The Chromebook App Filter provides real-time filtering and seamlessly integrates with Linewize Filter, ensuring your policies are consistently applied. This article outlines the steps to install the Chromebook App Filter on devices used by a single user managed by Microsoft Intune.
Alternatively, see how to install the Chromebook App Filter on devices in Shared Device Mode (SDM).
Important
The Chromebook App Filter can’t filter Progressive Web Apps (PWAs) because they run on Chrome OS rather than Android OS.
Before you begin
- Ensure you have managed devices.
- Your devices must meet the Qoria Filter minimum system requirements.
1. Add the Qoria Filter app
- Sign in to Microsoft Intune Admin Center.
- Go to Apps > Android, select Add.
- Under App Type, select Managed Google Play App from the dropdown.
- Search for and select Qoria Filter Tip: If you can’t see the app, search for com.qoria.uc.android.edu instead.
- Select Sync in the App pane to sync with the Managed Google Play service.
- Go to Apps > Android, select Qoria Filter from the list.
- Go to Properties > Edit.
- Select Add group, select the User group checkbox, then click Select.
- Review the settings before selecting Create.
2. Create a certificate
- Sign in to Linewize Filter.
- Go to Configuration > Self Service Certificates.
- Complete the required fields:
- Country (C): Select a country from the list.
- State/Province (ST): Enter your state.
- Locality (L): Enter your city.
- Organisation (O): Enter your school’s name.
- Common Name (CN): Enter your school’s domain name.
- Key size (bits): Select a key size, or use the default. Larger keys provide stronger security.
- Validity for (days): Enter the number of days the certificate remains valid. We recommend rotating certificates every two years.
- Select Generate.
- Copy the Signing Certificate and Signing Certificate Key for use in the next step.
- The certificate downloads automatically.
3. Create an app configuration policy
- In Microsoft Intune Admin Center.
- Go to Apps > Configuration.
- Select Create > Managed Devices.
- In the Basics step:
- Add a Name for the profile.
- For Platform, select Android Enterprise.
- For Profile Type, select Fully Managed, Dedicated and Corporate-Owned Work Profile Only.
- For Targeted app, select Qoria Filter.
- Select Next.
- In the Settings step:
- For Configuration settings format, select Use configuration designer.
- From the list of available configuration keys, select only the keys that contain Linewize in the name, as well as Hardware Id, then select OK. Note: Linewize Bypass Domains, Linewize Additional Device IDs, and Linewize Device Mac are optional and are not required for a valid configuration.
- Configure the selected settings as follows:
-
Linewize App Mode
- Select Android_Companion from the dropdown.
-
Linewize Device Identifier
- Enter the Linewize Filter Device ID that the device will register with.
-
Linewize Device Name
- Enter the Linewize Filter Device Name.
-
Linewize Region
- Select the region where your Linewize Filter is hosted:
syd-1 – US/NZ Region
syd-2 – AU Region
uk-1 – European Region
- Select the region where your Linewize Filter is hosted:
-
Linewize User Name
- For domain-joined devices, select variable as the value type and choose UserName.
- For non-domain-joined devices, select string and enter a manual username or email address.
-
Linewize Auth Secret
- Enter the preshared key from your Linewize Filter configuration. Go to Configuration > Agent Downloads and select Copy Preshared Key.
-
(Optional) Linewize Additional Device Identifiers
- If you have Linewize Filter Appliances, enter any Linewize Filter Device ID that are not the primary one.
- Hardware Id
- Select variable as the value type and choose Intune Device ID or
- Select string and enter a custom identifier. Note: The Hardware Id can be any value and is primarily used as a device identifier.
-
Linewize App Mode
- In the Assignments step:
- Select Add groups and assign the required device or user groups.
- Review the configuration, then select Review + Create.
- Select Create to add the App Configuration Profile to Intune.
4. Add a trusted certificate
- Go to Devices > Android devices > Configuration.
- Select Create > New Policy.
- For Platform, select Android Enterprise.
- For Profile type, select Trusted certificate.
- Select Create.
- In the Basics step:
- Add a name for the certificate.
- (Optional) Add a description.
- Select Next.
- In the Configuration settings step:
- Upload the certificate file downloaded during Create a certificate.
- In the Assignments step:
- Select Add groups, then select the required user or device group.
- Review the settings before selecting Create.
5. Create an always-on VPN policy
- Go to Devices > Android devices > Configuration.
- Select Create > New Policy.
- For Platform, select Android Enterprise.
- For Profile type, select Device Restrictions.
- Select Create.
- In the Basics step:
- Add a name for the profile.
- Select Next.
- In the Configuration settings step:
- Select the Connectivity dropdown.
- For Always-on VPN (work profile-level), select Enable.
- For VPN Client, select Custom.
- For Package ID, enter com.qoria.uc.android.edu
- Leave Lockdown mode turned off.
- Select Next.
- In the Assignments step:
- Select Add groups, then select the required user or device group.
-
Review the settings before selecting Create.
Note
You must restart the device for the Always-On VPN policy to take effect.