Blog Post

Intune Customer Success
3 MIN READ

Archive: Announcing new updates to the Android Enterprise fully managed devices preview

Intune_Support_Team's avatar
Intune_Support_Team
Silver Contributor
Jul 02, 2019

Updated 12/19/19 - We have received over 300 comments on the Android preview blog posts, and in those comments and occasional subsequent support cases, you helped us deliver Android Enterprise Fully Managed as generally available. You provided over 58 pieces of actionable feature feedback based on your experience with preview.

More information about the GA release can be found in our blog here: Microsoft Intune support for Android Enterprise fully managed devices is now generally available.

As this feature is now GA, new comments on this post will be turned off. As always, we want to hear from you! If you have any suggestions, questions, or comments, please visit us on our Tech Community page or our Twitter @IntuneSuppTeam. Your continued feedback helps make the product better, we are grateful for this community, thank you!

As we work towards delivering full support for the Android Enterprise fully managed device scenario, we are updating the capabilities currently available in preview. We will support Intune app protection policies on Android Enterprise fully managed devices. This will start to roll out now and anticipate it will be available for everyone by the end of the second week in July.


Before we get to what’s new, a quick shout out - thank you for continuing to use this preview and providing extensive dialog. We will keep working to address feedback you have raised in the comments section on prior Android Enterprise fully managed blog posts (preview 1 and preview 2), Twitter, and through other feedback channels.

 

Support for app protection policies on fully managed devices

We are happy to announce that we now have support for Intune app protection policies on fully managed devices. In scenarios where organizations want an additional layer of app compliance controls beyond full device controls, the automatically deployed Company Portal app will serve as the agent for the app protection policies. All the app protection policies will be supported at parity with the rest of your device scenarios.

 

Updates to the Microsoft Intune app

We’ve added new features to the Microsoft Intune app (preview) for Android. Users on fully managed Android devices can now:

  • View and manage the devices they've enrolled through the Intune Company Portal or Microsoft Intune app
  • Contact their organization for support
  • Send their feedback to Microsoft
  • View terms and conditions, if set by their organization

 
Update availability
These features are rolling out now and we expect they’ll be fully available by the first week of July. We will update this post as soon as the roll out is complete so that you can be sure that you have the full set of updates to test out the features.
 
In development features
The following workflows are still in development:
  • Remote access policies with certificate support (i.e. Wi-Fi, VPN, Email)
  • Certificate management
  • Support for managing or enabling system apps
  • Support for Mobile Threat defense
     

Customer Support for This Preview
We outlined above that not all features are yet available for use with the Intune Android fully managed scenario. The preview features are fully supported through our usual Intune support channels and are clearly labeled with “(preview)” in the Intune console.

 

Known Issues

As discussed in the comments, we do have a known issue with this release. If you blocked “Account Changes” in the user and accounts blade, then you won’t be able to enroll new devices with this update. We are working on addressing this issue to allow the device to register but prevent any subsequent unapproved account changes.

 

How Can You Reach Us?
As you use Preview 2 and test out the Android fully managed preview scenarios, we would appreciate your feedback on IT admin's enrollment profile configuration and end-user's device enrollment experiences. Keep us posted on your Android experience through comments on this blog post, through Twitter (@IntuneSuppTeam), and request any new features on UserVoice.

 
Documentation


Blog post updates:

  • 12/19/19 with an update that this preview feature is now GA!
Updated Dec 19, 2019
Version 5.0

40 Comments

Comments have been turned off for this post
  • Niels van Dijk's avatar
    Niels van Dijk
    Copper Contributor

    I'm using Samsung KME to automatically enroll fully managed devices.

     

    Some things I notice, after doing a factory reset to get into the Knox Enrollment state:

    - When the device has an active 4G connection, no option offered to setup a WiFi connection instead.

    - The Intune app gets installed, but not configured. The user has to start the app and complete some steps manually in order to get it managed by Intune.

     

    Are this limitations to the current state of the Preview?

  • AndyH16's avatar
    AndyH16
    Brass Contributor

    robbamberI have, albeit very briefly, experienced this with our devices (Moto G6, Android 9). I've issued reboots only for it to instantly reboot the device the moment it starts up - and checks the Device Policy, I assume. Though, after a couple of reboots they seem to behave.

  • robbamber's avatar
    robbamber
    Brass Contributor

    hey guys ... I'm posting in the hope that someone has a Samsung Note 9 and can test / confirm something for me ... 

    The Note 9 devices are have are showing some very strange behaviour ... they are configured for "secure startup" so the user has to enter a PIN when they first turn on the device ... simple enough ...

    However where I am struggling is that "rebooting the device from the Intune console puts the device into a state or constantly rebooting and having to enter my PIN" ... rebooting the phone manually works as expected ... 

    The only way I've found to resolve this is to leave it for a random amount of time (18 hours is my best score) and then on that lucky attempt the phone will stay turned on again ...

    Hoping someone has a Note 9 running Android 9 that they can try this with ...

    Cheers 

     

  • Peter Meuser's avatar
    Peter Meuser
    Copper Contributor

    Hi Rob, with "work profile on a fully managed device" I am referencing to the so far missing support for "Company-owned devices for knowledge workers" (or "COPE" as called more traditionally). Please see this definition by Google: https://developers.google.com/android/work/overview

     

  • robbamber's avatar
    robbamber
    Brass Contributor

    PKlapwijk 

    Thanks for the reply ..

    I also have the same issue with clicking "Resolve" and nothing happening, then you have to manually navigate to the correct place in the settings and set the PIN ... 

    In terms of configuration police showing as pending, I have seen something similar where the Configuration Policy update will not apply until any "Device Compliance" policies are removed ... once they are removed the Configuration Policy should apply, and then you can re-apply the Compliance Policy ...  

    Peter Meuser 

    Hey Peter, the only update I have had in terms of "Work Profile" was around Compliance Policies ... as it stands Work Profiles do not work in terms of Device Compliance, only Device Owner Compliance policies ... but I'm told that feature parity will be achieved between the 2 for GA ...  

  • Peter Meuser's avatar
    Peter Meuser
    Copper Contributor

    Will "work profile" on a fully managed device be considered as another feature of fully managed device scenario or will this be a new scenario by itself to be supported in the future?

  • I see no issues when the user logs on to the Intune app. I`m able to use the app to register the device. What I did notice, when we move on to get the device compliant the app shows we need to enable encryption. When we click Resolve, nothing happens, you are not redirected to set your startup PIN to start encryption.
    When I click Resolve under for example the message the PIN is to short, I`m redirected to the correct settings tab.
    Another issue I still see, the app configuration policy is applied, but still shows pending in the Intune portal.

  • AndyH16's avatar
    AndyH16
    Brass Contributor

    I get that page but it loads, so the grey placeholders have the expected text. But when we try to continue you get a message stating that your organization has blocked access - which we have, with the device configuration - only, apps like Outlook allow you to add email and 365 accounts without issue.

  • robbamber's avatar
    robbamber
    Brass Contributor

    AndyH16

    I am also still seeing strange behaviour with the Intune App ... when the user logs into the app I am presented with the below image instead of the page to register the phone ... is this something you have seen? ... currently awaiting a response on my case logged with Microsoft ... cheers ...

  • AndyH16's avatar
    AndyH16
    Brass Contributor

    As it stands, the Intune app is still unusable for us due to the (device configuration) restrictions on adding/editing users accounts - yet other Microsoft apps are able to work fine. Is a fix still being worked on?