Android device enrollment guide for Microsoft Intune (2024)

  • Article

Personal and organization-owned devices can be enrolled in Intune. Once enrolled, they receive the policies and profiles you create. You have the following options when enrolling Android devices:

  • BYOD: Android Enterprise personally owned devices with a work profile
  • Android Enterprise corporate owned dedicated devices (COSU)
  • Android Enterprise corporate owned fully managed (COBO)
  • Android Enterprise corporate owned work profile (COPE)
  • Android Open Source Project (AOSP)
  • Android device administrator (DA)

This article provides enrollment recommendations and includes an overview of the administrator and user tasks for each option.

There's also a visual guide of the different enrollment options for each platform:


Download PDF version | Download Visio version

Tip

This guide is a living thing. So, be sure to add or update existing tips and guidance you've found helpful.

Before you begin

For a list of all the Intune-specific prerequisites and configurations needed to prepare your tenant for enrollment, go to Enrollment guide: Microsoft Intune enrollment.

Note

After you create an enrollment profile and assign it to users or groups, don't rename the enrollment profile. It can prevent future enrollments. If you need to change the name of the enrollment profile, then:

  1. Create a new enrollment profile with the new name
  2. Assign the new profile to the your users & devices
  3. Delete the old profile

BYOD: Android Enterprise personally owned devices with a work profile

These devices are personal or BYOD (bring your own device) Android devices that access organization email, apps, and other data.

FeatureUse this enrollment option when
Use Google Mobile Services (GMS).✔️
Devices are personal or BYOD.✔️

You can mark these devices as corporate or personal.

You have new or existing devices.✔️
Need to enroll a few devices, or a large number of devices (bulk enrollment).✔️
Devices are associated with a single user.✔️
You use the optional device enrollment manager (DEM) account.✔️
Devices are managed by another MDM provider.

When a device enrolls, MDM providers install certificates and other files. These files must be removed. The quickest way may be to unenroll, or factory reset the devices. If you don't want to factory reset, then contact the other MDM provider for guidance.

Devices are owned by the organization or school.

Not recommended for organization-owned devices. Organization-owned devices should be enrolled using Android Enterprise fully managed (in this article), or using Android Enterprise corporate owned work profile (in this article).

Devices are user-less, such as kiosk, dedicated, or shared.

User-less or shared devices should be organization-owned. These devices should be enrolled using Android Enterprise dedicated devices.

Admin tasks (personally owned devices with a work profile)

This task list provides an overview. For more specific information, go to Set up enrollment of Android Enterprise personally owned work profile devices.

  • Be sure your devices are supported based on platform. For AOSP devices, see Android Open Source Project Supported Devices.
  • In the Intune admin center, connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, go to Connect your Intune account to your Managed Google Play account.

End user tasks (personally owned devices with a work profile)

Your users must do the following steps. For the specific user experience, go to enroll the device.

  1. Go to the Google Play store, and install the Company Portal app.

  2. Users open the Company Portal app, and sign in with their organization credentials (user@contoso.com). After they sign in, your enrollment profile applies to the device.

    Users may have to enter more information. For more specific steps, go to enroll the device.

Users typically don't like enrolling themselves, and may not be familiar with the Company Portal app. Be sure to provide guidance, including what information to enter. For some guidance on communicating with your users, see Planning guide: Step 5 - Create a rollout plan.

Android Enterprise dedicated devices

Previously referred to as COSU. These devices are organization-owned, and are supported by Google's Zero Touch. The only purpose is to be a kiosk-style device. They aren't associated with a single or specific user. These devices are commonly used to scan items, print tickets, get digital signatures, manage inventory, and more.

FeatureUse this enrollment option when
Use Google Mobile Services (GMS).✔️
Devices are owned by the organization or school.✔️
You have new or existing devices.✔️
Need to enroll a few devices, or a large number of devices (bulk enrollment).✔️
Devices are user-less, such as kiosk, dedicated, or shared.✔️
Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).

Devices are associated with a single user.

Not recommended. These devices should be enrolled using Android Enterprise fully managed.

You use the optional device enrollment manager (DEM) account.

The DEM account isn't supported.

Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.

Admin tasks (Dedicated devices)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise dedicated devices.

  • Be sure your devices are supported.

  • Factory reset the devices. This step is required.

  • In the Intune admin center, connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Intune app and other common Android Enterprise apps to the devices. For the specific steps, go to Connect your Intune account to your Managed Google Play account.

  • In the Intune admin center, create an enrollment profile, and have your dedicated device group(s) ready to receive the profile. For the specific steps, go to Set up Intune enrollment of Android Enterprise dedicated devices.

  • Enroll the devices in Intune. For the specific steps, go to Enroll your Android Enterprise devices.

    On Samsung's Knox devices, you can automatically enroll a large number of Android Enterprise devices using Samsung Knox Mobile Enrollment (KME). For more information, go to Automatically enroll Android devices by using Samsung's Knox Mobile Enrollment.

  • Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).

End user tasks (Dedicated devices)

Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch.
  2. After they enter the required information, your enrollment profile applies to the device. When the enrollment wizard completes, the device is ready to use.

Users typically don't like enrolling themselves, and may not be familiar with the Company Portal app. Be sure to provide guidance, including what information to enter. For some guidance on communicating with your users, see Planning guide: Step 5 - Create a rollout plan.

Android Enterprise fully managed

Previously referred to as COBO. These devices are organization-owned, and have one user. They're used exclusively for organization work; not personal use.

FeatureUse this enrollment option when
Use Google Mobile Services (GMS).✔️
Devices are owned by the organization or school.✔️
You have new or existing devices.✔️
Need to enroll a few devices, or a large number of devices (bulk enrollment).✔️
Devices are associated with a single user.✔️
Devices are user-less, such as kiosk, dedicated, or shared.

User-less devices should be enrolled using Android Enterprise dedicated devices (in this article).

Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).

Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.

You use the optional device enrollment manager (DEM) account

The DEM account isn't supported.

Admin tasks (Fully managed)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise fully managed devices.

  • Be sure your devices are supported.

  • Factory reset the devices. This step is required.

  • In the Intune admin center, connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, go to Connect your Intune account to your Managed Google Play account.

  • In the Intune admin center, enable fully managed user devices. For the specific steps, go to Set up Intune enrollment of Android Enterprise fully managed devices.

  • Enroll the devices in Intune. For the specific steps, go to Enroll your Android Enterprise devices.

  • Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).

    Using Samsung Knox Mobile Enrollment (KME), you can automatically enroll a large number of Android Enterprise Samsung Knox devices. For more information, go to Automatically enroll Android devices by using Samsung's Knox Mobile Enrollment.

End user tasks (Fully managed)

The specific steps depend on how you configured the enrollment profile. For the specific user experience, go to enroll the device.

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch. They may be asked to sign in with their organization credentials (user@contoso.com).

  2. After they enter the required information, your enrollment profile applies to the device.

    Users may have to enter more information. For more specific steps, go to enroll the device.

Users typically don't like enrolling themselves, and may not be familiar with the Company Portal app. Be sure to provide guidance, including what information to enter. For some guidance on communicating with your users, see Planning guide: Step 5 - Create a rollout plan.

Android Enterprise corporate owned work profile

Previously referred to as COPE. These devices are organization-owned, and have one user. They're used for organization work, and allow personal use.

FeatureUse this enrollment option when
Use Google Mobile Services (GMS).✔️
Devices are owned by the organization or school.✔️
You have new or existing devices.✔️
Need to enroll a few devices, or a large number of devices (bulk enrollment).✔️
Devices are associated with a single user.✔️
Devices are user-less, such as kiosk, dedicated, or shared.

User-less devices should be enrolled using Android Enterprise dedicated devices. Also, an organization administrator can enroll. When the device is enrolled, create a dedicated device profile, and assign this profile to this device.

Devices are personal or BYOD.

BYOD or personal devices should be enrolled using Android Enterprise personally owned devices with a work profile (in this article).

Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.

You use the optional device enrollment manager (DEM) account.

The DEM account isn't supported.

Admin tasks (Corporate owned with a work profile)

This task list provides an overview. For more specific information, go to Set up Intune enrollment of Android Enterprise corporate owned work profile.

  • Be sure your devices are supported.

  • Factory reset the devices. This step is required.

  • In the Intune admin center, connect your Intune organization account to your Managed Google Play account. When you connect, Intune automatically adds the Company Portal app and other common Android Enterprise apps to the devices. For the specific steps, go to Connect your Intune account to your Managed Google Play account.

  • In the Intune admin center, enable corporate-owned personal profile devices. For the specific steps, go to Set up Intune enrollment of Android Enterprise corporate-owned devices with work profile.

  • Enroll the devices in Intune. For the specific steps, go to Enroll your Android Enterprise devices.

  • Communicate to your users how they should enroll: Near Field Communication (NFC), Token, QR Code, Google Zero Touch, or Samsung Knox Mobile Enrollment (KME).

    Using Samsung Knox Mobile Enrollment (KME), you can automatically enroll a large number of Android Enterprise Samsung's Knox devices. For more information, go to Automatically enroll Android devices by using Samsung's Knox Mobile Enrollment.

End user tasks (Corporate owned with a work profile)

The specific steps depend on how you configured the enrollment profile. For the specific user experience, go to enroll the device.

  1. Users turn on the device, and are prompted for information, including the enrollment method: NFC, Token, QR Code, or Google Zero Touch. They may be asked to sign in with their organization credentials (user@contoso.com).

  2. After they enter the required information, your enrollment profile applies to the device.

    Users may have to enter more information. For more specific steps, go to enroll the device.

Users typically don't like enrolling themselves, and may not be familiar with the Company Portal app. Be sure to provide guidance, including what information to enter. For some guidance on communicating with your users, see Planning guide: Step 5 - Create a rollout plan.

Android Open Source Project (AOSP)

Note

Currently, there's limited OEM support for this enrollment method.

Also referred to as AOSP. These devices are organization-owned, and don't use Google Mobile Services (GMS). They can be kiosk-style devices that aren't associated with a single or specific user, or can have one user. They're used exclusively for organization work; not personal use.

When you create the Intune enrollment profile, you decide if the devices are userless, or are associated with a single user. For more information on these options, including supported OEMs, go to:

  • Set up Intune enrollment for Android (AOSP) corporate-owned userless devices
  • Set up Intune enrollment for Android (AOSP) corporate-owned user-associated devices
FeatureUse this enrollment option when
Use Google Mobile Services (GMS).

These devices don't support GMS (opens Android's web site). Some countries/regions don't support GMS.

If your devices will use GMS, then use dedicated devices (in this article) or fully managed (in this article) enrollment.

Devices are owned by the organization or school.✔️
You have new or existing devices.✔️
Need to enroll a few devices, or a large number of devices (bulk enrollment).

Can only enroll one device at a time.

Devices are associated with a single user.✔️
Devices are user-less, such as kiosk, dedicated, or shared.✔️
Devices are personal or BYOD.

Android Enterprise personally owned devices with a work profile (in this article) support GMS (opens Android's web site).

Devices are managed by another MDM provider.

To be fully managed by Intune, users need to unenroll from the current MDM provider, and then enroll in Intune.

You use the optional device enrollment manager (DEM) account

The DEM account isn't supported.

Admin tasks (AOSP)

This task list provides an overview. For more specific information, go to enrollment for AOSP corporate-owned userless devices and AOSP corporate-owned user-associated devices.

  • Be sure your devices are supported.

  • Factory reset the devices. This step is required. New devices might not require a factory reset.

  • In the Intune admin center, create an enrollment profile, and have your device group(s) ready. For the specific steps, go to:

    • AOSP corporate-owned userless devices
    • AOSP corporate-owned user-associated devices
  • Enroll the devices in Intune. For the specific steps, go to:

    • AOSP corporate-owned userless devices
    • AOSP corporate-owned user-associated devices

    During enrollment, the Microsoft Intune app and Microsoft Authenticator app automatically install and open on the device, which allows the device to enroll. The device is locked in the enrollment process until enrollment completes.

End user tasks (AOSP)

The specific steps depend on how you configured the enrollment profile.

Admins can complete the enrollment themselves, and then give the devices to the users. Or, users can enroll the devices using the following steps:

  1. Users turn on the device, and are prompted for information, including the enrollment method: QR Code. If you created a user-associated devices enrollment profile, then they may be asked to sign in with their organization credentials (user@contoso.com).

  2. If you created a userless devices enrollment profile, then wait for the enrollment wizard to complete. When it does, the device is ready to use.

    If you created a user-associated devices enrollment profile, then users enter the required information. Then, wait for the enrollment wizard to complete. For more specific steps, go to enroll the device.

Users typically don't like enrolling themselves, and may not be familiar with the Company Portal app. Be sure to provide guidance, including what information to enter. For some guidance on communicating with your users, see Planning guide: Step 5 - Create a rollout plan.

Android device administrator

Important

Microsoft Intune is ending support for Android device administrator management on devices with access to Google Mobile Services (GMS) on August 30, 2024. After that date, device enrollment, technical support, bug fixes, and security fixes will be unavailable. If you currently use device administrator management, we recommend switching to another Android management option in Intune before support ends. For more information, read Ending support for Android device administrator on GMS devices.

These Android devices are corporate, or personal/BYOD (bring your own device) devices that can access organization email, apps, and other data.

Google deprecated Android device administrator management in 2020 and Intune will be ending support for device administrator devices with access to Google Mobile Services in August 2024.

Microsoft recommends:

  • Don't enroll new devices using Android device administrator.

  • Enroll new devices using one of the other methods described in this article and/or using App protection policies.

  • Move existing Android device administrator devices to one of the other methods described in this article. If you will be moving them to Android Enterprise personally owned devices with a work profile (in this article), consider using the streamlined flow to move Android devices from device administrator to personally owned work profile management.

  • Create a device enrollment restriction to block device administrator enrollment. Android devices may try to enroll using device administrator before trying other enrollment methods. So, create the restriction to prevent this behavior. For more information, go to Set enrollment restrictions.

Next steps

  • MAM
  • iOS/iPadOS enrollment guide
  • Linux enrollment guide
  • macOS enrollment guide
  • Windows enrollment guide
Android device enrollment guide for Microsoft Intune (2024)

FAQs

How do I set up Android enrollment in Intune? ›

Create an enrollment profile
  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices > Enrollment.
  3. Select the Android tab.
  4. In the Enrollment Profiles section, choose Corporate-owned dedicated devices.
  5. Select Create profile.
  6. Enter the basics for your profile: ...
  7. Select Next to continue to Scope tags.
Jan 23, 2024

How can you use Intune to manage Android devices? ›

To enable Android Enterprise management in Intune, connect your Intune tenant account to your managed Google Play account. Set up work profile management for personally owned devices. This enrollment method creates a separate area on the device for work-related data so that personal things remain unaffected.

How do I know if my Android device is enrolled in Intune? ›

Open Android Settings and search for “work profile.” In the security settings, enable biometric / fingerprint login. You may test if your device is set up correctly by opening the Company Portal app. If you can see apps to get in the Company Portal, you have enrolled correctly.

What Android is required for Intune? ›

Intune requires Android 8. x or higher for device enrollment scenarios and app configuration delivered through Managed devices app configuration policies.

How do I enroll my Android phone with a QR code Intune? ›

On the Company Portal > Get QR code screen, tap NEXT. If you're prompted to allow the Intune app to use your camera, tap Allow. Scan the image of the QR code that's on your smart card-enabled device. The Intune app will start downloading and installing the certificates needed to access work or school resources.

What is the easiest way to enroll devices in Intune? ›

For personally owned devices, the Intune Company Portal app is the most common option. The user can download and install the Intune Company Portal app from the Microsoft Store and walk through the process within the app to enroll the device into Microsoft Intune.

Do you need an Intune license to enroll a device? ›

Whether you manually add users or synchronize from your on-premises Active Directory, you must first assign each user an Intune Plan 1 license before users can enroll their devices in Intune.

Do I need an Intune license for every device? ›

Each user using a primary device managed by Windows Intune requires a USL. Windows Intune delivers a unified PC and mobile device management solution. In all other cases an organization can switch plans but must do it manually by purchasing a new plan, reassigning licenses, and then cancelling the old plan.

What happens when a device is enrolled in Intune? ›

Your device enrolls in Microsoft Intune, a mobile device management provider, and registers with your organization. This step ensures that you're authorized to access your organization's email, apps, and Wi-Fi.

How long does it take for a device to enroll in Intune? ›

How long does the Intune Enrollment process take? We ask for your time and patience as the enrollment process can take up to 30 minutes.

What is the difference between user and device enrollment in Intune? ›

User Enrollment with the company portal is more of a streamlined enrollment process that provides a subset of device management options for admin, with user enrollment a user identity is created on the device using a managed Apple ID (federated), and the managed Apple ID can be used alongside the personal apple ID that ...

How do I enable MDM enrollment? ›

Enable Windows automatic enrollment
  1. Sign in to Microsoft Azure.
  2. Go to Microsoft Entra ID > Mobility (MDM and WIP).
  3. Select Microsoft Intune.
  4. Configure MDM User scope. Specify which users' devices should be managed by Microsoft Intune. ...
  5. Use the default values for the following URLs: MDM Terms of use URL. ...
  6. Select Save.
Nov 2, 2023

How do I create an Intune enrollment profile? ›

Create enrollment profile
  1. Sign in to the Microsoft Intune admin center.
  2. Go to Devices > iOS/iPadOS > iOS/iPadOS enrollment.
  3. Under Enrollment Options, choose Enrollment types.
  4. Select Create profile > iOS/iPadOS.
Jan 23, 2024

How do I enroll in Android Device Policy? ›

Open the Settings app and tap Accounts. Add the work account again and set up Android Device Policy. During enrollment, you must set up a work profile because it's required for Android Device Policy.

How do I register my Android device with Azure AD? ›

Follow these steps to register your app in Azure AD:
  1. Navigate to MaaS360 Settings > Corporate Settings and then tap Configure Microsoft Authenticator. ...
  2. After installing the app, tap the Configure Microsoft Authenticator option in the Corporate Settings again to initiate the device registration. ...
  3. Click Continue.
Dec 1, 2021

Top Articles
Latest Posts
Article information

Author: Gov. Deandrea McKenzie

Last Updated:

Views: 5783

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Gov. Deandrea McKenzie

Birthday: 2001-01-17

Address: Suite 769 2454 Marsha Coves, Debbieton, MS 95002

Phone: +813077629322

Job: Real-Estate Executive

Hobby: Archery, Metal detecting, Kitesurfing, Genealogy, Kitesurfing, Calligraphy, Roller skating

Introduction: My name is Gov. Deandrea McKenzie, I am a spotless, clean, glamorous, sparkling, adventurous, nice, brainy person who loves writing and wants to share my knowledge and understanding with you.