Android enterprise corporate owned dedicated shared devices

kevin deleux 36 Reputation points
2022-12-21T07:56:03.23+00:00

Hello all

We have a problem with our dedicated devices (kiosk) shared mode on Android devices.
We use the kiosk deployment of android devices for several purposes trough Intune-Endpoint manager. ( apprx 300 devices now) all working fine.

For specific use case we need to enroll an amount of devices (on this moment 50 but that will grow) in Azure AD shared device enrollment profile due to use of token.
The enrollment token is based on corporate-owned dedicated devices with Azure AD shared device mode.
Managed home app is adjusted for enforcing log on, time out, pin code ….
Also the MHS options in the device configuration profile are active.
We use the option to wipe all cached data on these devices.

Our problem is:

  • Some apps are working like expected, after a user log on, the SSO option works and when logging off the account is deleted in the app and no data remains in that app .
    o Examples: Office suite 365 android app (including word, excel, powerpoint and onedrive). Teams works perfectly
     Examples where the data and user account remains logged on: Sharepoint app, Outllook app (exchange is hybrid in our environment)
    Outlook: user data is deleted and not directly accesible but the mail account of the user is still there, if you click on it it will ask to logonn with that account. you can select another account but it needs to enforce wipe account when logoff.
  • Powerapps: deletes the user account after logoff but SSO doesn't work.

So when 1 user is logged on, he or she can use all apps on the device. When logging off, and giving the device to a colleague, the next user can logon but still see the personal data of the colleague (first logged on) in the outlook, and sharepoint app.
Word app and excel are no problems as described above.

We used app configuration profiles as well but they doesn’t seem to work like expected.
The biggest problem is the remaining data in the app(s). Sharepoint is the main problem, thats in fact the most important app we will need.

Desired situation:
An overlay logon screen (working at the moment), SSO on all apps when logging on. And removing all data from apps (account logout- not working on several apps)
Situation like: https://www.youtube.com/watch?v=y8fhA-FakSA
Used apps for these situation like mentioned: office suite + powerapps, sharepoint and a couple in house built apps (they already have the wipe data function build in and tested, and working fine).

There is also the camera app and gallery app. if someone knows how, we would like to wipe that data as well when user is logging off. but i gues we need and gallery app that have SAML built in...

We also built some app configuration pofiles but it doenst work like expected as well. do we need a json config for this matter to deploy in an app configuration policy/profile inside Intune.. or...

We used these links for information:
https://learn.microsoft.com/en-us/azure/active-directory/develop/msal-shared-devices

https://www.petervanderwoude.nl/post/android-enterprise-corporate-owned-dedicated-devices-and-azure-ad-shared-device-mode/

https://www.inthecloud247.com/getting-started-with-android-enterprise-dedicated-devices-with-aad-shared-mode/

Thank you for providing support on this matter.
Kind regards

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
242 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,270 questions
{count} votes