Android Enterprise - No prompt to create work profile (personnally owned)

Zac Schramm 21 Reputation points
2021-10-14T16:40:35.937+00:00

Hi,
I have a very strange issue which is really testing my patience.

Previously I used app protection policy and am looking to move to work profile. I have a new group 'new' of users that I assigned an enrollment restriction to allow Android Enterprise personally owned to enroll. When I sign in under users in this group, a prompt to create a work profile is raised, great!

The issue is I want to also pilot it in my daily usage and I was not a member of this group. So I have another group which is a 'pilot' group and I added this to the enrollment restrictions, device compliance, and device configuration policies. I deleted all the microsoft apps, signed out of everything MS related. I also deleted the device registration in Azure AD. When I log back into the company portal I don't get a prompt to create a work profile, it signs in fine.

If I try to sign-in via outlook, the login is blocked by conditional access since I require a compliant device for Office 365 apps. This just asks me to download and install the company portal which I am doing already.

If I sign in to the company portal under an account in the newly configured 'new' group on that same device, I do get a prompt for the work profile. So the issue is not the device, software version, etc, it is clearly the user / group settings. When I downloaded the company portal log file it said Enrollment Postponed. I waited overnight and no difference.

I don't really understand what could be blocking this as I went through all the settings and all the documentation says this is enabled by default already. The only real differences between these groups right now is that the 'old' group has MAM policies for mobile, and MDM for win10 whereas the new group has MAM-WE for win10, but that should be unrelated.

Any thoughts are appreciated.

Zac

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,247 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,334 questions
0 comments No comments
{count} votes

Accepted answer
  1. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2021-10-15T01:48:36.38+00:00

    @Zac Schramm , Agree with RahulJindal, we can firstly go to Troubleshooting+support, select the user we test and check the enrollment restriction to confirm if it is applied.
    140751-image.png
    Meanwhile, we can uninstall the company portal on the device and reinstall to try again to see if it can enroll successfully.

    If there's any update, feel free to let us know.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. Rahul Jindal [MVP] 9,146 Reputation points MVP
    2021-10-14T22:22:24.663+00:00

    Go under troubleshooting on the MEM admin portal and look for the policies applied against the user account you are using.

    0 comments No comments

  2. Zac Schramm 21 Reputation points
    2021-10-15T03:04:20.813+00:00

    Thank you both for your help, this was one of the issues and I discovered that I had a enrollment restriction policy that took priority over the one I wanted. (Not realizing that block was different from "Not configured" or similar options throughout other policies). So after resolving that I do have the correct restrictions applied to that user account now. I can also see that no app protection policy is applied to the account as well, so that is correct.

    After this I again confirmed that a 'new' group user still gets a prompt for a work profile right away where in same app instance 'old' group user still does not and is able to sign in successfully to company portal. I also uninstalled the app and reinstalled.

    I have a conditional access policy which I am trying to GRANT access to all cloud apps based on requiring device to be marked compliant (for android only). According to MS docs (https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/howto-conditional-access-policy-compliant-device) note at the bottom says blocking all cloud apps still allows device to enroll with intune. What is now also driving me nuts is I have 2 CA policies applied to this sign-in, the one requiring compliant device fails, but doesn't block login.

    I figured this policy would block login and then prompt for device enrollment perhaps. What am I missing here?

    140745-image.png


  3. Zac Schramm 21 Reputation points
    2021-10-15T14:41:16.89+00:00

    Crystal,

    Thanks, I didn't realize you could exclude these apps. However the policy is Failed currently and yet it allows the sign-in to succeed. So if we exclude intune (which according to that documentation link is not required) the policy will just be 'not applied', correct?

    140934-image.png

    140935-image.png

    I would also add that the company portal hasn't triggered the device to register either, even after waiting all night and trying again.

    What I really don't understand is how you trigger a device to register or MDM enroll. If I login to outlook app, the CA policy prevents this and outlook directs me to the google play store to install the company portal. As soon as I add the app protection policy back in, and try to sign-in to outlook, I get a prompt to register the device, so frustrating.... ;)


  4. Zac Schramm 21 Reputation points
    2021-10-21T17:43:23.19+00:00

    Okay so today I tried it again on the new phone and it worked! This time however I noticed a notification in the top right after signing into the company portal the was regarding setting up a work profile, so when I clicked it I got the prompt I was looking for.

    No further changes today besides deleting the device from AAD registration and disabling the app protection policy for this user.

    All resolved it looks like, thanks for both your help.

    Zac