如何为集成Intune SDK的Android应用添加系统应用权限
Got it, let's walk through exactly how to add these two permissions to your Android app for Intune SDK integration. It's a straightforward process, so let's break it down step by step:
Step 1: Declare Permissions in AndroidManifest.xml
The core change happens in your app's AndroidManifest.xml file (found under app/src/main/ in your Android Studio project).
Open the file, and inside the root <manifest> tag (but outside the <application> tag), add these two permission declarations:
<uses-permission android:name="android.permission.MANAGE_ACCOUNTS" /> <uses-permission android:name="android.permission.USE_CREDENTIALS" />
Important note: These are normal protection level permissions, meaning the Android system automatically grants them when your app is installed. Unlike GET_ACCOUNTS (which requires runtime requests on Android 6.0+), you don't need to prompt users to approve these two permissions manually.
Step 2: Verify Permission Status (Optional but Recommended)
While auto-granted, it's smart to confirm these permissions are active before relying on them (to handle edge cases like system-level restrictions). You can use the checkSelfPermission() method to verify:
Kotlin Example:
import android.content.Context import android.content.pm.PackageManager import androidx.core.content.ContextCompat fun checkIntunePermissions(context: Context): Pair<Boolean, Boolean> { val hasManageAccounts = ContextCompat.checkSelfPermission( context, android.Manifest.permission.MANAGE_ACCOUNTS ) == PackageManager.PERMISSION_GRANTED val hasUseCredentials = ContextCompat.checkSelfPermission( context, android.Manifest.permission.USE_CREDENTIALS ) == PackageManager.PERMISSION_GRANTED return Pair(hasManageAccounts, hasUseCredentials) }
Java Example:
import android.content.Context; import android.content.pm.PackageManager; import androidx.core.content.ContextCompat; public class PermissionChecker { public static boolean[] checkIntunePermissions(Context context) { boolean hasManageAccounts = ContextCompat.checkSelfPermission( context, android.Manifest.permission.MANAGE_ACCOUNTS ) == PackageManager.PERMISSION_GRANTED; boolean hasUseCredentials = ContextCompat.checkSelfPermission( context, android.Manifest.permission.USE_CREDENTIALS ) == PackageManager.PERMISSION_GRANTED; return new boolean[]{hasManageAccounts, hasUseCredentials}; } }
If either permission is unexpectedly denied, you can prompt users to check their app settings to re-enable them—though this scenario is rare for normal permissions.
Key Additional Notes
- Don't forget about
GET_ACCOUNTS: On Android 6.0 (API 23) to Android 10 (API 29), this is a dangerous permission that requires runtime requests. On Android 11+, this permission is deprecated, so follow Intune's latest documentation for alternative account access methods. - If the Company Portal proxy authentication flow stops working, double-check that all three required permissions are correctly declared and granted. Revocation of any of them will disable the flow as noted in your documentation.
内容的提问来源于stack exchange,提问作者Pallav Singh

