Intune APP/MAM moving to support Android 9 and higher. What does it mean and how does it affect you?

On September 3 2021, Microsoft published MC282986 in the Message center that Intune APP/MAM will be moving to support Android 9 and higher. According to Microsoft,

This change is to align with Office mobile apps for Android support of the last four major versions of Android and it will be coming into effect on October 1, 2021.

So what does it really mean?

If you are using app protection policies on any device that are running Android version 8.x or lower then these devices will no longer be officially supported for APP. 

APP policies will continue to be applied to devices running Android 6.x – Android 8.x however, if you do run into issues with an Office app and APP, Microsoft support will request you to update to a supported Office version for app troubleshooting.

So it appears that while APP will continue to apply on devices running Android versions older than 9.x, Microsoft will not support should you run into issues. This may be an issue for lot of organizations as a lot of devices that are being managed for APP, may still be running older versions of Android and considering the timing of this change, it doesn't give much of a time to organizations to formulate an action plan to prepare and address this.

However, if you are in a position to do something about this right away, then this is how you can take necessary actions in Intune.

1. Configure an APP Conditional launch setting with a Min OS version requirement to warn users.

b. Navigate to Apps->App Protection Policies
c. Select the relevant APP and click edit Conditional Launch in the properties or create a new one.
d. Add\Modify the Min OS Version and Action settings under Device Conditions as shown below and save.



If you want to know on how to create APP based on tier based data protection framework then you can head over to one of previous blogs Implementing App protection policies using Tier based Data Protection Framework for details.

2. Configure a device compliance policy for enrolled devices and set the action for non-compliance to send a message to users before marking them non-compliant.

b. Navigate to Devices->Android->Compliance policies
c. Select the relevant compliance policy and click edit for Compliance settings and Actions for noncompliance in the properties or create a new policy.
d. Add\Modify the Minimum OS version under Device Properties as shown below.


e. Add Send push notification to end user with value 0 under Action in Actions for noncompliance section as shown below.


Conclusion

In my opinion, this change can create challenges for organizations because there may be devices out there, that could be nearing end of life in terms of receiving OTA firmware updates or may not be supported at all to receive Android 9.0 or later. This obviously creates a procurement and supply challenge in trying to replace such devices. The good thing is that all is not lost and APP will still be continued to be applied after October 1, 2021, but there is a good chance that you will not receive any support from Microsoft if you run into any issues. As of now it is not clear as to when will Microsoft will fully pull the plug on supporting Android devices older than 9.0, but organizations will need to act fast in order to ensure that their end user devices are fully supported and protected for their corporate data.

Comments

Popular posts from this blog

How to force escrowing of BitLocker recovery keys using Intune

Intune: Configure Printers for Non-Administrative Users

Intune: UAC Elevation Prompt Behavior for Standard Users