# Deployment Android MDM - Managed Device

Implement SCA for your devices managed with Microsoft Endpoint Manager.\
Our App can be deployed automatically via Managed Google Play Store.

### Deploy SCA as Managed Google Play Store App <a href="#vpp-app-volume-purchase-program" id="vpp-app-volume-purchase-program"></a>

SCA is available for Managed Google Play Store.

You can deploy SCA through Microsoft Intune to your Android Enterprise devices via Managed Google Play Store.\
\
&#x20;

Managed Google Play, organizations can create and manage their own app catalog, set access controls and permissions, and enforce security policies for the apps they distribute.&#x20;

Your third-party MDM solution, must have a Google Account to access the Managed Google Play console, in order to deploy SCA to your managed devices.

1. Change to [iOS/iPadOS apps - Microsoft Intune admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsIosMenu/~/iosApps)
2. On the list of apps pane, **Secure Contacts** appears as a Apple Volume Purchase Program (VPP) app, select the app

Hint: Alternatively use this link to go directly to [Managed Google Play Console](https://endpoint.microsoft.com/#view/Microsoft_Intune_Apps/ManagedGoogleAppApprovalConsole) in Intune.

3. Search for "Provectus Secure Contacts" in your Google Play Console.
4. Click **Approve.**

<div align="left"><figure><img src="https://3880789596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4v109br9tFl1Rxk2qP0x%2Fuploads%2Fj1IxeK6jb7ajgCGquIG9%2Fimage.png?alt=media&#x26;token=b628b7aa-d061-4015-8ce3-0dc822073f29" alt="" width="563"><figcaption></figcaption></figure></div>

5. Click **Approve**, in order to accept app-permissions for SCA.

<div align="left"><figure><img src="https://3880789596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4v109br9tFl1Rxk2qP0x%2Fuploads%2FS2q4aQiUgxXtvV22Y9Er%2Fimage.png?alt=media&#x26;token=9aa3a8c2-cd9f-4a46-9c67-969f736e5d25" alt="" width="339"><figcaption></figcaption></figure></div>

6. Click on Done, to finish the setup the setup in Managed Google Play.

<div align="left"><figure><img src="https://3880789596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4v109br9tFl1Rxk2qP0x%2Fuploads%2FHDnaBTzLNiMVprCceFKG%2Fimage.png?alt=media&#x26;token=e499f726-6e3f-4d84-9828-e786b36848bc" alt="" width="375"><figcaption></figcaption></figure></div>

7. Next step, you need to sync Managed Google Play:\
   \
   Select **Tenant administration** > **Connectors and tokens** > **Managed Google Play**.<br>
8. In the **Managed Google Play** pane, choose **Sync**. The page updates the time and status of the last sync.
9. Change to Apps > Android&#x20;
10. On the list of apps pane, **Secure Contacts** appears as Managed Google Play store app, select the app.
11. Choose **Properties**. Go to Assignments and click on **Edit**&#x20;
12. On the Assignments tab, choose whether the app will be **Required** or **Available for enrolled devices**
13. Choose **Add group** under the assignment type you've selected and add your SCA test-group
14. Click on **Review + save** and on the next pane **Save**

### App Configuration Policy <a href="#app-configuration-policy" id="app-configuration-policy"></a>

It is mandatory to configure an App Configuration Policy for SCA to your managed devices

1. Login to Endpoint Manager with your Admin-Account
2. Go to Apps → App configuration policies or follow this link:\
   [App configuration policies - Microsoft Endpoint Manager admin center](https://endpoint.microsoft.com/#view/Microsoft_Intune_DeviceSettings/AppsMenu/~/appConfig)
3. Click on **Add** -> **Managed** **devices**<br>

   <div align="left"><figure><img src="https://3880789596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4v109br9tFl1Rxk2qP0x%2Fuploads%2F651GGiiqqrKvH880ZXue%2Fimage.png?alt=media&#x26;token=a5048445-122a-4c22-89e7-fe1364a0e839" alt=""><figcaption></figcaption></figure></div>
4. Enter a **Name** for App configuration policy e.g. “Secure Contacts App Configuration Managed”
5. Select as **Plattform** "Android Enterprise"&#x20;
6. Select as **Profile Type** the Profile for your testdevice e.g. "Fully Managed, Dedicated, and Corporate-Owned Work Profile Only"
7. Select as **Targeted app** "Provectus Secure Contacts"

<figure><img src="https://3880789596-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F4v109br9tFl1Rxk2qP0x%2Fuploads%2FmPW9yVr10ED9XBqmaHtX%2Fimage.png?alt=media&#x26;token=ff9ebefe-661e-4de0-a01f-3b08a69d901a" alt=""><figcaption></figcaption></figure>

8. Click on **Next**
9. In the Settings pane, choose for *Configuration settings format* - **Use configuration designer**
10. A full list of all configuration values can be found in the documentation: [AppConfigurationPolicy Name-Values for SCA](#app-configuration-policy)
11. Click on **Next**
12. **Add group** at *Included groups* in the Assignments-pane, choose your SCA test-group with **Select**.
13. Click on **Next** after adding SCA test-group
14. In the *Review + create* pane click on **Create**

&#x20;

### &#x20;<a href="#conditional-access-policy" id="conditional-access-policy"></a>
