Skip to content

Commit 4424af6

Browse files
committed
adding AOSP enrollment
1 parent 8c11792 commit 4424af6

2 files changed

Lines changed: 64 additions & 11 deletions

File tree

memdocs/intune/enrollment/android-enroll.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,7 +8,7 @@ keywords:
88
author: Lenewsad
99
ms.author: lanewsad
1010
manager: dougeby
11-
ms.date: 10/19/2021
11+
ms.date: 02/01/2022
1212
ms.topic: overview
1313
ms.service: microsoft-intune
1414
ms.subservice: enrollment
@@ -46,13 +46,16 @@ As an Intune administrator, you can enroll Android devices in the following ways
4646
- [Corporate-owned, user associated devices](android-aosp-corporate-owned-user-associated-enroll.md): For corporate-owned, single user devices intended exclusively for work and not personal use. Admins can manage the entire device.
4747
- [Corporate-owned, userless devices](android-aosp-corporate-owned-userless-enroll.md): For corporate-owned, shared devices. Admins can manage the entire device.
4848

49+
> [!TIP]
50+
> For guidance on which enrollment method is right for your organization, see [Deployment guide: Enroll Android devices in Microsoft Intune](..fundamentals/deployment-guide-enrollment-android.md).
51+
4952
## Prerequisites
5053

51-
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you are first setting up Intune for mobile device management.
54+
To prepare to manage mobile devices, you must set the mobile device management (MDM) authority to **Microsoft Intune**. See [Set the MDM authority](../fundamentals/mdm-authority-set.md) for instructions. You set this item only once, when you’re first setting up Intune for mobile device management.
5255

5356
For Android Enterprise, refer to the following support article from Google to ensure that Android Enterprise is available in your country or region: https://support.google.com/work/android/answer/6270910
5457

55-
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal additional permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
58+
For devices manufactured by Zebra Technologies, you may need to grant the Company Portal more permissions depending on the capabilities of the specific device. [Mobility Extensions on Zebra devices](../configuration/android-zebra-mx-overview.md) has more details.
5659

5760
For Samsung Knox Standard devices, there are [more prerequisites](android-samsung-knox-mobile-enroll.md).
5861

memdocs/intune/fundamentals/deployment-guide-enrollment-android.md

Lines changed: 58 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -7,7 +7,7 @@ keywords:
77
author: MandiOhlinger
88
ms.author: mandia
99
manager: dougeby
10-
ms.date: 04/14/2021
10+
ms.date: 02/01/2022
1111
ms.topic: conceptual
1212
ms.service: microsoft-intune
1313
ms.subservice: enrollment
@@ -18,7 +18,7 @@ ms.localizationpriority: high
1818
#ROBOTS:
1919
#audience:
2020
#ms.devlang:
21-
ms.reviewer: chmaguir
21+
ms.reviewer: chmaguir, priyar
2222
ms.suite: ems
2323
search.appverid: MET150
2424
#ms.tgt_pltfrm:
@@ -36,6 +36,7 @@ Personal and organization-owned devices can be enrolled in Intune. Once enrolled
3636
- [Android Enterprise corporate owned dedicated devices](#android-enterprise-dedicated-devices) (COSU)
3737
- [Android Enterprise corporate owned fully managed](#android-enterprise-fully-managed) (COBO)
3838
- [Android Enterprise corporate owned work profile](#android-enterprise-corporate-owned-work-profile) (COPE)
39+
- [Android Open Source Project (preview)](#android-open-source-project) (AOSP)
3940
- [Android device administrator](#android-device-administrator) (DA)
4041

4142
This article provides recommendations on the Android enrollment methods. It also includes an overview of the administrator and user tasks for each enrollment type.
@@ -56,9 +57,10 @@ These devices are personal or BYOD (bring your own device) Android devices that
5657
---
5758
| Feature | Use this enrollment option when |
5859
| --- | --- |
60+
| Uses Google Mobile Services (GMS). | ✔️ |
5961
| Devices are personal or BYOD. | ✔️ <br/><br/> You can mark these devices as corporate or personal. |
6062
| You have new or existing devices. | ✔️ |
61-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
63+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
6264
| Devices are associated with a single user. | ✔️ |
6365
| You use the optional device enrollment manager (DEM) account. | ✔️ |
6466
| Devices are managed by another MDM provider. | ❌ <br/><br/> When a device enrolls, MDM providers install certificates and other files. These files must be removed. The quickest way may be to unenroll, or factory reset the devices. If you don't want to factory reset, then contact the MDM provider. |
@@ -97,9 +99,10 @@ Previously referred to as COSU. These devices are organization-owned, and suppor
9799
---
98100
| Feature | Use this enrollment option when |
99101
| --- | --- |
102+
| Uses Google Mobile Services (GMS). | ✔️ Add text <br/><br/> ❌ Add text|
100103
| Devices are owned by the organization or school. | ✔️ |
101104
| You have new or existing devices. | ✔️ |
102-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
105+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
103106
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
104107
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
105108
| Devices are associated with a single user. | ❌ <br/><br/> Not recommended. These devices should be enrolled using Android Enterprise fully managed. |
@@ -131,9 +134,10 @@ Previously referred to as COBO. These devices are organization-owned, and have o
131134
---
132135
| Feature | Use this enrollment option when |
133136
| --- | --- |
137+
| Uses Google Mobile Services (GMS). | ✔️ |
134138
| Devices are owned by the organization or school. | ✔️ |
135139
| You have new or existing devices. | ✔️ |
136-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
140+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
137141
| Devices are associated with a single user. | ✔️ |
138142
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/> User-less devices should be enrolled using Android Enterprise dedicated devices.|
139143
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -174,9 +178,10 @@ Previously referred to as COPE. These devices are organization-owned, and have o
174178
---
175179
| Feature | Use this enrollment option when |
176180
| --- | --- |
181+
| Uses Google Mobile Services (GMS). | ✔️ |
177182
| Devices are owned by the organization or school. | ✔️ |
178183
| You have new or existing devices. | ✔️ |
179-
| Need to enroll a small number of devices, or a large number of devices (bulk enrollment). | ✔️ |
184+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
180185
| Devices are associated with a single user. | ✔️ |
181186
| Devices are user-less, such as kiosk, dedicated, or shared. | ❌ <br/><br/>User-less devices should be enrolled using Android Enterprise dedicated devices. Also, an organization administrator can enroll. When the device is enrolled, create a [dedicated device](../configuration/device-restrictions-android-for-work.md#device-experience) profile, and assign this profile to this device. |
182187
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
@@ -192,7 +197,7 @@ This task list provides an overview. For more specific information, see [Set up
192197
- Be sure your devices are [supported](supported-devices-browsers.md).
193198
- Factory reset the devices. This step is required.
194199
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, see [Connect your Intune account to your Managed Google Play account](../enrollment/connect-intune-android-enterprise.md).
195-
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md)..
200+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), enable corporate-owned personal profile devices. For the specific steps, see [Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile](../enrollment/android-corporate-owned-work-profile-enroll.md).
196201
- Enroll the devices in Intune. For the specific steps, see [Enroll your Android Enterprise devices](../enrollment/android-dedicated-devices-fully-managed-enroll.md).
197202
- Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).
198203

@@ -209,6 +214,51 @@ The specific steps depend on how you configured the enrollment profile. For the
209214

210215
[!INCLUDE [users-dont-like-enroll](../includes/users-dont-like-enroll.md)]
211216

217+
## Android Open Source Project
218+
219+
Also referred to as AOSP. Currently in [public preview](public-preview.md). These devices are organization-owned, and don't use Google Mobile Services (GMS). They can be kiosk-style devices that aren't associated with a single or specific user, or can have one user. They're used exclusively for organization work; not personal use.
220+
221+
**NEED EXAMPLES OF DEVICES THAT USE AOSP**
222+
223+
When you create the Intune enrollment profile, you decide if the devices are userless, or are associated with a single user. For more information on these options, see:
224+
225+
- [Set up Intune enrollment for Android (AOSP) corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
226+
- [Set up Intune enrollment for Android (AOSP) corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
227+
228+
---
229+
| Feature | Use this enrollment option when |
230+
| --- | --- |
231+
| Uses Google Mobile Services (GMS). | ❌ <br/><br/> AOSP doesn't use the [GMS](https://www.android.com/gms/) (opens Android's web site). |
232+
| Devices are owned by the organization or school. | ✔️ |
233+
| You have new or existing devices. | ✔️ |
234+
| Need to enroll a few devices, or a large number of devices (bulk enrollment). | ✔️ |
235+
| Devices are associated with a single user. | ✔️ |
236+
| Devices are user-less, such as kiosk, dedicated, or shared. | ✔️ |
237+
| Devices are personal or BYOD. | ❌ <br/><br/>BYOD or personal devices should be enrolled using [Android Enterprise personally owned devices with a work profile](#byod-android-enterprise-personally-owned-devices-with-a-work-profile) (in this article).|
238+
|Devices are managed by another MDM provider. | ❌ <br/><br/> To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune. |
239+
| You use the optional device enrollment manager (DEM) account | ❌ <br/><br/> The DEM account isn't supported. |
240+
241+
---
242+
243+
### Android Open Source Project administrator tasks
244+
245+
This task list provides an overview. For more specific information, see enrollment for [AOSP corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md) and [AOSP corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md).
246+
247+
- Be sure your devices are [supported](supported-devices-browsers.md), and can scan QR codes.
248+
- Factory reset the devices. This step is required. New devices might not require a factory reset.
249+
- In the [Endpoint Manager admin center](https://go.microsoft.com/fwlink/?linkid=2109431), create an enrollment profile, and have your device group(s) ready. For the specific steps, see:
250+
- [AOSP corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
251+
- [AOSP corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
252+
- Enroll the devices in Intune by scanning the QR code. For the specific steps, see:
253+
- [AOSP corporate-owned userless devices](../enrollment/android-aosp-corporate-owned-userless-enroll.md)
254+
- [AOSP corporate-owned user-associated devices](../enrollment/android-aosp-corporate-owned-user-associated-enroll.md)
255+
256+
During enrollment, the Microsoft Intune app and Microsoft Authenticator app automatically install and open on the device, which allows the device to enroll. The device is locked in the enrollment process until enrollment completes.
257+
258+
### Android Open Source Project end user tasks
259+
260+
It's not recommended for users to enroll AOSP devices. This task should be completed by administrators.
261+
212262
## Android device administrator
213263

214264
These Android devices are corporate, or personal/BYOD (bring your own device) devices that can access organization email, apps, and other data.
@@ -225,7 +275,7 @@ There are some situations when you must use Device Administrator enrollment:
225275

226276
- Android Enterprise requires access to Google services. Google services may not be available because of geography, or because of the device manufacturer. For example:
227277

228-
- There are places where Google services are not available, like China. In this situation, use Android device administrator enrollment.
278+
- There are places where Google services aren’t available, like China. In this situation, use Android device administrator enrollment.
229279
- Some devices are based on Android, but don't have access to Google Services, such as Amazon Fire tablets. In this situation, use Android device administrator enrollment.
230280

231281
- Android OS versions older than 5.0 must use Android device administrator enrollment. Android Enterprise enrollment isn't an option.

0 commit comments

Comments
 (0)