Skip to content

Commit 8d94b23

Browse files
Merge pull request #2672 from jeffgilb/patch-1
Update android-fully-managed-enroll.md
2 parents b68bec2 + d40015d commit 8d94b23

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

intune/android-fully-managed-enroll.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -63,8 +63,8 @@ To set up Android Enterprise fully managed device management, follow these steps
6363
1. Sign in to [Intune](https://go.microsoft.com/fwlink/?linkid=2090973) and choose **Device enrollment** > **Android enrollment** > **Corporate-owned, fully managed user devices (Preview)**.
6464
2. Under **Allow users to enroll corporate-owned user devices**, choose **Yes**.
6565

66-
[!NOTE]
67-
If you have an Azure AD Conditional Access policy defined that uses the *require a device to be marked as compliant* control and applies to **All Cloud apps**, **Android** and **Browsers** - you must exclude the **Microsoft Intune** cloud app from this policy. This is because the Android setup processes uses a Chrome tab to authenticate your users during enrolment. For more information, see [Azure AD Conditional Access Documentation](https://docs.microsoft.com/azure/active-directory/conditional-access/).
66+
> [!NOTE]
67+
> If you have an Azure AD Conditional Access policy defined that uses the *require a device to be marked as compliant* control and applies to **All Cloud apps**, **Android** and **Browsers** - you must exclude the **Microsoft Intune** cloud app from this policy. This is because the Android setup processes uses a Chrome tab to authenticate your users during enrolment. For more information, see [Azure AD Conditional Access Documentation](https://docs.microsoft.com/azure/active-directory/conditional-access/).
6868
6969
When this setting is set to **Yes**, it provides you with an enrollment token (a random string) and a QR code for your Intune tenant. This single enrollment token is valid for all your users and won't expire. Depending on the Android OS and version of the device, you can use either the token or QR code to enroll the kiosk device.
7070

0 commit comments

Comments
 (0)