Passbeam

Does Passbeam work with Android?

Yes. The Intune step generates profiles for both Android Enterprise deployment modes alongside Windows, iOS and macOS — Fully Managed, Dedicated and Corporate-Owned Work Profile for company-owned handsets, and Personally-Owned Work Profile for BYOD. They appear on the same page as the others, with the same SCEP and Wi-Fi settings.

The two modes are separate profiles in Intune rather than one profile with a switch, and picking the wrong one is the mistake to avoid: a Personally-Owned Work Profile SCEP profile deploys to nothing on a fully managed device, and the other way round. Passbeam names the exact profile type to choose for each.

Two Android-specific things the walkthrough calls out, because they cost time otherwise. On fully managed and dedicated devices, certificate access defaults to asking the user to approve every use — which on a kiosk means nobody is there to approve it and the certificate is never used, so the Apps step has to grant it silently. And a dedicated device has no user at all, so it needs a device certificate rather than a user one; a user certificate's {{UserPrincipalName}} has nothing to expand to and the profile simply fails to install.

One thing that reads as a problem and is not: Intune cannot revoke a certificate issued through a device-owner profile. Offboarding is unaffected, because Passbeam revokes at its own certificate authority and the connection is refused on the next authentication regardless of what Intune can and cannot withdraw.

On another MDM, the enrolment challenge works the same way on Android as on any other platform, provided the MDM can deliver a SCEP certificate to the handset.

If you hit something on a particular handset or Android version, raise a ticket with the model and the profile you deployed — that is the fastest way to get it looked at properly.

Related questions

Still stuck? Ask us, or read the rest of the knowledge base.