question

dilannanayakkara-8008 avatar image
0 Votes"
dilannanayakkara-8008 asked LuDaiMSFT-0289 commented

Doesnt work Restrcit copy and paste on COPE devices in Intune

Hi All,

I have enroll the one of test device as a Android Enterprise corporate-owned devices with work profile (COPE) and publish few manage apps. Then I have create a App protection policy with restrict copy&paste and assign it to the user group but it seems doesn't work so far.

I just want to restrict the copy&paste between applications.

appreciate the help on this.

Thanks,
Dilan

mem-intune-generalmem-intune-device-configurationsmem-intune-application-management
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

EswarKoneti-MVP avatar image
0 Votes"
EswarKoneti-MVP answered dilannanayakkara-8008 edited

Have you added the managed apps that are intune SDK supported?
Did you check the reporting for MAM protection policy if they are successfully applied to the user or not?
How is your MAM protection policy setting for restrict copy paste setting?

Thanks,
Eswar

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

HI @EswarKoneti-MVP,

Thank you very much for the reply.

Below are the managed apps which I have added.

82026-1.png

I have check under monitoring and seems app protection policy is yet to be applied. correct me if I am mistaken here. Can we apply the App protection policies to the COPE devices?

82037-4.png

Below are the MAM protection policy settings

82111-2.png

82049-3.png

@EswarKoneti-MVP I was wondering whether App protection policy is supporting for COPE devices or not?

Thanks again,
Dilan


0 Votes 0 ·
2.png (121.1 KiB)
3.png (107.7 KiB)
1.png (138.5 KiB)
4.png (60.4 KiB)
dilannanayakkara-8008 avatar image
0 Votes"
dilannanayakkara-8008 answered

Hi All,

[Update]

I have installed the outlook from personal Google play store for personal work space of Android device and it seems working fine. However if I deploy a Google managed Outlook via Intune to work profile it seems doesn't work so far. may be App protection policies will only be applied on personal work space.

So I was wondering is this the limitation of COPE (Android Enterprise corporate-owned devices with work profile) or is there any way that I can restrict share the data/copy&past from work profile applications which is reside in work profile space.

Thanks!
Dilan

5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered dilannanayakkara-8008 edited

@dilannanayakkara-8008 Thanks for posting in our Q&A.

App protection policy is supported for COPE devices. It seems that the app protection policy failed to be deployed to the COPE devices.

For this issue, could you please refer to the following article to validate the app protection policy?
https://docs.microsoft.com/en-us/mem/intune/apps/app-protection-policies-validate

If there is anything update, feel free to let us know.


If the response is helpful, please click "Accept Answer" and upvote it.
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@LuDaiMSFT-0289 thanks for the reply.

Are you mean Can we deploy the App protection policy on work profile apps or personal profile apps in COPE devices?

in my case App protection policy is working fine with Personal profile apps in COPE device. I was wondering whether app protection policies are support or not on Work profile apps.

Thanks,
Dilan

0 Votes 0 ·
LuDaiMSFT-0289 avatar image
0 Votes"
LuDaiMSFT-0289 answered LuDaiMSFT-0289 commented

@dilannanayakkara-8008 Thanks for your response.

For this issue, I have done the test in my lab. I deploy the app protection about the work profile app in the COPE device to my user group. The policy is deployed successfully and I can't copy and paste to unmanaged apps.

Given this situation, it is suggested to collect logs in the Android device.
https://docs.microsoft.com/en-us/mem/intune/apps/manage-microsoft-edge#use-edge-for-ios-and-android-to-access-managed-app-logs

With Q&A limitation, Q&A is not the best channel for such log analysis case. So we suggest to open a case to check on this. The following link describes how to open a case, we can refer to it:
https://docs.microsoft.com/en-us/mem/intune/fundamentals/get-support

Hope this issue will be solved as soon as possible.


If the response is helpful, please click "Accept Answer" and upvote it.

· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@dilannanayakkara-8008 You're welcome. Hope you will find the reason for this strange situation.

0 Votes 0 ·