You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/configmgr/core/servers/deploy/configure/azure-services-wizard.md
+3Lines changed: 3 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -261,6 +261,9 @@ To mitigate both cases, renew the secret key.
261
261
262
262
For more information on how to interact with these notifications, see [Configuration Manager console notifications](../../manage/admin-console-notifications.md).
263
263
264
+
> [!NOTE]
265
+
> You need to have at least the "Cloud Application Administrator" Azure AD role assigned to be able to renew the key.
266
+
264
267
### Renew key for created app
265
268
266
269
1. In the Configuration Manager console, go to the **Administration** workspace, expand **Cloud Services**, and select the **Azure Active Directory Tenants** node.
Copy file name to clipboardExpand all lines: memdocs/configmgr/osd/deploy-use/create-a-task-sequence-to-upgrade-an-operating-system.md
+3-1Lines changed: 3 additions & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -47,7 +47,7 @@ Before you create the task sequence, make sure the following requirements are in
47
47
- For a deployment package that contains the feature update, distribute it to a distribution point that the client can access. For more information, see [Download software updates](../../sum/deploy-use/download-software-updates.md).
48
48
49
49
> [!NOTE]
50
-
> If the feature update isn't already downloaded, you can manage the deployment package when you deploy the task sequence.
50
+
> If the feature update isn't already downloaded, you can manage the deployment package when you deploy the task sequence.
51
51
>
52
52
> When you deploy the task sequence, you can also select the option of **No deployment package** for the feature update. When clients run the task sequence, they download the feature update from peers or the Microsoft cloud.
53
53
>
@@ -62,6 +62,8 @@ Before you create the task sequence, make sure the following requirements are in
62
62
-**Allow clients to download delta content when available**: If you use Windows Delivery Optimization, the content that the client downloads may be much smaller.
63
63
64
64
#### Known issues with feature updates in a task sequence
65
+
Windows 11 Feature Upgrades are not visible to be selected from the Wizard. This happens if the License Terms of the desired Feature Upgrade have not been accepted yet. To do so navigate to the Feature Upgrade and select "Review Licence" from the context menu. Review and Accept the licensing terms to make this Upgrade "deployable".
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/android-enroll.md
+6-3Lines changed: 6 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ keywords:
8
8
author: Lenewsad
9
9
ms.author: lanewsad
10
10
manager: dougeby
11
-
ms.date: 10/19/2021
11
+
ms.date: 02/01/2022
12
12
ms.topic: overview
13
13
ms.service: microsoft-intune
14
14
ms.subservice: enrollment
@@ -46,13 +46,16 @@ As an Intune administrator, you can enroll Android devices in the following ways
46
46
-[Corporate-owned, user associated devices](android-aosp-corporate-owned-user-associated-enroll.md): For corporate-owned, single user devices intended exclusively for work and not personal use. Admins can manage the entire device.
47
47
-[Corporate-owned, userless devices](android-aosp-corporate-owned-userless-enroll.md): For corporate-owned, shared devices. Admins can manage the entire device.
48
48
49
+
> [!TIP]
50
+
> For guidance on which enrollment method is right for your organization, see [Deployment guide: Enroll Android devices in Microsoft Intune](../fundamentals/deployment-guide-enrollment-android.md).
51
+
49
52
## Prerequisites
50
53
51
-
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you are first setting up Intune for mobile device management.
54
+
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you’re first setting up Intune for mobile device management.
52
55
53
56
For Android Enterprise, refer to the following support article from Google to ensure that Android Enterprise is available in your country or region: https://support.google.com/work/android/answer/6270910
54
57
55
-
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal additional permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
58
+
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal more permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
56
59
57
60
For Samsung Knox Standard devices, there are [more prerequisites](android-samsung-knox-mobile-enroll.md).
Copy file name to clipboardExpand all lines: memdocs/intune/fundamentals/deployment-guide-enrollment-android.md
+75-10Lines changed: 75 additions & 10 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,12 +2,12 @@
2
2
# required metadata
3
3
4
4
title: Android device enrollment guide for Microsoft Intune
5
-
description: Enroll Android and Android Enterprise corporate-owned work profile, personally owned devices with a work profile, fully managed, and dedicated devices in Microsoft Intune. Decide which enrollment method to use, and get an overview of the administrator and end user tasks to enroll devices.
5
+
description: Enroll Android and Android Enterprise corporate-owned work profile, personally owned devices with a work profile, fully managed, AOSP, and dedicated devices in Microsoft Intune. Decide which enrollment method to use, and get an overview of the administrator and end user tasks to enroll devices.
6
6
keywords:
7
7
author: MandiOhlinger
8
8
ms.author: mandia
9
9
manager: dougeby
10
-
ms.date: 04/14/2021
10
+
ms.date: 02/02/2022
11
11
ms.topic: conceptual
12
12
ms.service: microsoft-intune
13
13
ms.subservice: enrollment
@@ -18,7 +18,7 @@ ms.localizationpriority: high
18
18
#ROBOTS:
19
19
#audience:
20
20
#ms.devlang:
21
-
ms.reviewer: chmaguir
21
+
ms.reviewer: chmaguir, priyar
22
22
ms.suite: ems
23
23
search.appverid: MET150
24
24
#ms.tgt_pltfrm:
@@ -36,6 +36,7 @@ Personal and organization-owned devices can be enrolled in Intune. Once enrolled
This article provides recommendations on the Android enrollment methods. It also includes an overview of the administrator and user tasks for each enrollment type.
@@ -56,9 +57,10 @@ These devices are personal or BYOD (bring your own device) Android devices that
56
57
---
57
58
| Feature | Use this enrollment option when |
58
59
| --- | --- |
60
+
| Use Google Mobile Services (GMS). | ✔️ |
59
61
| Devices are personal or BYOD. | ✔️ <br/><br/> You can mark these devices as corporate or personal. |
60
62
| You have new or existing devices. | ✔️ |
61
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
63
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
62
64
| Devices are associated with a single user. | ✔️ |
63
65
| You use the optional device enrollment manager (DEM) account. | ✔️ |
64
66
| Devices are managed by another MDM provider. | ❌ <br/><br/> When a device enrolls, MDM providers install certificates and other files. These files must be removed. The quickest way may be to unenroll, or factory reset the devices. If you don't want to factory reset, then contact the MDM provider. |
@@ -97,9 +99,10 @@ Previously referred to as COSU. These devices are organization-owned, and suppor
97
99
---
98
100
| Feature | Use this enrollment option when |
99
101
| --- | --- |
102
+
| Use Google Mobile Services (GMS). | ✔️ |
100
103
| Devices are owned by the organization or school. | ✔️ |
101
104
| You have new or existing devices. | ✔️ |
102
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
105
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
103
106
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
104
107
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
105
108
| Devices are associated with a single user. | ❌ <br/><br/> Not recommended. These devices should be enrolled using Android Enterprise fully managed. |
@@ -122,7 +125,12 @@ This task list provides an overview. For more specific information, see [Set up
122
125
123
126
### Android Enterprise dedicated devices end user tasks
124
127
125
-
It's not recommended for users to enroll Android Enterprise dedicated devices. This task should be completed by administrators.
128
+
Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:
129
+
130
+
1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch.
131
+
2. After they enter the required information, your enrollment profile applies to the device. When the enrollment wizard completes, the device is ready to use.
@@ -131,9 +139,10 @@ Previously referred to as COBO. These devices are organization-owned, and have o
131
139
---
132
140
| Feature | Use this enrollment option when |
133
141
| --- | --- |
142
+
| Use Google Mobile Services (GMS). | ✔️ |
134
143
| Devices are owned by the organization or school. | ✔️ |
135
144
| You have new or existing devices. | ✔️ |
136
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
145
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
137
146
| Devices are associated with a single user. | ✔️ |
138
147
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/> User-less devices should be enrolled using Android Enterprise dedicated devices.|
139
148
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -174,9 +183,10 @@ Previously referred to as COPE. These devices are organization-owned, and have o
174
183
---
175
184
| Feature | Use this enrollment option when |
176
185
| --- | --- |
186
+
| Use Google Mobile Services (GMS). | ✔️ |
177
187
| Devices are owned by the organization or school. | ✔️ |
178
188
| You have new or existing devices. | ✔️ |
179
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
189
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
180
190
| Devices are associated with a single user. | ✔️ |
181
191
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/>User-less devices should be enrolled using Android Enterprise dedicated devices. Also, an organization administrator can enroll. When the device is enrolled, create a [dedicated device](../configuration/device-restrictions-android-for-work.md#device-experience) profile, and assign this profile to this device. |
182
192
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -192,7 +202,7 @@ This task list provides an overview. For more specific information, see [Set up
192
202
- Be sure your devices are [supported](supported-devices-browsers.md).
193
203
- Factory reset the devices. This step is required.
194
204
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, see [Connect your Intune account to your Managed Google Play account](../enrollment/connect-intune-android-enterprise.md).
195
-
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md)..
205
+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md).
196
206
- Enroll the devices in Intune. For the specific steps, see [Enroll your Android Enterprise devices](../enrollment/android-dedicated-devices-fully-managed-enroll.md).
197
207
- Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).
198
208
@@ -209,6 +219,61 @@ The specific steps depend on how you configured the enrollment profile. For the
> Currently, there's limited OEM support for this enrollment method.
226
+
227
+
Also referred to as AOSP. Currently in [public preview](public-preview.md). These devices are organization-owned, and don't use Google Mobile Services (GMS). They can be kiosk-style devices that aren't associated with a single or specific user, or can have one user. They're used exclusively for organization work; not personal use.
228
+
229
+
When you create the Intune enrollment profile, you decide if the devices are userless, or are associated with a single user. For more information on these options, including supported OEMs, see:
230
+
231
+
-[Set up Intune enrollment for Android (AOSP) corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
232
+
-[Set up Intune enrollment for Android (AOSP) corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
233
+
234
+
---
235
+
| Feature | Use this enrollment option when |
236
+
| --- | --- |
237
+
| Use Google Mobile Services (GMS). | ❌ AOSP doesn't use [GMS](https://www.android.com/gms/) (opens Android's web site). For example, some countries don't support GMS. <br/><br/> If your devices will use GMS, then use [dedicated devices](#android-enterprise-dedicated-devices) (in this article) or [fully managed](#android-enterprise-fully-managed) (in this article) enrollment. |
238
+
| Devices are owned by the organization or school. | ✔️ |
239
+
| You have new or existing devices. | ✔️ |
240
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ❌ <br/><br/> Can only enroll one device at a time. |
241
+
| Devices are associated with a single user. | ✔️ |
242
+
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
243
+
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
244
+
|Devices are managed by another MDM provider. | ❌ <br/><br/> To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune. |
245
+
| You use the optional device enrollment manager (DEM) account | ❌ <br/><br/> The DEM account isn't supported. |
246
+
247
+
---
248
+
249
+
### Android Open Source Project administrator tasks
250
+
251
+
This task list provides an overview. For more specific information, see enrollment for [AOSP corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md) and [AOSP corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md).
252
+
253
+
- Be sure your devices are [supported](supported-devices-browsers.md).
254
+
- Factory reset the devices. This step is required. New devices might not require a factory reset.
255
+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), create an enrollment profile, and have your device group(s) ready. For the specific steps, see:
During enrollment, the Microsoft Intune app and Microsoft Authenticator app automatically install and open on the device, which allows the device to enroll. The device is locked in the enrollment process until enrollment completes.
263
+
264
+
### Android Open Source Project end user tasks
265
+
266
+
The specific steps depend on how you configured the enrollment profile.
267
+
268
+
Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:
269
+
270
+
1. Users turn on the device, and are prompted for information, including the enrollment method: QR Code. If you created a user-associated devices enrollment profile, then they may be asked to sign in with their organization credentials (`[email protected]`).
271
+
2. If you created a userless devices enrollment profile, then wait for the enrollment wizard to complete. When it does, the device is ready to use.
272
+
273
+
If you created a user-associated devices enrollment profile, then users enter the required information, and your enrollment profile applies to the device. For more specific steps, see [enroll the device](../user-help/enroll-device-android-microsoft-intune-app.md).
These Android devices are corporate, or personal/BYOD (bring your own device) devices that can access organization email, apps, and other data.
@@ -225,7 +290,7 @@ There are some situations when you must use Device Administrator enrollment:
225
290
226
291
- Android Enterprise requires access to Google services. Google services may not be available because of geography, or because of the device manufacturer. For example:
227
292
228
-
- There are places where Google services are not available, like China. In this situation, use Android device administrator enrollment.
293
+
- There are places where Google services aren’t available, like China. In this situation, use Android device administrator enrollment.
229
294
- Some devices are based on Android, but don't have access to Google Services, such as Amazon Fire tablets. In this situation, use Android device administrator enrollment.
230
295
231
296
- Android OS versions older than 5.0 must use Android device administrator enrollment. Android Enterprise enrollment isn't an option.
The `applicationInventory` entity will be removed from the Intune Data Warehouse in an upcoming Intune service release. We're introducing a more complete and accurate dataset that will be available in the UI and via our export API. For related information, see [Export Intune reports using Graph APIs](../fundamentals/reports-export-graph-apis.md).
0 commit comments