You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: memdocs/intune/enrollment/android-enroll.md
+6-3Lines changed: 6 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -8,7 +8,7 @@ keywords:
8
8
author: Lenewsad
9
9
ms.author: lanewsad
10
10
manager: dougeby
11
-
ms.date: 10/19/2021
11
+
ms.date: 02/01/2022
12
12
ms.topic: overview
13
13
ms.service: microsoft-intune
14
14
ms.subservice: enrollment
@@ -46,13 +46,16 @@ As an Intune administrator, you can enroll Android devices in the following ways
46
46
-[Corporate-owned, user associated devices](android-aosp-corporate-owned-user-associated-enroll.md): For corporate-owned, single user devices intended exclusively for work and not personal use. Admins can manage the entire device.
47
47
-[Corporate-owned, userless devices](android-aosp-corporate-owned-userless-enroll.md): For corporate-owned, shared devices. Admins can manage the entire device.
48
48
49
+
> [!TIP]
50
+
> For guidance on which enrollment method is right for your organization, see [Deployment guide: Enroll Android devices in Microsoft Intune](..fundamentals/deployment-guide-enrollment-android.md).
51
+
49
52
## Prerequisites
50
53
51
-
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you are first setting up Intune for mobile device management.
54
+
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you’re first setting up Intune for mobile device management.
52
55
53
56
For Android Enterprise, refer to the following support article from Google to ensure that Android Enterprise is available in your country or region: https://support.google.com/work/android/answer/6270910
54
57
55
-
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal additional permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
58
+
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal more permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
56
59
57
60
For Samsung Knox Standard devices, there are [more prerequisites](android-samsung-knox-mobile-enroll.md).
This article provides recommendations on the Android enrollment methods. It also includes an overview of the administrator and user tasks for each enrollment type.
@@ -56,9 +57,10 @@ These devices are personal or BYOD (bring your own device) Android devices that
56
57
---
57
58
| Feature | Use this enrollment option when |
58
59
| --- | --- |
60
+
| Uses Google Mobile Services (GMS). | ✔️ |
59
61
| Devices are personal or BYOD. | ✔️ <br/><br/> You can mark these devices as corporate or personal. |
60
62
| You have new or existing devices. | ✔️ |
61
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
63
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
62
64
| Devices are associated with a single user. | ✔️ |
63
65
| You use the optional device enrollment manager (DEM) account. | ✔️ |
64
66
| Devices are managed by another MDM provider. | ❌ <br/><br/> When a device enrolls, MDM providers install certificates and other files. These files must be removed. The quickest way may be to unenroll, or factory reset the devices. If you don't want to factory reset, then contact the MDM provider. |
@@ -97,9 +99,10 @@ Previously referred to as COSU. These devices are organization-owned, and suppor
97
99
---
98
100
| Feature | Use this enrollment option when |
99
101
| --- | --- |
102
+
| Uses Google Mobile Services (GMS). | ✔️ Add text <br/><br/> ❌ Add text|
100
103
| Devices are owned by the organization or school. | ✔️ |
101
104
| You have new or existing devices. | ✔️ |
102
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
105
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
103
106
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
104
107
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
105
108
| Devices are associated with a single user. | ❌ <br/><br/> Not recommended. These devices should be enrolled using Android Enterprise fully managed. |
@@ -131,9 +134,10 @@ Previously referred to as COBO. These devices are organization-owned, and have o
131
134
---
132
135
| Feature | Use this enrollment option when |
133
136
| --- | --- |
137
+
| Uses Google Mobile Services (GMS). | ✔️ |
134
138
| Devices are owned by the organization or school. | ✔️ |
135
139
| You have new or existing devices. | ✔️ |
136
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
140
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
137
141
| Devices are associated with a single user. | ✔️ |
138
142
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/> User-less devices should be enrolled using Android Enterprise dedicated devices.|
139
143
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -174,9 +178,10 @@ Previously referred to as COPE. These devices are organization-owned, and have o
174
178
---
175
179
| Feature | Use this enrollment option when |
176
180
| --- | --- |
181
+
| Uses Google Mobile Services (GMS). | ✔️ |
177
182
| Devices are owned by the organization or school. | ✔️ |
178
183
| You have new or existing devices. | ✔️ |
179
-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
184
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
180
185
| Devices are associated with a single user. | ✔️ |
181
186
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/>User-less devices should be enrolled using Android Enterprise dedicated devices. Also, an organization administrator can enroll. When the device is enrolled, create a [dedicated device](../configuration/device-restrictions-android-for-work.md#device-experience) profile, and assign this profile to this device. |
182
187
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -192,7 +197,7 @@ This task list provides an overview. For more specific information, see [Set up
192
197
- Be sure your devices are [supported](supported-devices-browsers.md).
193
198
- Factory reset the devices. This step is required.
194
199
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, see [Connect your Intune account to your Managed Google Play account](../enrollment/connect-intune-android-enterprise.md).
195
-
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md)..
200
+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md).
196
201
- Enroll the devices in Intune. For the specific steps, see [Enroll your Android Enterprise devices](../enrollment/android-dedicated-devices-fully-managed-enroll.md).
197
202
- Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).
198
203
@@ -209,6 +214,51 @@ The specific steps depend on how you configured the enrollment profile. For the
Also referred to as AOSP. Currently in [public preview](public-preview.md). These devices are organization-owned, and don't use Google Mobile Services (GMS). They can be kiosk-style devices that aren't associated with a single or specific user, or can have one user. They're used exclusively for organization work; not personal use.
220
+
221
+
**NEED EXAMPLES OF DEVICES THAT USE AOSP**
222
+
223
+
When you create the Intune enrollment profile, you decide if the devices are userless, or are associated with a single user. For more information on these options, see:
224
+
225
+
-[Set up Intune enrollment for Android (AOSP) corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
226
+
-[Set up Intune enrollment for Android (AOSP) corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
227
+
228
+
---
229
+
| Feature | Use this enrollment option when |
230
+
| --- | --- |
231
+
| Uses Google Mobile Services (GMS). | ❌ <br/><br/> AOSP doesn't use the [GMS](https://www.android.com/gms/) (opens Android's web site). |
232
+
| Devices are owned by the organization or school. | ✔️ |
233
+
| You have new or existing devices. | ✔️ |
234
+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
235
+
| Devices are associated with a single user. | ✔️ |
236
+
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
237
+
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
238
+
|Devices are managed by another MDM provider. | ❌ <br/><br/> To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune. |
239
+
| You use the optional device enrollment manager (DEM) account | ❌ <br/><br/> The DEM account isn't supported. |
240
+
241
+
---
242
+
243
+
### Android Open Source Project administrator tasks
244
+
245
+
This task list provides an overview. For more specific information, see enrollment for [AOSP corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md) and [AOSP corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md).
246
+
247
+
- Be sure your devices are [supported](supported-devices-browsers.md), and can scan QR codes.
248
+
- Factory reset the devices. This step is required. New devices might not require a factory reset.
249
+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), create an enrollment profile, and have your device group(s) ready. For the specific steps, see:
During enrollment, the Microsoft Intune app and Microsoft Authenticator app automatically install and open on the device, which allows the device to enroll. The device is locked in the enrollment process until enrollment completes.
257
+
258
+
### Android Open Source Project end user tasks
259
+
260
+
It's not recommended for users to enroll AOSP devices. This task should be completed by administrators.
261
+
212
262
## Android device administrator
213
263
214
264
These Android devices are corporate, or personal/BYOD (bring your own device) devices that can access organization email, apps, and other data.
@@ -225,7 +275,7 @@ There are some situations when you must use Device Administrator enrollment:
225
275
226
276
- Android Enterprise requires access to Google services. Google services may not be available because of geography, or because of the device manufacturer. For example:
227
277
228
-
- There are places where Google services are not available, like China. In this situation, use Android device administrator enrollment.
278
+
- There are places where Google services aren’t available, like China. In this situation, use Android device administrator enrollment.
229
279
- Some devices are based on Android, but don't have access to Google Services, such as Amazon Fire tablets. In this situation, use Android device administrator enrollment.
230
280
231
281
- Android OS versions older than 5.0 must use Android device administrator enrollment. Android Enterprise enrollment isn't an option.
0 commit comments