Not getting restriction related profile setting for Android devices in Intune

Nidhi Priya 661 Reputation points
2022-11-10T09:48:12.7+00:00

Hello Expert,

I need to apply below profile setting to Android devices, how to apply below setting to Android devices from Intune

Settings in UEM:

  1. Allow Outgoing Phone Calls
  2. Allow Send/Receive SMS
  3. Allow Keyguard UnRedacted Notifications
  4. Allow Safe Boot
  5. Allow disabling Application Verification
  6. Allow Wallpaper Change
  7. Allow System UI (Toasts, Activities, Alerts, Overlays)
  8. Enter list of package names separated by commas. Gmail and Boxer are allowed by default
  9. Allow System UI (Error Dialogs)
  10. Allow Auto Fill
  11. Allow work apps to access documents from personal apps
  12. Allow Modifying Applications in Settings
  13. Allow personal apps to access documents from work apps
  14. Allow Uninstalling Applications:
  15. Skip user tutorial and introductory hints
  16. Allow Accessibility Services
  17. Restrict Input Methods
  18. Allow USB Debugging
  19. Allow Mounting Physical Storage Media
  20. Allow Backup Service
  21. Allow Bluetooth Changes
  22. Allow VPN Changes
  23. Allow Mobile Network Changes
  24. Set Maximum Days for Disabling Work Profile
Microsoft Security | Intune | Configuration
Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
0 comments No comments

Answer accepted by question author
Crystal-MSFT 54,326 Reputation points Microsoft External Staff
2022-11-11T02:40:06.287+00:00

@Nidhi Priya , For your settings here are my findings:

1, Allow Outgoing Phone Calls
Only find the following setting with outgoing Phone calls.

Fully managed and dedicated devices
Notification windows: When set to Disable, window notifications, including toasts, incoming calls, outgoing calls, system alerts, and system errors aren't shown on the device

Personally owned with work profile:
Work profile notifications while device locked: Block prevents window notifications, including toasts, incoming calls, outgoing calls, system alerts, and system errors from showing on locked devices

2, Allow Send/Receive SMS,
Android device administration
SMS/MMS messaging (Samsung Knox only): Block prevents text messaging on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using SMS and MMS messaging.

3, Allow Wallpaper Change
Fully managed:
Allow user to modify wallpaper: Enable allows users to change the wallpaper image.

4, Allow System UI (Toasts, Activities, Alerts, Overlays)
Fully managed:
Enable launcher feed: Enable turns on the launcher feed, which shows calendars, documents, and recent activities.

5, Allow Keyguard UnRedacted Notifications, Allow Safe Boot, Allow disabling Application Verification, Enter list of package names separated by commas. Gmail and Boxer are allowed by default, Allow System UI (Error Dialogs),
No

6, Allow Auto Fill, Allow work apps to access documents from personal apps
Android device administration
Autofill (Samsung Knox only): Block prevents the browser from automatically filling in text. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Autofill.

Work profile
Data sharing between work and personal profiles: Choose if data can be shared between work and personal profiles.
Device default: Intune doesn't change or update this setting. By default, the OS might prevent users from sharing data in the work profile with the personal profile. Data in the personal profile can be shared in the work profile.

7, Allow Modifying Applications in Settings
No.

8, Allow personal apps to access documents from work apps
Data sharing between work and personal profiles: Choose if data can be shared between work and personal profiles.
No restrictions on sharing: Enables sharing across the work profile boundary in both directions. When you select this setting, apps in the work profile can share data with unbadged apps in the personal profile. This setting allows managed apps in the work profile to share with apps on the unmanaged side of the device. So, use this setting carefully.

9, Allow Uninstalling Applications, Skip user tutorial and introductory hints, Allow Accessibility Services, Restrict Input Methods, Allow USB Debugging, Allow Mounting Physical Storage Media,
No.

10, Allow Backup Service, Allow Bluetooth Changes
Android device administration
Google backup (Samsung Knox only): Block prevents devices from syncing to Google backup. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using Google backup.
Fully managed, dedicated, and corporate-owned work profile devices
Bluetooth configuration: Block prevents users from configuring Bluetooth on the device

11, Allow VPN Changes, Allow Mobile Network Changes, Set Maximum Days for Disabling Work Profile
No

Here are the links with device restrictions policies for your reference:
https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-for-work
https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android-enterprise-personal
https://learn.microsoft.com/en-us/mem/intune/configuration/device-restrictions-android#cellular-and-connectivity

For the settings that are not existing in Intune, you can feedback to Intune uservoice to see if we can get these features in the future:
https://feedbackportal.microsoft.com/feedback/forum/ef1d6d38-fd1b-ec11-b6e7-0022481f8472

Thanks for your understanding.


If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

Was this answer helpful?

0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.