The Chromebook App Filter (also known as the Filter for Android outside the US) provides real-time filtering and seamlessly integrates with Linewize Filter to consistently apply your policies. If your school uses single-user devices, you can use this article to deploy the Chromebook App Filter.
Important
Progressive Web Apps (PWAs) can be filtered when the Connect for Chrome extension is also deployed. Without the extension, PWAs run directly on Chrome OS and can’t be filtered by the Chromebook App Filter (Filter for Android) alone.
Before you begin
- Ensure you have managed devices.
- Your devices must meet the Qoria Filter minimum system requirements.
1. Create a certificate
- Sign in to Linewize Filter.
- Go to Configuration > Self Service Certificates.
- Complete the required fields:
- Country (C): Select a country from the list.
- State/Province (ST): Enter your state.
- Locality (L): Enter your city.
- Organisation (O): Enter your school’s name.
- Common Name (CN): Enter your school’s domain name.
- Key size (bits): Select a key size, or use the default. Larger keys provide stronger security.
- Validity for (days): Enter the number of days the certificate remains valid. We recommend rotating certificates every two years.
- Select Generate.
- Copy the Signing Certificate and Signing Certificate Key for use in the next step.
- The certificate downloads automatically.
2. Add the Qoria Filter app
- Sign in to Microsoft Intune Admin Center.
- Go to Apps > Android, select Add.
- Under App Type, select Managed Google Play App from the dropdown.
-
Search for and select Qoria Filter
Tip
If you can’t see the app, search for com.qoria.uc.android.edu instead.
- Select Sync in the App pane to sync with the Managed Google Play service.
- Go to Apps > Android, select Qoria Filter from the list.
- Go to Properties > Edit.
- Select Add group, select the User group checkbox, then click Select.
- Review the settings before selecting Create.
3. Create an app configuration policy
- In Microsoft Intune Admin Center.
- Go to Apps > Configuration.
- Select Create > Managed Devices.
- In the Basics step:
- Add a Name for the profile.
- For Platform, select Android Enterprise.
- For Profile Type, select Fully Managed, Dedicated and Corporate-Owned Work Profile Only.
- For Targeted app, select Qoria Filter.
- Select Next.
- In the Settings step:
- For Configuration settings format, select Use configuration designer.
-
From the list of available configuration keys, select only the keys that contain Linewize in the name, as well as Hardware Id, then select OK.
Note
Linewize Bypass Domains, Linewize Additional Device IDs, and Linewize Device Mac are optional and are not required for a valid configuration.
- Configure the selected settings as follows:
-
Linewize App Mode
- Select Android_Companion from the dropdown.
-
Linewize Device Identifier
- Enter the Linewize Filter Device ID that the device will register with.
-
Linewize Device Name
- Enter the Linewize Filter Device Name.
-
Linewize Region
- Select the region where your Linewize Filter is hosted:
syd-1 – US/NZ Region
syd-2 – AU Region
uk-1 – European Region
- Select the region where your Linewize Filter is hosted:
-
Linewize User Name
- For domain-joined devices, select variable as the value type and choose UserName.
- For non-domain-joined devices, select string and enter a manual username or email address.
-
Linewize Auth Secret
- Enter the preshared key from your Linewize Filter configuration. Go to Configuration > Agent Downloads and select Copy Preshared Key.
-
(Optional) Linewize Additional Device Identifiers
- If you have Linewize Filter Appliances, enter any Linewize Filter Device ID that are not the primary one.
- Hardware Id
- Select variable as the value type and choose Intune Device ID or
-
Select string and enter a custom identifier.
Note
The Hardware Id can be any value and is primarily used as a device identifier.
- Enter the Signing Certificate value, the first field created during the Create a certificate step.
- Enter the Signing Certificate Key, the second field created during the Create a certificate step.
-
Linewize App Mode
- In the Assignments step:
- Select Add groups and assign the required device or user groups.
- Review the configuration, then select Review + Create.
- Select Create to add the App Configuration Profile to Intune.
4. Add a trusted certificate
- Go to Devices > Android devices > Configuration.
- Select Create > New Policy.
- For Platform, select Android Enterprise.
- For Profile type, select Trusted certificate.
- Select Create.
- In the Basics step:
- Add a name for the certificate.
- (Optional) Add a description.
- Select Next.
- In the Configuration settings step:
- Upload the certificate file downloaded during Create a certificate.
- In the Assignments step:
- Select Add groups, then select the required user or device group.
- Review the settings before selecting Create.
5. Create an always-on VPN policy
- Go to Devices > Android devices > Configuration.
- Select Create > New Policy.
- For Platform, select Android Enterprise.
- For Profile type, select Device Restrictions.
- Select Create.
- In the Basics step:
- Add a name for the profile.
- Select Next.
- In the Configuration settings step:
- Select the Connectivity dropdown.
- For Always-on VPN (work profile-level), select Enable.
- For VPN Client, select Custom.
- For Package ID, enter com.qoria.uc.android.edu
- Turn Lockdown mode turned on.
- Select Next.
- In the Assignments step:
- Select Add groups, then select the required user or device group.
- Review the settings before selecting Create.
Note
You must restart the device for the Always-On VPN policy to take effect.