EducationSoftwareStrategy.com
StrategyCommunity

Knowledge Base

Product

Community

Knowledge Base

TopicsBrowse ArticlesDeveloper Zone

Product

Download SoftwareProduct DocumentationSecurity Hub

Education

Tutorial VideosSolution GalleryEducation courses

Community

GuidelinesGrandmastersEvents
x_social-icon_white.svglinkedin_social-icon_white.svg
Strategy logoCommunity

© Strategy Inc. All Rights Reserved.

LegalTerms of UsePrivacy Policy
  1. Home
  2. Topics

AppConfig on Intune for Android


Benjamin Reyes

Vice President, Product Management • MicroStrategy


This article details AppConfig on Intune for Android. This includes features like enrolling tablets/phones, app distribution, app configurations and restrictions, VPN and per-app VPN, and more.

Overview


To use AppConfig on Intune for Android, there are eight overarching steps you need to accomplish:

  1. Setup Managed Google Play
  2. Approve Company Portal and Set Enrollment Restrictions
  3. Enroll Devices
  4. Distribute the App
  5. Assign App to Groups
  6. Configurations and Restrictions
  7. Create and Install a VPN Profile
  8. Create and Install VPN Per-App

Setup Managed Google Play


Before using Intune to manage your Android devices with AppConfig, you must connect your Intune account to your Managed Google Play account. For instructions, see Connect your Intune account to your Managed Google Play account.

Approve Company Portal and Set Enrollment Restrictions


To ensure that users always have access to the most up-to-date version of the Company portal app, you must approve the Company Portal app for Android in the Managed Google Play store. By approving it, you make sure that each user gets automatic updates.

How to Approve Company Portal

  1. Navigate to the Company Portal app on the Managed Google Play Store.
  2. Sign into the Managed Google Play store with the same Google account that you used to configure the binding for Android Enterprise.
  3. Review the permissions in the dialog and click Approve. You must allow these permissions to allow the Company Portal app to manage the work profile on the device.
  4. Select Keep approved when the app requests new permissions.
  5. Click Save.


After, you must set enrollment restrictions. 
Android Enterprise work profiles are supported on certain Android devices. Any device that supports Android Enterprise work profiles also supports conventional Android management. Intune lets you specify how devices that support Android Enterprise work profiles should be managed from within Enrollment Restrictions.
By default, Android Enterprise work is not supported in Enrollment Restriction. As a result, all Android devices, including devices that support Android Enterprise work profiles, are enrolled as conventional Android devices. You must manually enable support of Android Enterprise work in Enrollment Restrictions to allow devices that support Android Enterprise work profiles to be enrolled as Android Enterprise work profile devices.

How to Set Enrollment Restrictions


For instructions, see Set enrollment restrictions.

Enroll Devices


Enrolling your Android device gives you access to company email, apps, and other work data. As part of enrollment, you set up a work profile, which separates the personal data on your device from your work data. 
For instructions, see Enroll your Android device in Intune.

Distribute the App


There are two ways you can distribute your app:

  • App Distribution with Google Play Store
    Similar to AirWatch, Intune app configurations and restrictions only support public apps, i.e. Android work apps downloaded from Google Play Store. For instructions to add Google Play Store apps, see Add Managed Google Play apps to Android enterprise devices with Intune.
  • App Distribution with an .apk File
    Alternatively, you can distribute your app with an .apk file. However, app distribution with an .apk file does not support app configurations and restrictions. As a result, this distribution is not recommended. For instructions, see Add an Android line-of-business app to Microsoft Intune.

Assign App to Groups


After you've added an app to Microsoft Intune, you can assign the app to users and devices. For instructions, see Assign apps to groups with Microsoft Intune.

Configurations and Restrictions

In Intune we can create configurations and restrictions with “App configuration policies” and assign them to app and user groups. 
For Android, the configurations can only be set for apps from the Google Play Store (Android Work). The configurations can be set either by a JSON editor or by a key-value configuration editor (suggested), which looks similar to AirWatch.
When the app is downloaded on a device, the configurations are loaded by RestrictinsManager'sgetApplicationRestrictions method, the same as the AppConfig with the Airwatch console. These values are pre-configured and control the behavior of the app.
For instructions, see Add app configuration policies for managed Android devices.
See Integrate with AppConfig-Compliant EMM Providers for more information on the available configuration options.

Create and Install a VPN Profile

To use VPN for Android AppConfig, first approve the VPN client app in the Google Play Store and distribute it to devices. Then you can create a VPN profile.

How to Create and Configure a VPN Profile


For instructions, see Create VPN Profile in Intune. After, see Configure VPN settings for devices running Android in Intune. Once the device policy is created, install the VPN profile on your device.

How to Install the VPN Profile on a Device

  1. Open the VPN client on your device.
  2. In Settings, tap External Control. Select Enabled to allow Intune to distribute the VPN profile to AnyConnect VPN client.
  3. Open the Company Portal app and select check device settings.
  4. Tap to install the corporate VPN profile on the notification that appears.
  5. Tap OK when VPN is applied.
  6. Open the switch AnyConnect VPN to connect the VPN.
  7. Input your credentials and tap connect.
  8. Confirm the connection request.


Now network requests of all Android work apps will go through the VPN.

Create and Install VPN Per-App


For instructions on how to create a VPN profile, create a custom configuration policy, and assign both policies, see Use a Microsoft Intune custom profile to create a per-app VPN profile for Android devices. Also see Assign users and device profiles in Microsoft Intune.
  KB483187


Comment

0 comments

Details

Knowledge Article

Published:

April 18, 2019

Last Updated:

February 16, 2024