Security
19 TopicsIs there any way to disable Google Play Protect (GPP) from an EMM or to otherwise whitelist apps from scanning?
I am very concerned about the Enhanced GPP features coming soon that are currently being piloted in other regions. https://security.googleblog.com/2023/10/enhanced-google-play-protect-real-time.html This is not a welcome feature whatsoever for the fully managed space where we have business apps written internally that are being installed on business devices, owned by that business. In no way do we want Google sitting in between deciding whether a very legitimate app written internally for an organization should be installed on devices that are purchased and owned by the same organization on fully managed devices. I would like a way to disable GPP completely, or at a minimum whitelist applications from scanning as we don't want Google interfering in the business operations. GPP is a helpful consumer protection features but fully managed devices should have the ability to be opted in or out of the program. Otherwise GPP can incorrectly flag a mission critical app and disable or remove it from a device, thereby bringing down a line-of-business application and an end customers operations. While the intentions of GPP are good, by blocking business apps Google themselves is becoming the malicious actor that GPP is ironically trying. to prevent.Solved38KViews13likes57CommentsCan you skip network connection in Android Enterprise Edition?
Hello community, We have Samsung XCover6 Pro Enterprise Edition sent to customer in May this year. (Android v.12) They have started the phone and then didn't enroll it. They have just started the phone and put it on the shelf and battery has died and now they have started the phone. There are two problems: 1. They can skip to connect to the Wi-Fi 2. Even if they connect to Wi-Fi the phone doesn't get enrolled, the enrollment phase never comes up, you can just continue to setup the normally If we remove the phone from Zero Touch Portal, hard wipe the device by connecting it to a PC and then upload it to ZTP and connect it to Wi-Fi. Then it starts with enrollment. So I wanted to test this myself. I took the exact same model of the phone Samsung XCover6 Pro Enterprise Edition from our shelf and started it and to my surprise I COULD NOT skip network connection. Now the only difference between the phone that I tested and the phone that we sent to the customer is that, we sent the phone to customer like 6 months ago. But my test phone purchased recently, like a month ago. I tested this with several different Enterprise phone models and got the exact same result! COULD NOT skip network connection. I had to connect to a network before continuing with the setup. This is exactly what I want because of the obvious reasons. So my questions: Isn't this policy / feature (that you MUST connect to a network) by default set to TRUE for all Android Enterprise? Or is it different based on Android version?Solved7.3KViews0likes14CommentsForce settings on Dedicated devices during enrollment
Hello all, I'm trying to deploy a Dedicated device profile in Microsoft Intune, I created the configuration profiles and the compliance policy with some settings, in specific about PIN creation and complexity, but during the setup users are not asked to enter any PIN, and at the end the device result non-compliant until the PIN is set and is fulfilling the rules I set. Is there by any chance a way to force the PIN creation request during the enrollment phase as happens for user-associated devices? Thanks in advance /Lucius5KViews1like7CommentsWork Profile Password Complexity affects Personal Space device password that unlocks the device : Intune
Hi, Personally owned devices with a work profile running on Android 12 and above devices today, we are over controlling their personal space by demanding complex password setup. there are two passwords affected by this Password complexity setting in Intune : The device password that unlocks the device The work profile password that allows users to access the work profile Even we choose medium complexity, user are getting a notification to change the device password to complex. this is not feasible for the BYOD scenario. Yes, i can understand security perspective avoid simple passcode, but policy shouldn't force for lengthy and complex passwords. how you configured this password complexity your environment ?.4.3KViews1like7CommentsSetting UntrustedAppsPolicy to DISALLOW_INSTALL does not prevent app installs
We have devices provisioned on an Android Enterprise policy where the AdvancedSecurityOverrides.UntrustedAppsPolicy is set to DISALLOW_INSTALL, but users are still able to download APKs via browser and install them. Is there another setting that someone is aware of that would prevent this behavior? Thanks all.3.6KViews0likes9CommentsExporting the MDM (Security) policy installed in my Work Profile (BYOD)
Hi, Greetings, We want to extract the MDM policy installed in our BYOD Work Profile device (without ADB way). We are using INTUNE as our MDM. any way we can view and export the installed security policy logs from my device ?. Regards, GoviSolved2.6KViews1like2CommentsHow to connect my google workspace account to zero touch enrollent
Hello everyone, I have a google business plus account and developing EMM android application and looking for zero touch enrolment but when i try to access zero touch from the admin console it says you don't have permission to access this page so my question is how can i enroll device to zero touch without reseller provided account i can't use zero touch directly from my admin console? if i can use then how could is possible? Thank you!2.3KViews0likes5Comments[Enhancement Request] Allow push notifications during OOBE setup process
Android does not allow any push notifications during the OOBE (out of box experience) setup process. This presents challenges during Intune enrollment because we require users to satisfy MFA (SMS or MS Authenticator) in order to complete Entra AD device registration and device enrollment. The inability to receive push notifications on the new Android they are configuring requires users to configure their MFA on a secondary device before starting the setup of the new device, or obtain a temporary access pass from our Security Team. If OOBE supported push notifications it would resolve this and provide a much simpler and easier enrollment/user experience.2.3KViews3likes4CommentsSecuring third party keyboard traffic
We are facing a situation where users are complaining about the default Samsung Keyboard that comes with Galaxy devices as the corporate device. We are looking into providing other options such as Gboard and Swiftkey but the problem is we are unable to fully secure traffic going to these third party services. For Gboard there are some options onthe MDM as amanaged app while Swiftkey does not have many options. Main reason we stick with Samsung is the Knox service plugin which helps secure the device more including keyboard however it only applies to samsung keyboard. With each other keyboard we introduce we have to rely on the key value pairs that come with the app to select options we can lock down as needed. Not all the app developers are enterprise focused so its hard to get any feature requests thoguh. Only other thing I can think of is blocking traffic at a network level to ensure nothing goes through but then we would need to know the addresses that are used. Has anyone faced this situation?1.8KViews0likes2Comments