How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer

Let’s discuss how to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer. A General Device Configuration Policy in Intune is a policy that helps IT admins manage and secure company-owned Android devices.

With this policy, you can easily set password rules, block or allow features like camera or Bluetooth, control security options such as encryption, manage network settings like Wi-Fi and VPN, limit app and store usage, and even lock the device to run only specific apps (kiosk mode).

This policy gives organisations an easy way to apply common settings and restrictions to keep devices safe and work-ready. Device Owner mode gives organisations end-to-end control over Android devices, making them secure, compliant, and used for work purposes.

Intune Copilot Explorer is an AI tool inside the Intune admin center that helps IT admins work with Intune data more easily. Instead of writing complex queries or searching through menus, admins can just type questions in plain language.

Patch My PC

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer

When IT admins use Intune Copilot Explorer to retrieve General Device Configuration Policies for Android Device Owner, they get a clear view of all the rules and restrictions currently applied to company-owned Android devices. Follow the steps below for more details.

  • Sign in to the Intune Admin Center.
  • From the left-hand menu, open the Explorer tab.
  • In the Show examples for section, choose Device Configuration as the category.
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.1
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.1

Device Configuration Policies

Device configuration policies help organisations and IT admins by providing a simple way to secure and manage devices. For organisations, these policies protect sensitive data. For IT admins, they reduce manual work by automatically applying settings such as Wi-Fi, VPN, and app configurations, etc.

  • In the Device Configuration section, you will see a list of options to choose from.
  • Here, we select the third option, which is “Get device configuration policies that are of the type device configuration policy type name.”
  • This option helps you quickly find and view all policies that match a specific type of device configuration, making it easier for admins to locate the exact policies they need without going through everything manually.

Read More – How to use Intune Explorer with Security Copilot to Access Devices Users Apps Compliance and Update Details

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.2
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.2

Get Device Configuration Policies that are of the Type Device Configuration Policy Type Name

The option “Get device configuration policies that are of the type Device configuration policy type name” requires you to fill in the “Device configuration policy type name” field to continue. This field has different choices based on platforms like Android, iOS, and macOS. In this case, we select “Android device owner general device configuration” to view the policies created for managing corporate-owned Android devices.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.3
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.3

Querying Android Device Owner General Device Configuration Policies in Intune

After filling the required filed the query is like “Get device configuration policies that are of the type Android device owner general device configuratin”. Click the Arrow next to the query and the copilot will generate the check the prompt and provide the query that there are 4 items in the results list.

This query retrieves information about device configuration policies from the Intune environment. It specifically filters for policies of a certain type and then organizes the relevant details into a structured format. The output includes the policy ID, name, type, template ID, and platform type, all bundled together for easier analysis and reporting.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.4
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.4

Other Useful Queries and Next Steps

Here are some other useful queries that IT admins can use in Intune Copilot Explorer to manage apps and devices in a simple way. The screenshots and table below give more details about these queries and explain the extra steps you can follow.

Other Useful QueriesNext Steps to Consider

Query: Get users with devices on Platform that have discovered app with name containing App Name installed
Reason: This query helps identify users with devices on a specific platform that have a particular app installed, which can be useful for tracking app deployment and usage.

Query: Get devices that have the managed app /Managed App installed on platform Managed App Platform
Reason: This query provides insights into which devices have a specific managed app installed, helping administrators ensure compliance and proper app management.

Query: Get users that have discovered app with name containing App Name on Platform published by Publisher installed
Reason: This query helps in identifying users with devices that have apps from a specific publisher installed, which is useful for managing app licenses and ensuring compliance.
Review the list of device configuration policies returned by the query to ensure they align with your organization’s security and compliance requirements. This helps in identifying any misconfigurations or outdated policies.

Use the detailed information about each policy (such as policy ID, name, type, template ID, and platform type) to create a comprehensive report for stakeholders. This report can be used to communicate the current state of device configuration policies and any necessary actions.

Cross-reference the policies with your organization’s compliance standards to identify any gaps or areas for improvement. This ensures that all devices are configured according to the latest security guidelines and helps in maintaining a secure environment.
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Table 1
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.5
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.5

End Results

In the end result from Security Copilot in Intune Explorer, the query shows that there are 4 items listed. These items are KIOSK Testing, CIS_Device lock restrictions_AE, Multi-app Kiosk, and another KIOSK Testing. Intune found 4 device configuration policies that match the search, and they are displayed clearly for the admin to review.

Device Configuration Policy
KIOSK Testing
KIOSK
CIS_Device lock restrictions_AE
Multi-app Kiosk
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Table 2
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.6
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.6

KIOSK Device Configuration Profile in Android Device Owner – Intune Copilot Explorer

The KIOSK Device is one of the result items found under General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer. This configuration profile is created under the Android Enterprise platform with the Device restrictions profile type. Within this profile, the settings are organized into different sections such as General, System security, and Device experience.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.7
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.7

CIS_Device lock restrictions_AE Device Configuration Profile in Android Device Owner – Intune Copilot Explorer

The CIS_Device lock restrictions_AE is the second item in the result under Device Configuration Profiles. This profile focuses on system security settings, specifically around the device password. It allows IT admins to enforce password requirements on Android devices, ensuring that users set strong passwords to protect company data and maintain device security.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.8
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.8

Multi-app Kiosk Device Configuration Profile in Android Device Owner – Intune Copilot Explorer

The Multi-app Kiosk is the third item in the result under Device Configuration Profiles. This profile includes settings for system security and device experience. It allows IT admins to lock a device so that only selected apps can be used, while also applying security rules.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.9
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.9

KIOSK Testing Device Configuration Profile in Android Device Owner – Intune Copilot Explorer

The KIOSK Testing is the 4th item in the results under Device Configuration Profiles. This profile includes settings under General, System security, and Device experience. It is mainly used for testing kiosk scenarios, where admins can apply restrictions, enforce security rules, and adjust how the device behaves to make sure the setup works as expected before rolling it out to more users.

How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer - Fig.10
How to Retrieve General Device Configuration Policies for Android Device Owner using Intune Copilot Explorer – Fig.10

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the latest step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, join the WhatsApp Community to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security, Career, etc.

Leave a Comment