You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/android-dedicated-devices-fully-managed-enroll.md
+16-16Lines changed: 16 additions & 16 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -92,15 +92,16 @@ Scan the QR code from the enrollment profile to enroll devices running Android 8
92
92
To use this method, zero-touch enrollment must be supported on devices and affiliated with a supplier that is part of the Android zero-touch enrollment service. For more information, such as prerequisites, where to purchase devices, and how to associate a Google Account with your corporate email, see [Zero-touch enrollment for IT admins](https://support.google.com/work/android/answer/7514005)(opens Android Enterprise Help).
93
93
94
94
This section describes how to:
95
-
* Enable the zero-touch enrollment iframe in the admin center
96
-
* Link a zero-touch account to Microsoft Intune and create a default zero-touch configuration
97
-
* Configure zero-touch configurations using the zero-touch enrollment portal
95
+
* Create a zero-touch configuration in the admin center
96
+
* Create a zero-touch configuration in the zero-touch enrollment portal
98
97
99
-
### Enable zero-touch iframe
100
-
Complete these prerequisites to enable the zero-touch iframe in the Microsoft Endpoint Manager admin center. The iframe lets you access the Google zero-touch enrollment portal from inside the admin center and reduces the number of screens you have to have open. To create configurations in the zero-touch enrollment portal instead, skip to [Create zero-touch configuration](android-dedicated-devices-fully-managed-enroll.md#create-zero-touch-configuration) in this section.
98
+
### Create zero-touch configuration in admin center
99
+
The zero-touch iframe lets you access the zero-touch enrollment portal from inside the Microsoft Endpoint Manager admin center. To enable the iframe, you must first add the *update app sync* permission and enable enrollment for corporate-owned, fully managed devices. After those steps are complete, the zero-touch enrollment option becomes visible in the admin center and you can link your account and create zero-touch configurations.
100
+
101
+
Complete the following steps to enable the iframe and create a new zero-touch configuration. To create configurations in the zero-touch enrollment portal instead, skip to [Create configuration in zero-touch enrollment portal](android-dedicated-devices-fully-managed-enroll.md#create-configuration-in-zero-touch-enrollment-portal).
101
102
102
103
#### Step 1: Add required permission
103
-
Add the *update app sync* permission.
104
+
Add the *update app sync* permission.
104
105
105
106
1. Sign in to the [Microsoft Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431)
106
107
admin.
@@ -114,14 +115,15 @@ admin.
114
115
9. Select **Save**.
115
116
116
117
#### Step 2: Enable enrollment for corporate-owned devices
118
+
Verify that enrollment is enabled for corporate-owned, fully managed devices.
117
119
118
120
1. In the admin center, go to **Devices** > **Enroll devices**.
119
121
2. Select **Android enrollment**.
120
122
3. Under **Enrollment profiles**, choose **Corporate-owned, fully managed user devices**.
121
123
4. Verify that the setting for **Allow users to enroll corporate-owned user devices**, is set to **Yes**.
122
124
123
-
### Link zero-touch account to Intune
124
-
Link a zero-touch account with your Microsot Intune account. This procedure takes place in the admin center. After you link your device and creates the account's default configuration for zero-touch enabled devices that are fully managed.
125
+
#### Step 3: Link zero-touch account to Intune
126
+
Link a zero-touch account with your Microsot Intune account. This procedure takes place in the admin center. After you link your device, Intune creates a default configuration policy. The policy is applied to fully managed, zero-touch enabled devices that are without an existing configuration.
125
127
126
128
1. In the admin center, go to **Devices** > **Enroll devices**.
127
129
2. Select **Android enrollment**.
@@ -132,18 +134,18 @@ Link a zero-touch account with your Microsot Intune account. This procedure take
132
134
6. A default configuration is created and a screen appears with basic information about the new configuration. Intune will automatically apply the default to any zero-touch enabled device that's without an existing configuration. Select **Next** to continue.
133
135
134
136
> [!TIP]
135
-
> The token used for the default configuration is for a fully managed device. If you want to create a zero-touch configuration for a corporate-owned work profile device or a dedicated device, see [Create configuration in Zero Touch](android-dedicated-devices-fully-managed-enroll.md#create-zero-touch-configuration) (in this article).
137
+
> The token used for the default configuration is for a fully managed device. If you want to create a zero-touch configuration for a corporate-owned work profile device or a dedicated device, see [Create configuration in zero-touch enrollment portal](android-dedicated-devices-fully-managed-enroll.md#create-configuration-in-zero-touch-enrollment-portal) (in this article).
136
138
6. Add support information to assist device users during setup.
137
139
7. Select **Save**.
138
140
139
-
Once your account is linked with Intune, zero-touch enabled devices are ready to receive the default configuration. You can view existing zero-touch configurations, edit support information, unlink the account, and link other accounts in the admin center. To change or create new configurations, use the steps in [Create a zero-touch configuration](android-dedicated-devices-fully-managed-enroll.md#create-zero-touch-configuration) (in this article).
141
+
Once your account is linked with Intune, zero-touch enabled devices are ready to receive the default configuration. You can view existing zero-touch configurations, edit support information, unlink the account, and link other accounts in the admin center.
140
142
141
-
### Create zero-touch configuration
143
+
### Create configuration in zero-touch enrollment portal
142
144
143
145
Add a zero-touch configuration in the Google zero-touch enrollment portal. If you haven't enabled the iframe in the Microsoft Endpoint Manager admin center, you can use the zero-touch enrollment portal to manage your configurations. You can create configurations for fully managed and dedicated devices, and corporate-owned devices with a work profile.
144
146
145
-
1. Sign in to the zero-touch enrollment portal with your Google Account.
146
-
2. Select the option to add a new configuration.
147
+
1. Sign in to the zero-touch enrollment portal with your Google account.
148
+
2. Select the option to add a new configuration.
147
149
3. Fill out the information in the configuration panel.
148
150
4. Select **Microsoft Intune** as the EMM DPC app.
149
151
5. Copy the following JSON text into the DPC extras field. Replace `YourEnrollmentToken` with the enrollment token you created as part of your enrollment profile. Be sure to surround the enrollment token with double quotes.
@@ -160,9 +162,7 @@ Add a zero-touch configuration in the Google zero-touch enrollment portal. If yo
6. Enter your organization's name and support information, which is shown on screen while users set up their devices.
162
164
163
-
For information about how to assign a default configruation or apply a configuration in the zero-touch portal, see [Zero-touch enrollment for IT admins](https://support.google.com/work/android/answer/7514005)(opens Android Enterprise Help).
164
-
165
-
165
+
For more information about how to assign a default configruation or apply a configuration in the zero-touch portal, see [Zero-touch enrollment for IT admins](https://support.google.com/work/android/answer/7514005)(opens Android Enterprise Help).
166
166
167
167
## Enroll by using Knox Mobile Enrollment
168
168
To use Samsung's Knox Mobile Enrollment, the device must be running Android OS version 8.0 or later and Samsung Knox 2.8 or higher. For more information, learn [how to automatically enroll your devices with Knox Mobile Enrollment](./android-samsung-knox-mobile-enroll.md).
0 commit comments