Use custom settings for Android Enterprise devices in Microsoft Intune
Чланак
Using Microsoft Intune, you can add or create custom settings for your Android Enterprise personally owned devices with a work profile using a custom profile. Custom profiles are a feature in Intune. They're designed to add device settings and features that aren't built in to Intune.
This feature applies to:
Android Enterprise personally owned devices with a work profile (BYOD)
Android Enterprise custom profiles use Open Mobile Alliance Uniform Resource Identifier (OMA-URI) settings to control features on Android Enterprise devices. These settings are typically used by mobile device manufacturers to control these features.
Intune supports the following limited number of Android Enterprise custom profiles:
This article shows you how to create a custom profile for Android Enterprise devices. It also provides an example of a custom profile that blocks copy-and-paste.
Profile type: Select Personally-owned work profile > Custom.
Select Create.
In Basics, enter the following properties:
Name: Enter a descriptive name for the profile. Name your profiles so you can easily identify them later. For example, a good profile name is Android Enterprise custom profile.
Description: Enter a description for the profile. This setting is optional, but recommended.
Select Next.
In Configuration settings > OMA-URI Settings, select Add. Enter the following settings:
Name: Enter a unique name for the OMA-URI setting so you can easily find it.
Description: Enter a description that gives an overview of the setting, and any other important details.
OMA-URI: Enter the OMA-URI you want to use as a setting.
Data type: Select the data type for this OMA-URI setting. Your options:
String
String (XML file)
Date and time
Integer
Floating point
Boolean
Base64 (file)
Value: Enter the data value you want to associate with the OMA-URI you entered. The value depends on the data type you selected. For example, if you select Date and time, select the value from a date picker.
After you add some settings, you can select Export. Export creates a list of all the values you added in a comma-separated values (.csv) file.
Select Save to save your changes. Continue to add more settings as needed.
Profile type: Select Personally-owned work profile > Custom.
In Basics, enter the following properties:
Name: Enter a descriptive name for the profile. Name your profiles so you can easily identify them later. For example, enter AE block copy paste custom profile.
Description: Enter a description for the profile. This setting is optional, but recommended.
Select Next.
In Configuration settings > OMA-URI Settings, select Add. Enter the following settings:
Name: Enter something like Block copy and paste.
Description: Enter something like Blocks copy/paste between work and personal apps.
OMA-URI: Enter ./Vendor/MSFT/WorkProfile/DisallowCrossProfileCopyPaste.
Data type: Select Boolean so the value for this OMA-URI is True or False.
Value: Select True.
Your settings look similar to the following image:
Select Save to save your changes. Continue to add more settings as needed. After you add some settings, you can select Export. Export creates a list of all the values you added in a comma-separated values (.csv) file.
After you enter the settings, your environment looks similar to the following image:
Plan and execute an endpoint deployment strategy, using essential elements of modern management, co-management approaches, and Microsoft Intune integration.
On Android Enterprise or Android for Work personally owned BYOD devices, you can restrict settings on the device using Microsoft Intune. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts.
On Android Enterprise or Android for Work devices owned by your organization, you can restrict settings on the device using Microsoft Intune. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts. Configure devices as a dedicated device kiosk to run one app, or multiple apps.
Add or create a custom profile for Android device administrator (DA) devices in Microsoft Intune. Create a WiFi profile with a preshared key, create a per-app VPN profile, or allow/block apps for Samsung Knox Standard devices.
See a list of all the Android device administrator settings you can control and restrict in Microsoft Intune. Use these settings to control the password, access Google Play, allow or prohibit apps, control the browser settings, block apps, backup to the Google cloud, and control the message, voice, data roaming, Wi-Fi, and Bluetooth connection options.
Overview of the different Microsoft Intune device profiles. Get info on GPO, features, restrictions, email, wifi, VPN, education, certificates, upgrade Windows 10/11, BitLocker and Microsoft Defender, Windows Information Protection, administrative templates, and custom device configuration settings in the Microsoft Intune admin center. Use these profiles to manage and protect data and devices in your company.