management
52 TopicsHow to prevent users from disabling global proxy settings on fully managed Android devices?
I develop a Custom DPC application for fully managed devices, and I am planning to configure global proxy settings for Android devices through our EMM Console. I want to restrict disabling these proxy settings, but I am unsure how to implement this restriction. I have reviewed the UserManager and DevicePolicyManager documentation but could not find any specific settings or policies to prevent users from modifying or disabling proxy configurations. Would anyone happen to know how to implement the restrictions that would prevent users from disabling proxy settings on fully managed Android devices? Thank you in advance for your help.76Views0likes4CommentsForce settings on Dedicated devices during enrollment
Hello all, I'm trying to deploy a Dedicated device profile in Microsoft Intune, I created the configuration profiles and the compliance policy with some settings, in specific about PIN creation and complexity, but during the setup users are not asked to enter any PIN, and at the end the device result non-compliant until the PIN is set and is fulfilling the rules I set. Is there by any chance a way to force the PIN creation request during the enrollment phase as happens for user-associated devices? Thanks in advance /Lucius5.1KViews1like8CommentsWork profile on S25 Ultra
Just bought a Galaxy S25 Ultra a few weeks ago and unfortunately I'm not able to create a work profile with MS Intune. I've tried all workarounds that I found on Reddit and Samsung community (https://us.community.samsung.com/t5/Galaxy-S25/New-S25-Ultra-Unable-to-setup-work-profile-using-company-portal/td-p/3126410/page/29). I think that this can be related to some Android Enterprise support because I could not find any reference of the models when searching for it. Does anyone else are having issues when trying to create a work profile on S25 series?136Views1like5Comments(COPE) Hide app in work profile
Hello, I have a small case I'd like to submit to the community for help please. A customer use Mobile Iron, and use Zero Touch to enroll our Android 14 products. In their DPC extras, they enabled the system apps and need to keep that way: "android.app.extra.PROVISIONING_LEAVE_ALL_SYSTEM_APPS_ENABLED":true, "android.app.extra.PROVISIONING_ADMIN_EXTRAS_BUNDLE":{ "workProfileEnabled": true, "quickStart":"true" } Now after the device is enrolled, the Work profile is filled with bunch of apps including unwanted ones like Netflix, Adobe, YT kids, ... From Mobile Iron, they want to hide/disable some apps, using "setApplicationHidden" but it doesn't work. At OEM side, we tested this API with the Test DPC and it works properly. My thinking was that as we are in COPE, and the apps that the customer wants to remove are from the Personal space, then this is not working as the MDM cannot interact with Personal space content. Does this make sense? Are there a way to hide the unwanted apps from the Work profile, despite having "leave all system apps" enabled from the ZT DPC extras? Anyone has any suggestions please? Thanks!153Views3likes13CommentsUnable to start AE (Android Enterprise) Enrollment in Microsoft Intune MDM
We are currently using Microsoft Intune Mobile Device management solution to manage Android mobile devices, and these devices are currently enrolled in the mode of Android Device Administrator in Microsoft Intune. Google has deprecated Android device administrator management, continues to remove management capabilities, and no longer provides fixes or improvements. Intune will be ending support for Android device administrator management on devices with access to Google Mobile Services GMS beginning December 31, 2024. Hence, we're trying to setup Android Enterprise method of enrollment in Microsoft Intune. As part of pre-requisites in Intune, it's essential to connect Microsoft Intune account to managed Google play account. As per Microsoft recommendation, we are using Microsoft Entra account to connect to Google Play. After entering the Entra account username & password, authentication is redirecting to Google sign-in page and ending with below error. Someone at ABCD.com domain has already signed up Microsoft Intune Reference Article: https://learn.microsoft.com/en-us/mem/intune/enrollment/connect-intune-android-enterprise#connect-accounts Note: ABCD.com should be referred as domain name registered & verified in Microsoft Entra.85Views0likes6CommentsCan not login with Google workspace account under restricting Personal google account on Intune
I am considering the introduction of Android Enterprise in my company and am testing the distribution of configuration policies from Intune. The enrollment profile is set to COBO (Android Enterprise corporate owned fully managed). I do not want users to log in with their personal Google accounts, so I want them to log in to apps like Google Meet with the Google Workspace account managed by the company. However, when I set the "Restrict personal accounts" policy in Intune to block, no Google accounts can be added at all. Conversely, if I disable this setting, both personal and Google Workspace accounts can be logged in. Does anyone know a solution to this?Solved61Views0likes1CommentIssue with Web Token in Google Managed Play JavaScript API
Hi everyone, We’re using the Managed Google Play JavaScript API to generate a Web UI by passing the web token obtained from Enterprises.createWebToken. However, we are encountering issues when trying to use the token in the iframe. According to the documentation ( https://developers.google.com/android/work/play/emm-api/managed-play-iframe ) , all pages in the iframe should be enabled by default. But in our case, the expected functionality is not working as intended. Has anyone else facing similar issues with the web token? Are there any known limitations or recent changes that might affect this?44Views0likes1CommentSilent installation of applications on TELPO devices using Android Enterprise
I have an Android application that I want to use on TELPO devices, but in a way that updates are downloaded silently on the device, meaning the user does not have to intervene to update or install an application. I understand that with the configurations offered by Android Enterprise, it is possible to set up a device to allow the actions I require.98Views0likes1CommentPlease help - new company, email & phone yet already enrolled??
I'm hoping someone can help, as I'm at a complete loss. I am the sole owner and operator for my newly formed design company, bought a new Moto G Play and created a new email for it. After some fiddling, though, I saw that it had Moto Device Management installed already, but asks for a code from my administrator... Again, it's only me and everything is brand new, but even Google won't let me sign up for an enterprise account, saying to talk to my admin. I've factory reset, yet the problem persists and strange apps/functions are happening with the phone, as if someone else is "managing" my company device already. I've scoured forums, FAQs and articles to no avail; in fact, learning of the capabilities, I'm quite worried. Luckily, I noticed it before putting anything besides that new email on it, but it's obviously compromised by someone else - there are many, many system apps now on it that aren't from the play store, nor came with the phone initially. What can I do? Any help is appreciated.95Views0likes0Comments