Skip to content

Commit 065da86

Browse files
committed
2209 release
1 parent a64632d commit 065da86

1 file changed

Lines changed: 48 additions & 13 deletions

File tree

memdocs/intune/configuration/device-restrictions-android-for-work.md

Lines changed: 48 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,12 @@
22
# required metadata
33

44
title: Android Enterprise device settings in Microsoft Intune
5-
description: On Android Enterprise or Android for Work devices, restrict settings on the device. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts. Configure devices as a dedicated device kiosk to run one app, or multiple apps.
5+
description: On Android Enterprise or Android for Work devices, restrict settings on the device using Microsoft Intune. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts. Configure devices as a dedicated device kiosk to run one app, or multiple apps.
66
keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 07/26/2022
10+
ms.date: 09/20/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -201,7 +201,7 @@ For corporate-owned devices with a work profile, some settings only apply in the
201201

202202
- **Threat scan on apps**: **Require** (default) enables Google Play Protect to scan apps before and after they're installed. If it detects a threat, it may warn users to remove the app from the device. When set to **Not configured**, Intune doesn't change or update this setting. By default, the OS might not enable or run Google Play Protect to scan apps.
203203

204-
- **Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but are not limited to:
204+
- **Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but aren't limited to:
205205

206206
- AES-GCM encryption of Bluetooth Long Term Keys
207207
- Wi-Fi configuration stores
@@ -553,7 +553,7 @@ If you want to enable side-loading, set the **Allow installation from unknown so
553553

554554
- **Clear local data in apps not optimized for Shared device mode**: Add any app not optimized for shared device mode to the list. The app's local data will be cleared whenever a user signs out of an app that's optimized for shared device mode. Available for dedicated devices enrolled with Shared mode running Android 9 and later.
555555

556-
When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out.
556+
When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out.
557557
- Users will need to sign out of an app that has been optimized for Shared Device mode. Microsoft apps that are optimized for Shared device mode on Android include Teams and Intune’s Managed Home Screen.
558558
- For apps that haven't been optimized for Shared Device mode, deleting application data extends to local app storage only. Data may be left in other areas of the device. User identifying artifacts such as email address and username may be left behind on the app and visible by others.
559559
- Non-optimized apps that provide support for multiple accounts could exhibit indeterminate behavior and are therefore not recommended.
@@ -670,42 +670,77 @@ The Intune default message is translated for all languages in the [Endpoint Mang
670670

671671
You can configure the following settings:
672672

673-
- **Short support message**: When users try to change a setting that's managed by the organization, a short message is shown. Use these settings to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**.
673+
- **Short support message**: When users try to change a setting that's managed by the organization, a short message is shown.
674674

675-
- **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language.
675+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
676+
677+
- **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language.
676678

677679
You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original short Intune default message is used and is translated:
678680

679681
`You do not have permission for this action. For more information, contact your IT admin.`
680682

681-
- **Select Locale**: Select the locale or region to show the message.
683+
- **Select Locale**: Select the locale or region to show a different custom message for that specific locale.
682684

683685
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
684686

685687
You can add multiple locales and messages.
686688

687689
- **Message**: Enter the text you want shown, a max of 200 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
688690

689-
- **Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown. Use this setting to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**.
690-
691-
In the short message, you can also select **Learn more** to see this long message.
691+
- **Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown.
692692

693-
Using these settings, you can customize this message and enter a different message for different languages.
693+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
694694

695-
- **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language.
695+
- **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language.
696696

697697
You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original long Intune default message is used and is translated:
698698

699699
`The organization's IT admin can monitor and manage apps and data associated with this device, including settings, permissions, corporate access, network activity and the device's location information.`
700700

701-
- **Select Locale**: Select the locale or region to show the message.
701+
- **Select Locale**: Select the locale or region to show a different custom message for that specific locale.
702702

703703
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
704704

705705
You can add multiple locales and messages.
706706

707707
- **Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
708708

709+
- **Lock screen message**: Enter the text you want shown on the device lock screen, a max of 4096 characters.
710+
711+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
712+
713+
- **All, except when specified**: The text you enter is shown for all languages. This text is automatically translated to the device's default language. If you don't enter a custom message, then Intune doesn't change or update this setting.
714+
715+
- **Select Locale**: Select the locale or region to show a different custom message for that specific locale.
716+
717+
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
718+
719+
You can add multiple locales and messages.
720+
721+
- **Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
722+
723+
When you configure the **Lock screen message**, you can also use the following device tokens to show device-specific information:
724+
725+
- `{{AADDeviceId}}`: Azure AD device ID
726+
- `{{AccountId}}`: Intune tenant ID or account ID
727+
- `{{DeviceId}}`: Intune device ID
728+
- `{{DeviceName}}`: Intune device name
729+
- `{{domain}}`: Domain name
730+
- `{{EASID}}`: Exchange Active Sync ID
731+
- `{{IMEI}}`: IMEI of the device
732+
- `{{mail}}`: Email address of the user
733+
- `{{MEID}}`: MEID of the device
734+
- `{{partialUPN}}`: UPN prefix before the @ symbol
735+
- `{{SerialNumber}}`: Device serial number
736+
- `{{SerialNumberLast4Digits}}`: Last four digits of the device serial number
737+
- `{{UserId}}`: Intune user ID
738+
- `{{UserName}}`: User name
739+
- `{{userPrincipalName}}`: UPN of the user
740+
741+
> [!NOTE]
742+
> Variables aren't validated in the UI and are case sensitive. As a result, you may see profiles saved with incorrect input. For example, if you enter `{{DeviceID}}`, instead of `{{deviceid}}` or `{{DEVICEID}}`, then the literal string is shown instead of the device's unique ID. Be sure to enter the correct information. All lowercase or all uppercase variables are supported, but not a mix.
743+
709744
## Personally owned devices with a work profile
710745

711746
These settings apply to Android Enterprise personally owned devices with a work profile (BYOD).

0 commit comments

Comments
 (0)