Configuration Profiles (Android)
Intune MDM (mobile device management) applies configuration to Android devices that can:
- Require a passcode or password on your device
- Remotely lock your device if you lose it, a benefit of using a passcode with your device
- Remove Stanford data from your device if it is lost or stolen, or when you leave Stanford
- Automatically configure the Stanford Wi-Fi network
- Detect whether a device has been rooted, and block rooted devices
- Require encryption of device storage
- Keep Stanford (work) data separate from your personal data
The work profile: what Stanford can and cannot manage
Personally owned and corporate owned Android devices enroll using an Android Enterprise work profile. The work profile is a separate, badged container on your device: work apps appear with a briefcase badge and are managed by Stanford.
Stanford manages only the work profile. Stanford cannot see or manage your personal apps, photos, messages, browsing, or files. Removing management (by you or by Stanford) removes the work profile and its data, and leaves everything personal untouched. For Microsoft's own reference, see Intune discovered apps.
On Stanford owned devices we also collect the following addition information from these categories:
- Battery
- Cellular
- Device Storage
- Network Adapters
- OS Version
- Sim Info
- System Info
List of Stanford University-managed configurations (as of July 2026)
| Profile / policy | What it does |
|---|---|
| [SU] Android Stanford Wi-Fi | Automatically connects your device to the Stanford Wi-Fi network (SSID: Stanford; open network, not hidden). Uses the device MAC address rather than a randomized one, so your device can be registered on the network. |
| Google App Access | Configures work profile settings: blocks copy-and-paste between work and personal profiles, allows adding and removing accounts (all account types), and configures a custom VPN client for work apps. |
Descriptions are intentionally high-level; specific settings are tuned over time. If you have a question about a specific setting, please submit a Help request.
Passcode and device requirements
The SU ADE Android Compliance policy checks that managed Android devices meet the following requirements:
| Feature | Requirement |
|---|---|
| Rooted devices | Blocked |
| Minimum Android version | 12 |
| Encryption of data storage on the device | Required |
| Password to unlock the device | Required (at least numeric, minimum length 4) |
| Password expiration | 365 days |
| Maximum inactivity before password is required | 5 minutes |
If your existing passcode already meets these requirements, for example if it is longer than the minimum, it is retained after enrollment.
How to view the management applied to your Android device
- Work profile apps appear with a briefcase badge.
- Navigate to Settings > Security & privacy > Device admin apps, or Settings > Accounts > Work (paths vary by manufacturer and Android version).
- Open the Company Portal or Microsoft Intune app to see what is managed and your compliance status.
Questions?
If you have questions, suggestions, or feedback, please submit a Help request.
