Impact of Intune's NFC restriction setting on IC card reading and Nearby Share
Hello,
I'm managing Android Enterprise devices via Intune and would like to confirm the behavior of a specific device restriction setting related to NFC.
■ Device: AQUOS wish4 (Android), enrolled as a fully managed device
■ Policy applied: Device configuration profile with "Beam data using NFC (work-profile level)" set to Block
■ Policy configuration path in Intune Admin Center:
Microsoft Intune Admin Center > Devices > Manage devices > Configuration
- Platform: Android Enterprise
- Profile type: Template > Device restrictions
- Configuration settings > General
- Beam data using NFC (work-profile level): Block
○ Background and expectation:
My understanding is that this setting is intended to block NFC-based data transfer (i.e., Android Beam) within the work profile.
However, I initially assumed it might also block general NFC usage, such as reading contactless transit cards or using mobile wallet services.
○ Test scenario and results:
After applying the policy to a fully managed AQUOS wish4 device, I observed the following:
- The NFC toggle remains available and functional under:
Settings > Connection settings > More connection settings > NFC - I installed an app that reads contactless transit cards used for public transportation (e.g., Suica or PASMO in Japan) and confirmed that it successfully retrieved the card balance via NFC
○ Interpretation:
Based on this behavior, I suspect that the policy only affects the deprecated Android Beam feature, which used NFC for peer-to-peer file sharing.
It does not block general NFC functionality such as card reading or mobile payments, nor does it impact newer sharing technologies like Nearby Share or Quick Share, which rely on Bluetooth and Wi-Fi Direct.
■ Questions:
- Is my understanding correct that "Beam data using NFC (work-profile level)" only restricts Android Beam functionality and does not affect general NFC usage?
- Is there a way to restrict Nearby Share / Quick Share on fully managed Android devices via Intune, or would that require a different configuration or approach?
Any insights, documentation references, or shared experiences would be greatly appreciated.
Thank you!