Skip to content

Commit 3868401

Browse files
authored
Merge pull request #6126 from Erikre/erikre-rel2111-8663319
erikre-rel2111-8663319
2 parents 4e0250a + 6cf762a commit 3868401

1 file changed

Lines changed: 14 additions & 1 deletion

File tree

memdocs/intune/configuration/device-restrictions-android-for-work.md

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 10/19/2021
10+
ms.date: 11/15/2021
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: configuration
@@ -446,6 +446,8 @@ End of comment -->
446446

447447
### Applications
448448

449+
#### Fully managed, dedicated, and corporate-owned work profile devices
450+
449451
- **Allow installation from unknown sources**: **Allow** lets users turn on **Unknown sources**. This setting allows apps to install from unknown sources, including sources other than the Google Play Store. It allows users to side-load apps on the device using means other than the Google Play Store. When set to **Not configured** (default), Intune doesn't change or update this setting. By default, the OS might prevent users from turning on **Unknown sources**.
450452

451453
- **App auto-updates (work profile-level)**: Devices check for app updates daily. Choose when automatic updates are installed. Your options:
@@ -464,6 +466,17 @@ End of comment -->
464466

465467
If you want to enable side-loading, set the **Allow installation from unknown sources** and **Allow access to all apps in Google Play store** settings to **Allow**.
466468

469+
#### Dedicated devices
470+
471+
- **Clear local data in apps not optimized for Shared device mode (Public Preview)**: Add any app not optimized for shared device mode to the list. The app's local data will be cleared whenever a user signs out of an app that's optimized for shared device mode. Available for dedicated devices enrolled with Shared mode running Android 9 and later.
472+
473+
When you use this setting, users cannot initiate sign out from non-optimized apps and get single sign-out.
474+
- Users will need to sign out of an app that has been optimized for Shared Device mode. Microsoft apps that are optimized for Shared device mode on Android include Teams and Intune’s Managed Home Screen.
475+
- For apps that have not been optimized for Shared Device mode, deleting application data extends to local app storage only. Data may be left in other areas of the device. User identifying artifacts such as email address and username may be left behind on the app and visible by others.
476+
- Non-optimized apps that provide support for multiple accounts could exhibit indeterminate behavior and are therefore not recommended.
477+
478+
All non-optimized apps should be thoroughly tested before being used in multi-user scenarios on shared devices to ensure they work as expected. For example, validate your core scenarios in each app, verify that the app signs out properly, and that all data is sufficiently cleared for your organization’s needs.
479+
467480
### Connectivity
468481

469482
#### Fully managed, dedicated, and corporate-owned work profile devices

0 commit comments

Comments
 (0)