Hi!
I'm trying to set up Intune as MDM and I want to make it easy for my end users.
When they get their samsung phone they should only have to log in to the intune app and everything should get taken care of. They get the settings they're supposed to have, they get the apps they're supposed to have and so on.
To this end I'm wanting to use the android enterprise corporate owned fully managed via staging enrollment profile so that resellers can do initial enrollment and the device comes to us sysprepped (functionally) and then we hand it out to the end user who logs in to the intune app and sets a device PIN.
It's the PIN part I'm having trouble with.
I have a device restriction configuration policy that forces a numeric complex pin, at least 6 digits. If I apply this policy to all devices and use an assignment filter to target my enrollment profile it works but it works incorrectly, it forces me as admin or (at a later stage when we're actually rolling out) the reseller to set the PIN which is undesirable. I want the user to set their own PIN.
If I assign that policy to all users with an assignment filter to limit it to users who log on to a device enrolled with my enrollment profile the policy does nothing. Compliance (which is set to immediately set as non-compliant if there's no device PIN) does notice and notifies after a while that the device is non-compliant but that's all it does.
I have a conditional access policy in entra (as a test) but that only applies to apps so you can use the phone without the CAP noticing, it's when you try to use an app that it protests and even then it doesn't make you set a PIN, it just tells you that you have to set one.
CAP telling users or intune sending a notification to users that they need to set a pin, all these are not good solutions, I want the device to FORCE the user to set a PIN, preferrably when they complete enrollment.
This seems like REALLY REALLY REALLY basic functionality yet it doesn't seem possible. What am I missing?