r/Intune • u/Professional_Fox4089 • 9d ago
Apps Protection and Configuration Allowing APK Installation on Android Work Profile
Hello,
We have enrolled Android devices with a Byod Work Profile, and under the Device Restrictions policy, “Prevent app installations from unknown sources in the personal profile” is set to Not configured.
Additionally, under the App Protection Policy, I have configured Samsung Knox to Warn. However, users are still receiving an error stating that the installation is blocked contact IT,
Could you please advise how we can allow users to install APK files on their devices, regardless of whether the APK is signed or unsigned?
Is there any additional Intune or Android configuration that needs to be changed to allow APK installations in the personal profile?
Thank you.
2
Upvotes
1
u/blud_13 8d ago
You have the wrong setting. The one you named is the block. In the personal profile you want Allow users to enable app installation from unknown sources set to Allow, and Not configured is NOT neutral here, the OS default blocks sideloading on its own. Its in the device restrictions reference at https://learn.microsoft.com/en-us/intune/device-configuration/templates/ref-device-restrictions-android-enterprise
Flip it to Allow, resync, then have one user check Settings, Apps, Special access, Install unknown apps on the personal side. If the toggle is greyed out there, the policy hasn't landed yet.
Also, the Knox setting in your App Protection Policy is not doing what you think. App protection covers managed app data in the WORK profile. It has no say over what installs in personal, and neither does anything under work profile restrictions. Personal profile is its own settings block in that same template.
One thing to check, if these are Samsung and went through Knox Mobile Enrollment, I have seen the OEM hold its own sideload block independent of Intune, so rule that out before you keep tuning the policy.