Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article lists and describes the Android Enterprise and AOSP settings you can configure in a settings catalog policy in Microsoft Intune. To learn more about the settings catalog, see Settings catalog overview.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
- Android Open Source Project (AOSP) corporate-owned userless devices (shared)
- Android Open Source Project (AOSP) corporate-owned user-associated devices (single user)
Before you begin
- At a minimum, sign into the Intune admin center as a member of the Policy and Profile Manager role. For more information on the built-in Intune roles, go to Role-based access control (RBAC) with Microsoft Intune.
- Create a settings catalog policy.
Android settings
These settings apply to the Android Enterprise enrollment types where Intune controls the entire device, including the following enrollment types:
- Fully managed devices
- Dedicated devices
- Corporate-owned devices with a work profile
To learn more about the different Android enrollment types, see Android Enrollment guide.
Device restriction
Device Password
Note
Users on fully managed, and corporate-owned work profile devices aren't prompted to set a password. The settings are required, but users might not be notified. Users need to set the password manually. The policy reports as failed until the user sets a password that meets your requirements.
To apply the device password settings during device enrollment, assign the device restriction profile to users, not devices. During enrollment, users are asked to set a screen lock. Then, they must choose a device password that meets all the requirements in this device restriction profile.
On dedicated devices, if the device is set up with single or multi-app kiosk mode, then users are prompted to set a password. Screens force and guide users to create a compliant password before they can continue using the device.
On dedicated devices that aren't using kiosk mode, users aren't notified of any password requirement. Users need to set the password manually. The policy reports as failed until the user sets a password that meets your requirements.
Required password type: Set the password's complexity requirements. More password requirements become available based on your selection.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Minimum password length: Enter the minimum number of digits or characters the password must have, between 4 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of characters required: Enter the number of characters the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of lowercase characters required: Enter the number of lowercase characters the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of uppercase characters required: Enter the number of uppercase characters the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of non-letter characters required: Enter the number of non-letters (anything other than letters in the alphabet) the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of numeric characters required: Enter the number of numeric characters (1, 2, 3, and so on) the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of symbol characters required: Enter the number of symbol characters (&, #, %, and so on) the password must have, between 0 and 16 characters.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of days until password expires: Enter the number of days, until the device password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. If the value is blank, Intune doesn't change or update this setting.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of passwords required before user can reuse a password: Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. If the value is blank, Intune doesn't change or update this setting.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Number of sign-in failures before wiping device: Enter the number of wrong passwords allowed before the device is wiped, from 4-11. If the value is blank, Intune doesn't change or update this setting.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Required unlock frequency: Select how long users have before they're required to unlock the device using a strong authentication method (password, PIN, or pattern).
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE) (At work profile level)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
Disable lock screen: If True, this setting blocks all Keyguard lock screen features from being used. If False, Intune doesn't change or update this setting. By default, when the device is in lock screen, the OS might allow all the Keyguard features, such as camera, fingerprint unlock, and more.
This feature applies to:
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)
General
Block Bluetooth: If True, this setting disables Bluetooth on the device so that users can't pair with other devices. If False, Intune doesn't change or update this setting. By default, the OS might enable Bluetooth on the device.
This feature applies to:
- Android Enterprise corporate-owned devices with a work profile (COPE)
- Android Enterprise corporate owned fully managed (COBO)
- Android Enterprise corporate owned dedicated devices (COSU)