<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Android Enrollment Question in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438033#M12301</link>
    <description>&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-05-13 at 11.49.15.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263920i85EB5FFB3E6F7ED0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Have you tested with the &lt;STRONG&gt;Email Domain name&lt;/STRONG&gt; (&lt;STRONG&gt;Systems Manager &amp;gt; General &amp;gt; End User authentication settings)&lt;/STRONG&gt; to manipulate the domain (ie: getting the &lt;EM&gt;username&lt;/EM&gt; from AD and then adding &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;acme.com to the end)?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 13 May 2024 10:50:45 GMT</pubDate>
    <dc:creator>Arthur Dent</dc:creator>
    <dc:date>2024-05-13T10:50:45Z</dc:date>
    <item>
      <title>Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438029#M12297</link>
      <description>&lt;P&gt;We recently setup AD integration on an MX for the purpose of enrolling a user's BYOD Android device.  We can make it work, but, the issue we run into is this:  When we create Android configuration setting, we can ONLY get it to work if we use the "Owner Email" and "Owner Username" as the values for their respective keys.  &lt;/P&gt;&lt;P&gt;&lt;BR /&gt;The problem with that is that the AD sync process only sets the user name as &lt;EM&gt;&lt;A href="mailto:username@domain.com" target="_blank" rel="nofollow noopener noreferrer"&gt;username@domain.com&lt;/A&gt;&lt;/EM&gt; which is replicated as the email address.  Unfortunately, we use&lt;EM&gt; &lt;A href="mailto:firstname.lastname@domain.com" target="_blank" rel="nofollow noopener noreferrer"&gt;firstname.lastname@domain.com&lt;/A&gt; &lt;/EM&gt;as our email address format.  Further, to successfully login, the user name must be in the format of &lt;EM&gt;domain\username &lt;/EM&gt;which is not what the AD sync sets as the owner username.&lt;/P&gt;&lt;P&gt;We tried using setting the key value type to TXT and using variables of $emailaddress$ and $username$ as the instructions indicated was possible but, either we did it wrong or it just doesn't work as designed.&lt;/P&gt;&lt;P&gt;At this point, we're stuck with having to manually adjust the owner information to get Androids to work.  iOS devices do not have this issue as you can set the domain information in the apple mail settings profile.&lt;/P&gt;&lt;P&gt;Any ideas/guidance would be appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 14:40:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438029#M12297</guid>
      <dc:creator>mrjrtykr</dc:creator>
      <dc:date>2024-05-08T14:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438030#M12298</link>
      <description>&lt;P&gt;I don't understand what the MX has to do with in this process.&lt;/P&gt;&lt;P&gt;The MDM users whatever Enatra ID wants to use for a username.  I don't understand wy you couldn't use  firstname.lastname@domain.com on the Android device.&lt;/P&gt;&lt;P&gt;What login screen is the user trying to log into?&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 21:28:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438030#M12298</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-05-08T21:28:16Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438031#M12299</link>
      <description>&lt;P&gt;Hold on - I think I am starting to understand.  You are actually authenticating directly against AD.&lt;/P&gt;&lt;P&gt;Could you authenticate against Entra ID instead?  Do you have Office 365?  That is probably an easier way to go.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 21:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438031#M12299</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2024-05-08T21:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438032#M12300</link>
      <description>&lt;P&gt;Thanks for the replies.  We're an on-prem Exchange shop at the moment.  And the only login option we see when the user launches the Meraki Systems Manager app is username and password.&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 21:33:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438032#M12300</guid>
      <dc:creator>mrjrtykr</dc:creator>
      <dc:date>2024-05-08T21:33:27Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438033#M12301</link>
      <description>&lt;P&gt;&lt;SPAN class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-05-13 at 11.49.15.png" style="width: 400px;"&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="image.png"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/263920i85EB5FFB3E6F7ED0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Have you tested with the &lt;STRONG&gt;Email Domain name&lt;/STRONG&gt; (&lt;STRONG&gt;Systems Manager &amp;gt; General &amp;gt; End User authentication settings)&lt;/STRONG&gt; to manipulate the domain (ie: getting the &lt;EM&gt;username&lt;/EM&gt; from AD and then adding &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;acme.com to the end)?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 10:50:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438033#M12301</guid>
      <dc:creator>Arthur Dent</dc:creator>
      <dc:date>2024-05-13T10:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438034#M12302</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/25577"&gt;@Arthur Dent&lt;/A&gt; &lt;/P&gt;&lt;P&gt;That is exactly how we have it configured.  Unfortunately, it sets the email address as &lt;EM&gt;&lt;A href="mailto:username@hattiesburgclinic.com" target="_blank" rel="nofollow noopener noreferrer"&gt;username@hattiesburgclinic.com&lt;/A&gt; &lt;/EM&gt;and the username is set to &lt;EM&gt;username@hattiesburgclinic.com&lt;/EM&gt;.  Our email address is based on &lt;EM&gt;&lt;A href="mailto:firstName.LastName@hattiesburgclinic.com" target="_blank" rel="nofollow noopener noreferrer"&gt;firstName.LastName@hattiesburgclinic.com&lt;/A&gt; &lt;/EM&gt;and the for the authentication to work, the username must be formated as hbclinic\&lt;EM&gt;username.&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 14:31:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438034#M12302</guid>
      <dc:creator>mrjrtykr</dc:creator>
      <dc:date>2024-05-13T14:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Android Enrollment Question</title>
      <link>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438035#M12303</link>
      <description>&lt;P&gt;&lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/25577"&gt;@Arthur Dent&lt;/A&gt; If this setup is actually supposed to pull in what we need, then we either have something misconfigured, or something is broken.&lt;/P&gt;</description>
      <pubDate>Mon, 13 May 2024 14:33:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/android-enrollment-question/m-p/5438035#M12303</guid>
      <dc:creator>mrjrtykr</dc:creator>
      <dc:date>2024-05-13T14:33:02Z</dc:date>
    </item>
  </channel>
</rss>

