How Google lets organisations manage Android devices that run Google Mobile Services. After a Managed Google Play account is connected, Intune handles four scenarios: fully managed, dedicated, corporate-owned work profile and personally owned work profile.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Android Enterprise in context, with comparison tables and the common traps.
Terms in this definition
- MANAGE
A Unity Catalog privilege allowing a principal to grant and revoke access on an object, hand over its ownership and drop it, all without being the owner. It gives no data access by itself and is not part of
ALL PRIVILEGES. - GMS
The set of Google apps and services on Android. Android Enterprise depends on it, while corporate devices that don't have it are handled by AOSP management.
- Managed Google Play
Google's business app store for Android Enterprise. Every Android Enterprise option in Intune stays unavailable until the tenant has been linked to it.
- Intune
Microsoft's device management service, once branded Microsoft Endpoint Manager. Its compliance policies are what the compliant-device grant in Conditional Access relies on.
- Fully managed
An Android Enterprise setup for company-owned devices that one person uses only for work, with Intune in control of the entire device.
- Dedicated
Running Azure Functions on an App Service plan, which removes the execution time limit and offers VNet integration on Basic and higher tiers.
- COPE
Company-owned Android Enterprise devices that people may also use privately. A work profile keeps work apart, and Intune manages that profile as well as the device as a whole.
- Personally owned work profile
Used for bring-your-own Android devices: Intune manages a separate work area on the phone, while the owner's own apps and data remain private.
Related terms
- Android Management API
The interface Google recommends for Android Enterprise; on devices, the Android Device Policy app enforces it. Intune runs corporate-owned devices on it already, and is migrating BYOD work profile devices too, replacing Company Portal there with the Microsoft Intune app.
- AOSP
Intune's option for company-owned headsets (AR and VR) and other Android hardware lacking Google Mobile Services, with or without an associated user. Rather than going through Android Enterprise, it uses the Authenticator and Microsoft Intune apps.
- COSU
Dedicated Android Enterprise devices that the organisation owns, used by nobody in particular or shared, and restricted to a set of tasks, as a kiosk would be.
- Device staging
A way of enrolling Android Enterprise devices in which a vendor or admin completes the provisioning using a staging token. Until a person signs in to the Microsoft Intune app, it remains userless, with Staging_ at the start of its name.
- Kiosk
A locked-down mode where a device can run only one app or a few chosen apps. On Windows, kiosks can be single-app or multi-app; on Android Enterprise, fully managed and dedicated devices can both use it.
- Microsoft Entra shared device mode
Lets Android Enterprise dedicated devices (and iOS/iPadOS) be enrolled with Authenticator set to shared mode, so one sign-in, and one sign-out, applies across every MSAL-based app.
- Microsoft Tunnel
Intune's VPN solution: a gateway hosted in containers on Linux. It connects Android Enterprise and iOS/iPadOS devices to resources held on premises, and Microsoft Defender acts as the app on each device.
- OEMConfig
An Android Enterprise approach where a device maker such as Samsung or Zebra ships an OEMConfig app exposing its own hardware settings, which Intune then sets via an OEMConfig profile (only one per device).