You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-platform-android.md
+18-18Lines changed: 18 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ keywords:
7
7
author: dougeby
8
8
ms.author: dougeby
9
9
manager: dougeby
10
-
ms.date: 05/07/2021
10
+
ms.date: 09/16/2021
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: fundamentals
@@ -87,7 +87,7 @@ The following tasks apply to both Android Enterprise and Android device administ
87
87
| Task | Detail |
88
88
| ---- | ------ |
89
89
|[Create a compliance policy](../protect/create-compliance-policy.md)|Get step-by-step guidance on how to create and assign a compliance policy to user and device groups. |
90
-
|[Add actions for noncompliance](../protect/actions-for-noncompliance.md)|Choose what happens when devices no longer meet the conditions of your compliance policy. You can add actions for noncompliance when you configure a device compliance policy, or later by editing the policy. |
90
+
|[Add actions for noncompliance](../protect/actions-for-noncompliance.md)|Choose what happens when devices no longer meet the conditions of your compliance policy. You can add actions for noncompliance when you configure a device compliance policy, or later by editing the policy. |
91
91
| Create [a device-based](../protect/create-conditional-access-intune.md) or [app-based](../protect/app-based-conditional-access-intune-create.md) Conditional Access policy.|Specify the app or services you want to protect and define the conditions for access.
92
92
|[Block access to apps that don't use modern authentication](../protect/app-modern-authentication-block.md)| Create an app-based Conditional Access policy to block apps that use authentication methods other than OAuth2. For example, you can block apps that use basic and form-based authentication. Before you block any access, sign in to Azure AD and review the [authentication methods activity report](/azure/active-directory/authentication/howto-authentication-methods-activity) to see if users are using basic authentication to access essential things (like meeting room calendar kiosks) you forgot about or are unaware of. |
93
93
@@ -97,7 +97,7 @@ Use the Intune endpoint security features to configure device security and to ma
97
97
98
98
The following tasks apply to both Android Enterprise and Android device administrator platforms.
99
99
100
-
| Task | Detail | Platform|
100
+
| Task | Detail | Platform|
101
101
| ---- | ------ | ------ |
102
102
|[Manage devices with endpoint security features](../protect/endpoint-security-manage-devices.md)|Use the **Endpoint security** settings in Intune to effectively manage device security and remediate issues for devices.|
103
103
|[Enable the mobile threat defense (MTD) connector for enrolled devices](../protect/mtd-connector-enable.md)|Enable the MTD connection in Intune so that MTD partner apps can work with Intune and your MTD device compliance policies. If you're not using Microsoft Defender for Endpoint, consider enabling the connector so that you can use another mobile threat defense solution. You can also [enable the MTD connector for devices not enrolled in Intune](../protect/mtd-enable-unenrolled-devices.md).|
@@ -111,16 +111,16 @@ Use Microsoft Intune to enable or disable settings and features on devices. To c
111
111
112
112
| Task | Detail | Platform |
113
113
| ---- | ------ | ------ |
114
-
|[Create a device profile in Microsoft Intune](../configuration/device-profile-create.md)|Learn about the different types of device profiles you can create for your organization.| Android Enterprise, Android device administrator |
114
+
|[Create a device profile in Microsoft Intune](../configuration/device-profile-create.md)|Learn about the different types of device profiles you can create for your organization.| Android Enterprise, Android device administrator |
115
115
|[Configure Wi-Fi profile](../configuration/wi-fi-settings-configure.md)|This profile enables people to find and connect to your organization's Wi-Fi network. For a description of the settings in this area, see the Wi-Fi settings reference for [Android Enterprise Wi-Fi settings](../configuration/wi-fi-settings-android-enterprise.md) or [Android device administrator Wi-Fi settings](../configuration/wi-fi-settings-android.md).|Android Enterprise, Android device administrator |
116
116
|[Configure VPN profile](../configuration/vpn-settings-configure.md)|Set up a secure VPN option, such as Microsoft Tunnel, for people connecting to your organization's network. For a description of the settings in this area, see the VPN settings reference for [Android Enterprise VPN settings](../configuration/vpn-settings-android-enterprise.md) or [Android device administrator VPN settings](../configuration/vpn-settings-android.md). | Android Enterprise, Android device administrator |
117
117
|[Configure email profile](../configuration/email-settings-configure.md)|Configure email settings so that people can connect to a mail server and access their work or school email. For a description of the settings in this area, see [Android Enterprise email settings](../configuration/email-settings-android-enterprise.md) or [Android device administrator email settings](../configuration/email-settings-android.md).| Android Enterprise, Android device administrator |
118
118
|[Restrict device features](../configuration/device-restrictions-configure.md)|Protect users from unauthorized access and distractions by limiting the device features they can use at work or school. For a description of the settings in this area, see [Android Enterprise device settings](../configuration/device-restrictions-android-for-work.md) or [Android device administrator device settings](../configuration/device-restrictions-android.md).|Android Enterprise, Android device administrator |
119
119
|[Configure custom settings for Android device administrator](../configuration/custom-settings-android.md)|Add or create custom settings that aren't built in to Intune, such as a per-app VPN profile and web protection with Microsoft Defender for Endpoint.|Android device administrator |
120
120
|[Configure Samsung Knox apps](../configuration/samsung-knox-apps-allow-block.md)|Create a custom profile to allow and block apps for Samsung Knox Standard devices.| Android device administrator|
121
121
|[Create custom profile for Android Enterprise](../configuration/custom-settings-android-for-work.md)|Add or create custom settings that aren't built in to Intune for personally owned devices.|Android Enterprise|
122
-
|[Configure Zebra Mobility Extensions (MX) profile](../configuration/android-zebra-mx-overview.md)|Use Zebra's Mobility Extensions (MX) profiles to customize or add more Zebra-specific settings in Intune.| Android device administrator|
123
-
|[Create OEMConfig configuration profile](../configuration/android-oem-configuration-overview.md)|Use OEMConfig to add, create, and customize OEM-specific settings for Android Enterprise devices.| Android Enterprise|
122
+
|[Configure Zebra Mobility Extensions (MX) profile](../configuration/android-zebra-mx-overview.md)|Use Zebra's Mobility Extensions (MX) profiles to customize or add more Zebra-specific settings in Intune.| Android device administrator|
123
+
|[Create OEMConfig configuration profile](../configuration/android-oem-configuration-overview.md)|Use OEMConfig to add, create, and customize OEM-specific settings for Android Enterprise devices.| Android Enterprise|
124
124
|[Customize branding and enrollment experience](../apps/company-portal-app.md)|Customize the Intune Company Portal and Microsoft Intune apps with your organization's branding to create a familiar experience for people enrolling their devices.|Android Enterprise, Android device administrator |
125
125
126
126
@@ -129,21 +129,21 @@ Set up authentication methods in Intune to ensure that only authorized people ac
129
129
130
130
| Task | Detail | Platform |
131
131
| ---- | ------ | ------ |
132
-
|[Require multi-factor authentication (MFA)](../enrollment/multi-factor-authentication.md)| Require people to supply two forms of credentials at time of enrollment.| Android Enterprise|
132
+
|[Require multi-factor authentication (MFA)](../enrollment/multi-factor-authentication.md)| Require people to supply two forms of credentials at time of enrollment.| Android Enterprise|
133
133
|[Create a trusted certificate profile](../protect/certificates-trusted-root.md)|Create and deploy a trusted certificate profile before you create a SCEP, PKCS, or PKCS imported certificate profile. The trusted certificate profile deploys the trusted root certificate to devices using SCEP, PKCS, and PKCS imported certificates.| Android Enterprise, Android device administrator |
134
-
|[Use SCEP certificates with Intune](../protect/certificates-scep-configure.md)| Learn what’s needed to use SCEP certificates with Intune, and configure the required infrastructure. After you do that, you can [create a SCEP certificate profile](../protect/certificates-profile-scep.md) or [set up a third-party certification authority with SCEP](../protect/certificate-authority-add-scep-overview.md).| Android Enterprise|
135
-
|[Use PKCS certificates with Intune](../protect/certificates-pfx-configure.md)|Configure required infrastructure (such as on-premises certificate connectors), export a PKCS certificate, and add the certificate to an Intune device configuration profile. |Android Enterprise, Android device administrator|
136
-
|[Use imported PKCS certificates with Intune](../protect/certificates-imported-pfx-configure.md)|Set up imported PKCS certificates, which enable you to [set up and use S/MIME to encrypt email](../protect/certificates-s-mime-encryption-sign.md). |Android Enterprise, Android device administrator|
137
-
|[Set up a derived credentials issuer](../protect/derived-credentials.md)| Provision Android devices with certificates that are derived from user smart cards. |Android Enterprise|
134
+
|[Use SCEP certificates with Intune](../protect/certificates-scep-configure.md)| Learn what’s needed to use SCEP certificates with Intune, and configure the required infrastructure. After you do that, you can [create a SCEP certificate profile](../protect/certificates-profile-scep.md) or [set up a third-party certification authority with SCEP](../protect/certificate-authority-add-scep-overview.md).| Android Enterprise|
135
+
|[Use PKCS certificates with Intune](../protect/certificates-pfx-configure.md)|Configure required infrastructure (such as on-premises certificate connectors), export a PKCS certificate, and add the certificate to an Intune device configuration profile. |Android Enterprise, Android device administrator|
136
+
|[Use imported PKCS certificates with Intune](../protect/certificates-imported-pfx-configure.md)|Set up imported PKCS certificates, which enable you to [set up and use S/MIME to encrypt email](../protect/certificates-s-mime-encryption-sign.md). |Android Enterprise, Android device administrator|
137
+
|[Set up a derived credentials issuer](../protect/derived-credentials.md)| Provision Android devices with certificates that are derived from user smart cards. |Android Enterprise|
138
138
139
139
## Deploy apps
140
140
141
141
As you set up apps and app policies, think about your organization's requirements, such as the platforms you'll support, the tasks people need to do, the type of apps they need to complete those tasks, and the groups who need those apps. You can use Intune to manage the whole device (including apps) or use Intune to manage apps only.
142
142
143
-
| Task | Detail |Platform|
143
+
| Task | Detail |Platform|
144
144
| ---- | ------ | ------ |
145
145
|[Add Google Play Store apps](../apps/store-apps-android.md)| Add Android apps from the Google Play Store. | Android device administrator|
146
-
|[Add managed Google Play apps](../apps/apps-add-android-for-work.md)| Add store apps, line-of-business (LOB) apps, and web apps through the managed Google Play Store.| Android Enterprise|
146
+
|[Add Managed Google Play apps](../apps/apps-add-android-for-work.md)| Add store apps, line-of-business (LOB) apps, and web apps through the Managed Google Play Store.| Android Enterprise|
147
147
|[Add Android Enterprise system apps](../apps/apps-ae-system.md)| Use Intune to enable and disable Android Enterprise system apps. | Android Enterprise|
148
148
|[Add web apps](../apps/web-app.md)| Add web apps to Intune and assign to groups. | Android device administrator|
149
149
|[Add built-in apps](../apps/apps-add-built-in.md)| Add built-in apps to Intune and assign to groups. | Android Enterprise, Android device administrator|
@@ -176,17 +176,17 @@ Intune supports the following enrollment methods for Android devices:
176
176
177
177
For information about each enrollment method and how to choose one that's right for your organization, see the [Android device enrollment guide for Microsoft Intune](deployment-guide-enrollment-android.md).
178
178
179
-
| Task | Detail | Platform|
179
+
| Task | Detail | Platform|
180
180
| ---- | ------ | ------ |
181
-
|[Connect Intune account to managed Google Play account](../enrollment/connect-intune-android-enterprise.md)| To enable Android Enterprise management in Intune, connect your Intune tenant account to your managed Google Play account. | Android Enterprise|
181
+
|[Connect Intune account to Managed Google Play account](../enrollment/connect-intune-android-enterprise.md)| To enable Android Enterprise management in Intune, connect your Intune tenant account to your Managed Google Play account. | Android Enterprise|
182
182
|[Set up work profile enrollment for personally owned devices ](../enrollment/android-work-profile-enroll.md)|Set up work profile management for personally owned devices. This enrollment method creates a separate area on the device for work-related data so that personal things remain unaffected.| Android Enterprise|
183
183
|[Set up work profile enrollment for corporate-owned devices](../enrollment/android-corporate-owned-work-profile-enroll.md)|Set up work profile management for corporate-owned devices intended for work and personal use. This enrollment method creates a separate area on the device for work-related data so that personal things remain unaffected. | Android Enterprise|
184
184
|[Set up enrollment for dedicated devices](../enrollment/android-kiosk-enroll.md)| Set up enrollment for corporate-owned, single-use, kiosk-style devices. | Android Enterprise|
185
-
|[Set up enrollment for fully managed devices](../enrollment/android-fully-managed-enroll.md)|Set up enrollment for corporate-owned devices that are associated with a single user and used exclusively for work.|Android Enterprise |
185
+
|[Set up enrollment for fully managed devices](../enrollment/android-fully-managed-enroll.md)|Set up enrollment for corporate-owned devices that are associated with a single user and used exclusively for work.| Android Enterprise |
186
186
|[Enroll dedicated, fully managed, or corporate-owned work-profile devices](../enrollment/android-dedicated-devices-fully-managed-enroll.md)|After you've set up Intune for Android Enterprise enrollment, enroll devices using one of the five supported enrollment methods. |Android Enterprise|
187
187
|[Set up device administrator enrollment](../enrollment/android-enroll-device-administrator.md)|Set up Android device administrator enrollment. This method of managing devices has been superseded by Android Enterprise, so we don't recommend enrolling new devices this way.| Android device administrator|
188
188
|[Use Samsung Knox Mobile Enrollment to automatically enroll Android devices](../enrollment/android-samsung-knox-mobile-enroll.md)|Set up Intune for Samsung Knox Mobile Enrollment (KME), which enables you to automatically enroll large numbers of corporate-owned Android devices. | Android Enterprise, Android device administrator|
189
-
|[Identify devices as corporate-owned](../enrollment/corporate-identifiers-add.md)| Assign corporate-owned status to devices to enable more management and identification capabilities in Intune. Corporate-owned status cannot be assigned to devices enrolled through Apple Business Manager. | Android Enterprise, Android device administrator |
189
+
|[Identify devices as corporate-owned](../enrollment/corporate-identifiers-add.md)| Assign corporate-owned status to devices to enable more management and identification capabilities in Intune. Corporate-owned status cannot be assigned to devices enrolled through Apple Business Manager. | Android Enterprise, Android device administrator |
190
190
|[Change device ownership](../enrollment/corporate-identifiers-add.md#change-device-ownership)|After a device has been enrolled, you can change its ownership label in Intune to corporate-owned or personal-owned. This adjustment changes the way you can manage the device.| Android Enterprise, Android device administrator|
191
191
|[Troubleshoot enrollment problems](/troubleshoot/mem/intune/troubleshoot-android-enrollment)|Troubleshoot and find resolutions to problems that occur during enrollment.|Android Enterprise, Android device administrator|
192
192
@@ -210,4 +210,4 @@ Check out these enrollment tutorials to learn how to do some of the top tasks in
210
210
*[Walk through Intune in Microsoft Endpoint Manager](tutorial-walkthrough-endpoint-manager.md)
211
211
*[Configure Slack to use Intune for enterprise mobility management (EMM) and app configuration](../apps/tutorial-configure-slack-enterprise-grid.md)
212
212
213
-
For the iOS/iPadOS version of this guide, see [Deployment guide: Manage iOS/iPadOS devices in Microsoft Intune](deployment-guide-platform-ios-ipados.md).
213
+
For the iOS/iPadOS version of this guide, see [Deployment guide: Manage iOS/iPadOS devices in Microsoft Intune](deployment-guide-platform-ios-ipados.md).
0 commit comments