Category Filter
 
 

Last updated: August 13, 2026

Android Device Management

This page provides a comprehensive overview of Android Device Management in MDM, covering three management modes — Fully Managed (Fully Managed (COSU and COBO, or previously Device Owner)), Work Profile (Personally-Owned Work Profile (BYOD, or previously Profile Owner)), and Fully Managed with Work Profile — along with their supported enrollment methods such as Zero Touch, Knox Mobile Enrollment, QR Code, NFC, and ADB for corporate devices, and QR Code, User Invitation, and Self Enrollment for BYOD. A detailed feature comparison table helps IT administrators select the most suitable management approach for their organizational security and compliance requirements.

Android Device Management in MDM enables IT administrators to centrally manage and secure Android devices across their organization. This document provides a comprehensive guide to the different management types available, such as Fully Managed (COSU and COBO, or previously Device Owner) and Personally-Owned Work Profile (BYOD, or previously Profile Owner) modes, and outlines the supported enrollment methods for each. It also includes a detailed comparison of features based on the chosen management type, helping admins select the most suitable approach for their organizational needs.


Android Management Mode

 

Scenarios

 

Enrollment Methods

 


Work Profile (Personally-Owned Work Profile (BYOD, or previously Profile Owner))
  • Used for employee-owned devices or BYOD
  • Secure container for work apps and policies
  • No control over personal apps and data
  1. Using a direct QR Code or Enrollment link
  2. Self Enrollment
  3. User invitations


Fully Managed (Fully Managed (COSU and COBO, or previously Device Owner))
  • Used for Company-owned devices
  • Devices deployed in kiosk mode;
    dedicated devices locked down to run only work applications



 

  1. Zero touch Enrollment
  2. Knox Mobile Enrollment
  3. QR Code (EMM Token) Enrollment
  4. NFC Enrollment
  5. ADB Enrollment

Fully Managed with a Work Profile
(Work Profile on Company-Owned Devices)

Company-owned devices with work and
personal profile separation, allowing employees
to use their devices for both work 
and personal activities while maintaining security and privacy

Android Device Management Types

  1. Company-Owned Device Management: For devices purchased and owned by the organization, ensuring full control and security. 
    Company-Owned Fully Managed Devices with a Work Profile: Company-owned devices configured with separate work and personal profiles, enabling employees to securely use the same device for both professional and personal purposes while ensuring privacy and corporate data protection. 
    Enrollment Methods:
    • Zero Touch Enrollment: 
      When to Use:
      1. You are deploying Android 9.0 or later devices purchased from authorized Zero-touch reseller partners.
      2. Large-scale enterprise roll-outs require hands-free, one-time setup.
      3. You need mandatory MDM management, applied automatically at first boot.
      4. Resellers can directly add devices to the Zero-touch portal, reducing admin effort.
      5. Devices should receive pre-assigned apps, profiles, and configurations automatically. 
        To learn more, visit our Zero Touch Enrollment guide.
    • Knox Mobile Enrollment: 
      When to Use:
      1. Your organization manages Samsung devices (running Android 6.0 or later).
      2. Devices are purchased from Samsung or KME-authorized resellers.
      3. You want a Samsung-specific equivalent of Zero-touch enrollment with added Knox security.
      4. Admins need to enforce MDM enrollment automatically on Samsung devices during initial setup.
      5. Ideal for enterprises standardising on Samsung hardware. 
        You can choose to enroll Samsung devices using Knox mobile enrollment, irrespective of the OS version if they are Knox-capable. You can view the list of Knox-capable devices. Additionally, you can also choose to enroll Samsung devices using QR code and NFC for bulk enrollment. 
        To learn more, visit our Knox Mobile Enrollment guide.
    • QR Code(EMM Token) Enrollment: 
      When to Use:
      1. Devices are not purchased from Zero-touch or Knox reseller partners.
      2. You are enrolling individual devices or small batches.
      3. The device supports Android 6.0 or later with a factory reset state.
      4. Enrollment needs to be done by scanning a QR code or entering an EMM token at the setup wizard.
        To learn more, visit our QR Code Enrollment guide.
    • NFC Enrollment: 
      When to Use: This is the faster enrollment. It requires the NFC Admin app and an NFC tag to be procured. Once set up, the admin can enroll a device by simply tapping it, eliminating the need to manually scan a QR code or enter a token. To learn more, visit our NFC Enrollment guide.
    • Android Debug Bridge (ADB) Enrollment: 
      When to Use: Use ADB enrollment for devices that are already set up and in use. These devices may already have apps, settings, or data on them, and this method allows you to enroll them into MDM without resetting or starting from scratch. It is also suitable for devices that do not have Google Play Services. To learn more, visit our ADB Enrollment guide.
  2. Personal Device Management (BYOD - Bring Your Own Device): For employee-owned Personal devices accessing corporate resources. 
    Enrollment Methods:
    • Direct QR Code Enrollment: IT Admin need to share the Enrollment URL or the QR Code with the user to enroll their personal devices.
    • User Invitation Enrollment: 
      When to Use:
      1. Admins want to invite single/bulk users via email or SMS with enrollment details.
      2. Suitable for both BYOD and corporate-owned personal devices.
      3. Best for larger groups or scenarios where users need guided instructions.
      4. Ensures each user receives a personalized enrollment link. 
        To learn more, visit our User Invitation Enrollment guide.
    • Self Enrollment: 
      When to Use:
      1. Administrators need to share the Self enrollment QR code or the Enrollment URL by Promoting Self Enrollment in the organization.
      2. Users need to download the MDM app from the Playstore and enroll their own devices using the Self Enrollment QR Code or the Enrollment URL.
      3. It Reduces IT admin overhead since users initiate the process themselves. 
        To learn more, visit our Self Enrollment guide.

Comparison of Supported Functionality by Management Type

This section outlines the key functionality available for each Android device management type, helping IT admins choose the right approach based on security and functionality requirements.

FunctionalityFully ManagedWork Profile on a 
Company owned device
Personal Device
Policy
PasscodeSupportedSupportedSupported
RestrictionsSupportedSupportedSupported
Workspace SecurityNot supportedSupportedSupported
WiFiSupportedSupportedSupported
VPNSupportedSupportedSupported
EmailNot supported
Applicable only for Samsung
Not supportedNot supported
Exchange ActiveSyncSupportedSupportedSupported
EFRPSupportedNot supportedNot supported
KioskSupportedNot supportedNot supported
WallpaperSupportedNot supportedNot supported
Asset Tag InformationSupportedNot supportedNot supported
Sound SettingsSupportedNot supportedNot supported
Global HTTP ProxySupportedSupportedSupported
CertificateSupportedSupportedSupported
SCEPSupportedSupportedSupported
Web ShortcutSupportedSupportedSupported
Web Content FilterSupportedSupportedSupported
Access Point NameSupportedNot supportedNot supported
OEM ConfigurationsSupportedSupportedSupported
APPS & UPDATE MANAGEMENT
Silent Installation of the Play Store AppsSupportedSupportedSupported
Silent Installation of in-house AppsSupportedNot supported
Requires user permission every time an in-house app is pushed
Not supported
Requires user permission every time an in-house app is pushed
Restricting side-loaded AppsSupportedSupportedSupported
Automate OS UpdatesSupportedNot supportedNot supported
Block listing AppsSupportedSupportedSupported
Multiple versions of in-house AppsSupportedSupportedSupported
Inventory
Device details such as model name, manufacturer name, UDID, etc.SupportedSupportedSupported
Limited
Tracking Device Battery LevelSupportedSupportedSupported
Locate DeviceSupportedSupportedSupported
Real Time Device AlertsSupportedSupportedSupported
Restart DeviceSupportedNot supportedNot supported
Tools
AnnouncementsSupportedSupportedSupported
Remote Troubleshooting (Remote Control and View)
Remote ControlSupportedNot supportedNot supported
Remote ViewSupportedSupportedSupported
Security Management
ContainerizationNot supportedSupportedSupported
Complete Wipe of the deviceSupportedNot supportedNot supported
Corporate Wipe of the deviceSupportedSupportedSupported
Remote LockSupportedSupportedSupported
Lost ModeSupportedSupportedSupported
Restrict users from resetting the deviceSupportedNot supportedNot supported
Restrict users from revoking MDM management.SupportedSupportedSupported
Clear/ Reset PasscodeSupportedSupportedSupported

Frequently Asked Questions

1. What are the two main Android management modes in ManageEngine MDM?

ManageEngine MDM supports two modes: Company-Owned Work Profile (WPCO/COPE, or Workspace Managed) (Personally-Owned Work Profile (BYOD, or previously Profile Owner)), which creates a separate work profile on BYOD or personal devices, and Full Device Management (Fully Managed (COSU and COBO, or previously Device Owner)), which gives the administrator complete control over corporate-owned devices.

2. Does ManageEngine MDM support managing Android devices without Google Services?

Yes. ManageEngine MDM supports managing AOSP (Android Open Source Project) devices that do not have Google Mobile Services, which is common for rugged, industrial, or custom-built Android devices.

3. Can Android enterprise management be used for both company-owned and personal devices?

Yes. Android enterprise supports both corporate-owned fully managed devices (Fully Managed (COSU and COBO, or previously Device Owner)) and personally owned devices with a work profile (Personally-Owned Work Profile (BYOD, or previously Profile Owner)/BYOD), allowing administrators to choose the appropriate management scope based on device ownership.

Jump To