Posts

Showing posts with the label device administrator

Move Android devices from device administrator to personally owned work profile management in Intune

Image
Back in April 2020,  Google announced deprecation of Android Device Administrator Management and since then no fixes or improvements have been added to DA. Now Microsoft recently announced that Intune will be ending support for device administrator management on devices with access to Google Mobile Services (GMS), beginning August 30, 2024. It is important to note that after Intune ends support for Android device administrator, devices with access to GMS will be impacted in the following ways:  1. Users won’t be able to enroll devices with Android device administrator. 2. Intune won’t make changes or updates to Android device administrator management, such as bug fixes, security fixes, or fixes to address changes in new Android versions. 3. Intune technical support will no longer support these devices. Moving from Android DA to Android AE. Luckily Microsoft have made it possible for organizations to move their Android enrollments from DA to AE without much hassle. It does invo...

EXO Device Mailbox Security Policy Vs Intune management policy

Image
While working on a customer requirement involving implementation of Intune APP (App Protection Policy) on BYOD (Bring Your Own Devices), I came across an issue on Android devices where on accessing Outlook for Android, the end user was being asked to 'Activate device administrator' as shown below. Having dealt with Exchange device mailbox policy in the past, I immediately knew what the issue was and thought of blogging about it to save others some time. If you navigate to Exchange admin portal > Mobile > Mobile device mailbox policy , then you should see a policy that is present in every tenant by default and set as optional . However, in case your users see the prompt to Activate device administrator, then chances are that either you have a separate custom policy created and assigned OR the default policy is modified requiring an encrypted device instead of being optional. As it was in my case. So what is happening here? One can use mobile device mailbox policies to mana...