You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/configuration/device-restrictions-android-for-work.md
+46-11Lines changed: 46 additions & 11 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -201,7 +201,7 @@ For corporate-owned devices with a work profile, some settings only apply in the
201
201
202
202
-**Threat scan on apps**: **Require** (default) enables Google Play Protect to scan apps before and after they're installed. If it detects a threat, it may warn users to remove the app from the device. When set to **Not configured**, Intune doesn't change or update this setting. By default, the OS might not enable or run Google Play Protect to scan apps.
203
203
204
-
-**Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but are not limited to:
204
+
-**Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but aren't limited to:
205
205
206
206
- AES-GCM encryption of Bluetooth Long Term Keys
207
207
- Wi-Fi configuration stores
@@ -553,7 +553,7 @@ If you want to enable side-loading, set the **Allow installation from unknown so
553
553
554
554
-**Clear local data in apps not optimized for Shared device mode**: Add any app not optimized for shared device mode to the list. The app's local data will be cleared whenever a user signs out of an app that's optimized for shared device mode. Available for dedicated devices enrolled with Shared mode running Android 9 and later.
555
555
556
-
When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out.
556
+
When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out.
557
557
- Users will need to sign out of an app that has been optimized for Shared Device mode. Microsoft apps that are optimized for Shared device mode on Android include Teams and Intune’s Managed Home Screen.
558
558
- For apps that haven't been optimized for Shared Device mode, deleting application data extends to local app storage only. Data may be left in other areas of the device. User identifying artifacts such as email address and username may be left behind on the app and visible by others.
559
559
- Non-optimized apps that provide support for multiple accounts could exhibit indeterminate behavior and are therefore not recommended.
@@ -670,42 +670,77 @@ The Intune default message is translated for all languages in the [Endpoint Mang
670
670
671
671
You can configure the following settings:
672
672
673
-
-**Short support message**: When users try to change a setting that's managed by the organization, a short message is shown. Use these settings to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**.
673
+
-**Short support message**: When users try to change a setting that's managed by the organization, a short message is shown.
674
674
675
-
-**All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language.
675
+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
676
+
677
+
-**All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language.
676
678
677
679
You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original short Intune default message is used and is translated:
678
680
679
681
`You do not have permission for this action. For more information, contact your IT admin.`
680
682
681
-
-**Select Locale**: Select the locale or region to show the message.
683
+
-**Select Locale**: Select the locale or region to show a different custom message for that specific locale.
682
684
683
685
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
684
686
685
687
You can add multiple locales and messages.
686
688
687
689
-**Message**: Enter the text you want shown, a max of 200 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
688
690
689
-
-**Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown. Use this setting to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**.
690
-
691
-
In the short message, you can also select **Learn more** to see this long message.
691
+
-**Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown.
692
692
693
-
Using these settings, you can customize this message and enter a different message for different languages.
693
+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
694
694
695
-
-**All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language.
695
+
-**All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language.
696
696
697
697
You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original long Intune default message is used and is translated:
698
698
699
699
`The organization's IT admin can monitor and manage apps and data associated with this device, including settings, permissions, corporate access, network activity and the device's location information.`
700
700
701
-
-**Select Locale**: Select the locale or region to show the message.
701
+
-**Select Locale**: Select the locale or region to show a different custom message for that specific locale.
702
702
703
703
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
704
704
705
705
You can add multiple locales and messages.
706
706
707
707
-**Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
708
708
709
+
-**Lock screen message**: Enter the text you want shown on the device lock screen.
710
+
711
+
Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**.
712
+
713
+
-**All, except when specified**: Enter the text you want shown for all languages, a max of 4096 characters. This text is automatically translated to the device's default language. If you don't enter a custom message, then Intune doesn't change or update this setting. By default, the OS might not show a lock screen message.
714
+
715
+
-**Select Locale**: Select the locale or region to show a different custom message for that specific locale.
716
+
717
+
For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text.
718
+
719
+
You can add multiple locales and messages.
720
+
721
+
-**Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish.
722
+
723
+
When you configure the **Lock screen message**, you can also use the following device tokens to show device-specific information:
724
+
725
+
-`{{AADDeviceId}}`: Azure AD device ID
726
+
-`{{AccountId}}`: Intune tenant ID or account ID
727
+
-`{{DeviceId}}`: Intune device ID
728
+
-`{{DeviceName}}`: Intune device name
729
+
-`{{domain}}`: Domain name
730
+
-`{{EASID}}`: Exchange Active Sync ID
731
+
-`{{IMEI}}`: IMEI of the device
732
+
-`{{mail}}`: Email address of the user
733
+
-`{{MEID}}`: MEID of the device
734
+
-`{{partialUPN}}`: UPN prefix before the @ symbol
735
+
-`{{SerialNumber}}`: Device serial number
736
+
-`{{SerialNumberLast4Digits}}`: Last four digits of the device serial number
737
+
-`{{UserId}}`: Intune user ID
738
+
-`{{UserName}}`: User name
739
+
-`{{userPrincipalName}}`: UPN of the user
740
+
741
+
> [!NOTE]
742
+
> Variables aren't validated in the UI and are case sensitive. As a result, you may see profiles saved with incorrect input. For example, if you enter `{{DeviceID}}`, instead of `{{deviceid}}` or `{{DEVICEID}}`, then the literal string is shown instead of the device's unique ID. Be sure to enter the correct information. All lowercase or all uppercase variables are supported, but not a mix.
743
+
709
744
## Personally owned devices with a work profile
710
745
711
746
These settings apply to Android Enterprise personally owned devices with a work profile (BYOD).
0 commit comments