question

DenisPasternak-3587 avatar image
0 Votes"
DenisPasternak-3587 asked DenisPasternak-3587 commented

Intune: Disable biometric unlock for Android devices (mssing options)

Hello,

I need to disable Face, Iris, Fingerprint unlock for Android devices.
I found that it was possible
https://eskonr.com/2020/11/the-case-of-unexplained-android-enterprise-work-profile-password-in-intune/

167455-chrome-fk1a8onfkj.png

Now
167462-applicationframehost-drmt7orlhc.png


but now these options are missing.
I know that Knox able to do this, but Knox plugin installation starts only after user will be able to set password. In my case I need to block these options for users on all kiosk mode devices.

Does anyone know how to disable it?
Or maybe someone knows how to use the OMA-URI for a ban?

Thank you.


mem-intune-generalmem-intune-device-configurationsmem-intune-enrollmentmem-intune-application-management
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

What is the enrollment method for your devices?

0 Votes 0 ·

Hi.


Corporate-owned dedicated devices
Manage device owner enrollments for kiosk and task devices.

Do you have this settings?

0 Votes 0 ·

1 Answer

TimmyAndersson avatar image
1 Vote"
TimmyAndersson answered DenisPasternak-3587 commented

Hey,

The guide you posted covers Android Enterprise work profile which is not the same scenario you are describing. Kiosk devices are enrolled as Dedicated devices and then put in to Kiosk mode in the configuration profile.

A dedicated devices is not linked to a specific user and during initial setup of a dedicated devices I cant remember that you ever are asked to set a pin, face unlock in that scenario. If you are please tell us a bit more about your configuration and enrollment method and make sure you are enrolling it as a Dedicated Device and that you don't have another policy forcing biometric or pin on your kiosk devices.

https://docs.microsoft.com/en-us/mem/intune/enrollment/android-kiosk-enroll


As you mentioned you have the capability to enable/disable those features with Knox and OEMConfig but I have never had to disable those on a Dedicated devices.

167465-image.png




I would suggest the following:

  1. Make sure you are enrolling your devices as Dedicated devices

  2. If you are using the Kiosk mode, make sure its enabled in your configuration

  3. Double check that you don't have another policy forcing biometrics or security features to your Dedicated devices

hope this helps, and if it does don't forget to click accept answer.




image.png (47.5 KiB)
· 3
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Timmy, please share you screen with setting.
I can`t find this setting.

0 Votes 0 ·

Hello.

All my enrollment profiles are "Corporate-owned dedicated devices"

But I don`t see any options

167591-chrome-8whlk3rhio.png

167576-4gbkn2zxsu.png

167567-applicationframehost-rth0zylf4k.png

167584-applicationframehost-x9er08ibkq.png

167518-applicationframehost-ii42yjzo3u.png

All profiles are looks like this:

167535-applicationframehost-55x4mt0ht3.png

"If you are using the Kiosk mode, make sure its enabled in your configuration" where can I check it?

Tahnk you.


0 Votes 0 ·

Yes, you can set preferences through Knox. But the problem is that Knox is installed after the setup mater.

The user is first prompted to enter a pincode, or use a biometric lock. And only then, the Knox Plugin is installed and even later the settings :)

167508-applicationframehost-esoutrbmcv.png

If there is a way to not allow the user to interact with interest until all programs are installed - that would solve some of my problems :)
Including, the user can have time to go into the device settings before the Home Screen is installed.


Thank you for your participation!


0 Votes 0 ·