Creating an App Configuration Policy

An App Configuration policy is required to link the SCEP certificate profile to the Mobile Security Protect app on Android devices. This section describes the procedure to create an App Configuration policy for Android devices in Microsoft Intune Admin Center.

Note:
Use this procedure only if you do not already have an App Configuration policy configured in Microsoft Intune. If an App Configuration policy already exists, do not create a new policy profile. Instead, modify the existing policy by following the procedure in Configuring the Application Configuration Settings and add the Certificate Alias property to the existing policy.
  1. Log in to Microsoft Intune Admin Center.
  2. Go to Apps > Manage Apps and click Configuration.

  3. Click Create > Managed devices.

  4. In the Basic tab:
    1. Enter a name for the policy.
    2. Select Platform as Android Enterprise.
    3. Select Profile Type as Personally-Owned Work Profile Only.
    4. In Targeted app, click Select app and select Mobile Security Protect on the right-side window.
    5. Click OK.
    6. Click Next.

  5. In the Settings tab:
    1. Under Configuration Settings, select Configuration settings format as Use Configuration Designer.

    2. Click Add.
    3. On the right-side window, select the Certificate Alias key and click OK.

    4. For the certificate alias key:
      1. Select Value type as Certificate.
      2. In Configuration value, select your SCEP certificate profile.

    5. Click Next.
  6. Go to the Assignments tab and in the Included groups section, click Add groups.
  7. Search and select the groups that you want to include.
  8. Click Next.
  9. Review the details and click Create.
Continue with Configuring Netskope Integration in Mobile Security Administrator Portal.