This post has been republished via RSS; it originally appeared at: Microsoft Tech Community - Latest Blogs - .
Microsoft Intune was recently alerted to an issue for Samsung devices enrolled with a work profile that, after updating to Android 12, some email and VPN applications are losing access to certificates when the user tries to access them (such as Gmail and AnyConnect VPN). The missing certificates prevent users from being able to access their email on Gmail and VPN apps. We are working closely with Samsung to resolve this issue but wanted to share temporary workarounds to help users access their VPN apps. We’ll update this post as more information becomes available.
AnyConnect VPN
Users attempting to use the AnyConnect VPN app will see a prompt from the app suggesting that the client certificate needed to make the connection could not be found and a valid certificate should be chosen. This issue can be addressed by clearing out the app data cache.
- Go to Settings > Work Profile > Apps > AnyConnect VPN > Storage > Clear Data.
- Upon opening AnyConnect VPN again, the app will request the certificates again in a popup prompt.
- Select the certificate to fix the problem.
Gmail
Users attempting to access Gmail on their device are prompted to select a certificate when accessing Gmail and then see a “Can’t reach server” message after selecting the appropriate certificate. In this scenario, there are two different approaches you can use to work around the issue; one is on the device and the other option is through IT administrator action.
Option 1: On a device - Remove and reinstall the work profile and Company Portal
- Open the Company Portal app> Menu > tap Remove Company Portal.
- Open Google Play app > select the Intune Company Portal app > Uninstall the app.
- In Google Play, Install the Intune Company Portal app.
- Open and sign into the Company Portal.
- Gmail in the work profile now works as expected.
Option 2 (IT administrators only): Remove and re-add the Gmail device configuration
- In the Microsoft Endpoint Manager admin center, create an exclusion group for the Gmail app.
-
Add the user(s) to the exclusion group.
-
Sync the policy on the Android device.
-
Confirm Gmail is removed from the device.
-
Remove the user from the exclusion group.
-
Confirm Gmail is added to the device.
-
Gmail in the work profile now works as expected.
