microsoft intune
81 TopicsGoogle Deleted Account that Links Managed Play Store
Hello all, We're facing an issue with our Intune/Managed Google Play connector. Google has deleted the account set up specifically to connect to our Managed Google Play instance in Intune. This has been an active link, with the last new device registered about 2 weeks ago and apps on devices being updated since then. We are currently unable to enroll new devices or add new apps. We are also unable to attempt to recover the account and have not been able to find a way to contact Google directly about the account issue. Barring being able to recover the account, are there ways for us to lessen the impact of creating a new account for the linkage? Or are we going to have to have all our Android BYOD users re-enroll their devices?25KViews5likes49CommentsBlocked USB file transfer
We are struggling with some user reports about blocked USB file transfer functionality on their Samsung A52 / A54 devices enrolled with corporate-owned work profile. Microsoft released a blog post about this issue here. Known Issue: Some management settings become permanent on Android 14 - Microsoft Community Hub We stumbled across the one-time hint about "do not upgrade non-Samsung devices to Android 14" in the advisory. Did not find any other information whether Samsung is also affected or not, but as we only have Samsung as corporate devices this seems also to apply to Samsung devices. After factory resetting the device and a fresh enrollment the USB file transfer is working as expected / configured! *15th March: please note: this post has been moved and been made into a new topic and new titleSolved22KViews0likes21CommentsIntune Enrollment QR Code - Two connection types
Hi, all I'm trying to modify our original enrollment token (Intune - Fully Managed Device QR Code) so that the device can enroll using mobile data OR any wifi network. I managed to add this to an existing QR code android.app.extra.PROVISIONING_USE_MOBILE_DATA":true, Unfortunately, using such a QR code on a phone that does not have mobile data transmission means that the enrollment process no longer asks for the WIFI network and ends in failure. To sum up, I want to create an enrollment code that works as follows: 1. Allow enrollment using mobile data. 2. If mobile data does not work - ask for any WIFI.18KViews1like6CommentsMaster ownership of Android devices
Factory Reset Protection / persistence is a powerful tool but it does not yet feel complete, and it is quite frustrating and potentially dangerous in its current state. It is not always apparent whether any given device is persistently linked using ZeroTouch, Intune or even Google Account FRP. While these tools are available to some, they are not a financially viable option for everyone, especially for consumers. There may be documentation describing the intimate intricacies of how all of these tools work and when/where they leave signs of their presence, but I cannot find it. I have not found a PSA from google for consumers saying "if you buy a second hand phone, check x, y and z to make sure it is not locked, otherwise someone can potentially remotely brick it." As a small company we have various scenarios where we provide phones to employees and also distribute loan/event devices for other small-medium companies, and don't necessarily have the ability to invest in enterprise-grade tools like ZT, InTune or Android Enterprise. If you think, on Windows all you need is to set the BIOS password and the Admin password and User Account Control takes care of the rest. Now take the android example, you add a google account and think it's safe with the user not knowing the password, but there is nothing to stop the user from adding their own personal google account, removing yours (no password required), setting their own PIN, and turning a $1000 phone into a paperweight. If they can unlock the phone, they are the master owner. There did used to be a feature for Multi-User on android but I haven't seen it in a long time, and I think there were performance issues with it as they all had to be loaded at once. While I may be lacking understanding knowledge and making some assumptions, should a consumer really need to know exactly how Android Enterprise works in depth just to buy a second hand/"refurbished" phone? And I dare anyone to get into a device after it's been factory reset while attached to a personal google account with a PIN set without hacking tools. I know there have been exploits with Talkback in the past but it's been patched now, and again these are not lengths to which consumers should need to go. If I knew someone's pattern (most common security type and very hard to hide effectively), and had their phone for 2 minutes, I could turn it into a paperweight simply by adding a disposable google account, removing theirs, and setting a PIN. How are we supposed to protect against that as a small business?14KViews7likes17CommentsEdit Intune QR Code to include wifi and Cellular Data
I have been following google docs on editing Intune QR code to include WIFI details to auto connect to wifi during enrollment based on the details i have updated the QR code and then using Notepad++ Plugin to generate QR Code with the edited details. When i scan to enroll it gives me error: Wrong QR Code. I have repalced token and checksun details for security purposes here . { "qrCodeContent": { "android.app.extra.PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME": "com.google.android.apps.work.clouddpc/.receivers.CloudDeviceAdminReceiver", "android.app.extra.PROVISIONING_DEVICE_ADMIN_SIGNATURE_CHECKSUM": "XXXXX", "android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION": "https://play.google.com/managed/downloadManagingApp?identifier=setup", "android.app.extra.PROVISIONING_WIFI_PASSWORD": "XXX", "android.app.extra.PROVISIONING_WIFI_SECURITY_TYPE": "WPA", "android.app.extra.PROVISIONING_WIFI_SSID": "FlatNetwork", "android.app.extra.PROVISIONING_ADMIN_EXTRAS_BUNDLE": { "com.google.android.apps.work.clouddpc.EXTRA_ENROLLMENT_TOKEN": "XXXXX" } }, "expirationDate": "2025-12-31T18:29:59.920206Z"Solved13KViews3likes13CommentsCopy-paste issue (COPE)
Hello Everyone, I have a slight issue with copy-paste on Corporate owned, personal enabled devices (COPE) managed via Intune. To put it simple - people can copy text from work profile to personal. Happy to be pointed to the basics if I missed something obvious, but I feel stuck. Intune configuration for COPE devices has 2 values: "allow" or "not configured" (not helpful). I had support cases open with Microsoft and Samsung, but former blames OS defaults, while latter blames Intune (not helpful). I couldn't identify the setting in OEMConfig (Knox Service Plugin), so got Google Enterprise account, configured it for Zero Touch enrolment using Intune token and realised that I was looking into "crossProfileCopyPaste" control and don't have a clue how to use it in DPC extras and if that's even possible. Is it possible to use AMAPI with Intune management? If yes, does anyone have any examples? What are other ways to restrict copy-paste from work profile to personal? I find it difficult to believe I'm the only one having the issue. Thank you in advance12KViews1like29CommentsRenaming Managed Google Play Organization
Hello, we built our Managed Google Play connector in Intune like three years ago with our company name as organization name. Meanwhile our company name as slightly changed and since the company name is shown on all corporate-owned android devices lock screen, we have a high interest in changing that to the correct name. Unfortunately I can not find any way to change that company name. I can only delete that organization. I do not find a way to contact Google directly for that issue, so that is why I ended up here. So here are the questions: What exactly happens to our devices, if we disconnect and delete the organization and reconnect to a new organization with correct name? All devices will reset? All apps will be gone? Are there other ways to configure what is shown on the lockscreen? Maybe it is possible to disable the display of the company name on the lockscreen completely? Or is there a way to contact Google to change that name for us? Any help appreciated. 😎 Regards11KViews2likes33CommentsRandomized Mac Address Disabled Option
Background: We use Zero Touch Enrollment for android and Intune for our android devices but run into issues with the Wi-Fi MAC Address being set to randomized by default. We preset the Device MAC Address on our on-prem android devices in our system for validation along with a certificate. These devices must have the Device MAC Address first and validate the certificate later. Issue: A device comes in and we have to enter the Wi-Fi setting before the device connect to Zero Touch Portal and Intune. Does seem like that big of issue but when you have a large number of devices and have to manually enter Wi-Fi settings or scan barcodes then this can waste a large amount of time - days. Best solution would be the ability to provision the device in Zero Touch Enrollment because only thing that would need to be done with on-prem device is power it on. Problem is missing MAC Address provisioning. "android.app.extra.PROVISIONING_WIFI_PASSWORD": "xxxxxxxxxxxxx", "android.app.extra.PROVISIONING_WIFI_SECURITY_TYPE": "WPA2", "android.app.extra.PROVISIONING_WIFI_SSID": "network-ssid", "android.app.extra.PROVISIONING_WIFI_HIDDEN": "true", "android.app.extra.PROVISIONING_WIFI_MAC_Address": "device", ???? Next best solution would just be a QR code we could scan to connect to our network, but I can't find any QR code generator that includes MAC address set to device MAC in the options. Most devices we have are Zebra and we do use StageNow but that does work well with newer androids.Solved9KViews0likes8CommentsHow to manage app using Intune
I want some suggestions on how to manage applications in our workplace. We purchased an Android app for our employees to work in the warehouse. The vendor provides two methods of getting the app to our devices. One is to download it directly from the Play Store, and the other is from the vendor's website. When something is broken, the vendor will roll back by uploading the new version of the app to the Play Store if the problem is informed on time. Sometimes, we have to go to the download site to download the previous version to solve the immediate issue due to the time zone difference. There, we want to manage the app using Intune. We want to deploy the apk directly to the device using Line Of Business. However, it only works if we enrolled devices using Device Administrator. Unfortunately, it is impossible now since Intune has stopped supporting this enrollment type. If we use the Play Stores managed private app to upload the apk, it would get an error with the package name. We do not think that the vendor will build different package names for every customer. So here is my question: How could we achieve something we achieved in the past and now we cannot? Intune said it is the change that Google made due to security reasons. Any suggestion would be much appreciated!!!8.9KViews0likes10CommentsIntune - Google Managed Play issue cannot complete the bind
Hi Everyone, sitting with an issue on three O365 tenants at the at the moment that I have escalated to Microsoft. Was hoping that someone else experienced this issue as well or can point me in the right direction. After opening the connector to bind the EMM (Intune) to the google play store the I grant Microsoft permissions to send both user and device information to Google is greyed out. I can close and the window and then reopen it and I can then tick the box. After that the Launch Google to connect now Button becomes available and the windows that pops up asks me to sign in with my google account. I have created numerous accounts, personal, work and school and tested with them. After the login into the google account it does not continue with the EMM setup. the box displays "The Page has expired. To restart your registration, please reload the page from your EMM console. Only way past that is to log out of the Gmail Account and then log in again with the same issue "The page has expired......" I have tried the connection from different devices, browsers, incognito... on different networks and have even tried it from a device with a vanilla install, Windows 10/11 and nothing helps. I have created different accounts on Google, personal, work and school etc, and the same issue. After logging in I can click on the google play icon in the left upper side and it shows the apps in the play store. I have attached screen shots.8.5KViews1like16Comments