Forum Discussion

tngvmd's avatar
tngvmd
Brass Contributor
Oct 22, 2024

Android 15 - CredentialProviderPolicy not surfaced by Intune

I have been having an issue with Android 15 devices. We use Authenticator as our password autofill provider. As soon as a device is updated from Android 14 to Android 15, the password autofill provider is no longer set and the setting to change it is 'blocked by work policy.' I have already tried removing all policies that apply to the devices (device config and device compliance policies) and factory resetting them. Simply having them enrolled as corporate owned fully managed devices causes this to happen. 

I raised the issue in the Android Enterprise community blog. A link to that is included below. Someone on that thread found that there is a policy in Android 14/15 called the credentialproviderpolicy. When that policy is blocked or unconfigured, this behavior happens. I cannot find anywhere in Intune where I can set this policy. It seems that it is allowed by default when managing Android 14 with Intune, but not set or blocked when the device switches to Android 15. 

Is there any way to specifically set a policy that is not reflected in the Intune UI? This is a blocker for being able to move more phones to Android 15. 

Link to Android Enterprise thread: https://www.androidenterprise.community/t5/admin-discussions/android-15-cannot-set-default-password-app/m-p/8827#M2105

Thanks,

Tom

10 Replies

  • tngvmd's avatar
    tngvmd
    Brass Contributor

    Is there any update on this? Not being able to set a password / passkey manager in Android is a significant security concern. 

  • tngvmd's avatar
    tngvmd
    Brass Contributor

    I agree. It is incredibly frustrating that this issue still persists. This is a significant security issue for us since people are resorting to keeping lists of user names and passwords in an unsecure manner to make copy and past for credentials easier. 

    • pinardm's avatar
      pinardm
      Copper Contributor

      Especially with Microsoft deprecating the autofill capabilities of Microsoft Authenticator, leaving all devices stuck with that policy without any way to switch to another provider.

  • HeathSFD's avatar
    HeathSFD
    Brass Contributor

    Hi folks,

    Sorry to necro this thread, but this issue persists.

    Google have identified this as a fixed bug on their end, as discussed here:

    https://issuetracker.google.com/issues/385775377?pli=1

    There is some further information here that pinpoints the area that we can't yet apply remediation to via Intune:

    https://www.androidenterprise.community/discussions/Conversations/android-15---cannot-set-default-password-app/8708

    The CredentialProviderPolicy setting is nowhere to be found in the available Intune policies for Fully-managed, Dedicated, and corporate-owned work profiles.

    It seems as if the ball is in Microsoft's court for this - has there been any traction on the issue?

    Thanks,
    H

  • kouhei-ioroi's avatar
    kouhei-ioroi
    Copper Contributor

    I am currently using ManageEngine and faced this issue while considering migrating to Intune in the future.
    I checked with Microsoft Intune support about this issue.
    It seems that the developers are already aware of the problem, and as of March 21, it has been reported that it will be fixed in a new feature in the second quarter of 2025 (April-June 2025).

  • pinardm's avatar
    pinardm
    Copper Contributor

    More than a year later, nothing to control this or work around it..

  • NexusEgo's avatar
    NexusEgo
    Copper Contributor

    Does anyone have an update on this issue or a workaround? We have recently started deploying Samsung S25 Ultras (Fully Managed Corporate-Owned) to select individuals and use Bitwarden. It appears to be blocked, with the same issue described above. This thread is four months old, but the issue persists as of March 2025.

Resources