Skip to main content

How to Set up AOSP Device Management - Microsoft Teams Android Devices Migration

How to Set up AOSP Device Management - Microsoft Teams Android Devices Migration

As Solutions Architect I've heard several questions about AOSP, and some IT Admins haven't taken action to make sure their companies are ready to it. So, in today's blog post I'm gonna walk you through AOSP DEVICE MANAGEMENT, and you will learn everything about this new way to manage teams android devices.
AOSP for Microsoft Teams Devices
IMPORTANT

Before beginning, keep in mind the following info:

  1. If your org doesn't enroll teams android devices in intune, you don't need to create AOSP policies and these settings in intune are not required.
  2. This new Mobile Device Enrollment (MDM) method replaces legacy Device Administrator enrollment method.  
  3. Once Device Administrator enrollment is deprecated, legacy devices that don't support AOSP will be signed out and unenrolled from Intune, therefore, sign back in without an Intune license assigned to their account.
  4. These guide is made for only Teams Android devices (let me know if you'd like to see a guide for non-teams devices, and I'll be happy to post it).
  5. As of today, AOSP doesn't support DEM Accounts, so if any of your teams devices are signed in using an account configured as DEM account, please remove the account as DEM before completing this guide. Stay tuned and keep checking this Microsoft documentation in order to know if AOSP supports DEM accounts in the future.
  6. Microsoft has said Teams Android Devices will be upgraded automatically in order to migrate them to AOSP. Be careful and make sure you enable this before May 15th, for more info click here. Firmware updates are no pauseable.
  7. This migration is intended to be completed without any user intervention. However, if your organization conditional access policies require user-interactive multi-factor authentication, after the migration, your device will be signed out and the user needs to sign in their device.
  8. Device Code Flow aka microsoft.com/devicelogin no longer supports user-interactive MFA. If user-interactive MFA is enforced with conditional access policies, users will need to log in on their device directly not via the web to ensure the MFA prompt appears.

As per as official hardware manufacture's website, after upgrading your systems to certain firmware that supports AOSP, and if AOSP is not enabled, your system will lose sing-in info, and you have to manually sign-in again, however, I already tested and my teams phone didn't and I didn't enable AOSP. However, I tried it with another phone, same account and it lost sign-in lol, therefore, just please be aware that could happen, btw it won't happen at all, if your org doesn't use Intune.

AOSP for Microsoft Teams Devices

Prerequisites

  1. Intune licenses assigned to your Teams Android devices (Phone, Panel, Room)
  2. Teams Android Devices deployed which are enrolled using Device Administrator.
  3. Teams Android Devices that are supported with AOSP Device Management

Enabling Android Open Source Project (AOSP) 

First, go to intune.microsoft.com and click on Devices -> Enrollment -> Android.

AOSP for Microsoft Teams Devices

Scroll down, look for Android Open Source Project title and under it, you will find "Corporate-owned, user-associated devices", click on it, and then click on Create policy.

AOSP for Microsoft Teams Devices

How to enable Microsoft AOSP

Type in the following settings:

  • Name: Meaningful name to identify it easily, for instance "Teams devices, Teams Android devices, etc."
  • Description: Describe this profile to let others in your org know what this enrollment policy is used for.
  • Token expiration date: 65 years is the default, I highly recommend you leave at 65 years to avoid expiration and issues. Keep in mind that an expired enrollment token will prevent any teams devices from completing a successful sign-in and block new devices from enrolling.

Setting the following parameters:

  • WiFi: Not Configured
  • For Microsoft Teams Devices: Enabled

 After setting things up, click on Next.

Teams Android Devices to AOSP

Note: If your token expiration date is limited to 90 days, no worries, it'll be extended in the future, but in the meantime, you must edit your policy and token expiration to renew it every 90 days. As you can see, mine was already updated and i was able to set it up to 65 years.

Finally, review, make sure everything is set correctly and then select Create.

Teams Android Devices to AOSP  

Everything is set and now your org and you are ready to enroll devices.

Teams Android Devices to AOSP

AOSP Device Management Configuration and Compliance Policies (if necessary)

If your organization requires device compliance for conditional access to be able to sign in successfully, you must create an AOSP compliance policy with supported compliance conditions, and assign it to ensure your devices are marked compliant after completing the migration. 

As of today, supported compliance conditions are as follows:

  • Rooted devices
  • Minimum OS version.
  • Maximum OS version.
  • Minimum Security patch level
  • Require encryption of data storage on device

If your org doesn't require it, these settings are not mandatory but optional, if you don't set them up, your devices will work well either way, however, they provide additional features, and security measures, so prolly you'd like to enable them.

Note: All certified teams Android devices enrolled in AOSP Management support configuration and compliance policies. Click here to see certified devices.
 

Compliance Policy

Compliance policies are used for checking supported parameters and make sure the devices meet those requirements and mark them compliant.

In intune, Click on Devices -> Compliance -> Create policy

Teams Android Devices to AOSP

Under platform, select Android (AOSP), and click on Create

Teams Android Devices to AOSP

Type in the following info:

  • Name: Meaningful name to identify it easily, for instance "Compliance Policy for Teams Android Devices"
  • Description: Describe this profile to let others in your org know what this enrollment policy is used for.

 After  typing in them, click on Next.

 Teams Android Devices to AOSP

To set up those parameters, be aware that companies are different and compliance policies might vary.I highly recommend you take a look at the following parameters:

  • Set Rooted devices to Block
  • Set Minimum OS version to match devices in your org (in my case, 10).
  • Set Require encryption of data storage on device to yes

After that, click on Next.

Teams Android Devices to AOSP

Add any desired actions to take for non-compliance devices and click on Next.

Teams Android Devices to AOSP

Under Included Groups, click on Add groups, or add all users, it depends on you, keep in mind you need to select the users and/or groups to assign this policy to.

For instance, click on Add groups, and look for the desire group and select it.

Note: The group must contain your Teams Android devices such as Panels, Phones and/or Rooms.  

Teams Android Devices to AOSP 

 

Teams Android Devices to AOSP

After adding users/groups, click on Next.

Teams Android Devices to AOSP

 

Finally review your policy settings, and if everything is okay, click on Create. 

Teams Android Devices to AOSP 

 

Teams Android Devices to AOSP

 

Configuration Policy (optional)

In intune, Click on Devices -> Configuration -> Create -> New Policy

 Teams Android Devices to AOSP

Select Android (AOSP) as platform and Templates as Profile type, then click on Device restrictions and Create.

Teams Android Devices to AOSP

Note: The only supported configuration policy for Teams Android devices enrolled in AOSP Management is the "Device Restrictions" profile.

Type in the following info:

  • Name: Meaningful name to identify it easily, for instance "Compliance Policy for Teams Android Devices"
  • Description: Describe this profile to let others in your org know what this enrollment policy is used for.

 After  typing in them, click on Next.

 Teams Android Devices to AOSP

Under general, Block Screen Capture is listed, set it to Yes, after that, click on Next.

Teams Android Devices to AOSP

Note: Only "Block Screen Capture" restriction is supported. Hopefully new restrictions will be supported soon.

Under Included Groups, click on Add groups and select your group.

Teams Android Devices to AOSP 

 

 Teams Android Devices to AOSP

Select Next buttom.

Teams Android Devices to AOSP

Review and create finally. 

AOSP for Microsoft Teams Devices


AOSP for Microsoft Teams Devices

That's all for today! Thanks for reading. If you have any questions, feel free to reach out. Remember to subscribe to this blog, my YT channel, and follow me on my social media.

Connect with me

If you like my blog, and it's helped you, let me know with a coffee 😃😄

Comments

Popular posts from this blog

How to Upgrade and Downgrade a Studio X or G7500 using Custom Server, Web UI or Poly Lens

There are several options to update and downgrade your Poly systems, today I'm going to show you how these 3 options (Custom Server, Web User Interface, Poly Lens Cloud) can be done.

Couldn't Connect to Workplace Join. Try again, or contact your admin

I was writing a new blog post about Microsoft Teams Panels, and guess what, dear reader? One user came across a new issue!! And he told me about it, so, let's talk about how to fix "Couldn't Connect to Workplace Join. Try again, or contact your admin".

How to Set up Poly Studio X Series | Configuring Studio X Series for the First Time

In this blog post, I'll be showing you how to configure your new Studio X30, X50 or X70.

Skypesettings.xml | XML Files for Microsoft Teams Rooms

Hey there!! Recently, I've been delivering tech training, and out of curiosity, I asked attendees about XML files, and many of them didn't know how to use and make them for their MTRoW, but guess what? Most of the people didn't know anything about them. Therefore, I'd like to share different options to be applied to your systems and help you get by on your journey.

Device Administrator Enrollment Requiered for Teams Android Authentication | Teams Android-based Systems Cannot Login

Hello, Everyone!! 👀 This will be a short blog post, but I just wanna make you aware of this new requirement. The rules have changed for MTRoA deployments, now we must turn on Device Admin Enrollment in Intune. In case you don't know where we can turn it on, or you haven't used Intune (Endpoint Manager), don't worry, this blog post will help you get by.