The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.
From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)
Intune supports six ways to manage Android devices, and the right one follows from two questions: who owns the device, and is it used by one person, by many, or for one task. The table summarises the options as Microsoft Learn describes them in the Android enrolment guide. Figure 3.1 shows how ownership and use lead to the four Android Enterprise options.
Android Enterprise is Google’s management framework, and four of the options belong to it. Android (AOSP) management covers corporate devices without GMS, and Android device administrator is the legacy option that remains only for a small set of non-GMS devices.
| Option (former nickname) | Ownership and use | Needs GMS | User affinity | Factory reset before enrolment | DEM account |
|---|---|---|---|---|---|
| Personally owned work profile (BYOD) | Personal device; work apps and data in a separate work profile | Yes | Single user | No | Supported |
| Corporate-owned work profile (COPE) | Company device, one user, personal use allowed | Yes | Single user | Yes | Not supported |
| Fully managed (COBO) | Company device, one user, work use only | Yes | Single user | Yes | Not supported |
| Dedicated (COSU) | Company device, kiosk-style, single purpose, shared or userless | Yes | None | Yes | Not supported |
| AOSP userless or user-associated | Company device without GMS (headsets and similar) | No | None or single user | Yes (new devices might not need it) | Not supported |
| Device administrator (DA) | Legacy; deprecated on GMS devices | Not applicable | Single user | No | Not applicable to new designs |
Points that separate the options:
Supported versions are set per management method. Microsoft Learn’s supported platforms page lists Android 10.0 and later for the user-based methods (personally owned work profile, corporate-owned work profile, fully managed, AOSP user-based) and Android 8.0 and later for the userless methods (dedicated and AOSP userless). Intune app protection policies and managed-apps app configuration also need Android 10.0 or later.
Common trap: Treating Android device administrator as a normal choice to allow or block alongside Android Enterprise - device administrator management is deprecated and no longer available for devices with access to Google Mobile Services; Intune ended support for it on GMS devices, and Microsoft recommends blocking it with an enrolment restriction and moving devices to an Android Enterprise option.
Common trap: Enrolling shared kiosk or userless corporate devices as fully managed - fully managed is for one user and work-only use; userless, single-purpose devices belong in the dedicated option (or AOSP userless when the device has no GMS).
This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Due on Amazon in December 2026, in Kindle and paperback editions.
About the book · MD-102 terms in the glossary · All MD-102 study notes
How Microsoft Entra registered, Entra joined and hybrid joined devices differ in ownership, sign-in, management and the scenarios each one suits.
The tenant-wide compliance settings and per-platform policies behind Intune compliance, and how a device's overall status is worked out.
Which devices can back up a local admin password to Entra ID or Active Directory, and how to build the Windows LAPS policy in Intune.
How user-driven, pre-provisioned and self-deploying Autopilot modes differ in join type, user interaction and TPM requirements.
What each Enrollment Status Page setting does, from blocking apps and time limits to quality updates during OOBE, and where to create profiles.
Which Intune remote action keeps personal data and which resets the device, with platform support, wipe options and daily limits.
How Intune update rings set quality and feature update deferrals, deadlines, grace periods and restart behaviour for groups of Windows devices.
How Intune app protection policies protect work data inside apps on enrolled and personal devices, and the three-level data protection framework.