Intune company portal enrollment fails after android 12 upgrade on my phone oppo reno 6 5G

Sahu, Nand 51 Reputation points
2021-12-30T12:39:33.667+00:00

Hi Sir/Madam,
I have an android phone called "OPPO reno6 5G" in which I was configured Intune company portal app to access my office email, it was working perfectly fine until I upgraded my phone from android 11 to android 12 by software update feature available in device.

After upgrade to android 12 my outlook mail started crashing so I removed the work profile, uninstalled the intune app, reinstalled it and tried to enroll my office email account but it fails at update device setting. I even reset my phone but still no luck.

I dig more and found below error on log.
It seems app is not getting some required internal permissions. It is not able to validate/check device compliance status as it always says "last checked: January 1,1 12.43 AM"

Please help me how to address this problem.

ERR_ com.microsoft.omadm.client.tasks.TemporaryOMADMClientExecutorTask 18749 01421 Caught exception while updating device policy java.lang.SecurityException: getPackagesForUid: UID 1010274 requires android.permission.INTERACT_ACROSS_USERS_FULL or android.permission.INTERACT_ACROSS_USERS or android.permission.INTERACT_ACROSS_PROFILES to access user .

ERR_ com.microsoft.omadm.client.tasks.TemporaryOMADMClientExecutorTask 18749 01443 Caught exception while running task request (startId = 1000001, TaskType=CheckComplianceAndEnforce [23]) java.lang.SecurityException: getPackagesForUid: UID 1010274 requires android.permission.INTERACT_ACROSS_USERS_FULL or android.permission.INTERACT_ACROSS_USERS or android.permission.INTERACT_ACROSS_PROFILES to access user .

161379-img1.jpeg161406-img2.jpeg161396-img3.jpeg

Microsoft Security | Intune | Enrollment
{count} votes

37 answers

Sort by: Most helpful
  1. Salo Rosencveig 1 Reputation point
    2022-02-03T22:29:20.23+00:00

    Hi @matrello ,

    I did some further investigation on that with my company Level 3, the issue that we are facing is not related to hardware information not being exposed in Android 12. We have tested this hardware information scenario with initial Android 12 beta releases and it has been supported by the Intune. So the information on the web on this information seems incorrect.

    Microsoft Intune is a SaaS solution and we cannot customize it according to our needs. The APIs which are used in MDM tools for device management are provided OEMs Google, Apple, etc. The new APIs are continuously being introduced with each new OS releases. According to feasibility MDM vendor use those API to implement features. We cannot make any additional customizations from any company that uses Microsoft Intune end.

    The issue which we are facing on our mobile devices is due to the custom OS which is present on our mobile device. Due to that custom OS, company portal application is not able get successful API call. We are not sure but this could be happening as device manufactures did not use the Google API with their Custom OS. (Maybe it related to the Chinese mobile companies OS we all reporting here)

    My company have already raised a Priority 1 ticket with Microsoft. Now we are waiting for the further comments on this from Microsoft and Google.


  2. BigCompanyEmployee 1 Reputation point
    2022-02-07T12:21:09.203+00:00

    Hello all,

    I got a new ColorOS Android 12 Update C43 including the January Security Patch. However in this Version the same Problem is happening.

    @matrello : You said you have C44 and it is also not fixed, so maybe we need to wait for C45 for it to be fixed?

    Do you know if there is a bug report somewhere at Google or OnePlus side so we can track the progress?

    Br,
    Stefan


  3. Alexis_P 1 Reputation point
    2022-02-10T15:36:09.787+00:00

    Hi,

    Same problem here with Oppo Android 12.

    0 comments No comments

  4. Nand Sahu 6 Reputation points
    2022-02-10T20:37:33.913+00:00

    Hello Everyone,
    There is no solution provided neither by phone manufacturer nor by Microsoft intune.

    The only solution is to downgrade your phone (for example on oppo reno6 downgrade to color OS 11 ) which automatically downgrade to android 11

    Let me know if anyone interested on downgrading their phone. I have a tool which support almost all major brand like one plus,realme,oppo,redmi,samsung ,lg etc. I can help to downgrade.


  5. Simon Burbery 691 Reputation points
    2022-02-12T11:49:27.287+00:00

    Hi Stefan, it may be because your are selecting a category rather than scanning a corporate work profile QR code. I did find a workaround but your IT may not want to change the setting... there is a default setting based on whether a device has been assigned a 'compliance profile'. The default is that a device is 'Compliant' which allows use of the device while the policies are applied in the background. It's recommended to change this to 'Not compliant' so that the policy has to apply and confirm compliance before allowing access. Since our phones cannot connect to Intune to pull the policy, they remain 'Not compliant' and cannot connect. I've been able to change this setting temporarily to 'Compliant' so that I can use my Oppo until the problem is fixed.

    The setting is here:
    https://endpoint.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesComplianceMenu/policySettings

    Good luck!, Simon


    Just confirming with my Oppo Find X3 Pro I am able to enrol using a Corporate Work Profile (with all the same policy and app settings), so it must be something specific to the Personal Work Profile configuration... I tried many different settings on my phone and intune but could not get the Personal profile working (with exactly the same issue as posted). After reading about downgrading I definitely did not want to have to do that !!

    If your company is blocking any use of apps outside of a work profile, you could request to change to a corporate one until this is resolved (they would send you a QR code for that)... not sure if it will work on the other models though.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.