tetto Mind sharing what commends you used?
I used the following commands when the system was waiting for the "next" prompt:
pm install-existing --user 18 app.grapheneos.gmscompat
pm install-existing --user 18 app.grapheneos.gmscompat.lib
pm install-existing --user 18 app.grapheneos.gmscompat.config
pm install-existing --user 18 com.google.android.gms
pm install-existing --user 18 com.android.vending
pm install-existing --user 18 com.microsoft.office.outlook
pm install-existing --user 18 com.microsoft.office.onenote
pm install-existing --user 18 com.microsoft.office.excel
pm install-existing --user 18 com.microsoft.teams
pm install-existing --user 18 app.vanadium.browser
Note that the user 18 was my specific user associated with the work profile. I don't recall the command I used to discover the user. I copied part of the instructions from another post and took a while to understand that the user would be different.
All of the apps were installed in my main profile, this was to avoid having to send an APK from another source.
In the meantime, I confirmed that the apps are updated in the work profile when the app in the main profile is updated. So that solves that security concern.
Note that I installed the play store but in the end I disabled it due to the errors of not being allowed due to the work policy. This was really annoying because Intune was trying to install more apps.
I did not have any issues with having Vanadium installed, don't know if this is due to being managed by the App Store or if I could install any app this way without the Intune policy complaining of unauthorised applications installed.