Share via

Personal Android Enterprise WiFi Configuration Profile

Anonymous
2023-01-05T12:36:57.64+00:00

Have set up a Personal Android Enterprise Wi-Fi Configuration Profile with a Dynamic Device Group Assignment based around it being a personal device and the Android Operating System.

My expectation was that when I enrolled the BYOD Android Enterprise work profile on my BYOD Android, it would at the same time push the Wi-Fi Config profile to said device.

However it isn't, it's just sitting there doing nothing (See Screenshot).

Bit of a naff question but does the device need to be in the vicinity of the SSID to push down to the Android Device? My thoughts are that it should push down to the phone on enrollment or during the 8 hour sync.

Any ideas, gratefully received.

Microsoft Security | Intune | Enrollment
Microsoft Security | Intune | Other
{count} votes

7 answers

Sort by: Most helpful
  1. Anonymous
    2023-01-09T08:21:38.23+00:00

    When you say corporate owned with work profile, are you referring to a device bought by the employer and the loaded with the work profile?

    Secondly, if you are using Personally owned profile, why wouldn’t you want it to access WPA2 authentication on the device?. It seems a bit odd that this option is precluded as they are connecting to the organisations WPA enabled WiFi networks.

    Finally tried the basic route for Fully, Managed, Dedicated, Corporate Work profile wifi option,it just got stuck in PENDING and would push down to the android device.


  2. Anonymous
    2023-01-07T13:23:44.603+00:00

    @Crystal-MSFT
    Nope still not being pushed down to BYOD Android.

    Did noticed had selected 1. Fully, Managed, Dedicated, Corporate Work profile wifi option rather that the 2. Personal Work profile wifi option.

    Did convert one of my WiFi config profiles to option 2, however all it asked for was SSID and whether the SSID should be hidden, No request to add WPA Pre-shared key.

    This did however push the SSID down to the BYOD Android, but unsure how it works if your not providing a password!


  3. Anonymous
    2023-01-06T15:53:24.707+00:00

    @Konstantinos Passadis

    1. Dynamic Device Group WLP BYOD Android Devices show Android Device on Intune as a Member as expected.
    2. Dynamic Device Group WLP BYOD Android Devices is in Included Assignment section only. There is nothing in the Exclude Assignment Section that would cause a problem.
    3. Device Assignment report for the 2 WiFi configuration Profiles show as pending and have for the last 2 days, so NO latency issues,
      @Crystal-MSFT
    4. On Android >Settings > Advanced > Managed Networks, neither WiFi SSID showing up.
    5. Yes WiFi profile have got the stated Group Assingment above.

    Finally as I said last time have got this working once, then removed the Work Profile from Android and tried again, noticed on 3/1/2023 an android enrolment failure. Intend to remove the work profile and retry.

    Will report back.

    0 comments No comments

  4. Crystal-MSFT 54,216 Reputation points Microsoft External Staff
    2023-01-06T01:44:20.93+00:00

    @Anonymous , Thanks for posting in Q&A. From your description, I know we have created a dynamic device group and assign WiFI profile to this group. But the WiFI profile is not applied after the enrollment. If there's any misunderstanding, feel free to let us know.

    For the WiFI profile will not apply immediately after the enrollment. on my point of view, this is because when we enroll the device, the device record in both AAD and Intune will be created and refer. For Dynamic device group, when a new device satisfies the rule join the organization, it may take some time like 30 minutes or longer to populate. To check if the member is added, you can check the members of the device group. Here is a link with more details for the reference:
    https://learn.microsoft.com/en-us/azure/active-directory/enterprise-users/groups-troubleshooting#troubleshooting-dynamic-memberships-for-groups

    After the device is added into the device group, then the device will apply the policy during its check in time. This will also cause some time delay. You can read more information with the check in estimated in the following link:
    https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-troubleshoot#how-long-does-it-take-for-devices-to-get-a-policy-profile-or-app-after-they-are-assigned

    Therefore, in our situation, the Intune WiFi profile will not be applied immediately after the device enrolled. We need to wait some time.

    Hope the above information can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  5. Konstantinos Passadis 19,691 Reputation points MVP
    2023-01-05T12:47:37.083+00:00

    Hello and welcome to Microsoft QnA!

    I would suggest first of all review : https://learn.microsoft.com/en-us/mem/intune/configuration/device-profile-assign

    and check the Support Matrix . Can you apply filters instead of Dynamic Groups ? As you can see it is Partially Supported.

    Also does the Wi-Fi appear on the Mobile ? Does it work when the user clicks on it?

    And first of all , make sure the profile is assigned !

    Please mark the answer as accepted if it helped and upvote !

    Thank you!

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.