cope
23 TopicsCopy-paste issue (COPE)
Hello Everyone, I have a slight issue with copy-paste on Corporate owned, personal enabled devices (COPE) managed via Intune. To put it simple - people can copy text from work profile to personal. Happy to be pointed to the basics if I missed something obvious, but I feel stuck. Intune configuration for COPE devices has 2 values: "allow" or "not configured" (not helpful). I had support cases open with Microsoft and Samsung, but former blames OS defaults, while latter blames Intune (not helpful). I couldn't identify the setting in OEMConfig (Knox Service Plugin), so got Google Enterprise account, configured it for Zero Touch enrolment using Intune token and realised that I was looking into "crossProfileCopyPaste" control and don't have a clue how to use it in DPC extras and if that's even possible. Is it possible to use AMAPI with Intune management? If yes, does anyone have any examples? What are other ways to restrict copy-paste from work profile to personal? I find it difficult to believe I'm the only one having the issue. Thank you in advance12KViews1like29CommentsFactory Reset Protection and Captive Portals
A bit of background on this, we're currently moving to use COPE Enrolment for all of our devices after using BYOD Enrolment for devices purchased by our org. Utilising BYOD we had issues with users signing into their gmail accounts and leaving the business and we were locked out of the device by Factory Reset Protection (We've used Knox Mobile Enrolment to solve this). This all made sense as it was a BYOD device and for consumers etc it makes a lot of sense. The problem we've encountered is even with COPE enroled devices, if a user doesn't remove their gmail account from the personal profile before resetting the device when the device is used again you're unable to use a Captive Portal network for setup again and this error message is received - "Unable to sign in to Wi-Fi AP. An unauthorised factory reset has been performed on this device. the sign-in screen cannot be accessed." Even after enrolling the device using a WPA2/3 Network and signing in with the google account in question and manually removing it then resetting the device we still have this issue, it's as if the FRP flag gets set and isn't being removed for some reason. It seems odd any network and even cellular allows you to continue but a captive portal connection doesn't. Has anyone else encountered this issue? Thanks.Solved9.6KViews0likes12CommentsWidgets on COPE - MS Intune
Hey, Unfortunately there are no settings and/or no chance configure Widgets on COPE in MS Intune. There is specific setting in Intune restrictions config profile to allow/disallow Widgets for BYOD method. Is this problem tied only MS Intune or is this something for Google? Majority of our 10k fleet enrolled as COPE and it's a big gap not having widgets available for Work Apps. Thanks Jarmo8.1KViews0likes19CommentsSamsung Secure Folder and DUAL messenger features - not available in COPE
Dear community, hope everyone had lovely Christmas time! I just wanted to raise one issue you also might been run into. It's about Samsung Secure Folder and Dual Messenger features on COPE enrolled devices. Unfortunately these features are not available in COPE enrolled Samsung devices. We used to have all 10k fleet enrolled as BYOD and Secure Folder/Dual Messenger features were/are available. Now only personal owned devices are enrolled as BYOD and corporate owned devices are enrolled as COPE method. Unfortunately there is no setting available for us to make this work on the COPE enrolled devices on EMM side. According to Samsung, they have not updated Secure Folder software in 5 years and and don't necessarily expect we will get any update. The "error message" is very misleading: "Security policy prevents the installation of Secure Folder". Because there is no security policy setup in EMM (Microsoft Intune) for this feature. It's just pure Samsung thing. As mentioned... Samsung Secure Folder solution does not work on COPE enrolled Samsung devices but nice surprise is that on ThinkPhone (Motorola) , Secure Folder works even on COPE. This also implies that Samsung really could make it work if they wanted to put in the development effort, as it is not totally restricted by the Android Enterprise architecture of COPE since the ThinkPhone is able to do it. But so far Samsung does not seem to still support this app much. More on this topic from here: https://communities.vmware.com/t5/Workspace-ONE-Discussions/Android-Samsung-Impossible-to-enable-Dual-Messenger-feature-or/td-p/2260737 -jarmo6.9KViews1like4Commentsblokking apps on private section using COPE profile with Intune
We have a use case where we use Android devices that are corporate-owned but also personally-enabled. Within our ogranisation, we want the capability to trace and block apps. However, this is currently not possible because the apps are installed in the private section. Is there a way to achieve this in the private section? We are using Microsoft Intune as our MDM (Mobile Device Management) environment.6.5KViews0likes9CommentsIntune COPE Device - Google Calendar crashes
Hello everyone, We have the problem that when I want to make the Google Calendar app available on a COPE device, it crashes after the welcome screen with the message "action not allowed". On Work Profile Only/BYOD it works without any problems. Are you aware of this problem? Could this be related to Intune automatically/default blocking the Google accounts in COPE? Thanks, Regards, Daniel6KViews0likes17CommentsIntune ZT enrollment - No virtual keyboard
Hello, I have different feedbacks where the virtual keyboard is not appearing at the Intune login page during a ZT enrollment, has anyone experienced the same issue and knows how to fix it please? Environment: - Android tablets running Android 13 - COPE mode - Google Gboard installed and setup as default input method - Zero Touch enrollment - After the enrollment start and goes to the Login to Microsoft account step, the virtual keyboard is not appearing when touching the fields Some leads: - Gboard is not allowed by default and got disabled during the enrollment? - Non system or protected apps (flags to add in the software?) got removed when starting the enrollment? Thanks!Solved3.8KViews0likes7CommentsSMS in Work Profile Error
I have COPE setup with Intune and getting an error when opening the native Samsung messages app (work profile). The app does not open and only encounters the following error: messages can only be used by the owner of the device. This Google article states that it should work by sending through the default sms app in personal profile. Has anyone come across this?3.6KViews0likes1CommentBasic WiFi-profiles (configuration profiles) do not deploy into Device
Dear all, Since three weeks ago we noticed issue to deploy basic Configuration profiles (WiFi) into devices (MDM is Intune). Problem ONLY occurs with newly enrolled COPE devices running on Android 15. So we think it's Android 15 (Google) issue on COPE enrolled devices because all the other scenarios working fine: BYOD enrolled devices get WiFi profiles successfully deployed to device (Android 14/15) COPE enrolled devices get WiFi profiles successfully deployed to device (Android 14) COPE enrolled devices do NOT get WiFi profiles successfully deployed to device (Android 15) Anyone else noticed the same/similar issue with Configuration profiles with Android 15 clients? Best Regards JarmoSolved2.9KViews2likes19CommentsAndroid COPE, Google Calendar "Action not allowed"
Dear Community, we wanted to use Google Calendar in Combination with Outlook Mobile (Sync Calendar) with Intune. Unfortunately, we are facing the issue, that Google Calendar does not start on our COPE enrollments. After setting permissions to Contacts, Calendar and Notifications we see just for a second the calendar, but then the message pops up "Action not allowed". On our BYOD enrollments there are no problems. I guess, this has something to do with Intune (App), but i cannot nail it down what the issue could be. It seems Company Portal App is doing something different, because why it's working for BYOD Devices? I was hoping that someone else here had the same issue with a possible fix. Maybe Google calendar wants to add a Google Account, which is of course blocked at work profile level... Thanks!Solved2.1KViews0likes3Comments