Teams Android OS Devices
Peacefully Coexisting (and Actually Working!) with
Microsoft Security and Compliance Policies (Part 1)
Introduction
At eGroup | Enabling Technologies, we define as a best practice the implementation of Microsoft Intune to provide device management used by authenticated users in Microsoft 365 tenants. The Intune component enrolls these devices and applies device compliance policies. We also define the configuration and use of Azure Active Directory (AAD) conditional access policies as a critical best practice for applying access controls during user authentication. This guidance is based on our recommendation that our clients adopt the Zero Trust security model for their organization. The broad definition of the model that we use is “Trust no one and harden everything.”
When configuring Intune profiles/policies and AAD conditional access policies, care must be taken to prevent problems for Teams (Android OS) phone and Teams Rooms on Android devices (“Teams devices” herein). Organizations usually configure these profiles/policies to control, protect, and manage their desktops, and both company and personally owned mobile devices. While documentation exists on how to treat Teams devices when creating these policies, it can be easily missed. If the policies are not correctly “tweaked” they will cause significant problems when they are applied to Teams devices; and they usually do end up getting applied automatically!
Teams devices can experience various problems with incorrectly configured policies:* Not being able to sign in * Randomly signing out + For a user, this would be annoying + Teams devices can and are used to place emergency calls. Emergency calls can be made from powered up and signed on Teams devices, even if the screen lock has been activated. From a health and safety perspective, deployed phones should almost never be in a signed-out state. * Freezing/crashing * Sign-in loops In this two-part series (Part 2 found here), we will describe how to configure these policies to peacefully coexist with your Teams devices. In this first part we will cover how to configure the Intune components and policies. In the second part , we will go over two additional Intune tasks and configuring your conditional access policies to prevent problems with your Teams devices. We will also touch on testing and Teams configuration profiles. This guidance should fix or prevent these problems from occurring on your Teams devices while not compromising the objective of Zero Trust.
What are the Policies Used For?
This article is not going to dive deeply into Intune Enrollment, Device Compliance, Configuration Profiles, Application Protection Policies and Azure Active Directory Conditional Access Policies. All five of these are components of Microsoft Intune; Conditional Access Policies really fall under Azure Active Directory, but they can be accessed from Intune. These topics are covered extensively by Microsoft and other parties. A user must have an Intune license to have their device enrolled into Intune.
All five policies fall under the heading of Device Management. They collectively allow an organization to manage the devices that their users sign into their tenant with. These are a critical component for the implementation of a Zero Trust security model for an organization. Devices fall into two major categories:
A Conditional Access Policy could be configured to block access to resources for a device marked as non-compliant. Android Device Platforms
There are two different Intune Device Platforms for Android devices:
High-Level Steps1. Create an Intune filter for Teams Phones. 2. Verify that the Android Device Administrator management method is enabled. 3. Configure the Android Enrollment Device Platform Restrictions. 4. Add the serial numbers of the Teams Phones as Corporate Device Identifiers. 5. Configure the Compliance Policy Settings. 6. Create a Device Compliance Policy for the Teams Phones. 7. Add an exclusion for the “Teams Phones” filter to existing Device Compliance Policies. 8. Add the “Teams Phones” filter as an exclusion to all Configuration Profiles created for the “Android Device Administrator” platform. 9. Check the Intune and Azure Active Directory Device limits. 10. Exclude Android Device Administrator devices from App Protection Policies for the Android Platform. 11. Add the Teams Phones exclusion query as a “Filter for devices” condition on existing Conditional Access Policies including Terms of Use Policies that have unsupported Teams Phones Settings. 12. Create a Teams Phones Conditional Access Policy. 13. Test the Teams Phones. 14. Create and apply a Teams Configuration Profile. 15. Test the Teams Phones with the applied Teams Configuration Profile. General Notes and Recommendations* Microsoft recommends using the “All Users” and “All Devices” Intune virtual-user groups. + These groups are available in all Intune tenants and do not require any management overhead. + They are highly scalable and optimized. * Re-use groups as much as possible. + It is more efficient to target a particular group with ten (10) policies than it is to create ten (10) groups with the same membership and assign ten (10) policies. * Make incremental group changes. + Large group membership changes in Azure AD can cause Intune’s targeting of assignments to policies to slow down significantly. Put another way, do not add 180,000 devices or users to the group all at once. Or don’t add three (3) child groups of 60,000 devices or users each to a parent group all at once. + Whether it’s a single group or the child-groups of a parent, plan to add no more than 30,000 users or devices to a group per day. * Use filters to include and exclude. + As a support statement, Microsoft does not recommend or support creating assignments to user groups and excluding a device group from the assignment or vice-versa. + The recommendation is to assign user groups to policies and use filters to include or exclude the appropriate devices. Detailed Configuration Steps###### Create an Intune filter for Teams Phones.
Type a name for the rule in the “Filter name” field.
Select “Android Device Administrator” from the “Platform” drop-down menu.
Click the “Next” button.
Add rules for the manufacturers of your Teams Phones. Use the “Contains” operator, the “Equal” operator can give unexpected results. You can expand these rules to include criteria for specific phone models.
Highlight and copy the rule in the “Rule Syntax” box. Create a text file and paste in the rule; you will use it later.
Click the “Next” button.
Click the “Create” button.
Click on “Android enrollment.”
Scroll down to the “Android Device Administrator” section.
Click on “Personal and corporate-owned devices with device administrator privileges.”
Make sure the checkbox next to “Use device administrator to manage devices….” is checked.
If it is, click the “X” to close the window.
If not, check the box and click the “OK” button.
Click “Enrollment device platform restrictions.”
Click the “Android restrictions” tab.
Click on “All User” in the “Default” Policy.
Click “Properties.”
Click the “Edit” button in the “Platform settings” section.
Click the “Allow” button in the “Platform” column of the “Android Device Administrator” row.
Click the “Block” button in the “Personally owned” column.
Click the “Review + save” button.
Click the “Save” button.
Click “Corporate device identifiers.”
Click the drop-down arrow next to “+ Add.”
Click “Enter manually.”
Choose “Serial number” (or IMEI as required) from the “Select identifier type” drop-down box.
Type in the serial number or IMEI in the “Identifier” text box.
Enter information in the “Details” text box.
Add additional rows as needed then click the “Add” button. Corporate Identifiers in a comma-separated value (.csv) files can also be imported.
Click “Compliance policy settings.”
Set “Mark devices with no compliance policy assigned as” to “Compliant.” This is a temporary setting. Switch it back to “Not-compliant” once all policies have been defined and tested.
Click the “Save” button.
Type a name for the policy in the “Name” field.
Add a description in the “Description” field.
Click the “Next” button.
Based on the current Compliance Policy supportability for Android Device Administrator, expand each of the policy subjects and follow the guidance below. The guidance is based on the information on the previously mentioned web page published on September 14, 2022.
Microsoft Defender for Endpoint
All Android devices
Click the “Next” button once you’ve completed your settings.
On the line with the “Mark device noncompliant” action type a “1” into the “Schedule (days after noncompliance) column. If a device is not compliant, it will be allowed to be signed into and function for one (1) day. This allows time for administrators to remediate the device to bring it into compliance. If you are applying this policy to a large number of devices, increase the length of this “grace” period.
Click the “Next” button.
Click “Add all devices.”
Click “Edit filter.”
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Next” button.
Click the “Save” button.
Click the “Create” button.
Click on the first policy that is not based on the “Android Device Administrator” platform. In this example, “IOS.”
Click on “Properties.”
Scroll down to “Included groups.”
If the groups are device groups or appear to be device groups, click the “Edit” button adjacent to the “Assignments” label.
If the groups are user groups, click the “X” in the upper right-hand corner and proceed to the next policy.
Click the “Edit filter” button.
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Review + Save” button.
Click the “Save” button.
Repeat these steps for the rest of the device Compliance Policies.
Scroll down until you can see the “Assignments” label in the Profile’s properties.
Click the “Edit” button.
Click on “Edit filter”
Click “Include filtered devices in assignment.”
Search for and select the previously created Intune filter, “Teams Phones.”
Click the “Select” button.
Click the “Review + Save” button.
Wrap Up
In this first article, we have covered how to configure most of the settings in Intune and its policies to accommodate Teams devices. In the second part, we will finish up the Intune configuration and dive into the setup of Conditional Access policies that will provide security and prevent problems for your Teams devices.
John MillerCloud Solutions Architect - eGroup | Enabling Technologies
The post Teams Android OS Devices Peacefully Coexisting (and Actually Working!) with Microsoft Security and Compliance Policies (Part 1) appeared first on eGroup.