Device restriction settings for Android in Microsoft Intune (2023)

  • Article

This article shows you all the Microsoft Intune device restrictions settings that you can configure for devices running Android. As part of your mobile device management (MDM) solution, use these settings to allow or disable features, set password requirements, control security, and more.

This feature applies to:

  • Android device administrator (DA)

Tip

If the settings you want are not available, you might be able to configure your devices using a custom profile.

Before you begin

Create an Android device administrator device restrictions configuration profile.

General

  • Camera: Block prevents access to the device camera. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow access to the device camera.

    Intune only manages access to the device camera. It doesn't have access to pictures or videos.

    (Video) Intune Enrollment limit & type restriction policy | Windows iOS Android | Microsoft Endpoint Manager

  • Copy and paste (Samsung Knox only): Block prevents copy-and-paste. Not configured allows copy and paste functions on devices.

  • Clipboard sharing between apps (Samsung Knox only): Block prevents using the clipboard to copy-and-paste between apps. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow copy and paste functions on devices.

  • Diagnostic data submission (Samsung Knox only): Block stops users from submitting bug reports from devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to submit the data.

  • Wipe (Samsung Knox only): Allows users to run a wipe action on devices. When set to Not configured (default), Intune doesn't change or update this setting.

  • Geolocation (Samsung Knox only): Block disables devices from using location information. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow devices to use the location information.

  • Power off (Samsung Knox only): Block prevents users from powering off device. It also prevents the Number of sign-in failures before wiping device setting from being configured, and from working. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to power off devices.

  • Screen capture (Samsung Knox only): Block prevents screenshots. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might let users capture the screen contents as an image.

  • Voice assistant (Samsung Knox only): Block disables the S Voice service. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using the S Voice service and app on devices. This setting doesn't apply to Bixby or the voice assistant for accessibility that reads the screen content aloud.

  • YouTube (Samsung Knox only): Block prevents users from using the YouTube app. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using the YouTube app on devices.

  • Shared devices (Samsung Knox only): Configure a managed Samsung Knox Standard device as shared. Allow lets users sign in and out of devices with their Azure AD credentials. Devices stay managed, whether they're in use or not.

    When used in with a SCEP certificate profile, this feature allows users to share a device with the same apps for all users. But, each user has their own SCEP user certificate. When users sign out, all app data is cleared. This feature is limited to LOB apps only.

    When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might prevent multiple users from signing in to the Company Portal app on devices using their Azure AD credentials.

  • Block date and time changes (Samsung Knox): Block prevents users from changing the date and time settings on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to change the date and time settings.

Password

  • Encryption: Select Require so that files on the device are encrypted. Not all devices support encryption. When set to Not configured (default), Intune doesn't change or update this setting. To configure this setting, and correctly report compliance, also configure:

    1. Password: Set to Require.
    2. Required password type: Set to At least numeric.
    3. Minimum password length: Set to at least 4.

    Note

    If an encryption policy is enforced, Samsung Knox devices require users to set a 6-character complex password as the device passcode.

All Android devices

These settings apply to Android 4.0 and newer, and Knox 4.0 and newer.

  • Maximum minutes of inactivity until screen locks: Enter the length of time a device must be idle before the screen is automatically locked. For example, enter 5 to lock devices after 5 minutes of being idle. When the value is blank or set to Not configured, Intune doesn't change or update this setting.

    (Video) Device configuration Profiles Create Android Enterprise Device Restrictions - Intune Training No#64

    On a device, users can't set a time value greater than the configured time in the profile. Users can set a lower time value. For example, if the profile is set to 15 minutes, users can set the value to 5 minutes. Users can't set the value to 30 minutes.

  • Number of sign-in failures before wiping device: Enter the number of wrong passwords allowed before devices are wiped, from 4-11. 0 (zero) might disable device wipe functionality. When the value is blank, Intune doesn't change or update this setting.

  • Password: Require users to enter a password to access devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to access devices without entering a password.

    Note

    Samsung Knox devices automatically require a 4-digit PIN during MDM enrollment. Native Android devices may automatically require a PIN to become compliant with Conditional Access.

Android 10 and later

  • Password complexity: Enter the required password complexity. Your options:

    • None (default): No password required.
    • Low: The password satisfies one of the following conditions:
      • Pattern
      • Numeric PIN has a repeating (4444) or ordered (1234, 4321, 2468) sequence.
    • Medium: The password satisfies one of the following conditions:
      • Numeric PIN doesn’t have a repeating (4444) or ordered (1234, 4321, 2468) sequence, and has minimum length of 4.
      • Alphabetic, with a minimum length of 4.
      • Alphanumeric, with a minimum length of 4.
    • High: The password satisfies one of the following conditions:
      • Numeric PIN doesn’t have a repeating (4444) or ordered (1234, 4321, 2468) sequence, and has minimum length of 8.
      • Alphabetic, with a minimum length of 6.
      • Alphanumeric, with a minimum length of 6.

    This setting applies to:

    • Android 10 and newer, but not on Samsung Knox.

    Important

    The Password complexity setting is a work in progress. In late October 2020, Password complexity will take effect on devices.

    If you set Password complexity to something other than None, then also set the Password setting to Require, which is found under the All Android devices section. Users with passwords that don't meet your complexity requirements receive a warning to update their password. If you don’t set the Password setting to Require, users with weak passwords won’t receive the warning.

Android 9 and earlier, or Samsung Knox (any version)

  • Minimum password length: Enter the minimum number of characters required, from 4-16. For example, enter 6 to require at least six numbers or characters in the password length.

  • Password expiration (days): Enter the number of days, until the device password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. When the value is blank, Intune doesn't change or update this setting.

  • Required password type: Enter the required password complexity level, and whether biometric devices can be used. Your options:

    • Device default

    • Low security biometric: Strong vs. weak biometrics (opens Android's web site)

    • At least numeric: Includes numeric characters, such as 123456789.

    • Numeric complex: Repeated or consecutive numbers, such as "1111" or "1234", aren't allowed. Before you assign this setting to devices, be sure to update the Company Portal app to the latest version on those devices.

      (Video) Locate your Android devices using Microsoft Intune

      When set to Numeric complex, and you assign the setting to devices running an Android version earlier than 5.0, then the following behavior applies:

      • If the Company Portal app is running a version earlier than 1704, no PIN policy applies to devices, and an error shows in the Microsoft Intune admin center.
      • If the Company Portal app runs the 1704 version or later, only a simple PIN can be applied. Android version earlier than 5.0 don't support this setting. No error is shown in the Microsoft Intune admin center.
    • At least alphabetic: Includes letters in the alphabet. Numbers and symbols aren't required.

    • At least alphanumeric: Includes uppercase letters, lowercase letters, and numeric characters.

    • At least alphanumeric with symbols: Includes uppercase letters, lowercase letters, numeric characters, punctuation marks, and symbols.

  • Prevent reuse of previous passwords: Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. When the value is blank, Intune doesn't change or update this setting.

  • Fingerprint unlock (Samsung Knox only): Block prevents using a fingerprint to unlock devices. When set to Not configured (default), Intune doesn't change or update this setting.By default, the OS might allow users to unlock devices using a fingerprint.

  • Smart Lock and other trust agents: Block prevents Smart Lock or other trust agents from adjusting lock screen settings. If the device is in a trusted location, then this feature, also known as a trust agent, lets you disable or bypass the device lock screen password. For example, use this feature when devices are connected to a specific Bluetooth device, or when devices are close to an NFC tag. You can use this setting to prevent users from configuring Smart Lock.

    When set to Not configured (default), Intune doesn't change or update this setting.

    This setting applies to:

    • Samsung KNOX Standard 5.0 and newer

Google Play Store

  • Google Play store (Samsung Knox only): Block prevents users from using the Google Play store. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow users to access the Google Play store on devices.

Restricted apps

This feature is supported on Android and Samsung Knox Standard devices.

  • Type of restricted apps list: Create a list of apps to allow or block on devices. This feature is supported on Android and Samsung Knox Standard devices. Your options:

    • Not configured (default): Intune doesn't change or update this setting.
    • Prohibited apps: List the apps (not managed by Intune) that users aren't allowed to install and run. If a user installs an app from this list, you're notified by Intune.
    • Approved apps: List the apps that users are allowed to install. To stay compliant, users must not install other apps. Apps that are managed by Intune are automatically allowed, including the Company Portal app.
  • Apps list: Add your app:

    • App store URL: Enter the Google Play Store URL of the app you want. For example, to add the Microsoft Remote Desktop app for Android, enter https://play.google.com/store/apps/details?id=com.microsoft.rdc.android.

      To find the URL of an app, open the Google Play store, and search for the app. For example, search for Microsoft Remote Desktop Play Store or Microsoft Planner. Select the app, and copy the URL.

    • App bundle ID: Enter the app bundle ID.

    • App name: Enter the name you want. This name is shown to users.

    • Publisher (optional): Enter the publisher of the app, such as Microsoft.

You can also Import a CSV file with details about the app, including the URL. Use the <app url>, <app name>, <app publisher> format. Or, Export an existing list that includes the restricted apps list in the same format.

Important

Device profiles that use the restricted app settings must be assigned to user groups, not device groups.

(Video) Create Intune Device Restriction Policy to Block App Store

Browser

  • Web browser (Samsung Knox only): Block prevents the default web browser from being used on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow the device's default web browser to be used.
  • Autofill (Samsung Knox only): Block prevents the browser from automatically filling in text. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Autofill.
  • Cookies (Samsung Knox only): Choose how to handle cookies from websites on devices. Your options:
    • Allow
    • Block all cookies
    • Allow cookies from visited web sites
    • Allow cookies from current web site
  • JavaScript (Samsung Knox only): Block prevents JavaScript from running in the browser. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow these scripts.
  • Pop-ups (Samsung Knox only): Block turns on Pop-up Blocker to prevent pop-ups in the web browser. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow pop-ups.

Allow or Block apps

Use these settings to allow, block, or hide specific apps on Samsung Knox Standard devices. Apps that are hidden can't be opened or ran by users.

Your options:

  • Apps allowed to be installed (Samsung Knox Standard only): Add apps that users can install. Users can't install apps that aren't on the list.
  • Apps blocked from launching (Samsung Knox Standard only): Enter the apps that users can't run on their device.
  • Apps hidden from user (Samsung Knox Standard only): Enter the apps that are hidden on devices. Users can't discover or run these apps.

For each setting, add your apps:

  • Add apps by package name: Enter the app name, and the name of the app package. Primarily used for line-of-business apps.
  • Add apps by URL: Enter the app name, and its URL in the Google Play store.
  • Add store app: Select an app from the existing list of apps you manage in Intune.

Cloud and Storage

  • Google backup (Samsung Knox only): Block prevents devices from syncing to Google backup. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using Google backup.
  • Google account auto sync (Samsung Knox only): Block prevents the Google account auto sync feature on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow Google account settings to be automatically synchronized.
  • Removable storage (Samsung Knox only): Block prevents devices from using removable storage. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow devices to use removable storage, like an SD card.
  • Encryption on storage cards (Samsung Knox only): Require enforces that storage cards must be encrypted. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow unencrypted storage cards to be used. Not all devices support storage card encryption. To confirm, check with the device manufacturer.

Cellular and Connectivity

  • Data roaming (Samsung Knox only): Block prevents data roaming over the cellular network. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow data roaming.
  • SMS/MMS messaging (Samsung Knox only): Block prevents text messaging on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using SMS and MMS messaging.
  • Voice dialing (Samsung Knox only): Block prevents users from using the voice dialing feature on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow voice dialing.
  • Voice roaming (Samsung Knox only): Block prevents voice roaming over the cellular network. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow voice roaming.
  • Bluetooth (Samsung Knox only): Block prevents using Bluetooth on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using Bluetooth.
  • NFC (Samsung Knox only): Block disables operations that use near field communication (NFC) on devices that support it. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow NFC operations.
  • Wi-Fi (Samsung Knox only): Block prevents using Wi-Fi on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using Wi-Fi.
  • Wi-Fi tethering (Samsung Knox only): Block prevents using Wi-Fi tethering on devices. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using Wi-Fi tethering.

Kiosk

Kiosk settings apply only to Samsung Knox Standard devices, and only to apps you manage using Intune.

  • Add apps you want to run when the device is in kiosk mode. In kiosk mode, only the apps you add run; apps not added don't run. Pre-installed browsers don't run as an app when the device is in kiosk mode. If a browser is required, consider using the Managed Browser.

    Your app options:

    • Add apps by package name: Primarily used for line-of-business apps. Enter the app name, and the name of the app package.
    • Add apps by URL: Enter the app name, and its URL in the Google Play store.
    • Add store app: Select an app from the existing list of apps you manage in Intune.
  • Screen sleep button: Block prevents or hides the screen sleep button. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow the screen sleep wake button on devices.

  • Volume buttons: Block prevents users from adjusting the volume by disabling the volume buttons. When set to Not configured (default), Intune doesn't change or update this setting. By default, the OS might allow using the volume buttons on devices.

Next steps

Assign the profile and monitor its status.

You can also create kiosk profiles for Android Enterprise and Windows 10 devices.

Feedback

Submit and view feedback for

This product This page

(Video) Device configuration Profiles Create Android Enterprise Work Profile Device Restriction - Intune #66

FAQs

How do I create device restrictions in Intune? ›

Create a device platform restriction
  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices > Enroll devices > Enrollment device platform restrictions.
  3. Select the tab along the top of the page that corresponds with the platform you're configuring. ...
  4. Select Create restriction.
Feb 21, 2023

How do I manage Android devices in Intune? ›

Android Enterprise fully managed administrator tasks
  1. Be sure your devices are supported.
  2. Factory reset the devices. ...
  3. In the Intune admin center, connect your Intune organization account to your Managed Google Play account. ...
  4. In the Intune admin center, enable fully managed user devices. ...
  5. Enroll the devices in Intune.
Mar 1, 2023

What settings on Android are supported Intune compliance settings? ›

Device Security - for Personally-Owned Work Profile
  • Block apps from unknown sources. Not configured (default) - This setting isn't evaluated for compliance or non-compliance. ...
  • Company portal app runtime integrity. ...
  • Block USB debugging on device. ...
  • Minimum security patch level. ...
  • Require a password to unlock mobile devices.
Feb 20, 2023

Where do I find device restriction settings? ›

Allow restricted settings
  1. On your Android device, open the Settings app.
  2. Tap Apps.
  3. Tap the app that you want to turn on a restricted setting for. Tip: If you can't find it, first tap See all apps or App info.
  4. Tap More. Allow restricted settings.
  5. Follow the on-screen instructions.

How do I change my device limit on Intune? ›

Sign in to the Microsoft Intune admin center. Go to Devices > Enrollment restrictions > Create restriction > Device limit restriction.

How do I manage non compliant devices in Intune? ›

Add actions for noncompliance
  1. Sign in to the Microsoft Intune admin center.
  2. Select Devices > Compliance policies > Policies, select one of your policies, and then select Properties. ...
  3. Select Actions for noncompliance > Add.
  4. Select your Action:
Feb 21, 2023

Where is Android Device Manager in settings? ›

Select "Security" from the Settings menu. Scroll down and tap "Device administrators". Ensure that "Android Device Manager" is checked.

How your Android device is managed? ›

Manage devices
  1. Open the Google Admin app .
  2. When prompted, enter your Google Account PIN.
  3. If necessary, switch to your administrator account: Tap Menu Down Arrow. to choose another account.
  4. Tap Menu. Devices.
  5. Tap the device or user.
  6. Tap Approve Approve. Or, next to the device name, tap More Approve device.

How do I disable a device on Intune? ›

Remove in device Settings app
  1. Open the Settings app.
  2. Go to Accounts > Access work or school.
  3. Select the connected account that you want to remove > Disconnect.
  4. To confirm device removal, select Yes.
Feb 28, 2023

What is device restrictions in Intune? ›

Intune includes device restriction policies that help administrators control Android, iOS/iPadOS, macOS, and Windows devices. These restrictions let you control a wide range of settings and features to protect your organization's resources. For example, administrators can: Allow or block the device camera.

What are the default device restrictions in Intune? ›

Intune device limit restrictions

You can allow a user to enroll up to 15 devices. To set a device limit restriction, sign in to Microsoft Intune admin center. Then go to Devices > Enrollment restrictions. For more information, see Create a device limit restriction.

What Android prerequisites does Intune require? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies. This requirement does not apply to Microsoft Teams Android devices as these devices will continue to be supported.

How do I turn on restrictions on Android? ›

Set up parental controls
  1. Open the Google Play app .
  2. At the top right, tap the profile icon.
  3. Tap Settings Family. Parental controls.
  4. Turn on Parental controls.
  5. To protect parental controls, create a PIN your child doesn't know.
  6. Select the type of content you want to filter.
  7. Choose how to filter or restrict access.

How do I manage Intune permissions? ›

Sign in to the Microsoft 365 admin center with a global administrator account > select Users > Active users > choose the user to give admin permissions. In the user pane, choose Manage roles under Roles. In the Manage roles pane, choose the admin permission to grant from the list of available roles.

What is the device limit for Device Enrollment Manager? ›

People signed in to a DEM account can enroll and manage up to 1,000 devices, while a standard non-admin account can only enroll 15. A DEM account requires an Intune user or device license, and an associated Azure AD user.

How do I force Intune to sync all devices? ›

Sign in to the Microsoft Intune admin center. Select Devices > All devices. In the list of devices you manage, select a device to open its Overview pane, and then select Sync. To confirm, select Yes.

How do I remove Intune device management from my Android? ›

Company Portal is a device management app and can't be uninstalled until you remove your device from it. Once that's done, tap and hold the Company Portal app icon until you see Uninstall. Tap Uninstall to remove the app. Alternatively, you can go to Settings > Apps > Company Portal > Uninstall.

How do I check my device settings in Intune Company Portal? ›

Open the Company Portal app for Android on your device. Tap Devices and then select your device. Under Device Settings Status, tap Check device settings. Company Portal will check your device to confirm that it's meeting your organization's policy requirements.

How are the settings that you assigned to devices and apps contained within Intune? ›

Microsoft Intune includes settings and features you can enable or disable on different devices within your organization. These settings and features are added to "configuration profiles" and then you can use Intune to apply or "assign" the profile to the devices.

How do I open device settings on Android? ›

Open the Android Settings from the Quick Settings

You can find a shortcut for the Settings app in the Quick Settings menu. To open the Quick Settings, swipe down from the top side of the screen. On some devices, you get the same result by swiping down from any part of the Home screen.

How to setup Android Device Manager? ›

To open the new Device Manager, do one of the following: From the Android Studio Welcome screen, select More Actions > Virtual Device Manager.
...
Select one of the following:
  1. Phone/Tablet.
  2. Wear OS.
  3. Android TV.
  4. Google TV.
  5. ChromeOS Device.
  6. Android Automotive.

How do I enable Android Device Manager? ›

To turn on Android Device Manager on your device, follow these steps:
  1. Touch > Google Settings.
  2. Touch Android Device Manager. You have the option of turning on the following Android Device Manager options: Remotely locate this device. You can use Android Device manager to show your device's location.

How do I manage my Android device administrator? ›

Sign in to the Microsoft Intune admin center and choose > Devices > Android > Android enrollment > Personal and corporate-owned devices with device administration privileges > Use device administrator to manage devices.

How do I know if my device is Intune managed? ›

Sign in to the Microsoft Intune admin center. Select Devices > All devices > select one of your listed devices to open its details: Overview shows the device name, and lists some key properties of the device, like whether it's a personal or corporate device, serial number, primary user, and more.

What is a fully managed device Android? ›

Full device management offers comprehensive device and app management capabilities for company-owned devices. This option gives you granular control over device data and security, as well as access to Android's full suite of app management features.

What should I disable in Device Manager? ›

Unnecessary hardware can be disabled in the Windows Device Manager. Review this list and disable any devices that you do not need, such as the Web camera, Bluetooth, DVD/CD-ROM drives, Ethernet or Wireless network adapters, and any other unneeded devices.

Can Intune wipe a personal device? ›

The device is retired from management with Intune. Wipe is not supported for Android personally-owned work profiles.

What does device restriction mean? ›

You can allow or restrict users to access various features of the device like Bluetooth, Camera, encrypting device data, etc. Only devices running Android 5.0 or above can be provisioned as Profile Owner or Device Owner.

How does Intune work on Android? ›

Intune supports the mobile device management (MDM) of Android devices to give people secure access to work email, data, and apps. This guide provides Android-specific resources to help you set up enrollment in Intune and deploy apps and policies to users and devices.

Which Android is required for Intune company portal? ›

Company Portal supports devices running Android 8.0 and later, including devices secured by Samsung KNOX Standard 2.4 and later.

Does Intune require device compliance? ›

To manage the compliance policy settings, sign in to Microsoft Intune admin center and go to Endpoint security > Device compliance > Compliance policy settings. This setting determines how Intune treats devices that haven't been assigned a device compliance policy.

How do I remove restrictions from apps on Android? ›

Change app permissions
  1. On your phone, open the Settings app.
  2. Tap Apps.
  3. Tap the app you want to change. If you can't find it, tap See all apps. ...
  4. Tap Permissions. If you allowed or denied any permissions for the app, you'll find them here.
  5. To change a permission setting, tap it, then choose Allow or Don't allow.

Can you put restrictions on an Android phone? ›

You can set up parental controls on Android through both the Google Family Link app and Google Play Store app. While the Google Family Link is designed primarily for Android, it can also be installed on an iOS device to manage accounts.

Why does my phone show restricted? ›

These calls appear restricted because the caller blocks their number from the caller IDs of the public to avoid stalking.

Where do I find restrictions on my Samsung phone? ›

Navigate to and open Settings, and then tap Digital Wellbeing and parental controls. Tap Parental controls, and then tap Get started. Select Child or teen, or Parent, depending on the device's user. In this case, tap Parent.

How do I assign permissions in Intune? ›

Sign in to the Microsoft Intune admin center with a global administrator account > Users > then choose the user you want to give admin permissions. Select Assigned roles > Add assignments. In the Directory roles pane, select the roles you want to assign to the user > Add.

How do I add a device category to Intune? ›

Step 1: Create device category in Intune
  1. Sign in to the Microsoft Intune admin center.
  2. Choose Devices > Device categories.
  3. Select Create device category to add a new category.
  4. Enter the name of the new category, such as HR and an optional description.
  5. Select Next.
Apr 14, 2023

Can you disable a device on Intune? ›

Remove in device Settings app

Open the Settings app. Go to Accounts > Access work or school. Select the connected account that you want to remove > Disconnect. To confirm device removal, select Yes.

How do I restrict apps on Intune? ›

In Intune
  1. Access the Apps Panel in Intune.
  2. Select Intune App protection.
  3. Verify that an app protection policy exists that includes that apps that you WOULD NOT like to be blocked.
Mar 10, 2022

How do I change permissions settings? ›

Change app permissions
  1. On your phone, open the Settings app.
  2. Tap Apps.
  3. Tap the app you want to change. If you can't find it, tap See all apps. ...
  4. Tap Permissions. If you allowed or denied any permissions for the app, you'll find them here.
  5. To change a permission setting, tap it, then choose Allow or Don't allow.

What is the easiest way to assign permissions? ›

Setting Permissions
  1. Access the Properties dialog box.
  2. Select the Security tab. ...
  3. Click Edit.
  4. In the Group or user name section, select the user(s) you wish to set permissions for.
  5. In the Permissions section, use the checkboxes to select the appropriate permission level.
  6. Click Apply.
  7. Click Okay.
Mar 31, 2023

What is the command to set permissions? ›

The chmod command enables you to change the permissions on a file. You must be superuser or the owner of a file or directory to change its permissions.

How do I set up Android enrollment in Intune? ›

Create an enrollment profile
  1. Sign in to the Microsoft Intune admin center and choose Devices > Android > Android enrollment > Android Enterprise > Corporate-owned dedicated devices.
  2. Choose Create and fill out the required fields. ...
  3. Choose Create to save the profile.
Feb 21, 2023

How are the settings that you assign to devices and apps contained within Intune? ›

Microsoft Intune includes settings and features you can enable or disable on different devices within your organization. These settings and features are added to "configuration profiles" and then you can use Intune to apply or "assign" the profile to the devices.

What is the difference between user group and device group in Intune? ›

Use device groups when you don't care who's signed in on the device, or if anyone is signed in. You want your settings to always be on the device. For users: Profile settings applied to user groups always go with the user, and go with the user when signed in to their many devices.

How do I remove an Android device from Intune management? ›

Sign in to Company Portal. Select Devices and then select the device you want to remove. Select the menu > Remove Device. Select OK to finish removing your device.

What does enabling a device in Intune do? ›

Simplify Windows enrollment for you and device users by enabling automatic enrollment in Microsoft Intune. This enrollment method enables devices to enroll automatically when they join or register in your Azure Active Directory.

What are the restrictions on MDM? ›

Users can't use their Apple devices to set up and configure other Apple devices. Users can't modify the Bluetooth setting. Users can't change any settings for the cellular plan. Users can't remove iOS and iPadOS-native apps.

Videos

1. MIH07 - Setup your Microsoft Intune Tenant - Enrolment restrictions and device settings
(CloudManagement.Community)
2. Device configuration Profiles Create Android Device Administration Device Restrictions - Intune #71
(Paddy Maddy)
3. Microsoft intune How to Enroll Android devices and configure the Compliance Policy
(Hasitha methmal willarachchi)
4. MS08 - How to Setup Android Enrollment with Intune
(Alien Tech Champion)
5. Set enrollment restrictions in Intune -Microsoft Intune Training Series video No#29
(Paddy Maddy)
6. S02E07 - Manage Android Devices with Intune - A Comprehensive Guide - Leon Ashton-Leatherland (I.T)
(Intune Training)
Top Articles
Latest Posts
Article information

Author: Greg Kuvalis

Last Updated: 21/10/2023

Views: 6053

Rating: 4.4 / 5 (75 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Greg Kuvalis

Birthday: 1996-12-20

Address: 53157 Trantow Inlet, Townemouth, FL 92564-0267

Phone: +68218650356656

Job: IT Representative

Hobby: Knitting, Amateur radio, Skiing, Running, Mountain biking, Slacklining, Electronics

Introduction: My name is Greg Kuvalis, I am a witty, spotless, beautiful, charming, delightful, thankful, beautiful person who loves writing and wants to share my knowledge and understanding with you.