|
2 | 2 | # required metadata |
3 | 3 |
|
4 | 4 | title: Android Enterprise device settings in Microsoft Intune |
5 | | -description: On Android Enterprise or Android for Work devices, restrict settings on the device. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts. Configure devices as a dedicated device kiosk to run one app, or multiple apps. |
| 5 | +description: On Android Enterprise or Android for Work devices, restrict settings on the device using Microsoft Intune. Restrict copy and paste, notifications, app permissions, data sharing, password length, sign in failures, use fingerprint to unlock, reuse passwords, and enable bluetooth sharing of work contacts. Configure devices as a dedicated device kiosk to run one app, or multiple apps. |
6 | 6 | keywords: |
7 | 7 | author: MandiOhlinger |
8 | 8 | ms.author: mandia |
9 | 9 | manager: dougeby |
10 | | -ms.date: 07/26/2022 |
| 10 | +ms.date: 09/20/2022 |
11 | 11 | ms.topic: conceptual |
12 | 12 | ms.service: microsoft-intune |
13 | 13 | ms.subservice: configuration |
@@ -201,7 +201,7 @@ For corporate-owned devices with a work profile, some settings only apply in the |
201 | 201 |
|
202 | 202 | - **Threat scan on apps**: **Require** (default) enables Google Play Protect to scan apps before and after they're installed. If it detects a threat, it may warn users to remove the app from the device. When set to **Not configured**, Intune doesn't change or update this setting. By default, the OS might not enable or run Google Play Protect to scan apps. |
203 | 203 |
|
204 | | -- **Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but are not limited to: |
| 204 | +- **Common Criteria mode**: **Require** enables an elevated set of security standards that are most often used in highly sensitive organizations, such as government establishments. Those settings include but aren't limited to: |
205 | 205 |
|
206 | 206 | - AES-GCM encryption of Bluetooth Long Term Keys |
207 | 207 | - Wi-Fi configuration stores |
@@ -553,7 +553,7 @@ If you want to enable side-loading, set the **Allow installation from unknown so |
553 | 553 |
|
554 | 554 | - **Clear local data in apps not optimized for Shared device mode**: Add any app not optimized for shared device mode to the list. The app's local data will be cleared whenever a user signs out of an app that's optimized for shared device mode. Available for dedicated devices enrolled with Shared mode running Android 9 and later. |
555 | 555 |
|
556 | | - When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out. |
| 556 | + When you use this setting, users can't initiate sign out from non-optimized apps and get single sign-out. |
557 | 557 | - Users will need to sign out of an app that has been optimized for Shared Device mode. Microsoft apps that are optimized for Shared device mode on Android include Teams and Intune’s Managed Home Screen. |
558 | 558 | - For apps that haven't been optimized for Shared Device mode, deleting application data extends to local app storage only. Data may be left in other areas of the device. User identifying artifacts such as email address and username may be left behind on the app and visible by others. |
559 | 559 | - Non-optimized apps that provide support for multiple accounts could exhibit indeterminate behavior and are therefore not recommended. |
@@ -670,42 +670,77 @@ The Intune default message is translated for all languages in the [Endpoint Mang |
670 | 670 |
|
671 | 671 | You can configure the following settings: |
672 | 672 |
|
673 | | -- **Short support message**: When users try to change a setting that's managed by the organization, a short message is shown. Use these settings to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**. |
| 673 | +- **Short support message**: When users try to change a setting that's managed by the organization, a short message is shown. |
674 | 674 |
|
675 | | - - **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language. |
| 675 | + Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**. |
| 676 | + |
| 677 | + - **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown. This text is also automatically translated to the device's default language. |
676 | 678 |
|
677 | 679 | You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original short Intune default message is used and is translated: |
678 | 680 |
|
679 | 681 | `You do not have permission for this action. For more information, contact your IT admin.` |
680 | 682 |
|
681 | | - - **Select Locale**: Select the locale or region to show the message. |
| 683 | + - **Select Locale**: Select the locale or region to show a different custom message for that specific locale. |
682 | 684 |
|
683 | 685 | For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text. |
684 | 686 |
|
685 | 687 | You can add multiple locales and messages. |
686 | 688 |
|
687 | 689 | - **Message**: Enter the text you want shown, a max of 200 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish. |
688 | 690 |
|
689 | | -- **Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown. Use this setting to customize this message. You can enter a different message for different languages. By default, this message is in **English (United States)**. |
690 | | - |
691 | | - In the short message, you can also select **Learn more** to see this long message. |
| 691 | +- **Long support message**: On the device, in **Settings** > **Security** > **Device admin apps** > **Device Policy**, a long support message is shown. |
692 | 692 |
|
693 | | - Using these settings, you can customize this message and enter a different message for different languages. |
| 693 | + Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**. |
694 | 694 |
|
695 | | - - **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't select a locale and don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language. |
| 695 | + - **All, except when specified**: This message is the Intune default message, and is shown for all languages. If you don't enter a custom message, then this text is automatically shown, and is automatically translated to the device's default language. |
696 | 696 |
|
697 | 697 | You can change this message. Any changes aren't translated. If you delete all the text in this message and leave this setting blank, then the following original long Intune default message is used and is translated: |
698 | 698 |
|
699 | 699 | `The organization's IT admin can monitor and manage apps and data associated with this device, including settings, permissions, corporate access, network activity and the device's location information.` |
700 | 700 |
|
701 | | - - **Select Locale**: Select the locale or region to show the message. |
| 701 | + - **Select Locale**: Select the locale or region to show a different custom message for that specific locale. |
702 | 702 |
|
703 | 703 | For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text. |
704 | 704 |
|
705 | 705 | You can add multiple locales and messages. |
706 | 706 |
|
707 | 707 | - **Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish. |
708 | 708 |
|
| 709 | +- **Lock screen message**: Enter the text you want shown on the device lock screen. |
| 710 | + |
| 711 | + Using the following settings, you can customize this message and enter a different message for different languages. By default, this message is in **English (United States)**. |
| 712 | + |
| 713 | + - **All, except when specified**: Enter the text you want shown for all languages, a max of 4096 characters. This text is automatically translated to the device's default language. If you don't enter a custom message, then Intune doesn't change or update this setting. By default, the OS might not show a lock screen message. |
| 714 | + |
| 715 | + - **Select Locale**: Select the locale or region to show a different custom message for that specific locale. |
| 716 | + |
| 717 | + For example, to show a custom message on devices using **Spanish** as the default language, select **Spanish (Spain)**. Only devices using the **Spanish (Spain)** default language will see your custom message. All other languages will see the **All, except when specified** message text. |
| 718 | + |
| 719 | + You can add multiple locales and messages. |
| 720 | + |
| 721 | + - **Message**: Enter the text you want shown, a max of 4096 characters. The text you enter isn't translated to the device's default language. So if you want to show a message in Spanish, enter the text in Spanish. |
| 722 | + |
| 723 | + When you configure the **Lock screen message**, you can also use the following device tokens to show device-specific information: |
| 724 | + |
| 725 | + - `{{AADDeviceId}}`: Azure AD device ID |
| 726 | + - `{{AccountId}}`: Intune tenant ID or account ID |
| 727 | + - `{{DeviceId}}`: Intune device ID |
| 728 | + - `{{DeviceName}}`: Intune device name |
| 729 | + - `{{domain}}`: Domain name |
| 730 | + - `{{EASID}}`: Exchange Active Sync ID |
| 731 | + - `{{IMEI}}`: IMEI of the device |
| 732 | + - `{{mail}}`: Email address of the user |
| 733 | + - `{{MEID}}`: MEID of the device |
| 734 | + - `{{partialUPN}}`: UPN prefix before the @ symbol |
| 735 | + - `{{SerialNumber}}`: Device serial number |
| 736 | + - `{{SerialNumberLast4Digits}}`: Last four digits of the device serial number |
| 737 | + - `{{UserId}}`: Intune user ID |
| 738 | + - `{{UserName}}`: User name |
| 739 | + - `{{userPrincipalName}}`: UPN of the user |
| 740 | + |
| 741 | + > [!NOTE] |
| 742 | + > Variables aren't validated in the UI and are case sensitive. As a result, you may see profiles saved with incorrect input. For example, if you enter `{{DeviceID}}`, instead of `{{deviceid}}` or `{{DEVICEID}}`, then the literal string is shown instead of the device's unique ID. Be sure to enter the correct information. All lowercase or all uppercase variables are supported, but not a mix. |
| 743 | +
|
709 | 744 | ## Personally owned devices with a work profile |
710 | 745 |
|
711 | 746 | These settings apply to Android Enterprise personally owned devices with a work profile (BYOD). |
|
0 commit comments