Managing Android devices using Microsoft Intune
The message indicates that Intune app protection policies (MAM) in the Android work profile do not allow any managed app to receive the work/school data being opened from Udemy via Microsoft Edge.
In an Android work profile, users can share or open work data only between apps that are installed in the work profile and are allowed by Intune policies. Outside the work profile, this restriction does not apply, which is why SSO works there.
To resolve this, an Intune administrator needs to:
- Verify that Udemy and Microsoft Edge are both installed inside the Android work profile (managed Google Play) and not only in the personal profile.
- Check the Android app protection policy (MAM) assigned to the user:
- Ensure the policy targets Udemy (if it is MAM-enabled) and Microsoft Edge as managed apps.
- Under data transfer settings, make sure at least one other managed app is allowed to open or receive this type of content.
- If necessary, create or update an app protection policy so that Edge (and any other required app) is included as an allowed receiving app for work/school data.
- After policy changes, have the user refresh policies (open Company Portal in the work profile, sync, then retry sign-in from Udemy).
If no suitable managed app can be configured to open the content, SSO via the work profile will continue to fail with this message and the organization’s Intune admin must adjust the policy design.
References: