Android Enterprise (COPE) - Device password not prompting

Steel Contributor

Hi,

i'm experience the following weird problem:

When enrolling Android devices with android enterprise COPE mode (fully managed with work profile) the password setup prompt isn't showing up for the end-user.

Afterwards the device is, of course, not compliant, because we want a passcode to be present.

 

Reffering to the these MS Docs:

  • Device default (default): Most devices don't require a password when set to Device default. 
    If you want to require users to set up a passcode on their devices,
    configure this setting to something more secure than Device default.

-> Of course i've already configured a more secure type than default (in this case Numeric).

By the way: All the other configuration profiles works just fine.

 

Any idea on how to deal with this?

At this moment i'm using a workaround with Conditional Access: When not compliance you can't do anything with the M365 world in your hands, unless you're device gets compliant. :D

 

Thanks in advance.

Greetings,

Patrick

5 Replies
Anyone? This should be really important to anyone, isn't it?
Just to "close" this one: I've found the solution by myself. (And it is quite logical. ;)
The Assignment of the corresponding profile was set to a dynamic group. While the initial setup flow the device object isn't in the corresping group, yet. Seems legit, isn't it?

@PatrickF11 

 

Did you had to wipe the device through intune and perform an enrollment via QR again? I've got the same issue. Out of the box device does not get the password prompt for the container while enrolling. When I wipe an enrolled one it gets the prompt. 

 

I'm also using a dynamic group for the devices. 

@mitcheman88 

Yes, i've got the exact same issue.

Already enrolled devices won't get the passcode. It seems that this only happens during enrollment.

Therefore i've switched to all device assignment for the passcode profile. (The few existing devices were setup manually with a device pin.)

@PatrickF11 

 

I think I have found a manual work around for this. 

When the device is enrolled and ready to go do the following: 

Swipe the screen down twice so you can see the buttons with the functions (wifi, BT, LTE etc). Swipe right untill you see work profile. Press and hold that button. You will be transported the settings of the work container. There is a switch (on samsung) that says: Use one lock (translated from dutch). Switch this to off, setup a Pin and you have a pin active for the work container. I have set my inactivaty profile to 1 minute  within intune and this seems to be enforced when I enable/setup the pin.

 

Hope this could be helpfull for you. I'm going to write this step down in the enrollment manual. So the interns over at the customers can do this for the employees.