Deploying an Android compliance policy
Now, we can look at our Android corporate devices. While BYOD is handled by App Protection policies (as we have no control over the device itself), we can force our managed devices to remain compliant to access corporate data. In this recipe, we are only going to be looking at corporate-owned and managed devices. Settings for other device types can be found here: https://learn.microsoft.com/en-gb/mem/intune/protect/compliance-policy-create-android-for-work#system-security-settings.
Getting started
As with the Windows policy, we will start by looking at the available options and what they do.
Compliance settings
We can run through the various compliance settings for our Android devices.
Microsoft Defender for Endpoint
Note that for these settings, you will require licensing for Defender for Endpoint. Double-check you have the correct licenses before enabling. It also requires the application to be deployed to and running on the...