Corporate-owned work profile enrollment

computerpaul2 16 Reputation points
2021-04-09T14:49:34.383+00:00

This question comes from MS doc found here: https://learn.microsoft.com/en-us/mem/intune/enrollment/android-dedicated-devices-fully-managed-enroll

When we switched from device administrator to Android Enterprise, having a work profile was the only enrollment option unless you wanted a fully managed device like for a kiosk. The work profile was a bit different, but we like it a lot having corporate data separated. A few months ago, we noticed there is an additional enrollment profile as well as compliance policies distinguishing between "Corporate-owned devices with work profile" and "Personally-owned devices with work profile". We still have the ability to apply Personal vs Corporate device ownership, but now we have these 2 mostly identical enrollment profiles where the only difference is that for corporate owned devices you have to enter in the "afw#setup" on a FRESH WIPED device.

Will there ever be a way to configure "Corporate-owned devices with work profile" without requiring the device be wiped first? If not, it will be quite the undertaking moving from Android device administrator if we tell everyone they need to wipe their phones first. For personal devices with a work profile it is not required, so what are the technical differences?

Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,244 questions
0 comments No comments
{count} votes

6 answers

Sort by: Most helpful
  1. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-04-09T15:30:42.82+00:00

    This is a question for Google. Intune is simply using the device management modes made available by the underlying Android platform and is thus subject to the design and constraints of those modes and their constraints.

    0 comments No comments

  2. computerpaul2 16 Reputation points
    2021-04-09T15:47:54.167+00:00

    I appreciate the quick reply, but after checking Android Ent documentation, they only have 3 deployment types whereas Microsoft added a 4th...
    86335-image.png

    86326-image.png

    0 comments No comments

  3. Jason Sandys 31,151 Reputation points Microsoft Employee
    2021-04-09T16:11:04.66+00:00

    I don't remember the exact mapping off-hand, but two of the Intune modes simply map to one of Android modes. I think it's the Personally-owner devices with work-profile and Corporate owned devices with work profile are just variations of the Personally-enabled Android mode.

    We in no way did or can change how Android works.

    0 comments No comments

  4. computerpaul2 16 Reputation points
    2021-04-09T19:49:47.127+00:00

    Yea absolutely. I wasn't suggesting a change in how Android works. Simply inquiring about the reasoning for a "company owned work profile" AND a "employee owned work profile". For all of our company owned devices that have a work profile now, it makes it seem like they are personal owned devices because of the enrollment profile.

    In order to get that device to show "corporate-owned" in the OS column, I had to wipe it first.
    86405-image.png

    Everything else between these devices are the same.

    Since we're moving away from Android device administrator, I'm trying to figure out if I need to tell every employee with a corporate phone that they need to wipe the device to continue using it.

    0 comments No comments

  5. Lu Dai-MSFT 28,341 Reputation points
    2021-04-12T06:36:43.217+00:00

    @computerpaul2 Thanks for posting in our Q&A.

    For this issue, based on the official article that you provided, I find that Intune enrollment for dedicated devices, fully managed devices, and corporate-owned with a work profile start with a factory reset. So, it is needed to wipe the corporate devices before enrollment.

    Thanks for understanding and have a nice day.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.