{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
        "slug": "dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/"
        },
        "title": "Preserve the OEMConfig schema context when investigating a changed setting",
        "summary": "Can Intune restore an older OEMConfig schema when an OEM app update changes its configuration behavior?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:24:36+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 242,
        "potentially_affected": "Use this investigation for Intune-enrolled Android Enterprise devices with a matching supported OEMConfig app. Confirm the particular manufacturer and application before interpreting a setting or contacting its support owner.",
        "dse_recommendation": "Capture the app and schema context with each approved configuration change.",
        "primary_source": {
            "name": "Use OEMConfig on Android Enterprise devices in Microsoft Intune - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune synchronizes the latest OEMConfig app from Google Play and does not retain older app or schema versions. The OEM controls the schema; Intune exposes it without validating or changing the schema itself. Microsoft directs schema errors and version conflicts to the OEM. The OEMConfig app, rather than Intune&#8217;s MDM agent, applies the device settings. <a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this investigation for Intune-enrolled Android Enterprise devices with a matching supported OEMConfig app. Confirm the particular manufacturer and application before interpreting a setting or contacting its support owner.</p>\n<h2>DSE recommendation</h2>\n<p>Capture the app and schema context with each approved configuration change. Retain the configured JSON and the OEM documentation used to interpret it. When behavior changes, compare the device&#8217;s actual app version and setting values with that record. Describe the affected property and expected behavior to the OEM instead of assuming Intune holds a previous schema ready for rollback. Keep any proposed app or policy change subject to the device owner&#8217;s change process.</p>\n<h2>Verification</h2>\n<p>On a representative approved device, inspect the effective property and its per-setting deployment result, then test the actual device behavior. Distinguish a saved profile from a correct OEM-defined value. If a schema or version problem remains, retain the smallest reproducible configuration and the observed app context for escalation. Do not invent an older schema or publish an untested configuration as a supported recovery path.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Use OEMConfig on Android Enterprise devices in Microsoft Intune</a>.</p>",
        "content_text": "Source facts\nIntune synchronizes the latest OEMConfig app from Google Play and does not retain older app or schema versions. The OEM controls the schema; Intune exposes it without validating or changing the schema itself. Microsoft directs schema errors and version conflicts to the OEM. The OEMConfig app, rather than Intune’s MDM agent, applies the device settings. Microsoft Learn.\nApplicability\nUse this investigation for Intune-enrolled Android Enterprise devices with a matching supported OEMConfig app. Confirm the particular manufacturer and application before interpreting a setting or contacting its support owner.\nDSE recommendation\nCapture the app and schema context with each approved configuration change. Retain the configured JSON and the OEM documentation used to interpret it. When behavior changes, compare the device’s actual app version and setting values with that record. Describe the affected property and expected behavior to the OEM instead of assuming Intune holds a previous schema ready for rollback. Keep any proposed app or policy change subject to the device owner’s change process.\nVerification\nOn a representative approved device, inspect the effective property and its per-setting deployment result, then test the actual device behavior. Distinguish a saved profile from a correct OEM-defined value. If a schema or version problem remains, retain the smallest reproducible configuration and the observed app context for escalation. Do not invent an older schema or publish an untested configuration as a supported recovery path.\nOfficial references\nMicrosoft Learn: Use OEMConfig on Android Enterprise devices in Microsoft Intune.",
        "content_markdown": "## Source facts\n\nIntune synchronizes the latest OEMConfig app from Google Play and does not retain older app or schema versions. The OEM controls the schema; Intune exposes it without validating or changing the schema itself. Microsoft directs schema errors and version conflicts to the OEM. The OEMConfig app, rather than Intune’s MDM agent, applies the device settings. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android).\n\n## Applicability\n\nUse this investigation for Intune-enrolled Android Enterprise devices with a matching supported OEMConfig app. Confirm the particular manufacturer and application before interpreting a setting or contacting its support owner.\n\n## DSE recommendation\n\nCapture the app and schema context with each approved configuration change. Retain the configured JSON and the OEM documentation used to interpret it. When behavior changes, compare the device’s actual app version and setting values with that record. Describe the affected property and expected behavior to the OEM instead of assuming Intune holds a previous schema ready for rollback. Keep any proposed app or policy change subject to the device owner’s change process.\n\n## Verification\n\nOn a representative approved device, inspect the effective property and its per-setting deployment result, then test the actual device behavior. Distinguish a saved profile from a correct OEM-defined value. If a schema or version problem remains, retain the smallest reproducible configuration and the observed app context for escalation. Do not invent an older schema or publish an untested configuration as a supported recovery path.\n\n## Official references\n\n[Microsoft Learn: Use OEMConfig on Android Enterprise devices in Microsoft Intune](https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Preserve the OEMConfig schema context when investigating a changed setting",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/",
                "headline": "Preserve the OEMConfig schema context when investigating a changed setting",
                "description": "Can Intune restore an older OEMConfig schema when an OEM app update changes its configuration behavior?",
                "abstract": "Can Intune restore an older OEMConfig schema when an OEM app update changes its configuration behavior?",
                "articleBody": "Source facts\nIntune synchronizes the latest OEMConfig app from Google Play and does not retain older app or schema versions. The OEM controls the schema; Intune exposes it without validating or changing the schema itself. Microsoft directs schema errors and version conflicts to the OEM. The OEMConfig app, rather than Intune’s MDM agent, applies the device settings. Microsoft Learn.\nApplicability\nUse this investigation for Intune-enrolled Android Enterprise devices with a matching supported OEMConfig app. Confirm the particular manufacturer and application before interpreting a setting or contacting its support owner.\nDSE recommendation\nCapture the app and schema context with each approved configuration change. Retain the configured JSON and the OEM documentation used to interpret it. When behavior changes, compare the device’s actual app version and setting values with that record. Describe the affected property and expected behavior to the OEM instead of assuming Intune holds a previous schema ready for rollback. Keep any proposed app or policy change subject to the device owner’s change process.\nVerification\nOn a representative approved device, inspect the effective property and its per-setting deployment result, then test the actual device behavior. Distinguish a saved profile from a correct OEM-defined value. If a schema or version problem remains, retain the smallest reproducible configuration and the observed app context for escalation. Do not invent an older schema or publish an untested configuration as a supported recovery path.\nOfficial references\nMicrosoft Learn: Use OEMConfig on Android Enterprise devices in Microsoft Intune.",
                "datePublished": "2026-09-10T00:24:36+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-440-preserve-the-oemconfig-schema-context-when-investigating-a-changed-setting/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Preserve the OEMConfig schema context when investigating a changed setting"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 242,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Use OEMConfig on Android Enterprise devices in Microsoft Intune - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-configuration/templates/configure-oemconfig-android"
                }
            }
        ]
    }
}