Skip to content
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile

Written By Jitesh Kumar
Last Updated January 22, 2024
Posted In Android
SHARE

Let’s learn how you can allow or block Accounts to Add in Android Personally Owned Work Profile using Intune. Admins can manage whether users can add or remove work profile accounts in the Settings app. This feature is crucial for organizations to use their personal devices for work purposes while ensuring security.

Android Personally Owned Work Profiles provides the capability to either allow or block specific user accounts from being added. When administrators choose to allow certain accounts, they are essentially permitting users to add those accounts to their Android Work Profiles.

This flexibility is beneficial for employees who may need to access work-related resources, such as emails or documents, from their personal devices. Note that this does not affect the accounts that are automatically added in Settings when a user enrolls, or accounts entered directly into work apps.

On the other hand, the ability to block specific accounts is a security measure that organizations can leverage to prevent unauthorized access or potential data breaches. By restricting the addition of certain accounts, administrators can minimize the risk of sensitive corporate information falling into the wrong hands or being accessed by individuals without the appropriate permissions.

Patch My PC

On personally owned devices with a work profile (BYOD) and corporate owned devices with work profile (COPE), Google accounts can’t be added to the Settings app > Accounts > Work.

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile

Enabling the “Allow or Block Accounts to Add in Android Personally Owned Work Profile” feature in Microsoft Intune involves configuring specific settings within the Android device restriction profile. Here’s a step-by-step guide:

  • Sign in to Microsoft Intune Admin Center https://intune.microsoft.com/
  • Click on Devices > Android > Configuration Policies. I selected the existing configuration profile (Device Restriction) for modification.

You can check more details, you wanted to create device restriction policies from scratch, Enforcing Screen Lock For Android Devices In Intune

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.1
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.1

You can see the different categories of applied configuration in the configuration settings for Android Enterprise personally owned devices with a work profile (BYOD). The Work profile settings allow you to configure the policy to control work profile accounts.

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.2
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.2

Here you can review the available restriction settings under Work profile settings. You can select and customize them as per our requirements. In the Add and remove accounts, you will find three options to be configured. By default, Allowed all accounts types, except Google accounts. You can also configure to allow or block accounts types from the available options.

SettingsDescription
Add and remove accountsThis setting allows or prevents accounts from being added in the work profile, including Google accounts.
Table 1 – Allow or Block Accounts to Add in Android Personally Owned Work Profile
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.3
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.3

Block all account types: Prevents users from manually adding or removing accounts in the work profile. For example, when you deploy the Gmail app into the work profile, you can prevent users from adding or removing accounts in this work profile.

Allow all account types: Allows all accounts, including Google accounts. These Google accounts are blocked from installing apps from the Managed Google Play Store. You can also configure:

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.4
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.4

The next step is to review the setup policy and Save. A notification prompt will appear when you save the profile, Profile “HTMD Android Device Restriction Policy” saved successfully.

Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.5
Intune Allow or Block Accounts to Add in Android Personally Owned Work Profile Fig.5

Once the configuration is applied to the device, based on the specified settings, you either can continue using the account inside or completely block adding the account. On personally owned devices with a work profile, Google accounts can’t be added to the Settings app > Accounts > Work.

We are on WhatsApp. To get the latest step-by-step guides and news updates, Join our Channel. Click here –HTMD WhatsApp.

Author

About Author – JiteshMicrosoft MVP, has over six years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus is Windows 10/11 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Android

Microsoft Intune Finally Restores Password Manager Support for Android Enterprise Devices

Key Takeaways By default, Android blocks third-party password manager and credential apps on managed work devices. With this new Intune setting, IT admins can allow trusted apps like Microsoft Authenticator or other password managers to securely save and autofill passwords and passkeys. This also helps organizations enable passkey sign-ins and control which apps are trusted […]

AC Anoop C Nair 3 min read
Android

Microsoft Teams on Android to Support Third-Party Meetings with SIP Integration

Key Takeaways Microsoft Teams on Android to Support Third-Party Meetings with SIP Integration! Microsoft is improving cross-platform communication by enabling Microsoft Teams users on Android devices to join third-party meetings using Session Initiation Protocol (SIP). Recently added to the Microsoft 365 roadmap, this upcoming feature helps organizations connect different communication platforms more easily. Microsoft Teams […]

AC Anoop C Nair 4 min read
Android

Microsoft Announces Teams Optimization for Windows App on iOS and Android

Key Takeaways Microsoft Announces Teams Optimization for Windows App on iOS and Android In this post we are discussing, Microsoft Announces Teams Optimization for Windows App on iOS and Android. Microsoft has officially announced the general availability of Teams optimizations for Windows App on both iOS and Android devices. This update is a better for […]

AC Anoop C Nair 3 min read
Android

Microsoft Intune Enhances Line-of-Business App Management for Android Devices

Key Takeaways Hey, let’s discuss about Microsoft Intune Enhances Line-of-Business App Management for Android Devices. Several improvements are planned for Android Enterprise management. Support for Entra accounts for the AE connector will be introduced, along with better web enrollment for BYO (Bring Your Own) work profiles. There will also be clearer provisioning status updates and […]

AC Anoop C Nair 3 min read