devices

<figure><img src="/files/cio1muteNl1HTY8oR7u6" alt=""><figcaption></figcaption></figure>

* Configure the setting for *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/B4cYc6JbHwkNjCZKd9cw" alt=""><figcaption></figcaption></figure>

&#x20;

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name**  | **Value**   |
| --------- | ----------- |
| `Default` | `app-prefs` |

\
This option is needed for SCA to open phone-settings on the iOS/iPadOS device.

{% hint style="success" %}
Proceed with the other settings according to your best practice for App Protection Policy&#x20;
{% endhint %}

{% hint style="info" %}
For more information about App Protection policies, you can check Microsoft Docs.\
[App protection policies overview - Microsoft Intune | Microsoft Docs](https://learn.microsoft.com/en-us/mem/intune/apps/app-protection-policy)
{% endhint %}


# Requirement - Open phone-settings

* Configure the setting *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name**  | **Value**   |
| --------- | ----------- |
| `Default` | `app-prefs` |

\
This option is needed for SCA to open phone-settings on the iOS/iPadOS device.


# Requirement - Open Maps app

* Configure the setting *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name** | **Value** |
| -------- | --------- |
| `maps`   | `maps`    |

\
This option is required for SCA to open the Maps app on the iOS/iPadOS device when an address is tapped.


# Requirement - Open GoogleMaps  app

* Configure the setting Send org data to other apps at least with the restrictive option e.g. Policy managed apps in the Data protection-pane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name**           | **Value**          |
| ------------------ | ------------------ |
| `comgooglemapsurl` | `comgooglemapsurl` |

This option is required for SCA to open the GoogleMaps app on the iOS/iPadOS device when an address is tapped.


# Requirement - Open WebExTeams

* Configure the setting *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name**   | **Value**                       |
| ---------- | ------------------------------- |
| WebExTeams | webexteams;webexteams-intunemam |

This option is required for SCA to open WebExTeams on the iOS/iPadOS device when WebExTeams button is tapped.

| **Name**   | **Value**                                            |
| ---------- | ---------------------------------------------------- |
| WebExTeams | com.cisco.wx2.android;com.cisco.wx2.android.msintune |

This option is required for SCA to open WebExTeams on the Android device when WebExTeams button is tapped.


# Requirement - Open WhatsApp

* Configure the setting *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name** | **Value** |
| -------- | --------- |
| whatsapp | whatsapp  |

\
This option is required for SCA to open WhatsApp on the iOS/iPadOS device when WhatsApp button is tapped.


# Requirement - Open Facetime

* Configure the setting *Send org data to other apps at least* with the restrictive option e.g.\
  *Policy managed apps* in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/ILUBnGS7g3o8rCURPtDQ" alt=""><figcaption></figcaption></figure>

* Add for the setting “Select apps to exempt” the following Name/Value

| **Name** | **Value** |
| -------- | --------- |
| facetime | facetime  |

\
This option is required for SCA to open Facetime on the iOS/iPadOS device when Facetime button is tapped.


# Requirement - Open email-link from SCA in Outlook

* Configure the setting *Restrict web content transfer with other apps* with the option Microsoft Edge in the *Data protection-*&#x70;ane for App Protection Policies.

<figure><img src="/files/Fms5Xxa9dtxHh0clNFNF" alt=""><figcaption></figcaption></figure>

This option is needed for SCA to open Outlook as email-client on the iOS/iPadOS device.&#x20;

When a user opens an email link in a managed app(e.g. outlook, teams or Secure Contacts app), Outlook (managed app) will open.

{% hint style="warning" %}
This option does affect all web content in managed apps e.g. a web-links you would like to open from outlook or email-links from teams. Users need to install Microsoft Edge from the app-store to open web-content.

It is recommended to add Microsoft Edge and Outlook to your managed apps.
{% endhint %}


# Requirement - Open sms/message-link from SCA in iMessage

In case you use AppProtection and cannot open a contact via SCA in iMessage.\
\
When a user tips on the Message-Button in SCA, this Setting needs to be set in order to be able to transfer the contact's number to iMessage.\
\
\- Configure the setting *Transfer messaging data to - A specific messaging app*\
*-* Configure the following value for *Messaging App URL Scheme*

```
sms:
```

<figure><img src="/files/dISEPZHQAcwnsA0N4ioU" alt=""><figcaption></figcaption></figure>

When a user tips on the Message-Button in SCA, this Setting needs to be active in order to be able to open the number in iMessage.


# Deployment for your Devices in Intune

Our App is fully implemented in Microsoft Intune, depending what kind of devices you use you have to set different Configurations, e.g. Managed or Supervised Devices have another scope of policies than Unmanaged Devices.\
\
For managed Devices we recommend to use the IntuneMAMUPN-Key in App Configuration Policy for Intune, for App Protection Policy.\
\
In the next chapter you will find recommendations how to deploy SCA in your Intune tenant.<br>

{% content-ref url="/pages/P8LuQkoyJJjchmeFUmsK" %}
[Deployment iOS - MAM-WE - APP only](/documentation/deployment-sca/deployment-for-your-devices-in-intune/deployment-ios-mam-we-app-only)
{% endcontent-ref %}

{% content-ref url="/pages/sXopwMoRHHDRxhvhpd0I" %}
[Deployment iOS MDM - Managed & Complaint Device](/documentation/deployment-sca/deployment-for-your-devices-in-intune/deployment-ios-mdm-managed-and-complaint-device)
{% endcontent-ref %}

{% content-ref url="/pages/LBfL6dF5kJic6eMKIEuw" %}
[Deployment iOS MDM - Managed Device & APP](/documentation/deployment-sca/deployment-for-your-devices-in-intune/deployment-ios-mdm-managed-device-and-app)
{% endcontent-ref %}


# Deployment iOS - MAM-WE - APP only

Implement SCA as [Mobile Application Management (MAM) App](https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-mamwe) within Microsoft Endpoint Manager.\
Our App can be downloaded from the App Store directly and installed on any device.\
The moment a user connects with the AAD-account Access control via Azure AD Conditional Access enforces our App to require a App Protection Policy for the SCA.

### App Protection Policy

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App protection policies or follow this link:\
   [App protection policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appProtection)
3. Click on **Create policy** and select **iOS/iPadOS**
4. Enter a Name for your Policy e.g. “Secure Contacts App Protection Policy”
5. Click **Next**
6. In the Apps pane, change *Target to apps on all device types* to **No**\
   Select the box **Unmanaged** for *Device types*<br>

   <figure><img src="/files/ZQuXoLUNSko6SdJJ1xEO" alt=""><figcaption></figcaption></figure>
7. Click on **+ Select public apps** and search for “Secure Contacts”
8. Select the app and confirm with **Select**
9. Click **Next** on the Apps pane
10. Please proceed configuring App Protection Policies as recommended by Microsoft
11. Finish the setup by clicking on **Create**

{% hint style="info" %}
You can use all policies in App Protection Policies as recommended by Microsoft.\
It is possible to add SCA to your existing App Protection Policy.
{% endhint %}

### Conditional Access Policy

For SCA is mandatory to create a Conditional Access-Policies or you can add SCA to your existing Conditional Access Policies

1. Login to Endpoint Manager with your Admin-Account
2. Go to Endpoint security → Conditional access or follow this link:\
   [Conditional Access - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies)
3. Click on **New policy** to create a new Conditional Access policy
4. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
5. Go to ***Users or workload identities*** in *Assignments*
6. *Include* your SCA-Testgroup to **Users and Groups**\
   \
   ![](/files/TphoReUsx01CTpRVxeLP)<br>
7. Go to ***Cloud apps or actions*** in *Assignments*
8. *Include as Cloud Apps the apps* **Office 365** and **Provectus - Secure Contacts**\
   \
   ![](/files/l0ZWctEyVrXzqqqM7Bgk)<br>
9. Set mandatory Conditions for your environment
10. Go to *Grant* in the *Access controls* pane
11. Set **Require app protection policy**\
    \
    ![](/files/m2CWHmzIWXYWXMaIhXkV)<br>
12. Set *Enable Policy* to **On**
13. Click on **Create**

{% hint style="info" %}
According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using these data sources.
{% endhint %}


# Deployment iOS MDM - Managed & Complaint Device

Implement SCA within Microsoft Endpoint Manager for you Compliant Device\
The moment a user connects with the AAD-account Access control via Azure AD Conditional Access enforces our App to require a complaint device.

### Compliance Policy

1. Login to Endpoint Manager with your Admin-Account
2. Go to Devices → Compliance policies or follow this link:\
   [Compliance policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/DevicesComplianceMenu/~/policies)
3. Click on **Create policy** and select **iOS/iPadOS** as Plattform and click on **Create**
4. Enter a Name for your Policy e.g. “Secure Contacts App Compliance Policy”
5. Set necessary *Compliance settings* and *Actions for noncompliance* depending on environment
6. Confirm each **Next**
7. In *Assignments* pane, click **Add group** and search for SCA-Testgroup & confirm **Select**
8. Click on **Next**
9. Click on **Create** in *Review + create* pane

<figure><img src="/files/HRv6MO095haJA71TjKPo" alt=""><figcaption></figcaption></figure>

### Conditional Access Policy&#x20;

1. Go to Endpoint security → Conditional access or follow this link:\
   [Conditional Access - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies)
2. Click on **New policy** to create a new Conditional Access policy
3. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
4. Go to ***Users or workload identities*** in *Assignments*
5. *Include* your SCA-Testgroup to **Users and Groups**\
   \
   ![](/files/D6jgBTB23SG4C9gOYeQk)<br>
6. Go to ***Cloud apps or actions*** in *Assignments*
7. *Include as Cloud Apps the apps* **Office 365** and **Provectus - Secure Contacts**\
   \
   ![](/files/CSFWdZiWBE6Fwr5vjM4K)<br>
8. Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value *Mobile apps and desktop clients*
9. Go to *Grant* in the *Access controls* pane
10. Set **Require compliant device**\
    \
    ![](/files/9OuFb6rnCpNIra3PKJq5)<br>
11. Set *Enable Policy* to **On**
12. Click on **Create**

{% hint style="info" %}
According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using these data sources.
{% endhint %}


# Deployment iOS MDM - Managed Device & APP

Implement SCA for your devices managed with Microsoft Endpoint Manager.\
Our App can be deployed automatically as iOS Store App or Volume Purchase Program App.

### App Configuration Policy <a href="#app-configuration-policy" id="app-configuration-policy"></a>

It is mandatory to configure an App Configuration Policy for SCA to your managed devices

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App configuration policies or follow this link:\
   [App configuration policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appConfig)
3. Click on **Add** -> **Managed** **devices**<br>

   <div align="left"><figure><img src="/files/sBfbjSEdvmyYtIneeEk7" alt=""><figcaption></figcaption></figure></div>
4. Enter a **Name** for App configuration policy e.g. “Secure Contacts App Configuration Managed”
5. Add “Secure Contacts” by clicking *Targeted app -* **Select app** **(1)** and search for “Secure Contacts” and select the app **(2)** and click on **OK (3)**
6. Click on **Next**
7. In the Settings pane, choose for *Configuration settings format* - **Use configuration designer**
8. A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](#app-configuration-policy)
9. Click on **Next**
10. **Add group** at *Included groups* in the Assignments-pane, choose your SCA test-group with **Select**.
11. Click on **Next** after adding SCA test-group
12. In the *Review + create* pane click on **Create**

&#x20;

### App Protection Policy <a href="#app-protection-policy" id="app-protection-policy"></a>

You can add SCA to your existing App Protection Policies or add a new one for testing.

1. Go to [App protection policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appProtection) and login with your credentials
2. Click on **Create policy** and select **iOS/iPadOS**
3. Enter a Name for your Policy e.g. “Secure Contacts App Protection Policy Managed”
4. Click **Next**
5. In the Apps pane, change *Target to apps on all device types* to **No**
6. Select the box **Managed** for *Device types*<br>

   <figure><img src="/files/vfZlEqjzEtHWjqPrybKZ" alt=""><figcaption></figcaption></figure>
7. Click on **+ Select public apps** and search for “Secure Contacts”
8. Select the app and confirm with **Select**
9. Click **Next** on the Apps pane
10. Please proceed configuring App Protection Policies as recommended by Microsoft
11. Finish the setup by clicking on **Create**\
    &#x20;

### Conditional Access Policy  <a href="#conditional-access-policy" id="conditional-access-policy"></a>

1. Go to Endpoint security → Conditional access or follow this link:\
   [Conditional Access - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_AAD_IAM/ConditionalAccessBlade/~/Policies)
2. Click on **New policy** to create a new Conditional Access policy
3. Enter a Name for the Policy e.g. “Secure Contacts Conditional Access Policy”
4. Go to ***Users or workload identities*** in *Assignments*
5. *Include* your SCA-Testgroup to **Users and Groups**\
   \
   ![](/files/ddBSW0WX6SQGBrc4UttM)<br>
6. Go to ***Cloud apps or actions*** in *Assignments*
7. *Include as Cloud Apps the apps* **Office 365** and **Secure Contacts**\
   \
   ![](/files/03oO97VnWKhFhJEpcLWI)<br>
8. Set mandatory Conditions for your environment e.g. tick as a Condition for Client apps the value *Mobile apps and desktop clients*
9. Go to *Grant* in the *Access controls* pane
10. Set **Require app protection policy**

    &#x20;\
    ![](/files/CDvu4GTwBLaukUJdZI5u)<br>
11. Set *Enable Policy* to **On**
12. Click on **Create**

{% hint style="info" %}
According to Microsoft, it is **mandatory** to target **Office 365** and **Secure Contacts** as Cloud App in your Conditional Access Policy in order to correctly implement SCA.\
It is required to add **Office 365** as Cloud App, because our Enterprise Application\
(Provectus - Secure Contacts) is using these data sources.
{% endhint %}


# Deployment Android MDM - Managed Device

Implement SCA for your devices managed with Microsoft Endpoint Manager.\
Our App can be deployed automatically via Managed Google Play Store.

### Deploy SCA as Managed Google Play Store App <a href="#vpp-app-volume-purchase-program" id="vpp-app-volume-purchase-program"></a>

SCA is available for Managed Google Play Store.

You can deploy SCA through Microsoft Intune to your Android Enterprise devices via Managed Google Play Store.\
\
&#x20;

Managed Google Play, organizations can create and manage their own app catalog, set access controls and permissions, and enforce security policies for the apps they distribute.&#x20;

Your third-party MDM solution, must have a Google Account to access the Managed Google Play console, in order to deploy SCA to your managed devices.

1. Change to [iOS/iPadOS apps - Microsoft Intune admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsIosMenu/~/iosApps)
2. On the list of apps pane, **Secure Contacts** appears as a Apple Volume Purchase Program (VPP) app, select the app

Hint: Alternatively use this link to go directly to [Managed Google Play Console](https://endpoint.microsoft.com/#view/Microsoft_Intune_Apps/ManagedGoogleAppApprovalConsole) in Intune.

3. Search for "Provectus Secure Contacts" in your Google Play Console.
4. Click **Approve.**

<div align="left"><figure><img src="/files/l5zToZW9u9EM9FzlBFBl" alt="" width="563"><figcaption></figcaption></figure></div>

5. Click **Approve**, in order to accept app-permissions for SCA.

<div align="left"><figure><img src="/files/DYpiUeXCHU6gLLRvKeVs" alt="" width="339"><figcaption></figcaption></figure></div>

6. Click on Done, to finish the setup the setup in Managed Google Play.

<div align="left"><figure><img src="/files/C58XW4BV7QSLSqrxBhXf" alt="" width="375"><figcaption></figcaption></figure></div>

7. Next step, you need to sync Managed Google Play:\
   \
   Select **Tenant administration** > **Connectors and tokens** > **Managed Google Play**.<br>
8. In the **Managed Google Play** pane, choose **Sync**. The page updates the time and status of the last sync.
9. Change to Apps > Android&#x20;
10. On the list of apps pane, **Secure Contacts** appears as Managed Google Play store app, select the app.
11. Choose **Properties**. Go to Assignments and click on **Edit**&#x20;
12. On the Assignments tab, choose whether the app will be **Required** or **Available for enrolled devices**
13. Choose **Add group** under the assignment type you've selected and add your SCA test-group
14. Click on **Review + save** and on the next pane **Save**

### App Configuration Policy <a href="#app-configuration-policy" id="app-configuration-policy"></a>

It is mandatory to configure an App Configuration Policy for SCA to your managed devices

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App configuration policies or follow this link:\
   [App configuration policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appConfig)
3. Click on **Add** -> **Managed** **devices**<br>

   <div align="left"><figure><img src="/files/sBfbjSEdvmyYtIneeEk7" alt=""><figcaption></figcaption></figure></div>
4. Enter a **Name** for App configuration policy e.g. “Secure Contacts App Configuration Managed”
5. Select as **Plattform** "Android Enterprise"&#x20;
6. Select as **Profile Type** the Profile for your testdevice e.g. "Fully Managed, Dedicated, and Corporate-Owned Work Profile Only"
7. Select as **Targeted app** "Provectus Secure Contacts"

<figure><img src="/files/ufZqDux1ghf4GMsEbH0g" alt=""><figcaption></figcaption></figure>

8. Click on **Next**
9. In the Settings pane, choose for *Configuration settings format* - **Use configuration designer**
10. A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](#app-configuration-policy)
11. Click on **Next**
12. **Add group** at *Included groups* in the Assignments-pane, choose your SCA test-group with **Select**.
13. Click on **Next** after adding SCA test-group
14. In the *Review + create* pane click on **Create**

&#x20;

### &#x20;<a href="#conditional-access-policy" id="conditional-access-policy"></a>


# App Configuration Policy -Name/Values for SCA

### Overview

The **Secure Contacts App (SCA)** supports configuration through **App Configuration Policies** provided by any Mobile Device Management (MDM) solution.\
With these policies, administrators can **customize app features, apply licenses, and specify which data sources SCA uses for contact synchronization**.

> Microsoft Intune is one common example of an MDM system that can deliver these policies, but SCA works with **any MDM platform** that supports standard key–value configuration.

By assigning the appropriate key–value pairs, you can centrally manage how SCA behaves across your organization.

### Main Configuration Keys

Below is an overview of the most commonly used configuration keys in SCA. Each key controls a specific feature or integration.

<table><thead><tr><th width="282.1429443359375">Configuration Key</th><th>Purpose</th></tr></thead><tbody><tr><td><a href="/pages/doZ8G3P50c1ykuVo5iO8"><strong>SecContacts.Defaults</strong></a></td><td>Customize app features and change default behavior.</td></tr><tr><td><a href="/pages/MdzEvXLRrfsBlBmAy6cU"><strong>SecContacts.Licenses</strong></a></td><td>Apply the app license.</td></tr><tr><td><a href="/pages/8D2OlTOatgYtgjl4JVp3"><strong>SecContacts.AADGroups</strong></a></td><td>Use Azure AD groups as separate contact sources within SCA.</td></tr><tr><td><a href="/pages/bf6qlzjqFL3ODEf6GONt#seccontacts.serviceurls"><strong>SecContacts.ServiceUrls</strong></a></td><td>Connect Microsoft Dataverse (DVRS) to use contacts stored by apps built on the Dataverse platform (e.g. Dynamics 365, Power Apps, etc.).</td></tr><tr><td><a href="/pages/l3ku470gJjjS1ucIS7wz"><strong>SecContacts.AzureBlobStorage</strong></a></td><td>Connect Azure Blob Storage (ABS) to use contacts exported from any app (including on-premises) via CSV/JSON using the SCA Blob Storage connector.</td></tr><tr><td><a href="/pages/d4Z004r5FHTPNK745aEK"><strong>SecContacts.SharedMailboxContacts</strong></a></td><td>Use Exchange Online shared mailboxes as an optional data source for contacts.</td></tr><tr><td><a href="/pages/MapUYDr96Lka6BOTA5uO"><strong>SecContacts.CustomDatasourceNames</strong></a></td><td>Rename any data source or ID in SCA to a more descriptive, user-friendly name.</td></tr></tbody></table>

A sample configuration for your App Configuration Policy could look like this:

<figure><img src="/files/AoSR08OLkcch1lZ8vybd" alt=""><figcaption><p>Note: This is just an example for illustration</p></figcaption></figure>

### Best Practice

* Start with [**SecContacts.Defaults**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.defaults) to configure the basic app behavior that fits your organization.
* Apply [**SecContacts.Licenses**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.licenses) early so users are properly licensed from the start.
* Use [**SecContacts.AADGroups**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-aad-filters-and-groups-1) if you want to organize your Azure AD groups as **separate contact sources** within SCA.
* Apply [**CustomDatasourceNames**](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.customdatasourcenames) to give your data sources clear and user-friendly names.
* Add [**ServiceUrls**](https://docs.secure-contacts.com/documentation/pages/bf6qlzjqFL3ODEf6GONt#seccontacts.serviceurls), [**AzureBlobStorage**](https://docs.secure-contacts.com/documentation/pages/bf6qlzjqFL3ODEf6GONt#seccontacts.azureblobstorage), or [**SharedMailboxContacts**](https://docs.secure-contacts.com/documentation/pages/bf6qlzjqFL3ODEf6GONt#seccontacts.sharedmailboxcontacts) only if you need extra contact sources beyond Azure AD.

{% hint style="success" %}
When you make changes to your app configuration, it may take some time for the updates to be applied to the device.

For apps protected by **Intune App Protection Policies (MAM without device enrollment)**, app configuration and protection policy updates are **typically applied within about an hour**. To force immediate application, the user must **log out and log back in** or **manually sync via the Company Portal**.
{% endhint %}

{% hint style="info" %}
**Note:** This delay applies only to **MAM (app protection) scenarios**. For fully enrolled **MDM devices**, app configuration and compliance policies are delivered through the device management channel and usually apply much faster. The delay with MAM is expected behavior and not an error.
{% endhint %}


# SCA Configuration - SecContacts.Defaults

### SecContacts.Defaults <a href="#seccontacts.licenses-this-setting-is-for-applying-the-app-license-s-." id="seccontacts.licenses-this-setting-is-for-applying-the-app-license-s-."></a>

This setting is for customizing app features and change defaults.

Secure Contacts App has several features and defaults that can be changed via SecContacts.Defaults.

* Name: `SecContacts.Defaults`
* Value: `[{"name":"<feature or default name>", "value":"<custom value>"}]`

The Value property is a JSON Array of `name` `value` pairs.\
You can add one or multiple defaults here.

Replace **\<feature or default name>** with a name of a feature or default to be changed.

* e.g. `AAD_Enabled` or `Favorites_Enabled` etc.

See List of available feature and default below.

Replace **\<custom value>** with a value for the feature or default to be changed.

* e.g. `true` or `false` or `0` or `1` or `2` or `3`

For example, if you want to add more features use `,`  as delimiter:

```json
[ 
  {"name":"<feature or default name>", "value":"<custom value>"} ,
  {"name":"<feature or default name>", "value":"<custom value>"} ,
  {"name":"<feature or default name>", "value":"<custom value>"} 
] 
```

{% hint style="danger" %}
Please be aware that “SecContacts.Defaults” is the **Name** of this setting.\
As **Value** you need to create a JSON Array
{% endhint %}

{% hint style="info" %}
When you make changes to your app configuration, it may take some time for the updates to be applied to the device, depending on your MDM system and enrollment type. To force immediate application, the user must **log out and log back in**.
{% endhint %}

### List of features or default name

The following tables show available values for the corresponding feature or default below:

#### **Enable or Disable Features**

<table><thead><tr><th width="240">Feature name</th><th width="134.33333333333331" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>SMSButton_Enabled</td><td align="center">true</td><td>True to enable or false to disable the SMS/iMessage feature</td></tr><tr><td>WhatsAppButton_Enabled</td><td align="center">false</td><td>True to enable or false to disable the WhatsApp Messenger feature. <a href="/pages/QwsPG3TIp8HocqCn4ULv">Allow this</a> in the App Protection policy, if necessary</td></tr><tr><td>SignalButton_Enabled</td><td align="center">false</td><td>True to enable or false to disable the Signal Messenger feature</td></tr><tr><td>TelegramButton_Enabled</td><td align="center">false</td><td>True to enable or false to disable the Telegram Messenger feature</td></tr><tr><td>EmailButton_Enabled</td><td align="center">true</td><td>True to enable or false to disable the EmailButton feature</td></tr><tr><td>TeamsButton_Enabled</td><td align="center">true</td><td>True to enable or false to disable the TeamsButton feature</td></tr><tr><td>FaceTimeButton_Enabled</td><td align="center">false</td><td>True to enable or false to disable the FaceTimeButton feature. <a href="/pages/eLfdQiyMFoe4YtqkLY0k">Allow this</a> in the App Protection policy, if necessary</td></tr><tr><td>WebExTeamsButton_Enabled</td><td align="center">false</td><td>True to enable or false to disable the WebExTeamsButton feature. <a href="/pages/ccWgAen2Qttz3Hlibmtz">Allow this</a> in the App Protection policy, if necessary</td></tr><tr><td>AnonymousCall_Enabled</td><td align="center">true</td><td>True to enable or false to disable the AnonymousCall feature (Enterprise License only)</td></tr><tr><td>TeamsStatus_Enabled</td><td align="center">true</td><td>True to enable or false to disable the TeamsStatus feature (Enterprise License only)</td></tr><tr><td>ShortCutPanel_Enabled</td><td align="center">true </td><td>True to enable or false to disable the ShortCutPanel feature</td></tr><tr><td>AAD_Enabled</td><td align="center">true</td><td>True to enable or false to disable the datasource AAD</td></tr><tr><td>APC_Enabled</td><td align="center">true</td><td>True to enable or false to disable the datasource APC</td></tr><tr><td>GAL_Enabled</td><td align="center">true</td><td>True to enable or false to disable the datasource GAL</td></tr><tr><td>D365_Enabled </td><td align="center">false</td><td>True to enable or false to disable the datasource D365 (Enterprise License only)</td></tr><tr><td>DVRS_Enabled </td><td align="center">false</td><td>True to enable or false to disable the datasource DVRS (Enterprise License only)</td></tr><tr><td>ABS_Enabled</td><td align="center">false</td><td>True to enable or false to disable the datasource ABS (Enterprise License only)</td></tr><tr><td>SMC_Enabled</td><td align="center">false</td><td>True to enable or false to disable the datasource SMC (Enterprise License only)</td></tr><tr><td>vCard_Enabled</td><td align="center">true</td><td>True to enable or false to disable the vCard feature</td></tr><tr><td>SettingsMenu_Enabled</td><td align="center">true</td><td>True to enable or false to disable access to SCA settings menu</td></tr><tr><td>VacationMode_Enabled</td><td align="center">true</td><td>True to enable or false to disable the Vacation Mode feature (Enterprise License only)</td></tr><tr><td>OfficeLocation_Enabled</td><td align="center">true</td><td>True to enable or false to disable the displaying office location.  (Enterprise License only)</td></tr><tr><td>OrganisationChart_Enabled</td><td align="center">true</td><td>True to enable or false to disable the displaying AAD manager / organisation chart. (Enterprise License only)</td></tr><tr><td>ContactAddresses_Enabled</td><td align="center">true</td><td>True to enable or false to disable the display of the contact addresses. Addresses can be tapped to open Maps. <a href="/pages/fWQR3WNltxxMyppkv4Vf">Allow this</a> in the App Protection policy, if necessary (Enterprise License only)</td></tr><tr><td>iOSForceOutlook_Enabled</td><td align="center">false</td><td>Set to <code>true</code> to force Outlook as default Email Client for SCA on iOS. This provides an alternative way to achieve the same result as using an Intune <a href="/pages/qL9LbB4oIIBoY5YnKi7N">App Protection Policy</a>.</td></tr><tr><td>iOSForceGoogleMaps_Enabled</td><td align="center">false</td><td>Set to <code>true</code> to use GoogleMaps App instead of iOS's native Maps App. <a href="/pages/ex5yFT3dHJY7FiyNVQcM">Allow this</a> in the App Protection policy, if necessary.</td></tr><tr><td>MobilePhoneToMessengerBinding_Enabled</td><td align="center">true</td><td>False to allow MobilePhone related functions for any phone number instead of just for "mobile" phone numbers</td></tr><tr><td>ContactNotes_Enabled</td><td align="center">true</td><td>Set to <code>true</code> to allow notes in contacts. Set to <code>false</code> to hide and disable the notes field. </td></tr><tr><td>ContactHintText_Enabled</td><td align="center">true</td><td>Set to <code>true</code> to display or <code>false</code> to hide the Info text at contact details page bottom.</td></tr><tr><td>ShareContacts_Enabled</td><td align="center">false</td><td>Set to <code>true</code> to enable share contacts feature. Set to <code>false</code> to disable share contacts feature.<br>(Enterprise License only)</td></tr><tr><td>UserLogin_Enabled</td><td align="center">true</td><td><p>Determines whether user login is permitted in the Secure Contacts App. </p><p>When set to <code>false</code>, login access is blocked. Users are shown an <em>"Access blocked by Administrator"</em> message and are automatically logged out after confirming it.</p></td></tr></tbody></table>

#### **Initial Value set by default**

{% hint style="warning" %}
InitValues are only set once after the app has been started for the very first time. \
For testing purposes proceed like below: \
\
The best practice for testing recently changed \_InitValue settings is: \
1\) Logoff from the app, \
2\) Delete the app from the device, \
3\) Download and launch the app again.
{% endhint %}

<table><thead><tr><th width="289.6189778645833">Default name</th><th width="130.000244140625" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>Favorites_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate Favorites switch in settings.</td></tr><tr><td>LogViewer_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the LogViewer switch in settings.</td></tr><tr><td>FullnameOrder_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate the Fullname order reverse switch in settings.</td></tr><tr><td>ShowCompanyName_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the Show Company Name switch in settings.</td></tr><tr><td>ShowDepartment_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate the Show Department switch in settings.</td></tr><tr><td>ShowJobtitle_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate the Show Jobtitle switch in settings.</td></tr><tr><td>ShowDataSource_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the Show Data Source switch in settings.</td></tr><tr><td>TeamsStatus_InitValue </td><td align="center">0</td><td>Initially set the TeamsStatus option to list (3) + details or contact details (2) or contact list (1) or disabeled (0).</td></tr><tr><td>SearchAllDatasources_InitValue </td><td align="center">true</td><td>True for initially activate or false to deactivate the Search all Datasources switch in settings.</td></tr><tr><td>AAD_InitValue </td><td align="center">true</td><td>True for initially activate or false to deactivate the AAD Datasource switch in settings.</td></tr><tr><td>APC_InitValue </td><td align="center">true</td><td>True for initially activate or false to deactivate the APC Datasource switch in settings.</td></tr><tr><td>GAL_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the GAL Datasource switch in settings.</td></tr><tr><td>D365_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the D365 Datasource switch in settings. (Enterprise License only)</td></tr><tr><td>DVRS_InitValue </td><td align="center">false</td><td>True for initially activate or false to deactivate the DVRS Datasource switch in settings. (Enterprise License only)</td></tr><tr><td>ABS_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate the ABS Datasource switch in settings. (Enterprise License only)</td></tr><tr><td>SMC_InitValue</td><td align="center">false</td><td>True for initially activate or false to deactivate the SMC Datasource switch in settings. (Enterprise License only)</td></tr></tbody></table>

#### Appearance and Functions

<table><thead><tr><th width="279.7142333984375">Name</th><th width="149.9998779296875" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>PhoneNumberParseCountryCode_Option</td><td align="center">false</td><td>Specify a 2-letter country code, e.g. "DE" or "US". Phone numbers that do not have the full international format, will be completed with the regional format of the country code defined. </td></tr><tr><td>PhoneNumberIngoreInvalid_Option</td><td align="center">false</td><td><p>The default value "false" will add all phone numbers to SCA without filtering.</p><p><br>Use "true" to filter out phone numbers without valid international format. </p></td></tr><tr><td>PhoneNumberExtensionInfix_Option</td><td align="center">null</td><td>Replaces phone number extension marker e.g. 'ext' > '398' to any custom infix provided.</td></tr><tr><td>ForceSync2LocalContacts_Option</td><td align="center">false</td><td>If set to <code>true</code> SCA will always use sync to local contacts for android caller id mode. If set to <code>false</code> SCA will use auto detection for android caller id mode. (Android only)</td></tr><tr><td>AADuseUPNasEmail_Option</td><td align="center">false</td><td>If set to <code>true</code> SCA uses <strong>two Email sources</strong> for <strong>AAD</strong> contacts (UserPrincipalName and Email)<br>If set to <code>false</code> SCA uses just one Email source for <strong>AAD</strong> contacts (Email)</td></tr><tr><td>ContactHintTextDE_Option</td><td align="center">Alle Kontakte in dieser App sind schreibgeschützt, mit Ausnahme deiner persönlichen Kontakte</td><td>Customize the Info text at contact details page (de)</td></tr><tr><td>ContactHintTextEN_Option</td><td align="center">All contacts in this app are read-only, except for your personal contacts</td><td>Customize the Info text at contact details page (en)</td></tr><tr><td>ContactHintTextES_Option</td><td align="center">Todos los contactos de esta aplicación son de sólo lectura, excepto tus contactos personales</td><td>Customize the Info text at contact details page (es)</td></tr><tr><td>ContactHintTextFR_Option</td><td align="center">Tous les contacts de cette application sont en lecture seule, à l'exception de vos contacts personnels</td><td>Customize the Info text at contact details page (fr)</td></tr><tr><td>TeamsStatusLocked_Option</td><td align="center">false</td><td>True to lock or false to unlock the TeamsStatus Button. If locked the user can no longer change a predefined TeamsStatus_InitValue. To set a fixed TeamsStatus mode, e.g. to be displayed only on the contact details page.</td></tr><tr><td>UseMSTeamsForOutboundPhoneCalls_Option</td><td align="center">false</td><td>True to route outbound "phone" calls to Teams instead of Phone App</td></tr><tr><td>SortDataSourcesByName_Option</td><td align="center">false</td><td>True to change data source sorting in settings from “by ID” to “by Name”</td></tr><tr><td>CustomTermsOfUseUrl_Option</td><td align="center">null</td><td>URL for a custom Terms of Use; set this if you want your users to accept your own Terms of Use before they can use SCA.</td></tr><tr><td>DisplayCompanyInCallerID_Option</td><td align="center">true</td><td>Set to <code>true</code> to display the company name in the caller ID. Set to <code>false</code> to show only the first and last name without the company name.</td></tr><tr><td>AADonlyEnabledAccounts_Option</td><td align="center">true</td><td>Set to <code>true</code> to include only <em>enabled</em> AAD user accounts in the AAD data source. Set to <code>false</code> to include <em>all</em> AAD user accounts.</td></tr></tbody></table>

#### Personal Contacts

<table><thead><tr><th width="290">Name</th><th width="129.80924479166669" align="center">Default value</th><th>Desciption</th></tr></thead><tbody><tr><td>APCeditor_Enabled</td><td align="center">true</td><td>Set to <code>true</code> to enable, or <code>false</code> to disable the ability for users to create, edit, and delete their own personal Outlook contacts (APC) directly within the app. (Enterprise License only)</td></tr><tr><td>APCfolders_Enabled</td><td align="center">false</td><td>Set to <code>true</code> to include personal Outlook contacts (APC) stored in (hidden) folders. Set to <code>false</code> to include only contacts stored in the root folder of the APC.</td></tr><tr><td>APCfoldersCombine_Enabled</td><td align="center">true</td><td>Set to <code>true</code> to combine all contacts from all APC folders into a single data source. Set to <code>false</code> to display each APC folder as a separate data source (auto-enumerated).</td></tr><tr><td>APChighPrioCombine_Option</td><td align="center">true</td><td>Set to <code>true</code> to give APC contacts the highest priority during contact merging. Set to <code>false</code> to apply standard contact combination rules.</td></tr><tr><td>AllowContactWithoutPhoneNumberAPC_Option</td><td align="center">true</td><td>Set to <code>true</code> to allow contacts without phone number for APC. Set to <code>false</code> to not allow contacts without phone number for APC.</td></tr></tbody></table>

#### Service Menu Access

<table><thead><tr><th width="290">Name</th><th width="129.80924479166669" align="center">Default value</th><th>Desciption</th></tr></thead><tbody><tr><td>ServiceMenu_Enabled</td><td align="center"><a data-footnote-ref href="#user-content-fn-1">true</a></td><td>True to enable or false to disable access to hidden Service Menu</td></tr><tr><td>ServiceMenu_SetAccessPin</td><td align="center">1234</td><td>Set a new Pin for accessing Service Menu</td></tr></tbody></table>

#### Resync Reminder

<table><thead><tr><th width="289.5239664713542">Name</th><th width="130.4285888671875" align="center">Default value</th><th>Desciption</th></tr></thead><tbody><tr><td>ResyncReminder_Enabled</td><td align="center">true</td><td>True to enable or false to disable the Resync Reminder feature.</td></tr><tr><td>ResyncReminderInterval_Option</td><td align="center">720</td><td>To set an interval (in hours) to generate a Resync Reminder Notification (default = 720) == 30 days</td></tr></tbody></table>

#### vCard Defaults

<table><thead><tr><th width="290.000244140625">Name</th><th width="129.857177734375" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>vCard_enabled</td><td align="center">true</td><td>True to enable or false to disable the vCard feature</td></tr><tr><td>vCard_Url</td><td align="center">null</td><td>null by default<br>Optionally, you can define a default URL for your vCard e.g. https://webpage.domain</td></tr><tr><td>vCard_Street</td><td align="center"> auto</td><td>If set to "null" the street input field is empty.<br>If set to "auto" the street input field gathers the data from Azure AD.<br>Optionally, you can define a default value for your street here.</td></tr><tr><td>vCard_PostalCode</td><td align="center">auto</td><td>If set to "null" the postal code input field is empty.<br>If set to "auto" the postal code input field gathers the data from Azure AD.<br>Optionally, you can define a default value for your postal code here.</td></tr><tr><td>vCard_City</td><td align="center">auto</td><td>If set to "null" the city input field is empty.<br>If set to "auto" the city input field gathers the data from Azure AD.<br>Optionally, you can define a default value for your city here.</td></tr><tr><td>vCard_Country</td><td align="center">auto</td><td>If set to "null" the county input field is empty.<br>If set to "auto" the county input field gathers the data from Azure AD.<br>Optionally, you can define a default value for your county here.</td></tr><tr><td>vCardDefaultReadOnly_Option</td><td align="center">false</td><td>Set to <code>true</code> to make the default/system vCard read-only. Set to <code>false</code> to allow editing of the default/system vCard.</td></tr><tr><td>vCardOnlyDefaultAllowed_Option</td><td align="center">false</td><td><p>Set to <code>true</code> to make only the default/system vCard available. Set to <code>false</code> to allow users to create additional vCards.</p><p><br></p></td></tr></tbody></table>

#### CI customization options

<table><thead><tr><th width="303">Name</th><th width="125" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>HighlightColor_Option</td><td align="center">#328DE2</td><td>Set primary button, switch, link &#x26; UI color for Light and Dark mode at once.<br>(Enterprise License only)</td></tr><tr><td>HighlightColorLightMode_Option</td><td align="center">#328DE2</td><td>Set primary button, switch, link &#x26; UI color for Light mode.<br>(Enterprise License only)</td></tr><tr><td>HighlightColorDarkMode_Option</td><td align="center">#328DE2</td><td>Set primary button, switch, link &#x26; UI color for Dark mode.<br>(Enterprise License only)</td></tr><tr><td>CDimageUri_Option<br><br><em>MenuImageURI_Option (legacy)</em></td><td align="center">null</td><td>Set set image URI for the optional company logo image visible on loading page, vcard qr-code and license viewer page. https only. Will be auto download once and then cached indefinitely until new URI is set. Supports JPG and PNG images. Square or rectangular PNG with transparent background recommended<strong>.</strong> (Enterprise License only)</td></tr></tbody></table>

{% hint style="success" %}
More information about **CI Customization** and configuration instructions can be found [here](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-ci-customization)
{% endhint %}

#### iOS Contact Provider (CPE)

<table><thead><tr><th width="303">Name</th><th width="125" align="center">Default value</th><th>Description</th></tr></thead><tbody><tr><td>CPE_Enabled</td><td align="center">false</td><td><p>Enables or disables the CPE functionality entirely. If set to <code>true</code> contacts from specified SCA data sources can be made system-wide available in iOS via the CPE. </p><p>(Enterprise License only)</p></td></tr><tr><td>CPEDataSources_Option</td><td align="center">APC</td><td>Defines which SCA data sources may be shared with iOS through the CPE. This is a comma-separated list of SCA source IDs e.g. <code>"AAD,APC,GAL"</code> </td></tr><tr><td>CPEDataSources_InitValue </td><td align="center">APC</td><td>Determines which SCA data sources are initially activated in the CPE Settings and shared with iOS via the Contact Provider Extension (CPE). The value is a comma-separated list of SCA source IDs, e.g.<code>"AAD,APC,GAL"</code> Users must still explicitly enable the Contact Provider, as required by iOS. Once enabled, the configured data sources are activated automatically and do not need to be selected manually.</td></tr><tr><td>CPEDataSources_Enabled</td><td align="center">true</td><td>Specifies whether users can select the available SCA data sources themselves. If set to <code>true</code> users will see an option within the app to choose sources. If set to <code>false</code> the selection is locked and a predefined configuration is enforced. </td></tr><tr><td>CPECompany_Enabled</td><td align="center">true</td><td>Defines whether a contact's company name can be shared with iOS.</td></tr><tr><td>CPEJobtitle_Enabled</td><td align="center">true</td><td>Defines whether a contact's job title can be shared with iOS.</td></tr><tr><td>CPEDepartment_Enabled</td><td align="center">true</td><td>Defines whether a contact's department name can be shared with iOS.</td></tr><tr><td>CPEAddresses_Enabled</td><td align="center">true</td><td>Defines whether a contact's address(es) can be shared with iOS.</td></tr><tr><td>CPEPhonenumbers_Enabled</td><td align="center">true</td><td>Defines whether a contact's phone number(s) can be shared with iOS.</td></tr><tr><td>CPEEmailaddresses_Enabled</td><td align="center">true</td><td>Defines whether a contact's email address(es) can be shared with iOS.</td></tr></tbody></table>

{% hint style="success" %}
More information about **iOS Contact Provider (CPE)** and configuration instructions can be found [here](/sca-3.0-public-beta/ios-contact-provider-cpe)
{% endhint %}

[^1]:


# SCA Configuration - SecContacts.Licenses

### SecContacts.Licenses <a href="#seccontacts.licenses-this-setting-is-for-applying-the-app-license-s-." id="seccontacts.licenses-this-setting-is-for-applying-the-app-license-s-."></a>

This setting is for applying the App license(s).

* Name: `SecContacts.Licenses`
* Value: `[{"name":"<license name>", "key":"<license key>"}]`

The Value property is a JSON Array of `name` `key` pairs,\
You can add one or multiple license keys here.

Replace **\<license name>** with the unique name to identify the license

* e.g. `EnterpriseLicense2023`

Replace **\<license key>** with the license key you've purchased

* e.g. `XcTAQTzgO00KQE+Dkr{...}FnxMDuzJ6xI=`

### Example

```json
[
  {
    "name": "EnterpriseLicense2026",
    "key": "XcTAQTzgO00KQE+Dkr{...}FnxMDuzJ6xI="
  }
]
```

{% hint style="success" %}
To use SCA, you need a valid license. Reach out to us to [get a trial license key](https://secure-contacts.com/en/testlizenz-anfordern/).
{% endhint %}


# SCA Configuration - AAD filters

### **SecContacts.AADFilters** <a href="#seccontacts.aadfilters" id="seccontacts.aadfilters"></a>

This setting is for customizing the querying parameters for AZURE AD contacts.

Secure Contacs App is querying **AZURE AD via directory.read.all** and **will use any AAD account as contact which contains at least an displayname and a bussiness or mobile phonenumber**.

Per default it ignores all "external AAD" accounts which have a UPN containing "#EXT#@" as well as the administrator account.

This is basically an "all in" with some default exceptions. With AADFilters you can extend these exceptions.

* Name: `SecContacts.AADFilters`
* Value: `[{"property":"<aad-property>", "operator":"<target-operator>", "value":"<target-value>"}]`

The Value property is a JSON Array of `property` `operator` `value` trio.\
You can add one or multiple filter here.

Replace **\<aad-property>** with the AAD property you want to for filter for

* e.g. `userPrincipalName` or `displayName`

Replace **\<target-operator>** with an operator

* e.g. `contains` or `equals` or `equalsAny`

Replace **\<target-value>** with the value you want to for filter for

* e.g. `administrator` or `johndoe` or `#EXT#@`

When using the `equalsAny` operator, provide a list of **target-values** as one single string with `;` as delimiter.

* e.g. `administrator;johndoe;someotheruser`

Currently only **userPrincipalName** and **displayName** are supported as **aad-property**.<br>


# SCA Configuration - SecContacts.AADGroups

### **SecContacts.AADGroups** <a href="#seccontacts.aadgroups" id="seccontacts.aadgroups"></a>

This setting defines Azure AD groups to filter which AAD accounts are used as contacts in SCA.

* Name: `SecContacts.AADGroups`
* Value: `[{"name":"<AAD group name>", "value":"<AAD group ID>"}]`

The Value property is a JSON array of `name`/`value` pairs. You can add one or more AAD groups to the array.

* If there is only a single entry, SCA treats it as the default `AAD` data source and it replaces the default AAD datasource, which normally includes all AAD contacts.
* If you want to include all users plus specific groups, add a group containing all AAD users (e.g., `All Users`) along with the additional groups.

SCA treats each group as an individual data source and assigns it a sequential ID automatically, such as AAD1, AAD2, and so on.

Replace `<AAD group name>` with the name of the group (e.g., AppMemberGroup) and `<AAD group ID>` with its Object ID (e.g., `15e3a3d2-50a6-43e3-137e-a44316d0b448`).

### **Optional properties**

<table><thead><tr><th width="210.1429443359375">Property</th><th width="103.4285888671875">Type</th><th>Description</th></tr></thead><tbody><tr><td><code>transitive</code></td><td>string</td><td>If <code>true</code>, includes all members of nested groups recursively.</td></tr><tr><td><code>epHomePhone</code></td><td>string</td><td>Maps to an <strong>extension property</strong> in Azure AD for Home Phone.</td></tr><tr><td><code>epPrivateMobilePhone</code></td><td>string</td><td>Maps to an <strong>extension property</strong> in Azure AD for Private Mobile Phone.</td></tr></tbody></table>

### Examples

**Minimal configuration (single entry)**

```json
[
  {
    "name": "AppMemberGroup",
    "value": "15e3a3d2-50a6-43e3-137e-a44316d0b448"
  }
]
```

With a single entry, SCA treats this group as the default `AAD` data source, replacing the normal default that includes all AAD contacts.

**Single group with optional properties**

```json
[
  {
    "name": "AppMemberGroup",
    "value": "15e3a3d2-50a6-43e3-137e-a44316d0b448",
    "transitive": "true",
    "epHomePhone": "HomePhoneCustom",
    "epPrivateMobilePhone": "PrivateMobileCustom"
  }
]
```

Replace placeholders like `<HomePhoneCustom>` with the actual name of the corresponding extension property in Azure AD.

### Multiple groups (3 groups example)

```json
[
  {
    "name": "AppMemberGroup",
    "value": "15e3a3d2-50a6-43e3-137e-a44316d0b448",
    "transitive": "true"
  },
  {
    "name": "HRGroup",
    "value": "d1a2b3c4-5678-90ab-cdef-1234567890ab"
  },
  {
    "name": "AllUsers",
    "value": "0f1e2d3c-4567-89ab-cdef-9876543210fe"
  }
]
```

In this example:

* `AppMemberGroup` becomes `AAD1`
* `HRGroup` becomes `AAD2`
* `AllUsers` becomes `AAD3`

Including the `AllUsers` group ensures that all AAD users remain part of the contacts, in addition to the specific groups.

**Optional properties allow SCA to:**

* Include nested group members (`transitive: true`)
* Map Azure AD extension properties for Home or Private Mobile numbers (`epHomePhone`, `epPrivateMobilePhone`)

This gives full control over which accounts appear as contacts and how their phone numbers are sourced.

{% hint style="success" %}
[Rename SCA data sources](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.customdatasourcenames) to make them clear and understandable for end users
{% endhint %}


# Copy of SCA Configuration - SecContacts.AADGroups

### **SecContacts.AADGroups** <a href="#seccontacts.aadgroups" id="seccontacts.aadgroups"></a>

**This setting allows you to define an Azure AD group that filters which AAD accounts are used as contacts.** Only members of the selected group will be synchronized and shown as AAD contacts in SCA.

* Name: `SecContacts.AADGroups`
* Value: `[{"name":"<AAD group name>", "value":"<AAD group ID>"}]`

The Value property is a JSON Array of `name` `value` pairs.

{% hint style="success" %}
You can add one or multiple AADGroups to this array as needed. Each group becomes a separate data source in SCA and is auto-enumerated. e.g. AAD1, AAD2, etc. &#x20;
{% endhint %}

Replace **\<AAD group name>** with the name of the AAD Group

* e.g. `AppMemberGroup`

Replace **\<AAD group ID>** with the Object Id of the AAD Group

* e.g. `15e3a3d2-50a6-43e3-137e-a44316d0b448`

{% hint style="danger" %}
To use full AAD and add another group as a data source in SCA, add a group that contains all your AAD users (e.g. All Users) along with the additional group to your configuration.
{% endhint %}

### Optional properties for SecContacts.AADGroups in SCA 3.0

* Name: `SecContacts.AADGroups`
* Value: `[{"name":"<AAD group name>", "value":"<AAD group ID>", "transitive":"true", "epHomePhone":"<ext.prop.HomePhone>", "epPrivateMobilePhone":"<ext.prop.MobilePhone>"}]`

The `Value` is a JSON array containing one or more AAD groups. Each object in the array must include the mandatory fields:

Replace **\<AAD group name>** with the name of the AAD Group

* e.g. `AppMemberGroup`

Replace **\<AAD group ID>** with the Object Id of the AAD Group

* e.g. `15e3a3d2-50a6-43e3-137e-a44316d0b448`

You may also optionally include:

* `transitive`: Set to `"true"` to include nested (transitive) group members
* `epHomePhone`: Replace **\<ext.prop.HomePhone>** with the name of the extension property name that holds the home phone number of an AAD user object&#x20;
* `epPrivateMobilePhone`: Replace **\<ext.prop.MobilePhone>** with the name of the extension property name that holds the private mobile phone number of an AAD user object

{% hint style="success" %}
You can add one or multiple AADGroups to this array as needed. Each group becomes a separate data source in SCA and is auto-enumerated. e.g. AAD1, AAD2, etc. &#x20;
{% endhint %}

{% hint style="success" %}
[Rename SCA data sources](/documentation/app-configuration-policy-name-values-for-sca/sca-configuration-seccontacts.customdatasourcenames) to make them clear and understandable for end users
{% endhint %}




---

[Next Page](/llms-full.txt/1)

