Enhancing the Work Profile experience with system apps

This week is all around enhancing the Work Profile experience with the most common system apps on Android devices. Getting the right system apps available within the Work Profile can enhance the user experience and the data separation. Mainly the latter actually, as for more apps the experience will be divided between a personal app and a work app. And that’s not always the best user experience. That could be useful when looking at for example the Camera app. Without adding that app to the Work Profile, all movies and pictures will be stored in the Personal Profile. This post will start with a quick overview of the most common Android Enterprise system apps, followed with the steps for managing (read: enabling) those apps. This …

Read more

Android Enterprise and Microsoft Intune: A quick summary

This week my post is a few days later, as my post is an extension of my session at the Workplace Ninja Virtual Summit 2021. At the virtual summit I did a session about Why you might want to use corporate-owned devices with Work Profile. During that session I shared a summary about Android Enterprise and I zoomed in on the capabilities of corporate-owned devices with Work Profile. This post will provide a summary of that session about the different important components of Android Enterprise and how that integrates and works with Microsoft Intune, followed with a zoom-in on corporate-owned devices with Work Profile. Most of that information will be summarized in tables and slides. The slides (PDF) of that session are available for download here. Android …

Read more

Integrating Samsung Knox E-FOTA One with Microsoft Intune

This week is all about Samsung Knox Enterprise Firmware-Over-The-Air (E-FOTA). Samsung Knox E-FOTA is available in three editions, of which Samsung Knox E-FOTA One is the most advanced edition. That edition is also the subject of this post. Knox E-FOTA enables organizations to manage OS versions and security updates on corporate Samsung Knox devices. That enables organizations to extensively test updates on their devices in combination with their apps to make sure that new OS versions and security updates won’t cause any issues. Together with Microsoft Intune that experience can be even better. Microsoft Intune can be used to configure already managed Samsung Knox devices to use Knox E-FOTA and Microsoft Intune can also be used to synchronize groups with Samsung Knox devices to Knox …

Read more

Using Samsung Knox Mobile Enrollment with Microsoft Intune

This week is all about using Samsung Knox Mobile Enrollment (KME) for automatically enrolling Samsung Knox devices into Microsoft Intune. The idea of Samsung KME is similar to Windows Autopilot and Apple ADE. It’s all about streamlining the enrollment experience for corporate-owned devices. By using Samsung KME in combination with Microsoft Intune, a smooth out-of-the-box experience enables users to be up-and-running in no time. That can be achieved by uploading Samsung Knox devices in Samsung KME and assigning MDM profiles to those devices. This post will start with the important prerequisites, followed with the steps for creating a MDM profile in Samsung KME. This post ends with assigning the MDM profile to devices in Samsung KME and a quick look at the user experience. Note: …

Read more

Quick tip: Enable browser access on Android Enterprise corporate-owned devices

This week a quick tip about enabling browser access on Android Enterprise Corporate-Owned Fully Managed devices and Android Enterprise Corporate-Owned devices with Work Profile, to work with device-based Conditional Access. That will enable the user to eventually use different apps for accessing company data. That includes for example using the Chrome browser app for accessing SharePoint Online or Exchange Online. On the Android Enterprise devices, this requires a configuration in the Microsoft Authenticator app. In this post I’ll simply provide the steps that are required within the Microsoft Authenticator app. Note: Before providing the mentioned steps, a big thank you to Pat Freeman for pointing me in the right direction. Enable browser access in the Microsoft Authenticator app When knowing the availability of the setting, …

Read more

Android Enterprise and Microsoft Intune: And Android Device Policy

I’ve mentioned Android Device Policy before, earlier this year, in my post about Android Enterprise and Microsoft Intune. In that post, however, I’ve only briefly mentioned that app, while that app is an important piece of the Microsoft management solution for corporate-owned devices. That’s why I thought it would be good to devote a blog post to that app. To simply show it’s importance. Android Device Policy is really important for configuring managed devices and also provides some nice capabilities. The importance should be familiar with any IT administrator, responsible for managing Android devices, and those capabilities are sometimes slightly hidden, but provide a good starting point for troubleshooting. Especially when verifying whether settings are already applied or not. In this post I’ll start with …

Read more

Android Enterprise and Microsoft Intune: And the additional configuration layer

This week is all around another Android Enterprise related subject. This week is about the additional configuration layer that is also known as OEMConfig. OEMConfig provides OEMs with the capabilities of building an additional configuration layer on top of the configuration layer that is provided out-of-the-box via the Android Management API. That provides Microsoft Intune with the possibility to implement support for OEMConfig and that provides the OEM with the possibility to implement additional configuration options via OEMConfig. That enables the OEM to quickly introduce new features, without having to wait on Microsoft Intune to introduce those new features. In this post I’ll start with a further introduction to OEMConfig, followed with an example of using OEMConfig. In that example I’ll use the Samsung Knox …

Read more

Getting started with Microsoft Defender for Endpoint for Android

Microsoft recently declared Microsoft Defender for Endpoint (MDE) for Android – previously known as Microsoft Defender ATP for Android – general available. That’s really good news and also a really good trigger for a new blog post. MDE for Android provides protection against phishing, unsafe network connections, and malicious apps. All events and alerts around those subjects will be available in the Microsoft Defender Security Center and will be used to determine the risk level of the device. To add-on to that, through the connection with Microsoft Intune that risk information can be used to determine the compliance of the device with the company policies and to determine the eventual access of the device to company data. In this post I want to start with …

Read more

Getting started with Android Enterprise Corporate-Owned devices with Work Profile

Microsoft has recently declared the Android Enterprise Corporate-Owned devices with Work Profile deployment scenario (sometimes also referred to as management scenario) feature complete. That’s really good news and also a really good trigger for a new blog post. This time I’ll skip the different deployment scenarios and use cases, as I’ve written about those here and here. Just to create a good starting point, I’ll start with a quick summary about the main characteristics of this specific deployment scenario in the table below. These characteristics will help with determining if this deployment scenario will fit on the use case. For a complete overview with the different deployment scenarios, please refer to my previous post around this subject. Note: Keep in mind that the user experience …

Read more

Android Enterprise corporate-owned dedicated devices and Azure AD shared device mode

This week is all around the Android Enterprise corporate-owned dedicated devices deployment scenario. That deployment scenario is designed to address the typical kiosk-type devices, which are often referred to as the corporate-owned, single-use (COSU) use case. This week is specifically focused on enrolling those devices in to Azure AD shared device mode. That mode will provide users with a single sign-on and single sign-out experience across all of the participating apps on the device. In other words, users will be able to sign in to the device and will automatically be signed in to any participating apps. That enables an organization to provide a little personalized experience across dedicated devices that are shared between multiple users. In this post I’ll have a look at the …

Read more