Skip to content

Latest commit

 

History

History
294 lines (203 loc) · 23.4 KB

File metadata and controls

294 lines (203 loc) · 23.4 KB
title Android device enrollment guide for Microsoft Intune
description Enroll Android and Android Enterprise corporate-owned work profile, personally owned devices with a work profile, fully managed, AOSP, and dedicated devices in Microsoft Intune. Decide which enrollment method to use, and get an overview of the administrator and end user tasks to enroll devices.
author MandiOhlinger
ms.author mandia
ms.date 04/23/2024
ms.topic article
ms.reviewer chmaguir, priyar
ms.collection
M365-identity-device-management

Enrollment guide: Enroll Android devices in Microsoft Intune

Personal and organization-owned devices can be enrolled in Intune. Once enrolled, they receive the policies and profiles you create. You have the following options when enrolling Android devices:

This article provides enrollment recommendations and includes an overview of the administrator and user tasks for each option.

There's also a visual guide of the different enrollment options for each platform:

A visual representation of Intune enrollment options by platform
Download PDF version | Download Visio version

Before you begin

For a list of all the Intune-specific prerequisites and configurations needed to prepare your tenant for enrollment, go to Enrollment guide: Microsoft Intune enrollment.

Note

After you create an enrollment profile and assign it to users or groups, don't rename the enrollment profile. It can prevent future enrollments. If you need to change the name of the enrollment profile, then:

  1. Create a new enrollment profile with the new name
  2. Assign the new profile to the your users & devices
  3. Delete the old profile

BYOD: Android Enterprise personally owned devices with a work profile

These devices are personal or BYOD (bring your own device) Android devices that access organization email, apps, and other data.


Feature Use this enrollment option when
Use Google Mobile Services (GMS).
Devices are personal or BYOD.

You can mark these devices as corporate or personal.
You have new or existing devices.
Need to enroll a few devices, or a large number of devices (bulk enrollment).
Devices are associated with a single user.
You use the optional device enrollment manager (DEM) account.
Devices are managed by another MDM provider.

When a device enrolls, MDM providers install certificates and other files. These files must be removed. The quickest way might be to unenroll, or factory reset the devices. If you don't want to factory reset, then contact the other MDM provider for guidance.
Devices are owned by the organization or school.

Not recommended for organization-owned devices. Organization-owned devices should be enrolled using Android Enterprise fully managed (in this article), or using Android Enterprise corporate owned work profile (in this article).
Devices are user-less, such as kiosk, dedicated, or shared.

User-less or shared devices should be organization-owned. These devices should be enrolled using Android Enterprise dedicated devices.

Admin tasks (personally owned devices with a work profile)

This task list provides an overview. For more specific information, go to Set up enrollment of Android Enterprise personally owned work profile devices.

End user tasks (personally owned devices with a work profile)

Your users must do the following steps. For the specific user experience, go to enroll the device.

  1. Go to the Google Play store, and install the Company Portal app.

  2. Users open the Company Portal app, and sign in with their organization credentials ([email protected]). After they sign in, your enrollment profile applies to the device.

    Users might have to enter more information. For more specific steps, go to enroll the device.

[!INCLUDE users-dont-like-enroll]

Tip

There is a short, step-by-step video to help your users in enroll their devices in Intune:

Enroll your Android device

Android Enterprise dedicated devices

Previously referred to as COSU. These devices are organization-owned, and are supported by Google's Zero Touch. The only purpose is to be a kiosk-style device. They aren't associated with a single or specific user. These devices are commonly used to scan items, print tickets, get digital signatures, manage inventory, and more.


Feature Use this enrollment option when
Use Google Mobile Services (GMS).
Devices are owned by the organization or school.
You have new or existing devices.
Need to enroll a few devices, or a large number of devices (bulk enrollment).
Devices are user-less, such as kiosk, dedicated, or shared.
Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).
Devices are associated with a single user.

Not recommended. These devices should be enrolled using Android Enterprise fully managed.
You use the optional device enrollment manager (DEM) account.

The DEM account isn't supported.
Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.

Admin tasks (Dedicated devices)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise dedicated devices.

End user tasks (Dedicated devices)

Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch.
  2. After they enter the required information, your enrollment profile applies to the device. When the enrollment wizard completes, the device is ready to use.

[!INCLUDE users-dont-like-enroll]

Android Enterprise fully managed

Previously referred to as COBO. These devices are organization-owned, and have one user. They're used exclusively for organization work; not personal use.


Feature Use this enrollment option when
Use Google Mobile Services (GMS).
Devices are owned by the organization or school.
You have new or existing devices.
Need to enroll a few devices, or a large number of devices (bulk enrollment).
Devices are associated with a single user.
Devices are user-less, such as kiosk, dedicated, or shared.

User-less devices should be enrolled using Android Enterprise dedicated devices (in this article).
Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).
Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.
You use the optional device enrollment manager (DEM) account

The DEM account isn't supported.

Admin tasks (Fully managed)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise fully managed devices.

End user tasks (Fully managed)

The specific steps depend on how you configured the enrollment profile. For the specific user experience, go to enroll the device.

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch. They can be asked to sign in with their organization credentials ([email protected]).

  2. After they enter the required information, your enrollment profile applies to the device.

    Users might have to enter more information. For more specific steps, go to enroll the device.

[!INCLUDE users-dont-like-enroll]

Android Enterprise corporate owned work profile

Previously referred to as COPE. These devices are organization-owned, and have one user. They're used for organization work, and allow personal use.


Feature Use this enrollment option when
Use Google Mobile Services (GMS).
Devices are owned by the organization or school.
You have new or existing devices.
Need to enroll a few devices, or a large number of devices (bulk enrollment).
Devices are associated with a single user.
Devices are user-less, such as kiosk, dedicated, or shared.

User-less devices should be enrolled using Android Enterprise dedicated devices. Also, an organization administrator can enroll. When the device is enrolled, create a dedicated device (Device experience) profile, and assign this profile to this device.
Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).
Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.
You use the optional device enrollment manager (DEM) account.

The DEM account isn't supported.

Admin tasks (Corporate owned with a work profile)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise corporate owned work profile.

End user tasks (Corporate owned with a work profile)

The specific steps depend on how you configured the enrollment profile. For the specific user experience, go to enroll the device.

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch. They can be asked to sign in with their organization credentials ([email protected]).

  2. After they enter the required information, your enrollment profile applies to the device.

    Users might have to enter more information. For more specific steps, go to enroll the device.

[!INCLUDE users-dont-like-enroll]

Android Open Source Project (AOSP)

Note

Currently, there's limited OEM support for this enrollment method.

Also referred to as AOSP. These devices are organization-owned, and don't use Google Mobile Services (GMS). They can be kiosk-style devices that aren't associated with a single or specific user, or can have one user. They're used exclusively for organization work; not personal use.

When you create the Intune enrollment profile, you decide if the devices are userless, or are associated with a single user. For more information on these options, including supported OEMs, go to:


Feature Use this enrollment option when
Use Google Mobile Services (GMS).

These devices don't support GMS (opens Android's web site). Some countries/regions don't support GMS.

If your devices will use GMS, then use dedicated devices (in this article) or fully managed (in this article) enrollment.
Devices are owned by the organization or school.
You have new or existing devices.
Need to enroll a few devices, or a large number of devices (bulk enrollment).

Can only enroll one device at a time.
Devices are associated with a single user.
Devices are user-less, such as kiosk, dedicated, or shared.
Devices are personal or BYOD.

Android Enterprise personally owned devices with a work profile (in this article) support GMS (opens Android's web site).
Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.
You use the optional device enrollment manager (DEM) account

The DEM account isn't supported.

Admin tasks (AOSP)

This task list provides an overview. For more specific information, go to enrollment for AOSP corporate-owned userless devices and AOSP corporate-owned user-associated devices.

End user tasks (AOSP)

The specific steps depend on how you configured the enrollment profile.

Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:

  1. Users turn on the device, and are prompted for information, including the enrollment method: QR Code. If you created a user-associated devices enrollment profile, then they might be asked to sign in with their organization credentials ([email protected]).

  2. If you created a userless devices enrollment profile, then wait for the enrollment wizard to complete. When it does, the device is ready to use.

    If you created a user-associated devices enrollment profile, then users enter the required information. Then, wait for the enrollment wizard to complete. For more specific steps, go to enroll the device.

[!INCLUDE users-dont-like-enroll]

Android device administrator

[!INCLUDE android_device_administrator_support]

These Android devices are corporate, or personal/BYOD (bring your own device) devices that can access organization email, apps, and other data.

Google deprecated Android device administrator management in 2020. Intune is ending support for device administrator devices with access to Google Mobile Services in August 2024.

Microsoft recommends:

Related articles