Overview
This guide is intended to be used only to configure shared phones for use in the plant that need to be portable, but can't be tied to an individual. For example, a generic shipping phone. If a phone can be assigned to an individual, but needs to be limited to plant use, refer to the "Plant WiFi Smart Phone Setup" guide instead. If the phone does not need to be portable, refer to the "Common Area phone - Desk Phone Setup" guide on the right
To accomplish this an Android Phone is setup in Azure AD Shared mode so that it can be locked down to only a few applications.
Prerequisites
A common area phone user account must be setup to sign on to the phone. Refer to the "Common Area Phone Accounts" section in the General Teams Administration article on the right for further instructions.
Phone Setup
The phone is inrolled from the setup screen "AAD Teams Portable Phone" barcode. When connecting to wifi you can scan a wireless barcode by clicking Add new network, then clicking the barcode symbol. You do not sign in to Intune / Company Portal with this method.
- Power on the phone. DO NOT PRESS any buttons. You will be presented with a screen like the following. (On newer phones this may just say welcome)
- Tap anywhere in the white space until a camera appears; typically, this is 7 or 8 taps.
- If you receive any other prompts restart the phone and make sure that tapping in the white space is the first thing you do.
- Once the camera appears, scan the barcode to start the enrollment process. (This should auto connect to wifi)
- In Endpoint manager navigate to Devices > Android > Android Enrollment.
- Click Corporate-owned dedicated devices.
- Click the ... menu to the right of "AAD Teams Portable Phone"
- Click View Enrollment Token.
- Scan the barcode.
- If prompted to connect to wifi.
- Either click on the wireless network or click Add New Network.
- Click the Barcode icon to the right.
- Scan the barcode to connnect.
- You will be taken to a screen that states, “This device belongs to your organization” Tap Next.
- You will now be taken to a screen like the following. During this time your phone will get connected to WiFi and prepare for the next steps. This may take a minute or two.
- Once you are brought to a screen titled “Set up your phone” tap Accept and Continue.
- Please wait a few moments while the setup is initialized. During this time, you may see screens like the following. Once this is complete you will see a Next button appear at the bottom of the screen.
- Tap Next to continue.
- You will now be taken to a screen like the following while this checks for updates. This may take a moment or two.
- You will now be taken to a screen about the Google services, Tap More to review, you will likely need to tap this twice.
- Tap Accept to continue.
- If desired, you can review the information listed.
- Tap “I have read and agree to all of the above” then tap Next to continue.
- You may briefly see a screen stating that the device is being updated.
- Was not at this step on S9 - You will now need to accept the settings for Chrome. Tap Accept & continue.
- Was not at this step on S9 - The device should now start to update.
- Tap Install to begin configuring your work apps.
- You will see a screen like the following as this installs, once the next button appears, tap this to continue. (When complete, you may need to tap Done)
- Tap Set up under Register your device. (If prompted)
- Tap Next to register your device.
- This may take a few moments to complete, once it is complete you will see a Next button appear at the bottom of the screen. Tap Next to categorize your device. (I saw a done button)
- Select CQC Corporate Owned Mobile Device, then tap OK.
- Tap Done to complete the process.
- Once this is complete you will be taken to a screen like the following. If you aren't connected to WiFi automatically, connect to WiFi. At this point your phone is configured, but your apps may still be installing. It is recommended that you wait about five minutes before using the phone.
-
- You may see a screen like the following as your device is updated with the initial settings.
-
-
If you would like to check the status of the installation, tap the Google play icon, to be taken to a screen like the following which will show the installation progress.
-
- The device will now be enrolled and policies will be pushed to the device This will take several minutes. During this time you may be able to complete some of the steps below in the Manual Configuration Section.
- Once this is done you should see a message to grant notification permission, tap grant. (If necessary tap "Got it" to dismiss the instructions at the bottom)
- Tap managed home screen
- Tap Allow
- You should now be taken to a sign in screen.
- Tap sign in
- Tap the back button to return to the main screen.
- Once this is complete, restart your phone to complete the setup.
- Open Teams and sign in.
- Enter the username, then tap Next. (The username is in the format cap-loc-name@cqc.com; for example cap-sps-sup1@cqc.com)
- Enter the password from the database (Under Common Area Phones), then tap Sign In.
- Your device will be updated and begin to sign you in.
- If you did not complete the Manual Configuration, you may do so now.
Manual Configuration
Once you are taken to a limited screen with just managed settings, perform the following steps to configured the phone.
- Tap managed settings.
- Tap the i
- Tap exit Kiosk
- Enter the pin
- Tap settings
- search for side key, tap side key.
- Change Press and hold to power off menu
- tap back, then search for screen timeout.
- Set this to 10 minutes.
- tap back then look for never sleeping apps
- tap never sleeping apps
- Tap the plus
- select teams
- tap add
- Search for "Appear on Top" then add Teams
- You may also be able to find this under the app properties.
- On older phones this may be listed as overlay.
- On Android 12 you need to open apps, then click the menu, then choose special access.
- You may also want to setup a weekly reboot.
- return to the app list.
- Tap managed home screen
- Locate and open the Host app to open Teamviewer.
- You will be prompted to enable the universal add on, tap enable.
- This will open accessibility.
- Tap on universal add on.
- Turn on universal add on , if prompted to allow, tap allow. You do not need to add the shortcut.
- You will then prompted for display over the top of other apps
- Tap settings
- Locate Host
- Select the slider to allow display over apps.
- Tap back to return to the previous screen.
- Open teams
- The phone is now ready to use.
Update Information in Endpoint manager
- Locate the device in endpoint manager.
- Typically this is the most recently enrolled device
- On the device you can find the current device name by opening Managed Settings. Then tapping on the i to bring up device information.
- Click properties, then rename.
- The name should be in the format "cap-loc-name_AzureADSharedMode_Date"
- For example cap-sps-ndd3_AzureADSharedMode_8/30/2022_5:16 PM
- Choose a device Category.
- Enter any relevant notes.
- Click Save.
- Note: You may need to refresh the page for the new name to be displayed.
Intune Setup
Note: The managed home screen is not configured to allow sign in because due to an undocumented change by Microsoft, using this method will cause the phone to become logged out any time the phone crashes or is restarted.
Devices are grouped using the dynamic group EMM_AAD-TeamsMobilePhone (There is a test group that can be used EMM_Test_AAD_Managed_HomeScreenSettings)
The enrollment barcode is configured as AAD Teams Portable Phone
Device Configuration - AAD Teams Portable Phone - Device Restrictions
App Configuration - AAD Teams Portable Phone - Managed Home Screen Settings
This requires the following apps to be deployed: Managed home screen and Teams
Troubleshooting
Strange Boot Screen
In the unlikely event that you encounter a screen similar to the following when you first power on the phone, please press and hold the side button and the volume down button until the phone restarts (about 7 seconds).
If Teams is acting strangely, or does not open at all, you may want to try re-installing Teams. This can be done by doing the following.
- Identify the serial number of the device.
- It may be necessary to unlock the device to find this.
- Locate the device in Endpoint Manager.
- Make note of the device name.
- Add the device to the sg-Uninstall-Teams in Azure Active Directory, then wait for the app to uninstall.
- You can sometimes speed up this process by initiating a reboot in Endpoint Manager.
- Once you have confirmed that Teams is removed, reboot the device again to ensure all cache is removed.
- Remove the device from the sg-Uninstall-Teams group in Azure Active Directory.
- Once you have confirmed that Teams is installed, reboot the device again to ensure a fresh start.
- Verify that Teams is working properly
- Re-configure Android settings for Teams.
- Tap managed settings.
- Tap the i
- Tap exit Kiosk
- Enter the pin
- Tap settings
- search for never sleeping apps
- tap never sleeping apps
- Tap the plus
- select teams
- tap add
- Search for "Appear on Top" then add Teams
- You may also be able to find this under the app properties.
- On older phones this may be listed as overlay.
- On Android 12 you need to open apps, then click the menu, then choose special access.
- return to the app list.
- Tap managed home screen
Chat not available in Teams
So far this has only happened on one phone, however it's possible that this change may need to happen for all WiFi phones using a generec account.. It appears that Microsoft may be tightening up the licensing for the Common Area Phone license so that devices with this license can only use phone and meeting functionality and not chat.
This may look similar to the following.
To fix this do the following.
- replace the Shared Device License with an F3 license and a Microsoft Teams Phone Standard license.
- Note you may need to temporarily assign an E5 license because you will be lowering the level of some licenses.
- Reboot the phone.
- If after rebooting the phone does not update, it may be necessary to sign out the account.
- Tap managed settings.
- Tap the i
- Tap exit Kiosk
- Enter the pin
- Tap settings
- Open Accounts
- Remove the account for the user.
- Reboot the phone.
- Sign into Teams with the user account.