From 13d599f7a0ff4f58fb25ca6aec37a274abd0781e Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:28:02 -0800 Subject: [PATCH 01/12] compliance article for CM --- .../understand/fundamentals-of-compliance.md | 54 +++++++++++++++++++ .../understand/fundamentals-of-security.md | 4 +- 2 files changed, 57 insertions(+), 1 deletion(-) create mode 100644 memdocs/configmgr/core/understand/fundamentals-of-compliance.md diff --git a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md new file mode 100644 index 00000000000..6754feca813 --- /dev/null +++ b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md @@ -0,0 +1,54 @@ +--- +title: Compliance in Configuration Manager +author: dougeby +ms.author: dougeby +manager: dougeby +audience: ITPro +ms.topic: conceptual +ms.service: configuration-manager +ms.collection: + - tier1 + - essentials-compliance +description: Learn about compliance certifications, dependencies, and features in Configuration Manager supporting data protection and regulatory requirements. +ms.date: 12/3/2024 +--- + +# Compliance in Configuration Manager + +Configuration Manager supports compliance features to help organizations meet national, regional, and industry-specific regulations. Configuration Manager aligns with Microsoft's commitment to data protection, privacy, and compliance, by offering tools to help secure and manage data effectively. + +## Shared responsibility model + +Microsoft ensures that Configuration Manager complies with various industry standards and regulatory frameworks. However, customers are responsible for implementing their data protection and compliance strategies to align with their specific organizational requirements. + +## Compliance dependencies + +Configuration Manager leverages other Microsoft services for compliance, including: + +- [Microsoft Entra ID](/entra/fundamentals/whatis): Identity and access management. +- [Microsoft Intune](/mem/intune): Enforces device compliance and conditional access policies. + +## Microsoft Intune capabilities for compliance + +Microsoft Intune helps enforce compliance policies and protect organizational data specifically for Intune: + +- **Conditional Access**: Ensures only compliant devices and apps managed by Intune can access sensitive data. See [Conditional Access](/mem/intune/protect/conditional-access). +- **Device Compliance Enforcement**: Enforces device compliance policies to meet organizational security requirements. See [Device Compliance Policies](/mem/intune/protect/device-compliance-get-started). + +For more information about Intune compliance capabilities, visit the [Microsoft Intune documentation](/mem/intune). +For more information about how to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune, see [What is co-management?](/mem/configmgr/comanage/overview). + +## Data encryption + +Use Configuration Manager to manage BitLocker Drive Encryption (BDE) for on-premises Windows clients, which are joined to Active Directory. It provides full BitLocker lifecycle management that can replace the use of Microsoft BitLocker Administration and Monitoring. For more information, see [Plan for BitLocker management](../protect/plan-design/bitlocker-management.md). + +## Compliance features + +Configuration Manager includes several compliance features that help organizations manage device compliance. For more information, see [Ensure device compliance with Configuration Manager](../compliance/understand/ensure-device-compliance.md). + +## Related articles + +- [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) +- [Microsoft Trust Center](https://www.microsoft.com/trust-center) +- [Additional privacy information](../security/additional-privacy.md) +- [Fundamentals of security](fundamentals-of-security.md) diff --git a/memdocs/configmgr/core/understand/fundamentals-of-security.md b/memdocs/configmgr/core/understand/fundamentals-of-security.md index 17e78bb96a2..aff3337f7eb 100644 --- a/memdocs/configmgr/core/understand/fundamentals-of-security.md +++ b/memdocs/configmgr/core/understand/fundamentals-of-security.md @@ -10,7 +10,9 @@ author: banreet ms.author: banreetkaur manager: apoorvseth ms.localizationpriority: medium -ms.collection: tier3 +ms.collection: +- essentials-security +- tier3 ms.reviewer: mstewart,aaroncz --- From dce674e5dd5089517dbd5707d6974289879bba2a Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:36:37 -0800 Subject: [PATCH 02/12] compliance article for CM2 --- .../configmgr/core/understand/fundamentals-of-compliance.md | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md index 6754feca813..a7ef437aea5 100644 --- a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md +++ b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md @@ -40,15 +40,15 @@ For more information about how to concurrently manage Windows 10 or later device ## Data encryption -Use Configuration Manager to manage BitLocker Drive Encryption (BDE) for on-premises Windows clients, which are joined to Active Directory. It provides full BitLocker lifecycle management that can replace the use of Microsoft BitLocker Administration and Monitoring. For more information, see [Plan for BitLocker management](../protect/plan-design/bitlocker-management.md). +Use Configuration Manager to manage BitLocker Drive Encryption (BDE) for on-premises Windows clients, which are joined to Active Directory. It provides full BitLocker lifecycle management that can replace the use of Microsoft BitLocker Administration and Monitoring. For more information, see [Plan for BitLocker management](/mem/configmgr/protect/plan-design/bitlocker-management). ## Compliance features -Configuration Manager includes several compliance features that help organizations manage device compliance. For more information, see [Ensure device compliance with Configuration Manager](../compliance/understand/ensure-device-compliance.md). +Configuration Manager includes several compliance features that help organizations manage device compliance. For more information, see [Ensure device compliance with Configuration Manager](/mem/configmgr/compliance/understand/ensure-device-compliance). ## Related articles - [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) - [Microsoft Trust Center](https://www.microsoft.com/trust-center) -- [Additional privacy information](../security/additional-privacy.md) +- [Additional privacy information](/mem/configmgr/security/additional-privacy.md) - [Fundamentals of security](fundamentals-of-security.md) From ec48425b3fe596698faf5e113b9b34d87abca7bb Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:39:01 -0800 Subject: [PATCH 03/12] compliance article for CM3 --- .../configmgr/core/understand/fundamentals-of-compliance.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md index a7ef437aea5..5ee2fccd868 100644 --- a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md +++ b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md @@ -36,7 +36,8 @@ Microsoft Intune helps enforce compliance policies and protect organizational da - **Device Compliance Enforcement**: Enforces device compliance policies to meet organizational security requirements. See [Device Compliance Policies](/mem/intune/protect/device-compliance-get-started). For more information about Intune compliance capabilities, visit the [Microsoft Intune documentation](/mem/intune). -For more information about how to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune, see [What is co-management?](/mem/configmgr/comanage/overview). +> [!NOTE] +> For more information about how to concurrently manage Windows 10 or later devices by using both Configuration Manager and Microsoft Intune, see [What is co-management?](/mem/configmgr/comanage/overview). ## Data encryption From 148c6deb19f7fc75bcda28a0a68b6c8f1c64ac01 Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:43:02 -0800 Subject: [PATCH 04/12] compliance article for CM4 --- memdocs/configmgr/core/understand/fundamentals-of-compliance.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md index 5ee2fccd868..19e29358358 100644 --- a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md +++ b/memdocs/configmgr/core/understand/fundamentals-of-compliance.md @@ -51,5 +51,5 @@ Configuration Manager includes several compliance features that help organizatio - [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) - [Microsoft Trust Center](https://www.microsoft.com/trust-center) -- [Additional privacy information](/mem/configmgr/security/additional-privacy.md) +- [Additional privacy information](/mem/configmgr/security/additional-privacy) - [Fundamentals of security](fundamentals-of-security.md) From 24eb1b145a093b4d9ccb3fd7515e164b682279e4 Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:47:20 -0800 Subject: [PATCH 05/12] compliance article for CM5 --- memdocs/configmgr/compliance/TOC.yml | 2 ++ .../understand/fundamentals-of-compliance.md | 6 +++--- 2 files changed, 5 insertions(+), 3 deletions(-) rename memdocs/configmgr/{core => compliance}/understand/fundamentals-of-compliance.md (94%) diff --git a/memdocs/configmgr/compliance/TOC.yml b/memdocs/configmgr/compliance/TOC.yml index 8abbcd105eb..33ed3f4729d 100644 --- a/memdocs/configmgr/compliance/TOC.yml +++ b/memdocs/configmgr/compliance/TOC.yml @@ -3,6 +3,8 @@ items: href: index.yml - name: Understand and explore items: + - name: Understand compliance in Configuration Manager + href: understand/fundamentals-of-compliance.md - name: Ensure device compliance href: understand/ensure-device-compliance.md - name: Get started diff --git a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md b/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md similarity index 94% rename from memdocs/configmgr/core/understand/fundamentals-of-compliance.md rename to memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md index 19e29358358..f37730e4df1 100644 --- a/memdocs/configmgr/core/understand/fundamentals-of-compliance.md +++ b/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md @@ -1,5 +1,5 @@ --- -title: Compliance in Configuration Manager +title: Understand compliance in Configuration Manager author: dougeby ms.author: dougeby manager: dougeby @@ -13,7 +13,7 @@ description: Learn about compliance certifications, dependencies, and features i ms.date: 12/3/2024 --- -# Compliance in Configuration Manager +# Understand compliance in Configuration Manager Configuration Manager supports compliance features to help organizations meet national, regional, and industry-specific regulations. Configuration Manager aligns with Microsoft's commitment to data protection, privacy, and compliance, by offering tools to help secure and manage data effectively. @@ -52,4 +52,4 @@ Configuration Manager includes several compliance features that help organizatio - [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) - [Microsoft Trust Center](https://www.microsoft.com/trust-center) - [Additional privacy information](/mem/configmgr/security/additional-privacy) -- [Fundamentals of security](fundamentals-of-security.md) +- [Fundamentals of security](/mem/core/understand/fundamentals-of-security) From 11001dbd4f3f39f7374215152e3b87b23f0250f0 Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:52:51 -0800 Subject: [PATCH 06/12] compliance article for CM6 --- .../compliance/understand/fundamentals-of-compliance.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md b/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md index f37730e4df1..b88d4cf1121 100644 --- a/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md +++ b/memdocs/configmgr/compliance/understand/fundamentals-of-compliance.md @@ -51,5 +51,5 @@ Configuration Manager includes several compliance features that help organizatio - [Microsoft Privacy Statement](https://privacy.microsoft.com/privacystatement) - [Microsoft Trust Center](https://www.microsoft.com/trust-center) -- [Additional privacy information](/mem/configmgr/security/additional-privacy) -- [Fundamentals of security](/mem/core/understand/fundamentals-of-security) +- [Additional privacy information](/mem/configmgr/core/plan-design/security/additional-privacy) +- [Fundamentals of security](/mem/configmgr/core/understand/fundamentals-of-security) From 7d188f6b23ab4907a8f26e47b4e9991fbc286435 Mon Sep 17 00:00:00 2001 From: Doug Eby <17034284+dougeby@users.noreply.github.com> Date: Tue, 3 Dec 2024 17:55:44 -0800 Subject: [PATCH 07/12] compliance article for CM7 --- memdocs/configmgr/compliance/TOC.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/configmgr/compliance/TOC.yml b/memdocs/configmgr/compliance/TOC.yml index 33ed3f4729d..5c3a3741e61 100644 --- a/memdocs/configmgr/compliance/TOC.yml +++ b/memdocs/configmgr/compliance/TOC.yml @@ -3,7 +3,7 @@ items: href: index.yml - name: Understand and explore items: - - name: Understand compliance in Configuration Manager + - name: Understand compliance href: understand/fundamentals-of-compliance.md - name: Ensure device compliance href: understand/ensure-device-compliance.md From e4cbd24a6fe8d25f3b11e4b593fb5bc5f754d5d6 Mon Sep 17 00:00:00 2001 From: Laura Newsad Date: Mon, 9 Dec 2024 14:18:25 -0500 Subject: [PATCH 08/12] Updated note for deprecation --- .../intune/includes/android-device-administrator-support.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/memdocs/intune/includes/android-device-administrator-support.md b/memdocs/intune/includes/android-device-administrator-support.md index 6338e8f11ff..3f3fa72c642 100644 --- a/memdocs/intune/includes/android-device-administrator-support.md +++ b/memdocs/intune/includes/android-device-administrator-support.md @@ -4,7 +4,7 @@ description: include file author: lenewsad ms.service: microsoft-intune ms.topic: include -ms.date: 06/12/2024 +ms.date: 12/09/2024 ms.author: lanewsad ms.custom: include file ms.collection: @@ -13,4 +13,4 @@ ms.collection: --- > [!IMPORTANT] -> Microsoft Intune is ending support for Android device administrator management on devices with access to Google Mobile Services (GMS) on December 31, 2024. After that date, device enrollment, technical support, bug fixes, and security fixes will be unavailable. If you currently use device administrator management, we recommend switching to another Android management option in Intune before support ends. For more information, see [Ending support for Android device administrator on GMS devices](https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-ending-support-for-android-device-administrator/ba-p/3915443). +> Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services (GMS). If you currently use device administrator management, we recommend switching to another Android management option. For more information, see [Ending support for Android device administrator on GMS devices](https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-ending-support-for-android-device-administrator/ba-p/3915443). Support and help documentation remain available for devices without GMS, running Android 15 and earlier. From 634cc0fb8bfeba33f5b246c353a901cf6742e7e8 Mon Sep 17 00:00:00 2001 From: Laura Newsad Date: Wed, 11 Dec 2024 12:55:06 -0500 Subject: [PATCH 09/12] Update android-device-administrator-support.md PM feedback --- .../intune/includes/android-device-administrator-support.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/memdocs/intune/includes/android-device-administrator-support.md b/memdocs/intune/includes/android-device-administrator-support.md index 3f3fa72c642..5fd923c6c12 100644 --- a/memdocs/intune/includes/android-device-administrator-support.md +++ b/memdocs/intune/includes/android-device-administrator-support.md @@ -4,7 +4,7 @@ description: include file author: lenewsad ms.service: microsoft-intune ms.topic: include -ms.date: 12/09/2024 +ms.date: 12/31/2024 ms.author: lanewsad ms.custom: include file ms.collection: @@ -13,4 +13,4 @@ ms.collection: --- > [!IMPORTANT] -> Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services (GMS). If you currently use device administrator management, we recommend switching to another Android management option. For more information, see [Ending support for Android device administrator on GMS devices](https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-ending-support-for-android-device-administrator/ba-p/3915443). Support and help documentation remain available for devices without GMS, running Android 15 and earlier. +> Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services (GMS). If you currently use device administrator management, we recommend switching to another Android management option. Support and help documentation remain available for some devices without GMS, running Android 15 and earlier. For more information, see [Ending support for Android device administrator on GMS devices](https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-ending-support-for-android-device-administrator/ba-p/3915443). From 6a58a42f1003001d39d0bc0793c0c06b45eacad4 Mon Sep 17 00:00:00 2001 From: Laura Newsad Date: Thu, 12 Dec 2024 13:40:47 -0500 Subject: [PATCH 10/12] Dec 31 blurb DA deprecation For 24563742 --- memdocs/intune/fundamentals/whats-new.md | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/memdocs/intune/fundamentals/whats-new.md b/memdocs/intune/fundamentals/whats-new.md index 7490981d7f9..3cb36760a4e 100644 --- a/memdocs/intune/fundamentals/whats-new.md +++ b/memdocs/intune/fundamentals/whats-new.md @@ -7,7 +7,7 @@ keywords: author: brenduns ms.author: brenduns manager: dougeby -ms.date: 12/09/2024 +ms.date: 12/31/2024 ms.topic: conceptual ms.service: microsoft-intune ms.subservice: fundamentals @@ -75,6 +75,13 @@ You can use RSS to be notified when this page is updated. For more information, ### Tenant administration --> +## Week of December 30, 2024 + +### Device enrollment + +#### Intune ends support for Android device administrator on devices with access to Google Mobile Services +As of December 31, 2024, Microsoft Intune no longer supports Android device administrator management on devices with access to Google Mobile Services (GMS). This change comes after Google deprecated Android device administrator management and ceased support. Intune support and help documentation remains for devices without access to GMS running Android 15 or earlier, as well as Microsoft Teams devices migrating to Android Open Source Project (AOSP) management. For more information about how this change impacts your tenant, see [Intune ending support for Android device administrator on devices with GMS access in December 2024](https://techcommunity.microsoft.com/blog/intunecustomersuccess/intune-ending-support-for-android-device-administrator-on-devices-with-gms-in-de/3915443). + ## Week of December 9, 2024 ### Tenant administration From bc61a7585780ae823df7ff87e63f3079c7cf5d55 Mon Sep 17 00:00:00 2001 From: Laura Newsad Date: Thu, 12 Dec 2024 13:44:25 -0500 Subject: [PATCH 11/12] Update whats-new.md Acrolinx --- memdocs/intune/fundamentals/whats-new.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/memdocs/intune/fundamentals/whats-new.md b/memdocs/intune/fundamentals/whats-new.md index 3cb36760a4e..8b524d4af38 100644 --- a/memdocs/intune/fundamentals/whats-new.md +++ b/memdocs/intune/fundamentals/whats-new.md @@ -80,7 +80,7 @@ You can use RSS to be notified when this page is updated. For more information, ### Device enrollment #### Intune ends support for Android device administrator on devices with access to Google Mobile Services -As of December 31, 2024, Microsoft Intune no longer supports Android device administrator management on devices with access to Google Mobile Services (GMS). This change comes after Google deprecated Android device administrator management and ceased support. Intune support and help documentation remains for devices without access to GMS running Android 15 or earlier, as well as Microsoft Teams devices migrating to Android Open Source Project (AOSP) management. For more information about how this change impacts your tenant, see [Intune ending support for Android device administrator on devices with GMS access in December 2024](https://techcommunity.microsoft.com/blog/intunecustomersuccess/intune-ending-support-for-android-device-administrator-on-devices-with-gms-in-de/3915443). +As of December 31, 2024, Microsoft Intune no longer supports Android device administrator management on devices with access to Google Mobile Services (GMS). This change comes after Google deprecated Android device administrator management and ceased support. Intune support and help documentation remains for devices without access to GMS running Android 15 or earlier, and Microsoft Teams devices migrating to Android Open Source Project (AOSP) management. For more information about how this change impacts your tenant, see [Intune ending support for Android device administrator on devices with GMS access in December 2024](https://techcommunity.microsoft.com/blog/intunecustomersuccess/intune-ending-support-for-android-device-administrator-on-devices-with-gms-in-de/3915443). ## Week of December 9, 2024 From 1965ce73052aa780db8298f4404f91848832ef2f Mon Sep 17 00:00:00 2001 From: Erik Reitan Date: Thu, 12 Dec 2024 14:11:53 -0800 Subject: [PATCH 12/12] erikre-docs-30467181 --- .../apps/app-configuration-managed-home-screen-app.md | 4 +++- memdocs/intune/apps/manage-without-gms.md | 6 ++---- 2 files changed, 5 insertions(+), 5 deletions(-) diff --git a/memdocs/intune/apps/app-configuration-managed-home-screen-app.md b/memdocs/intune/apps/app-configuration-managed-home-screen-app.md index 2020c4cd077..db49c80a223 100644 --- a/memdocs/intune/apps/app-configuration-managed-home-screen-app.md +++ b/memdocs/intune/apps/app-configuration-managed-home-screen-app.md @@ -37,7 +37,9 @@ The Managed Home Screen is the application used for corporate-owned Android Ente ## When to configure the Microsoft Managed Home Screen app -First, ensure that your devices are supported. Intune supports the enrollment of Android Enterprise dedicated devices and fully managed devices running OS version 8.0 and above that reliably connect to Google Mobile Services. Similarly, Managed Home Screen supports Android devices running OS version 8.0 and above. + [!INCLUDE [android_device_administrator_support](../includes/android-device-administrator-support.md)] + +First, ensure that your devices are supported. Intune supports the enrollment of Android Enterprise dedicated devices and fully managed devices running OS version 8.0 and above. Similarly, Managed Home Screen supports Android devices running OS version 8.0 and above. Typically, if settings are available to you through device configuration profiles (**Devices** > **Manage devices** > **Configuration**), configure the settings there. Doing so will save you time, minimize errors, and will give you a better Intune-support experience. However, some of the Managed Home Screen settings are currently only available via the **App configuration policies** pane in the Intune admin center. Use this document to learn how to configure the different settings either using the configuration designer or a JSON script. Additionally, use this document to learn what Managed Home Screen settings are available using device configuration profiles. You may also see [Device settings](../configuration/device-restrictions-android-for-work.md#device-experience) for a full list of settings available in **Devices** > **Manage devices** > **Configuration** that impact the Managed Home Screen. diff --git a/memdocs/intune/apps/manage-without-gms.md b/memdocs/intune/apps/manage-without-gms.md index bfea7580abe..4b92cde69ef 100644 --- a/memdocs/intune/apps/manage-without-gms.md +++ b/memdocs/intune/apps/manage-without-gms.md @@ -37,10 +37,8 @@ Microsoft Intune uses Google Mobile Services (GMS) to communicate with the Micro > [!NOTE] > These GMS related limitations also apply to Device Administrator management and Android (AOSP) Management. -> [!NOTE] -> Microsoft Intune is ending support for [Android device administrator management](../enrollment/android-enroll-device-administrator.md) on devices with access to Google Mobile Services (GMS) on December 31, 2024. After that date, device enrollment, technical support, bug fixes, and security fixes will be unavailable. -> For devices running Android 15 or earlier that don't have access GMS (excluding Microsoft Teams certified Android devices), Intune will continue allowing device administrator enrollment and will maintain limited support, since Android Enterprise management is unavailable to these devices. However, device administrator use on these devices is still not recommended, since Google's device administrator deprecation means there could be future functionality impact outside Intune's ability to mitigate. -> For more information, and to learn about alternatives to device administrator, see [Ending support for Android device administrator on GMS devices](https://techcommunity.microsoft.com/t5/intune-customer-success/microsoft-intune-ending-support-for-android-device-administrator/ba-p/3915443). +[!INCLUDE [android_device_administrator_support](../includes/android-device-administrator-support.md)] + ## Install the Intune Company Portal app without access to the Google Play Store ### For users outside of People's Republic of China