Home

enrollment restriction depending on device category

%3CLINGO-SUB%20id%3D%22lingo-sub-341632%22%20slang%3D%22en-US%22%3Eenrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-341632%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20everyone%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20want%20to%20achieve%20the%20follwing%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAn%20Android%20user%20starts%20to%20register%20his%20device%20in%20the%20companyportal%20app.%3C%2FP%3E%3CP%3EI%20provided%20two%20device%20categories%20(e.g.%20BYOD%20and%20COPE).%3C%2FP%3E%3CP%3EWhen%20the%20user%20chooses%20BYOD%20the%20Android%20Enterprise%20%2F%20Work%20profile%20enrollment%20should%20start.%3C%2FP%3E%3CP%3EWhen%20the%20user%20chooses%20COPE%20the%20Android%20%22Default%22%20enrollment%20should%20start.%20(No%20matter%20if%20the%20device%20supports%20work%20profile%20or%20not)%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAt%20this%20moment%2C%20no%20matter%20what%20is%20selected%2C%20the%20android%20enterprise%20enrollment%20will%20start%2C%20if%20the%20device%20supports%20it%2C%20otherwise%20the%20%22default%22%20enrollment%20is%20used.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%2C%3C%2FP%3E%3CP%3EPatrick%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-341632%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-353867%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-353867%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3Eby%20default%20we%20don't%20want%20to%20use%20the%20fully%20managed%20devices%2C%20because%20even%20the%20company%20owned%20devices%20are%20used%20as%20COPE%20devices%20(Corporate%20owned%20personally%20enabled).%3CBR%20%2F%3EThis%20will%20provide%20a%20better%20acceptance%20for%20the%20user.%3CBR%20%2F%3EThe%20%22default%22%20Android%20Enrollment%20would%20be%20an%20option%2C%20because%20this%20isn't%20as%20restricted%20as%20the%20fully%20managed%20option.%3CBR%20%2F%3EThe%20perfect%20solution%20would%20be%2C%20that%20the%20user%20could%20choose%20the%20device%20category%20during%20the%20enrollment%20with%20the%20company%20portal%20app%20(private%20device%20or%20corporate%20device)%20and%20depending%20on%20this%20choice%20the%20device%20will%20run%20into%20Work%20Profile%20enrollment%20or%20native%20android%20enrollment.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-353558%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-353558%22%20slang%3D%22en-US%22%3E%3CP%3EThe%20best%20option%20for%20your%20environment%20will%20be%20to%20use%20enrollment%20for%20%22corporate-owned%2C%20fully%20managed%20user%20devices%22%2C%20once%20it%20is%20out%20of%20preview.%20It%20has%20limited%20features%20at%20the%20moment%2C%20but%20will%20be%20the%20proper%20way%20to%20manage%20corporate%20Android%20devices%20going%20forward.%20Here's%20a%20blog%20post%20about%20it%3A%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FMicrosoft-Intune-announces-preview-of-support-for-Android%2Fba-p%2F314747%22%20target%3D%22_blank%22%3Ehttps%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2FIntune-Customer-Success%2FMicrosoft-Intune-announces-preview-of-support-for-Android%2Fba-p%2F314747%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20a%20workaround%2C%20you%20can%20try%20creating%20dynamic%20group%20memberships%20based-on%20the%20categories%20you%20created%2C%20and%20target%20those%20device%20groups%20with%20the%20appropriate%20config%20profile%20(Platform%3A%20Android%20or%20Android%20enterprise).%20I'm%20not%20sure%20if%20this%20would%20be%20an%20effective%20option%20though.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-342367%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-342367%22%20slang%3D%22en-US%22%3EHi%20and%20thank%20you%20again%20for%20your%20reply.%3CBR%20%2F%3EI%20already%20know%20how%20to%20use%20corporate%20identifiers.%3CBR%20%2F%3EBut%20what%20to%20do%20next%2C%20when%20set%20up%20the%20corporate%20identifier%3F%3CBR%20%2F%3EThe%20next%20Android%2C%20which%20is%20known%20in%20identifiers%20already%2C%20will%20set%20up%20with%20work%20profile%2C%20too.%20(And%20not%20as%20default%20android%20enrollment)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-342334%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-342334%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CFONT%20face%3D%22Segoe%20UI%2CSegoeUI%2CSegoe%20WP%2CHelvetica%20Neue%2CHelvetica%2CTahoma%2CArial%2Csans-serif%22%3E%3CFONT%20color%3D%22%23b00000%22%3EY%3CSPAN%3Eou%20need%20to%20identify%20devices%20as%20corporate-owned.%26nbsp%3B%3CFONT%20color%3D%22%23007600%22%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fcorporate-identifiers-add%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fcorporate-identifiers-add%3C%2FA%3E%3C%2FFONT%3E%3C%2FSPAN%3E%3C%2FFONT%3E%3C%2FFONT%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-342313%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-342313%22%20slang%3D%22en-US%22%3EHi%2C%3CBR%20%2F%3E%3CBR%20%2F%3EAndroid%20Work%20profile%20enrollment%20is%20already%20enabled%20and%20is%20working%20pretty%20well.%3CBR%20%2F%3EMy%20problem%20is%2C%20that%20i%20don't%20want%20corporate%20devices%20to%20be%20enrolled%20as%20a%20work%20profile%20device%2C%20but%20as%20a%20conventional%20Android%20device.%3CBR%20%2F%3EThe%20enrollment%20restrictions%20are%20configured%20as%20default.%20(Android%2C%20Android%20work%20profile%2C%20ios%20and%20windows%20is%20allowed.)%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-342175%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-342175%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPlease%20check%20your%20Enrollment%20restriction%20and%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fandroid-work-profile-enroll%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3ESet%20up%20Android%20work%20profile%20enrollments%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-469769%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-469769%22%20slang%3D%22en-US%22%3E%3CP%3EJust%20a%20short%20response%2C%20because%20of%20a%20new%20Techcommunity%20Account.%20%3A)%3C%2Fimg%3E%20%5BIgnore%20me%5D%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-469781%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-469781%22%20slang%3D%22en-US%22%3EBecause%20of%20a%20new%20techcommunity%20account%2C%20this%20is%20just%20a%20short%20response%20to%20follow%20up%20the%20thread.%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-481019%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-481019%22%20slang%3D%22en-US%22%3E%3CP%3EHi%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEven%20though%20the%20device%20is%20under%20full%20management%2C%20you%20can%20still%20allow%20the%20user%20to%20add%20a%20personal%20Google%20account%20and%20switch%20between%20work%20and%20personal%20in%20Google%20Play.%3C%2FP%3E%3CP%3EIf%20you%20have%20no%20reason%20for%20full%20management%20eg.%20if%20you%20do%20not%20want%20to%20do%20a%20full%20device%20wipe%2C%20just%20use%20work%20profiles%20instead.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20really%20should%20start%20to%20move%20away%20from%20Device%20Admin%20as%20it%20will%20be%20deprecated%20this%20summer.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-499174%22%20slang%3D%22en-US%22%3ERe%3A%20enrollment%20restriction%20depending%20on%20device%20category%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-499174%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F310475%22%20target%3D%22_blank%22%3E%40almennn%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you%20for%20your%20response.%3C%2FP%3E%3CP%3EAt%20this%20moment%20we're%20not%20using%20fully%20managed%20devices%2C%20so%20we%20work%20with%20the%20work%20profile%20option%20only.%3C%2FP%3E%3CP%3EThis%20seems%20to%20be%20a%20good%20way%20for%20us.%20Thank%20you%20anyway.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Deleted
Not applicable

Hi everyone,

 

i want to achieve the follwing:

 

An Android user starts to register his device in the companyportal app.

I provided two device categories (e.g. BYOD and COPE).

When the user chooses BYOD the Android Enterprise / Work profile enrollment should start.

When the user chooses COPE the Android "Default" enrollment should start. (No matter if the device supports work profile or not)

 

At this moment, no matter what is selected, the android enterprise enrollment will start, if the device supports it, otherwise the "default" enrollment is used.

 

Thank you,

Patrick :)

 

9 Replies

Hi,

 

Please check your Enrollment restriction and Set up Android work profile enrollments

 

Hi,

Android Work profile enrollment is already enabled and is working pretty well.
My problem is, that i don't want corporate devices to be enrolled as a work profile device, but as a conventional Android device.
The enrollment restrictions are configured as default. (Android, Android work profile, ios and windows is allowed.)
Hi and thank you again for your reply.
I already know how to use corporate identifiers.
But what to do next, when set up the corporate identifier?
The next Android, which is known in identifiers already, will set up with work profile, too. (And not as default android enrollment)

The best option for your environment will be to use enrollment for "corporate-owned, fully managed user devices", once it is out of preview. It has limited features at the moment, but will be the proper way to manage corporate Android devices going forward. Here's a blog post about it: https://techcommunity.microsoft.com/t5/Intune-Customer-Success/Microsoft-Intune-announces-preview-of...

 

As a workaround, you can try creating dynamic group memberships based-on the categories you created, and target those device groups with the appropriate config profile (Platform: Android or Android enterprise). I'm not sure if this would be an effective option though.

Hi,

by default we don't want to use the fully managed devices, because even the company owned devices are used as COPE devices (Corporate owned personally enabled).
This will provide a better acceptance for the user.
The "default" Android Enrollment would be an option, because this isn't as restricted as the fully managed option.
The perfect solution would be, that the user could choose the device category during the enrollment with the company portal app (private device or corporate device) and depending on this choice the device will run into Work Profile enrollment or native android enrollment.

Just a short response, because of a new Techcommunity Account. :) [Ignore me]

Hi,

 

Even though the device is under full management, you can still allow the user to add a personal Google account and switch between work and personal in Google Play.

If you have no reason for full management eg. if you do not want to do a full device wipe, just use work profiles instead.

 

You really should start to move away from Device Admin as it will be deprecated this summer.

@almennn 

Thank you for your response.

At this moment we're not using fully managed devices, so we work with the work profile option only.

This seems to be a good way for us. Thank you anyway.

 

Related Conversations
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
30 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
7 Replies