restrict android personal profile
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Hello community,
We have a couple of Android tablets that are used by two different Microsoft accounts.
One of them is managed through the Intune company portal and the work profile.
The other one we like to use the personal profile, do you know any way/app how we can remotely allow/block the apps the user can use. We want to block the user from installing other apps from the Play Store and block the use of some of the pre-installed apps.
I hope my topic is in the right forum. If not, please feel free to correct me.
Thanks in advance!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
Have you tried fully managed profile, you can remove system apps, only allow approved apps. But you won't have a separate work and personal profile.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago - last edited 3 weeks ago
You should be able to do this. In our MDM it's called application run control and takes affect on entire device, so if i would add for example chrome per bundle id there, it will diappear from the device (private and work profile) and not able to be installed again.
So i guess there can be something in Intune but as i don't use Intune (luckily) i don't know if they have build in that possibility there as well.
But i would need to test and check this as I currently don'T use BYOD.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago - last edited 3 weeks ago
I did some testing and it only affects apps in work profile (so my remembering was totally wrong, sorry for that).
So, the only thing i know of you can block is installation from unknown sources (in both profiles).
I guess i mixed it up with COPE but this needs to be testedfrom your side as well and not sure if this is a possibility to think about as this makes completely difference in the purpose the device is handled and controlled.
What's the reason you want block apps in private part of a BYOD (which should be ideally untouched by a company)? For me your request looks more like you need to look for COPE or fully managed device enrollment.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago
We have two M365 accounts, and the data should be separated for both profiles while still being managed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
3 weeks ago - last edited 3 weeks ago
That sounds weird to me somehow.
So, they should be used at the same time? If not you should investigate into shared device.
If yes, you can add multiple accounts to the app and switch between them just inside the app. But ofc then the data is not entirely separated.
Not sure if you look into something like "secured folder" Motorola provides on their (latest) devices but they don't have tablets as their tablets are provide via Lenovo which use different oem.
- restrict android personal profile in Admin discussions
- Few customers not able to install applications in personal profile after work profile is setup. in Admin discussions
- Work Profile Environment Only in Admin discussions
- Google workspace enrolled devices, enable applications in work profile in Admin discussions
- Taming the tech jargon: your guide to enterprise mobility acronyms in Admin resources