Skip to content
Block Android Device Manufacturer Enrollment in Intune

Block Android Device Manufacturer Enrollment in Intune

Written By Jitesh Kumar
Last Updated November 10, 2022
Posted In Intune
SHARE

In this post, you will learn about the process to Block Android Device Manufacturer Enrollment in Intune. Device platform restrictions let you restrict enrollment based on device models.

There are two types of device enrollment restrictions you can configure in Microsoft Intune, Device platform restrictions define which platforms, versions, and management types can enroll and Device limit restrictions define how many devices each user can enroll.

Each restriction type comes with one default policy that you can edit and customize as needed. Intune applies the default to all user and userless enrollments until you assign a higher-priority policy.

If you are interested to know how the management has evolved and the different management modes that are on Android Enterprise, Joy will be talking about Android Management in general with Intune Android Management With Intune | Android Enterprise.

Patch My PC

Let’s learn how to create enrollment notifications in Intune MEM Admin portal. Set up enrollment notifications in Microsoft Intune to notify users of newly enrolled devices, Configure Device Enrollment Notifications In Intune.

Block Android Device Manufacturer Enrollment in Intune

This restriction blocks device made by specific manufacturers and is applicable to Android devices only. It is in the admin center under Enrollment device platform restrictions.

  • Sign in to the Microsoft Intune admin center https://endpoint.microsoft.com.
  • Select Devices, and under Device enrollment click on Enroll Devices to configure the restrictions in the Intune admin center.
Click on Enroll device - Block Android Device Manufacturer Enrollment in Intune Fig.1
Click on Enroll device – Block Android Device Manufacturer Enrollment in Intune Fig.1

There are two options to create Intune Device-type policies. You can update the default policy, which is deployed to All Users. This policy would be a tenant-wide setting for all users. Or you can create a custom device type policy and deploy it to a set of groups.

In the Enrollment device platform restrictions, Under Android restrictions, select the device type restrictions -> Default -> or choose the Custom restriction that you want to set.

Device type restrictions - Block Android Device Manufacturer Enrollment in Intune Fig.2
Device type restrictions – Block Android Device Manufacturer Enrollment in Intune Fig.2

Select Properties. Scroll down and click on Edit in the Platform settings.

Edit Platform Settings - Block Android Device Manufacturer Enrollment in Intune Fig.3
Edit Platform Settings – Block Android Device Manufacturer Enrollment in Intune Fig.3

Device platform restrictions define which platforms, versions, and management types can enroll. Here, you can restrict device platforms, OS versions, manufacturer, and personally owned devices.

The Minimum OS version is already configured here, Let’s block android devices by providing specific manufacturers, For Example I want to block Xiamoi and Realme manufacturer to not enroll in Intune. Added Xiaomi, Realme together separated by commas and space in between, and click on Review + Save.

Specify Device Manufacturer - Block Android Device Manufacturer Enrollment in Intune Fig.4
Specify Device Manufacturer – Block Android Device Manufacturer Enrollment in Intune Fig.4

A notification will appear automatically in the top right-hand corner with a message. Here you can see, Restriction saved successfully. Here you can also see the configured settings.

Block Android Device Manufacturer Enrollment in Intune Fig.5
Block Android Device Manufacturer Enrollment in Intune Fig.5

End User Experience

On an Android device, As soon as you install Intune Company Portal app on the device model (Xiaomi or Realme) based on our inputs above. In the enrollment process, you may receive the below message in case the device model is not supported to use by your organization.

Intune Company Portal helps and allows you, as an employee or student in your organization, to securely access those resources and install, uninstall apps, and view, edit, add and remove your enrolled devices.

Read more, Intune Company Portal App for Windows 11 Android | Install and Uninstall

Block Android Device Manufacturer Enrollment in Intune Fig.6
Block Android Device Manufacturer Enrollment in Intune Fig.6

After clicking the Open, you should sign in to your Company portal. The Company portal helps you access company resources and keep them secure.

Select Sign IN from the Company portal Window. Enter your Email address and password to Sign in to the Company Portal app on your Mobile.

.Block Android Device Manufacturer Enrollment in Intune Fig.7
.Block Android Device Manufacturer Enrollment in Intune Fig.7

After entering your work account, you may directly land on the Company Portal App without asking to set up your device to access it. You will no longer be able to manage or access company resources. Let us know your experience with the enrollment, Am I missing some prompt here?

.Block Android Device Manufacturer Enrollment in Intune Fig.8
.Block Android Device Manufacturer Enrollment in Intune Fig.8

Author

Written by

Jitesh has over 5 years of working experience in the IT Industry. He writes and shares his experiences related to Microsoft device management technologies and IT Infrastructure management. His primary focus area is Windows 10 Deployment solution with Configuration Manager, Microsoft Deployment Toolkit (MDT), and Microsoft Intune.

Discussion · 2 comments

  1. Hi

    Great article, do you know if it is possible to use an allow list? Like I would only allow Samsung Android Phones?

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Intune

Simplify Windows Devices to Run Only the Required Applications using Intune

Key Takeaways Hey, let’s learn about Simplify Windows Devices to Run Only the Required Applications using Intune. This policy lets administrators replace the default windows shell with a custom or lightweight shell. it improves performance by using system resources and is useful for devices that run a dedicated application. If the policy is disabled or […]

AC Anoop C Nair 8 min read
Intune

Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune

Key Takeaways In this post we are discussing about Enhance macOS Compliance with Custom Security and Compliance Checks to Improve Device Security using Microsoft Intune. Microsoft has announced the general availability of Custom Compliance Settings for macOS in Microsoft Intune. The feature helps organizations strengthen security controls while supporting many types of macOS management scenarios. […]

AC Anoop C Nair 4 min read
Intune

Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune

Key Takeaways In this post we are discussing Manage Samsung Galaxy Firmware Versions to Improve Security and Compliance using Microsoft Intune. Microsoft Intune has received a new update that expands firmware management capabilities for Samsung Galaxy devices through Firmware Versionsintegration. This enhancement gives IT administrators more control over firmware and operating system updates, helping them […]

AC Anoop C Nair 4 min read
Intune

MS Intune Adds Windows Registry Data Collection to Device Inventory for Single Values All Key Values and Subkeys

Key Takeaways Microsoft Intune 2607 introduces Windows Registry Data collection in Device Inventory, allowing IT admins to verify actual device configurations without relying on custom discovery or remediation scripts. Using the Properties Catalog, admins can collect registry information through Single Value, All Values Under a Key (Non-Recursive), or Same Value Across Subkeys. MS Intune Adds […]

AC Anoop C Nair 5 min read