Intune: Disable biometric unlock for Android devices (mssing options)

Mountain Pond 1,181 Reputation points
2022-01-22T22:35:01.68+00:00

Hello,

I need to disable Face, Iris, Fingerprint unlock for Android devices.
I found that it was possible
https://eskonr.com/2020/11/the-case-of-unexplained-android-enterprise-work-profile-password-in-intune/

167455-chrome-fk1a8onfkj.png

Now
167462-applicationframehost-drmt7orlhc.png

but now these options are missing.
I know that Knox able to do this, but Knox plugin installation starts only after user will be able to set password. In my case I need to block these options for users on all kiosk mode devices.

Does anyone know how to disable it?
Or maybe someone knows how to use the OMA-URI for a ban?

Thank you.

Microsoft Intune Configuration
Microsoft Intune Configuration
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Configuration: The process of arranging or setting up computer systems, hardware, or software.
1,729 questions
Microsoft Intune Application management
Microsoft Intune Application management
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Application management: The process of creating, configuring, managing, and monitoring applications.
876 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,254 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
4,365 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Timmy Andersson 411 Reputation points MVP
    2022-01-23T08:20:04.473+00:00

    Hey,

    The guide you posted covers Android Enterprise work profile which is not the same scenario you are describing. Kiosk devices are enrolled as Dedicated devices and then put in to Kiosk mode in the configuration profile.

    A dedicated devices is not linked to a specific user and during initial setup of a dedicated devices I cant remember that you ever are asked to set a pin, face unlock in that scenario. If you are please tell us a bit more about your configuration and enrollment method and make sure you are enrolling it as a Dedicated Device and that you don't have another policy forcing biometric or pin on your kiosk devices.

    https://learn.microsoft.com/en-us/mem/intune/enrollment/android-kiosk-enroll

    As you mentioned you have the capability to enable/disable those features with Knox and OEMConfig but I have never had to disable those on a Dedicated devices.

    167465-image.png

    I would suggest the following:

    1. Make sure you are enrolling your devices as Dedicated devices
    2. If you are using the Kiosk mode, make sure its enabled in your configuration
    3. Double check that you don't have another policy forcing biometrics or security features to your Dedicated devices

    hope this helps, and if it does don't forget to click accept answer.

    1 person found this answer helpful.