Setting up Android Enterprise Corporate-Owned Work Profile
Start course

In this course, we review the enrollment options available and processes to follow for enrolling Android devices in Microsoft 365.

Learning Objectives

  • An overview of the many enrollment options available for Android devices
  • Learn the prerequisites needed before enrolling Android devices in Microsoft 365 via Intune 
  • Cover Android Enterprise, Android Device Administrator, and Android Open Source Project enrollment options

Intended Audience

This course is intended for those who wish to learn about Enrolling Android devices in Microsoft 365.


You will require a basic understanding of Mobile Device Management in Microsoft 365.

Welcome to Android Enterprise Corporate-Owned Work Profiles.

So, the next Android Enterprise enrollment option that I want to cover is the Android Enterprise Corporate-Owned Work Profile, which is a single-user device that’s owned by the organization and meant for both corporate and personal use.

Setting up Android Enterprise Corporate-Owned Work Profiles allows end users to keep their work info on their devices and their personal info on those devices separate. This ensures that their personal data and applications remain private, while allowing admins to control certain features and settings of the device, including stuff like device password settings, Bluetooth and data roaming, and factory reset protection.

To use Android Enterprise Corporate-Owned Work Profiles with your devices, they must be running Android OS version 8.0 and above, and they must run a distribution of Android that offers GMS connectivity. The devices themselves must have GMS available and they need to be able to connect to GMS.

Now to set up Android Enterprise corporate-owned work profile device management, you need to set your MDM authority to Microsoft Intune, and you must connect your Intune tenant account to your Managed Google Play account. Once you’ve done this, you need to create an enrollment profile.

As was the case with the other Android options, you should also create device groups so you can target apps and policies to users and devices.

Once you’ve completed these steps, you can enroll your corporate-owned work profile devices.

Like with the other methods, when you create the enrollment profile, you receive an enrollment token and a QR code. You can use either the token or QR code to enroll your devices.

When users enroll their devices, the Microsoft Intune app is automatically installed during enrollment. Since it’s required for enrollment, it cannot be uninstalled.

I do want to mention here that when using Android Enterprise corporate-owned work profile devices, the only apps that can be installed are those that have their Assignment type set to Required. Apps are installed from the Managed Google Play store in the same manner as Android Enterprise personally-owned work profile devices, and they are automatically updated whenever the app developer publishes an update to Google Play.

About the Author
Learning Paths

Tom is a 25+ year veteran of the IT industry, having worked in environments as large as 40k seats and as small as 50 seats. Throughout the course of a long an interesting career, he has built an in-depth skillset that spans numerous IT disciplines. Tom has designed and architected small, large, and global IT solutions.

In addition to the Cloud Platform and Infrastructure MCSE certification, Tom also carries several other Microsoft certifications. His ability to see things from a strategic perspective allows Tom to architect solutions that closely align with business needs.

In his spare time, Tom enjoys camping, fishing, and playing poker.