Microsoft Intune
Device enrollment

Android settings catalog in Microsoft Intune

In brief

The article now documents additional Android settings, including work profile inactivity, eSIM removal during wipes, screen power behavior, and separate device and work profile locks, with supported enrollment types, platform versions, defaults, and value requirements.

What Intune admins need to know

Administrators can use the updated applicability and configuration details to select supported settings and values when creating Android policies. No action is required.

This summary was assembled from the tracked documentation change. Verify important details in the full Microsoft Learn article.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review Android Intune settings catalog settings listin Microsoft Intune

This article lists and describes the Android Enterprise and AOSP settings you can configure in a settings catalog policy in Microsoft Intune. When you create the settings catalog profile, use the settings described in this article as a reference.

  • Android Enterprise corporate owned fully managed (COBO)

  • Android Enterprise corporate owned dedicated devices (COSU)

  • Location: ContolsControls the location services on the device. Your options:

    • Device default - Intune doesn't change or update this setting. By default, the OS allows end users to turn location services on or off.
    • Location enabled - Requires location services to be on and prevents end users from turning them off.
    • Android Enterprise corporate owned fully managed (COBO)
    • Android Enterprise corporate owned dedicated devices (COSU)
  • Number of days work profile is allowed to be switched off: Enter the number of days the work profile can stay off. Enter 0 to disable this setting. For any other value, the minimum is 3 days. There's no documented upper limit.

    Applies to:

    • Android Enterprise corporate-owned devices with a work profile (COPE)
  • Remove all eSIMs during a device wipe: Controls whether eSIMs are removed when a corporate-owned device is wiped while this policy applies. If True, all eSIMs are removed during the wipe. If False (default), this setting doesn't request that eSIMs be removed. The OS might still remove eSIMs when required. Supported on Android 15 and later. For information about the remote action, see Wipe devices with Microsoft Intune.

    Applies to:

    • Android Enterprise corporate-owned devices with a work profile (COPE)
    • Android Enterprise corporate owned fully managed (COBO)
    • Android Enterprise corporate owned dedicated devices (COSU)
  • Skip first use hints: If True, hides or skips suggestions from apps that step through tutorials, or hints when the app starts. If False, Intune doesn't change or update this setting. By default, the OS might show these suggestions when the app starts.

    Applies to:

    • Android Enterprise corporate owned fully managed (COBO)
    • Android Enterprise corporate owned dedicated devices at work profile level (COSU)

Power

  • Screen timeout: Enter the amount of time, in seconds, before the screen turns off. The value must be greater than 0 and shouldn't be greater than the Time to lock screen setting.

    Applies to:

    • Android Enterprise corporate-owned devices with a work profile (COPE) > Work profile level on Android 15 and later
    • Android Enterprise corporate owned fully managed (COBO) on Android 9 and later
    • Android Enterprise corporate owned dedicated devices (COSU) on Android 9 and later
  • Screen on while device plugged in: Select one or more battery charging modes where the screen stays on while the device is plugged in. Your options are AC, USB, and Wireless. If no modes are selected, Intune doesn't configure this setting, and the device uses its default screen timeout behavior.

    AC and USB are supported on Android 6.0 and later. Wireless is supported on Android 8.1 and later.

    Applies to:

    • Android Enterprise corporate owned fully managed (COBO)
    • Android Enterprise corporate owned dedicated devices (COSU)

System Security

  • Require Common Criteria mode: If True, enables an elevated set of security standards on the device most often used in highly sensitive organizations, like government establishments. If False, Intune doesn't change or update this setting.

These settings require users to set a password that protects only the work profile on their device. It applies to corporate apps and data, and doesn't affect personal apps or settings. You can configure complexity requirements, like length and character types, and enforce password expiration.

  • Block one lock for device and work profile: Configure a work profile password requirement before using this setting. If True, users must use separate locks for the device and work profile. If False (default), users can use a common lock for the device and work profile. Supported on Android 9 and later.

  • Number of days until password expires: Enter the number of days, until the device password must be changed, from 1-365. For example, enter 90 to expire the password after 90 days. When the password expires, users are prompted to create a new password. When the value is blank, Intune doesn't change or update this setting.

  • Number of passwords required before user can reuse a password: Use this setting to restrict users from creating previously used passwords. Enter the number of previously used passwords that can't be used, from 1-24. For example, enter 5 so users can't set a new password to their current password or any of their previous four passwords. When the value is blank, Intune doesn't change or update this setting.

Daily Intune.Admin.News

Get daily email updates

Get a concise summary of the latest Microsoft Intune updates delivered straight to your inbox.

Loading the secure signup form…