android
75 TopicsMicrosoft Managed Home Screen: Unwanted Samsung One UI 8.0 Elements Appearing
Hello Tech Community, Our organization is currently deploying a configuration in Microsoft Intune using a Corporate-owned dedicated device enrollment profile. We’ve applied a device restriction policy to configure Samsung tablets in Multi-app Kiosk mode, with Managed Home Screen set as the launcher. Instead of using an app configuration policy, Managed Home Screen is configured through the device restrictions policy. We’ve left the device navigation options unconfigured, which should hide the following UI elements: Android Overview button Android Home button Android App drawer Once all policies and required apps are installed, Managed Home Screen successfully acts as the launcher for end-users to sign in. Overall, this works well; however, we’ve encountered an intermittent issue: After multiple lock/unlock cycles, the navigation bar sometimes reappears, showing the Overview, Home, and App Drawer buttons. This allows users to access background apps that are not exposed through Managed Home Screen, which defeats the kiosk experience. Device details: Samsung Galaxy Tab S10 FE Android 16, One UI 8.0 Managed Home Screen version: 2.2.0.107721 Has anyone experienced this behavior or have recommendations to prevent these UI elements from reappearing? I’ll gladly provide additional details about our configuration if needed. Thank you!477Views6likes2CommentsManaged Home Screen Woes
Setting up a Company Owned Dedicated (kiosk) Android device can be a bit challenging to get just right. After several hours of reading Reddit, Microsoft, and Personally owned blogs and threads, I figured I would consolidate everything I have found to hopefully have this show up on someone else's Google results. (Main link for Managed Home Screen Configuration: https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-managed-home-screen-app ) Calling issues with Managed Home Screen The Issue: Devices were able to receive phone calls, but the only notification was in the default system's notification tray; this was while the device was locked and unlocked. This posed an issue as we would like to 1) disable the default system tray and 2) We need at least the phone to light up when it was locked to let the users know they're getting a call. The Solution: After researching it is my assumption that the underlying issue is that while the phone is managed, and enrolled as a Company Owned Dedicated Device, for some reason the UI elements are NOT identified as managed items. So the administrator must deploy the following applications as Android Enterprise System Apps and set them as required installs: com.samsung.android.incallui --- I named this Call UI, Publisher Android com.android.server.telecom --- I named this Telecom (1 of 2 Req for Phone App), Publisher Android com.samsung.android.app.telephonyui --- I named this Telephony UI (2 of 2 Req for Phone App), Publisher Android (Yes, these are probably not the "Android Designated Application Name" but that's what they're staying as in my tenant.) That's it. Done. Phone was able to receive calls with the normal quarter of the top screen notification, as well as a full screen notification if the device was locked. However, some previous research also let me to these other items that may help someone else from googling: The Android Phone App Package ID / Android Phone App Bundle ID / Samsung Phone App is: com.samsung.android.dialer --- I named this Phone, Publisher Samsung (unsure for Google, Motorola, etc phones, this works for Samsung) This needs to be set as required as well, and assumedly placed on the managed home screen for the user to make calls (unsure if it is needed to receive calls only... if you have some type of use case for that?). Most predominant links relating to the issue: Article 1: https://www.reddit.com/r/Intune/comments/t427kv/shared_android_phonecalls_from_kiosk_mode/ Article 2: https://www.reddit.com/r/Intune/comments/vxw8xn/comment/ifylsaz/?utm_source=share&utm_medium=web2x&context=3 Managed Home Screen Conflicts App Configuration Policies currently don’t really show you any information as to why or what a conflict is; just that it’s conflicting (thanks, Microsoft). Some common issues I’ve seen around is that while some configurations are available in both the Device Configuration Profile and the App Configuration Policy; you should not apply these settings in both places (see the tables of configurations on the Microsoft doc for Managed Home Screen at the top of this article). Personally, I like having the configurations setup as: Managed Home Screen App Config Policy: Configuration Key Value Type Configuration Value Exit lock task mode password string 123456 MAX time outside MHS integer 600 MAX inactive time outside MHS integer 180 Enable MAX time outside MHS bool TRUE Enable MAX inactive time outside MHS bool TRUE Enable easy access of debug menu bool TRUE Define Theme Color string light Applications in folder are ordered by name bool TRUE Application order enabled bool TRUE Device's serial number choice {{SerialNumber}} Show device name bool TRUE Show Device Info setting bool TRUE Show Volume setting bool TRUE Show Flashlight setting bool TRUE Show Bluetooth setting bool TRUE Show Managed Setting bool TRUE Show Wi-Fi setting bool TRUE Battery and Signal Strength indicator bar bool TRUE Set device wall paper string https://i.imgur.com/OPlCeFG.jpg Lock Home Screen bool TRUE Enable notifications badge bool TRUE (Exiting Kiosk mode is then within the Device Managed Settings > i > Exit Kiosk Mode with the ‘Exit lock task mode password’ pin.) Dedicated Device Configuration Policy: (In my experience, this is an overview of the settings that should / shouldn’t be set with Managed Home Screen. This is not all the settings, that’s a lot of typing. But this will give you a good start. I am sure not all of these affect the Managed Home Screen as well, but at least the ones under Device Experience do.) General: Permission Policy – Default Date and Time – Block Factory Reset, Status Bar – Blocked Skip first hints – Enable Power Button Menu – Block System Error Warnings – Allow Enabled System Navigation Features – Home and overview buttons System Notifications and Information – Show both Device Experience: Enrollment Type – Dedicated Device Kiosk Mode – Multi-App Custom Layout – Enable (Note: all of these apps need to be deployed and set as required) App Notification Badges – Enable Virtual Home Button thru Wi-Fi Configuration– ALL Not Configured (as these are configured within the App Configuration Policy!) Bluetooth, Flashlight, Media, Quick access to device info – Enabled Managed Home Screen Background I found that the best place to configure this is only within the App Configuration Policy. The main issue everyone seems to face is that the image URL must end with a ‘.jpg’. This is very easily overcome; find an image on Google, Download it, Go to Imgur, Upload it (watch your ad), Right click it afterwards, then click Copy Image Link. Boom imgur.com/somerandomletters.jpg Finding the Android App Identifier Honestly, this is a lot more complicated than it needs to be. Note: Adding the Managed Home Screen app to the Home Screen shows up as Managed Settings and works great. Here’s a list of the common ones: App Name Store URL App Identifier Calendar https://play.google.com/store/apps/details?id=com.samsung.android.calendar com.samsung.android.calendar Camera https://play.google.com/store/apps/details?id=com.sec.android.app.camera com.sec.android.app.camera Clock https://play.google.com/store/apps/details?id=com.google.android.deskclock&hl=en-US com.google.android.deskclock Gallery https://play.google.com/store/apps/details?id=com.sec.android.gallery3d com.sec.android.gallery3d Google Play Store com.android.vending Microsoft Intune https://play.google.com/store/apps/details?id=com.microsoft.intune&hl=en-US com.microsoft.intune Managed Home Screen https://play.google.com/store/apps/details?id=com.microsoft.launcher.enterprise&hl=en-US com.microsoft.launcher.enterprise Microsoft OneDrive https://play.google.com/store/apps/details?id=com.microsoft.skydrive&hl=en-US com.microsoft.skydrive Microsoft Outlook https://play.google.com/store/apps/details?id=com.microsoft.office.outlook&hl=en-US com.microsoft.office.outlook Microsoft Teams https://play.google.com/store/apps/details?id=com.microsoft.teams&hl=en-US com.microsoft.teams Phone https://play.google.com/store/apps/details?id=com.samsung.android.dialer com.samsung.android.dialer Samsung Notes https://play.google.com/store/apps/details?id=com.samsung.android.app.notes&hl=en-US com.samsung.android.app.notes Settings https://play.google.com/store/apps/details?id=com.android.settings com.android.settings There were a LOT of articles and treads I read about these issues and I cannot possibly find them all again to post here. But here are a few to try and give credit: https://learn.microsoft.com/en-us/mem/intune/apps/app-configuration-managed-home-screen-app https://www.reddit.com/r/Intune/comments/t427kv/shared_android_phonecalls_from_kiosk_mode/ https://www.reddit.com/r/Intune/comments/vxw8xn/comment/ifylsaz/?utm_source=share&utm_medium=web2x&context=3 https://github.com/petarov/google-android-app-ids (Some of these are incorrect for my use cases (needed Android apps not Google Apps)) https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work?WT.mc_id=Portal-Microsoft_Intune_DeviceSettings https://learn.microsoft.com/en-us/mem/intune/apps/apps-ae-system#enable-a-system-app-in-intune15KViews4likes2CommentsAzureADSharedMode - Teams without PIN
I prepared in Intune profile for Samsung devices in kiosk mode with a multi-app setting. I added Teams, Outlook, Egde and Managed Home Screen as apps. In addition, I also created a configuration profile for the Managed Home Screen application in which I set that it is necessary to configure a PIN for the session. I also set the Require PIN code after returning from screen saver option. Everything works great until the user leaves the Teams app on or someone calls the user logged into Teams. At this point, no PIN is needed to unlock the device. You can easily access Teams of the logged-in user. The user is asked for the session PIN only when he wants to switch to another app. I didn't set screen lock in android settings because in my opinion it's pointless since the device is in shared mode. Have you encountered anything like this? It poses a potential security risk if a logged-in user leaves the Teams app open, puts the phone down and walks away from it, and at that moment someone calls the phone and the person who picks it up without probelm gets access to the logged-in user's teams.560Views1like2CommentsOutlook and Android 9 (Pie)
Since updating to Android 9, I'm unable to send unmanaged content to Outlook (Work profile) as an attachment. The device configuration policy is set so "Apps in work profile can handle sharing requests from personal profile", but Outlook generates the following: ERROR: Unable to add attachment due to IO error Other managed apps in the work profile are able to receive unmanaged content from the personal profile, and devices running Android 8 are still able to use Outlook (Work profile) to receive unmanaged content. I've opened a ticket with Microsoft, but was wondering if anyone else come across this?4.8KViews1like5CommentsAndroid : SSO Application Protection Policy - Edge
When a user launches our Play Store Application, authenticates (SSO, SAML2) on the app, they are presented with the form, enter the username and password, click sign in, and then the user is presented with "You can't get there from here" and a link to "Launch in Edge". When "Launch in Edge is clicked the user receives "ERR_UNKNOWN_URL_SCHEME" in the application. Outside of the application, Edge is launched, and is directed to login.microsoftonline.com:443, then is redirected to our home page/user control panel of our browser based application, not the application running on the device. It seems like Intune has defined our application as being browser based. Is this due to the application not interpreting the URL 'https-intunemam://login.microso.....' ? Would an exception be needed for our application to use the native browser? Any direction would be helpful.2.9KViews1like2CommentsVideo playback not working within Android Enterprise
Hi, we're working on an issue, we can't solve right now. Let me outline this in detail: The Android device is managed within the deployment type COBO. (Fully managed user device) The Apps like OneDrive are protected with App Protection Polices which allow to save files to OneDrive, Sharepoint and to local device storage. The Gallery App (com.sec.android.gallery3d) is published and installed as an Android Enterprise system app. Downloading a video file from onedrive is working because APP is allowing it. Playing this video File inside OneDrive is working. On to the issues: Playing this video File inside the Files- App is not working. ("There is an unknown error") Playing this video File inside the Gallery- App is not working. (The thumbnail is only a grey squared picture with an exclamation mark.) Sometimes, directly after downloading it is playing for about 5 seconds, afterwards theres another popup stating some codec issues. (No matter what type of video is used). We've tested this with different smartphone vendors and different M365 tenants already. Are there any ideas or do you experienced similar issues? Any feedback is highly appreciated. Kind regards Patrick1.3KViews1like3CommentsAndroid Enterprise Dedicated - Import PKCS Certificate
My organization is transitioning to Dynamics 365 and is now onboarding our Android fleet to Microsoft's "https://docs.microsoft.com/en-us/dynamics365/supply-chain/warehousing/install-configure-warehouse-management-app". This application requires that we distribute a shared private certificate to our devices to authenticate, however this appears to be something not possible with Android Enterprise Dedicated enrollment. Intune's https://docs.microsoft.com/en-us/mem/intune/protect/certificates-imported-pfx-configure profiles appear to be limited to users only, and since these are dedicated enrolled devices, one does not appear to exist. Is anyone familiar with a UPN I'm not seeing that is assigned to Android Dedicated devices or an easier way to do this? When setting up a new Imported PKCS I have the option to specify a user UPN, and the documentation appears to show this as a supported scenario. Any help would be greatly appreciated!1.5KViews1like1CommentIssues with Android Enterprise enrollment in Intune (Corporate Identifiers; enrollment tokens)
I'm writing this post to draw attention to some issues I've come across with Intune recently. 1.) The first issue is that the Corporate Identifiers (IMEI's/serial numbers) are not documented accurately (Identify corporate-owned devices with IMEI or serial number ). It should be nice and clear in the docs articles, and unfortunately it's just not, and instead is misleading. IMEI DOES work to make Android Enterprise - Work profile devices be marked automatically upon enrollment as "Ownership = Corporate". 2.) Unfortunately, IMEI / SN cannot be used for the same purpose when enrolling devices as Fully Managed. This is a bit of a problem, because of the next issue.... 3.) The enrollment token for Android Enterprise Fully Managed is non-revocable / non-expiring. Meanwhile the other two corporate-aimed enrollment types - Dedicated / COPE - have their enrollment profile tokens both auto-expiring and revocable. The docs articles explain when you'd want to revoke the tokens: Revoke tokens You can immediately expire the token/QR code. From this point on, the token/QR code is no longer usable. You might use this option if you: accidentally share the token/QR code with an unauthorized party complete all enrollments and no longer need the token/QR code But strangely, the Fully Managed enrollment type is left in the dark with no protection either from Corporate Identifiers, or revocable/expiring tokens. Might as well point out here too that Intune's Enrollment Restrictions do not help with Fully Managed either. So essentially anyone can BYOD to Android Enterprise Fully Managed, as long as they're allowed to enroll any number of devices and haven't exceeded their maximum allowed number of devices. I do get that BYOD devices enrolled as Fully Managed would be a fairly low threat, but it is still unclear why this gap has been left open.3.8KViews1like0CommentsAndroid App not listing in Company portal app on samsung device
I have uploaded a managed google play private app to my intunes account and added to the android device which is enrolled using the same account. I get the status in portal that waiting for install status. But the app is not shown in portal app on the device. None of the apps are shown in portal app of the device. Can you please help me through what has to be done to show the apps. I tried using android work profile and also play store intunes portal.Any help will be appreciated as i am blocked with the process. Thanks Sindhu25KViews1like9Comments