{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
        "slug": "dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/"
        },
        "title": "Verify cross-app sign-out separately from Android shared-device enrollment",
        "summary": "Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:56+00:00",
        "modified_at": "2026-09-10T02:11:19+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 204,
        "potentially_affected": "Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application's session design.",
        "dse_recommendation": "Require the application owner to identify how each app participates in shared-device sign-in and sign-out.",
        "primary_source": {
            "name": "Get started with Android frontline worker devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. <a href=\"https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application&#8217;s session design.</p>\n<h2>DSE recommendation</h2>\n<p>Require the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.</p>\n<h2>Verification</h2>\n<p>Use two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Get started with Android frontline worker devices</a>.</p>",
        "content_text": "Source facts\nFor Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. Microsoft Learn.\nApplicability\nUse this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application’s session design.\nDSE recommendation\nRequire the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.\nVerification\nUse two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.\nOfficial references\nMicrosoft Learn: Get started with Android frontline worker devices.",
        "content_markdown": "## Source facts\n\nFor Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android).\n\n## Applicability\n\nUse this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application’s session design.\n\n## DSE recommendation\n\nRequire the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.\n\n## Verification\n\nUse two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.\n\n## Official references\n\n[Microsoft Learn: Get started with Android frontline worker devices](https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Verify cross-app sign-out separately from Android shared-device enrollment",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/",
                "headline": "Verify cross-app sign-out separately from Android shared-device enrollment",
                "description": "Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?",
                "abstract": "Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?",
                "articleBody": "Source facts\nFor Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. Microsoft Learn.\nApplicability\nUse this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application’s session design.\nDSE recommendation\nRequire the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.\nVerification\nUse two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.\nOfficial references\nMicrosoft Learn: Get started with Android frontline worker devices.",
                "datePublished": "2026-09-10T00:22:56+00:00",
                "dateModified": "2026-09-10T02:11:19+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Verify cross-app sign-out separately from Android shared-device enrollment"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 204,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Get started with Android frontline worker devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android"
                }
            }
        ]
    }
}