Managing Android devices using Microsoft Intune
The behavior matches Intune enrollment being blocked by the very controls configured to prevent personal enrollment, before the corporate identifier check is evaluated.
Key points from the configuration and behavior:
- Android Device Administrator enrollment is enabled.
- Enrollment restrictions are configured to block personally owned devices.
- Corporate device identifiers (IMEI/serial) are uploaded for the Samsung devices.
- Devices are currently managed by Ivanti MDM.
- Error during registration: “Your IT support has not authorized management for this device.”
- In Corporate Device Identifiers, the device shows as “never contacted”.
From the provided documentation:
- Devices that are currently enrolled in another MDM must be unenrolled before enrolling in Intune. For Android device administrator, a factory reset is not required, but unenrollment from the existing MDM is required before Intune enrollment.
- Enrollment restrictions are evaluated during enrollment, and personal devices can be blocked entirely via platform restrictions.
- Corporate identifiers are evaluated when the device actually enrolls; if enrollment is blocked earlier by restrictions, the device never reaches the identifier check and therefore shows as “never contacted”.
Given this, the most likely causes and resolutions are:
- Existing Ivanti MDM management
- Devices must be unenrolled from Ivanti before Intune can manage them. If the device is still under Ivanti MDM, Intune enrollment can fail early.
- Action: For a test device, fully remove Ivanti MDM management (unenroll from Ivanti) and then attempt Intune enrollment again.
- Enrollment restriction blocking before corporate identifier check
- The error text and the “never contacted” status indicate that the enrollment platform restriction is blocking the device as “personal” before Intune evaluates the IMEI/serial corporate identifier.
- Intune uses corporate identifiers to mark devices as corporate when they enroll. Devices that enroll without matching identifiers are marked as personal. If enrollment is blocked at the “personal device” stage, the identifier match is never reached.
- Action path:
- Temporarily relax the Android enrollment restriction for a small pilot group so that personally owned Android Device Administrator devices are allowed.
- Ensure the test device’s IMEI/serial is correctly entered (no formatting errors) in Corporate Device Identifiers.
- Unenroll the test device from Ivanti.
- Enroll again via Company Portal and confirm that Intune now marks the device as corporate based on the identifier.
- Once confirmed, refine restrictions (for example, use group‑based restrictions so only devices for specific users are allowed to enroll) while still allowing the enrollment to reach the identifier check.
- Android Device Administrator limitations and best practices
- For Android Device Administrator:
- IMEI and serial number corporate identifiers are supported only with Android 9 and earlier.
- If devices are newer (Android 10+), corporate identifiers for Device Administrator may not behave as expected.
- Action: Verify OS version of the Samsung devices. If they are above the supported level, consider moving to Android Enterprise (work profile or corporate‑owned work profile) and using the corresponding enrollment and restriction model instead of Device Administrator.
- For Android Device Administrator:
- Confirm MDM authority and general enrollment configuration
- Ensure MDM authority is set to Microsoft Intune and that Android Device Administrator enrollment is explicitly enabled under Devices → Enrollment → Android → Android device administrator.
- If not already done, confirm that the tenant is not still using an older MDM authority configuration that could interfere with Intune enrollment features.
- Use Intune diagnostics for confirmation
- Run the “Intune Android enrollment” diagnostic from the Microsoft 365 admin center (Support → Help & support → type “Intune Android enrollment”) against an affected user to confirm whether enrollment restrictions or other configuration issues are blocking enrollment.
Summary of recommended steps:
- Pick one test device and user from the Conditional Access group.
- Fully unenroll the device from Ivanti MDM.
- Verify the device’s IMEI/serial is correctly present in Corporate Device Identifiers and that the OS version is within the supported range for Android Device Administrator identifiers.
- For that user, temporarily allow Android Device Administrator personal enrollment via a less restrictive enrollment restriction policy.
- Reattempt enrollment and verify that the device is marked as corporate in Intune.
- Adjust enrollment restrictions to use group‑based targeting and, if needed, plan migration to Android Enterprise for long‑term management.
References: