Which Android enrollment profiles is most suited to my requirements?

Muneer Jahangeer 341 Reputation points
2023-01-20T13:33:02.9766667+00:00

I have a new requirement from business.,

The Android device must be fully managed (i.e., the Android device should only contain specified business apps. similar to kiosk multi-app). Permission is also required to deploy a custom apk app that is not published on the Google Play store.

Which enrollment profile is most suited to these requirements?

Tried below options with no success:

Corporate-Owned, Fully managed user device  - I gave this a try. Allow installation from unknown sources is enabled. I was able to instal the custom APK file, however the admin eventually erased it.

Corporate-Owned dedicated devices – "Allow installation from unknown sources Allow" was turned on. The apk file could be downloaded, however there is no instal option.

Corporate-Owned devices with work profile – Businesses want devices that can be fully managed and don't want to allow for personal usage.

Would you kindly assist someone in responding to my question?

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
235 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
874 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,331 questions
0 comments No comments
{count} votes

Accepted answer
  1. Ruud Gijsbers Rademakers 551 Reputation points
    2023-01-21T20:29:19.39+00:00

    Hi Muneer, depending on the additional requirements all three enrollment types will work. For the deployment of the custom APK, you can upload it to your Managed Google Play store.

    Navigate to Apps in the Intune portal, select add => Managed Google Play App

    User's image

    After clicking select, you can choose Private Apps on the left

    User's image

    Here you can upload your private apps

    User's image

    After uploading, you need to sync your store and after the sync you will be able to push the app to your devices.

    Regards,

    Ruud


2 additional answers

Sort by: Most helpful
  1. Crystal-MSFT 42,961 Reputation points Microsoft Vendor
    2023-01-23T01:25:09.2666667+00:00

    @Muneer Jahangeer, Thanks for posting in Q&A.

    In General, Android Enterprise enrollment has its own scenario to use. For Corporate-Owned, Fully managed user device, it is used for the work use and is single user device. For Android Enterprise dedicated, this is single use device. such as digital signage, ticket printing, or inventory management. For corporate-owned with a work profile, this is for corporate-owned device and user can access both personal data and work data. You can see more details in the following link:

    https://learn.microsoft.com/en-us/mem/intune/enrollment/android-enroll

    If the device is single user use and don't want any personal data, Android Corporate-Owned, Fully managed can be a good option. For this method, the app installation is only from Managed Google Play.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/android-fully-managed-enroll

    In general, there are three types of apps that are available with Managed Google Play:

    • Managed Google Play store app
    • Managed Google Play private app
    • Managed Google Play web link

    For Managed Google Play private app, these are LOB apps published to Managed Google Play by Intune admins. These apps are private and are available only to your Intune tenant. Maybe you can consider this kind app.

    https://learn.microsoft.com/en-us/mem/intune/apps/apps-add-android-for-work#managed-google-play-app-types

    Hope it can help.


    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.

    0 comments No comments

  2. Muneer Jahangeer 341 Reputation points
    2023-01-23T15:46:31.6233333+00:00

    Managed Google Play private (LOB) app publishing directly in the Microsoft Endpoint Manager admin center - Failed to upload few APKs files. Error : The package name xxxx is already used by another application.

    Managed Google Play private (LOB) app publishing using the Google Developer Console - I've followed the instructions from this page- [https://support.google.com/googleplay/android-developer/answer/9874937#zippy=, paid and joined in developer program,

    User's image

    When I followed the "publish to your organisation" guidelines,

    User's image

    In the Google Play Console, I don't see any options from steps 2 to 10,

    User's image

    Is my account is fully activated?