SOLVED
Home

force enrollment on android device

%3CLINGO-SUB%20id%3D%22lingo-sub-469826%22%20slang%3D%22en-US%22%3Eforce%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-469826%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei'm%20facing%20the%20following%20behavior%20and%20try%20to%20understand%20why%20this%20happens.%3C%2FP%3E%3CP%3EWhen%20a%20special%20user%20is%20signing%20in%20to%20Outlook%20for%20Android%20the%20following%20message%20appears%3A%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%22Help%20us%20to%20ensure%20the%20safety%20of%20your%20device.%3C%2FP%3E%3CP%3ETo%20continue%2C%20you%20need%20to%20install%20the%20Intune%20Enterprise%20Portal%20App%20and%20register%20your%20device.%20This%20app%20helps%20you%20better%20protect%20organizational%20data.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20no%20idea%2C%20why%20the%20device%20seems%20to%20be%20enforced%20to%20register%20in%20Intune.%20All%20the%20other%20devices%20in%20our%20company%20behave%20normal.%20(normal%20in%20my%20understanding%20%3B)%3C%2Fimg%3E%3C%2FP%3E%3CP%3ENormal%20means%3A%20App%20Protection%20Policies%20are%20applied%20when%20using%20e.g.%20Outlook%20on%20an%20unregistered%20device.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAny%20idea%20is%20appreciated.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EPatrick%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-469826%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-471138%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-471138%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3B%20On%20Android%2C%20the%20Intune%20Company%20Portal%20app%20is%20required%20to%20enforce%20app%20protection%20policies.%20End-users%20do%20not%20need%20to%20enroll%20their%20device%2C%20but%20the%20app%20is%20still%20required%20.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fend-user-mam-apps-android%23access-apps%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fintune%2Fend-user-mam-apps-android%23access-apps%3C%2FA%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-479540%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-479540%22%20slang%3D%22en-US%22%3E%3CP%3EThat%20is%20confusion%20reported%20to%20Microsoft%20log%20time%20ago.%3CBR%20%2F%3EOn%20iOS%20user%20will%20be%20asked%20to%20install%20MS%20Authenticator%20ap%20which%20is%20ok.%3C%2FP%3E%3CP%3EBut%20on%20Android%20they%20asked%20to%20use%20Company%20portal%20which%20is%20confusing.%20I%20already%20faced%20an%20issue%20with%20users%20who%20saw%20message%20to%20install%20Intune%20app%20an%20just%20aborted%20configuration%20because%20they%20didn't%20want%20to%20enroll%20phone.%20So%20on%20Android%20it%20is%20really%20essential%20to%20explain%20difference%20between%20Device%20Registration%20and%20Device%20Enrollment.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-499196%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-499196%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254026%22%20target%3D%22_blank%22%3E%40eglockling%3C%2FA%3E%26nbsp%3BJust%20to%20make%20it%20clear%20to%20me%3A%3C%2FP%3E%3CP%3EWhen%20i%20use%20an%20Android%20device%20and%20i%20did%20not%20have%20the%20Company%20Portal%20app%20installed%2C%20no%20app%20protection%20policy%20is%20applied%3F%20And%3A%20To%20apply%20the%20app%20protection%20policy%20the%20user%20is%20forced%20to%20install%20the%20intune%20company%20portal%20app.%20(no%20need%20to%20register%20within%20the%20app%2C%20right%3F)%3C%2FP%3E%3CP%3ESo%20that%20means%2C%20once%20i%20have%20app%20protection%20policies%20set%20up%20for%20android%20devices%2C%20no%20user%20is%20able%20to%20use%20e.g.%20outlook%2C%20until%20he%2Fshe%20has%20the%20intune%20company%20portal%20app%20installed%2C%20because%20the%20Outlook%20app%20is%20covered%20by%20an%20app%20protection%20policy%2C%20right%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-499228%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-499228%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F144823%22%20target%3D%22_blank%22%3E%40Alexander%20Vanyurikhin%3C%2FA%3E%26nbsp%3BYou're%20right%2C%20that%20is%20really%20confusing..%3C%2FP%3E%3CP%3EWhat%20do%20you%20mean%20with%20%22difference%20between%20Device%20Registration%20and%20Device%20Enrollment.%22%3C%2FP%3E%3CP%3EHow%20can%20i%20register%20a%20android%20device%20without%20enrollment%3F%20Or%20do%20you%20mean%3A%20When%20the%20user%20only%20has%20the%20company%20portal%20app%20installed%20and%20not%20configured%2C%20this%20is%20registration.%20When%20the%20user%20has%20signed%20in%20to%20company%20portal%20app%20and%20went%20through%20the%20process%2C%20the%20device%20is%20enrolled.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-503586%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-503586%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3B%20That's%20correct.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-503774%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-503774%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3B%20You%20can%20sign-in%20to%20the%20Company%20Portal%20app%20on%20a%20device%20to%20register%20it%2C%20just%20don't%20complete%20the%20enrollment.%20There%20should%20be%20an%20option%20to%20%22postpone%22%20after%20signing-in.%20The%20Authenticator%20app%20is%20no%20longer%20required%20on%20iOS%20to%20enforce%20app%20protection%20policies%2C%20it%20is%20enforced%20by%20the%20mobile%20apps%20themselves.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-511402%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-511402%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254026%22%20target%3D%22_blank%22%3E%40eglockling%3C%2FA%3Eare%20you%20sure%20about%20that%3F%20I%20followed%20a%20session%20by%20Lexi%20Torres%20in%20March%20on%20Ignite%20the%20Tour%20and%20there%20was%20still%20shown%20a%20slide%20the%20Authenticator%20app%20is%20used%20as%20broker%20app%20for%20App%20Protection%20Policies.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-523248%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-523248%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F254026%22%20target%3D%22_blank%22%3E%40eglockling%3C%2FA%3E%26nbsp%3BThank%20you%20for%20your%20reply.%3C%2FP%3E%3CP%3EA%20quote%20from%20MS%3A%3C%2FP%3E%3CBLOCKQUOTE%3E%3CP%3E%3CSPAN%3EHowever%2C%20the%20user%20does%20not%20have%20to%20launch%20or%20sign%20into%20the%20Company%20Portal%20app%20before%20they%20can%20use%20apps%20that%20are%20managed%20by%20app%20protection%20policies.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FBLOCKQUOTE%3E%3CP%3ESo%20it%20seems%20not%20be%20necessary%20to%20sign%20in.%3C%2FP%3E%3CP%3EBut%20what%20for%20should%20a%20user%20sign%20in%2C%20then%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EEdit%3A%3C%2FP%3E%3CP%3EWhat%20i%20just%20tested%3A%20When%20a%20user%20has%20outlook%20already%20configured%20and%20i'm%20going%20to%20rollout%20the%20app%20protection%20policies%20the%20user%20isn't%20prompted%20to%20download%20the%20company%20portal%20app.%20And%3A%20The%20user%20isn't%20using%20the%20app%20protection%20policies%20and%20feels%20wonderfully%20free%20using%20outlook%20for%20android%20without%20any%20reglementations.%20%3A%5C%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-527966%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-527966%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%26nbsp%3B%20Thanks%20for%20the%20follow-up.%20Good%20to%20know%20that%20the%20sign-in%20is%20not%20required.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-528034%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-528034%22%20slang%3D%22en-US%22%3E%22because%20the%20Outlook%20app%20is%20covered%20by%20an%20app%20protection%20policy%2C%20right%3F%22%3CBR%20%2F%3EJust%20posting%20for%20the%20sake%20of%20clarity%20for%20others%2C%20not%20necessarily%20specific%20to%20your%20scenario%2C%20Patrick.%3CBR%20%2F%3EOutlook%20is%20covered%20by%20app%20protection%20policies%20if%20they%20assigned%20to%20that%20user%20group%20the%20end%20user%20is%20a%20member%20of.%20The%20Intune%20SDK%20is%20built-in%20to%20Outlook%2C%20but%20nothing%20is%20%22activated%22%20until%20a%20policy%20is%20applied.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-546096%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-546096%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F172380%22%20target%3D%22_blank%22%3E%40Steve%20Bucci%3C%2FA%3E%26nbsp%3BThank%20you%20for%20your%20reply.%20Thats%20why%20i%20said%20%22...%3CSPAN%3Eonce%20i%20have%20app%20protection%20policies%20set%20up%20for%20android%20devices..%22%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%3CSPAN%3EOf%20course%20this%20is%20not%20the%20%22fault%22%20of%20intune.%20The%20admin%20should%20consider%20of%20the%20policies%20used%2C%20of%20course.%20%3A)%3C%2Fimg%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-547897%22%20slang%3D%22en-US%22%3ERe%3A%20force%20enrollment%20on%20android%20device%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-547897%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F275685%22%20target%3D%22_blank%22%3E%40PatrickF11%3C%2FA%3E%20understood%20and%20you%20were%20totally%20correct.%26nbsp%3B%20I%20was%20just%20trying%20to%20expand%20on%20this%20for%20the%20next%20person%20to%20find%20the%20thread.%20%26nbsp%3B%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%20for%20adding%20to%20the%20community%20knowledge.%20It%20is%20appreciated.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Frequent Contributor

Hello,

 

i'm facing the following behavior and try to understand why this happens.

When a special user is signing in to Outlook for Android the following message appears:

 

"Help us to ensure the safety of your device.

To continue, you need to install the Intune Enterprise Portal App and register your device. This app helps you better protect organizational data."

 

I have no idea, why the device seems to be enforced to register in Intune. All the other devices in our company behave normal. (normal in my understanding ;)

Normal means: App Protection Policies are applied when using e.g. Outlook on an unregistered device.

 

Any idea is appreciated. :)

Patrick

11 Replies

@PatrickF11  On Android, the Intune Company Portal app is required to enforce app protection policies. End-users do not need to enroll their device, but the app is still required .

 

https://docs.microsoft.com/en-us/intune/end-user-mam-apps-android#access-apps

That is confusion reported to Microsoft log time ago.
On iOS user will be asked to install MS Authenticator ap which is ok.

But on Android they asked to use Company portal which is confusing. I already faced an issue with users who saw message to install Intune app an just aborted configuration because they didn't want to enroll phone. So on Android it is really essential to explain difference between Device Registration and Device Enrollment.

@eglockling Just to make it clear to me:

When i use an Android device and i did not have the Company Portal app installed, no app protection policy is applied? And: To apply the app protection policy the user is forced to install the intune company portal app. (no need to register within the app, right?)

So that means, once i have app protection policies set up for android devices, no user is able to use e.g. outlook, until he/she has the intune company portal app installed, because the Outlook app is covered by an app protection policy, right?

@Alexander Vanyurikhin You're right, that is really confusing..

What do you mean with "difference between Device Registration and Device Enrollment."

How can i register a android device without enrollment? Or do you mean: When the user only has the company portal app installed and not configured, this is registration. When the user has signed in to company portal app and went through the process, the device is enrolled.

@PatrickF11  That's correct.

Solution

@PatrickF11  You can sign-in to the Company Portal app on a device to register it, just don't complete the enrollment. There should be an option to "postpone" after signing-in. The Authenticator app is no longer required on iOS to enforce app protection policies, it is enforced by the mobile apps themselves.

@eglockling Thank you for your reply.

A quote from MS:

However, the user does not have to launch or sign into the Company Portal app before they can use apps that are managed by app protection policies.

So it seems not be necessary to sign in.

But what for should a user sign in, then?

 

Edit:

What i just tested: When a user has outlook already configured and i'm going to rollout the app protection policies the user isn't prompted to download the company portal app. And: The user isn't using the app protection policies and feels wonderfully free using outlook for android without any reglementations. :\

@PatrickF11  Thanks for the follow-up. Good to know that the sign-in is not required.

"because the Outlook app is covered by an app protection policy, right?"
Just posting for the sake of clarity for others, not necessarily specific to your scenario, Patrick.
Outlook is covered by app protection policies if they assigned to that user group the end user is a member of. The Intune SDK is built-in to Outlook, but nothing is "activated" until a policy is applied.

@Steve Bucci Thank you for your reply. Thats why i said "...once i have app protection policies set up for android devices.."

 

Of course this is not the "fault" of intune. The admin should consider of the policies used, of course. :)

@PatrickF11 understood and you were totally correct.  I was just trying to expand on this for the next person to find the thread.  

Thanks for adding to the community knowledge. It is appreciated.

Related Conversations
Extentions Synchronization
Deleted in Discussions on
3 Replies
Tabs and Dark Mode
cjc2112 in Discussions on
36 Replies
flashing a white screen while open new tab
Deleted in Discussions on
14 Replies
Stable version of Edge insider browser
HotCakeX in Discussions on
35 Replies
Security Community Webinars
Valon_Kolica in Security, Privacy & Compliance on
9 Replies