FREE STUDY NOTES · MD-102

Intune Android management options: work profile, fully managed, dedicated and AOSP

The six ways Intune manages Android devices, from personal work profiles to fully managed, dedicated and AOSP, and how to choose between them.

From Ultra Transcenders MD-102 by Tony Rough (coming December 2026)

Intune supports six ways to manage Android devices, and the right one follows from two questions: who owns the device, and is it used by one person, by many, or for one task. The table summarises the options as Microsoft Learn describes them in the Android enrolment guide. Figure 3.1 shows how ownership and use lead to the four Android Enterprise options.

A decision tree. User-owned devices go to the personally owned work profile. Organisation-owned devices branch by use into corporate-owned work profile, fully managed and dedicated. Each option shows its use, what Intune manages, whether there is personal space and whether a factory reset comes first.
Figure 3.1: Choosing an Android Enterprise management option

Android Enterprise is Google’s management framework, and four of the options belong to it. Android (AOSP) management covers corporate devices without GMS, and Android device administrator is the legacy option that remains only for a small set of non-GMS devices.

Option (former nickname) Ownership and use Needs GMS User affinity Factory reset before enrolment DEM account
Personally owned work profile (BYOD) Personal device; work apps and data in a separate work profile Yes Single user No Supported
Corporate-owned work profile (COPE) Company device, one user, personal use allowed Yes Single user Yes Not supported
Fully managed (COBO) Company device, one user, work use only Yes Single user Yes Not supported
Dedicated (COSU) Company device, kiosk-style, single purpose, shared or userless Yes None Yes Not supported
AOSP userless or user-associated Company device without GMS (headsets and similar) No None or single user Yes (new devices might not need it) Not supported
Device administrator (DA) Legacy; deprecated on GMS devices Not applicable Single user No Not applicable to new designs

Points that separate the options:

Supported versions are set per management method. Microsoft Learn’s supported platforms page lists Android 10.0 and later for the user-based methods (personally owned work profile, corporate-owned work profile, fully managed, AOSP user-based) and Android 8.0 and later for the userless methods (dedicated and AOSP userless). Intune app protection policies and managed-apps app configuration also need Android 10.0 or later.

Common trap: Treating Android device administrator as a normal choice to allow or block alongside Android Enterprise - device administrator management is deprecated and no longer available for devices with access to Google Mobile Services; Intune ended support for it on GMS devices, and Microsoft recommends blocking it with an enrolment restriction and moving devices to an Android Enterprise option.

Common trap: Enrolling shared kiosk or userless corporate devices as fully managed - fully managed is for one user and work-only use; userless, single-purpose devices belong in the dedicated option (or AOSP userless when the device has no GMS).

Get the whole book

This note is one section of Ultra Transcenders MD-102: Managing and Securing Microsoft 365 Endpoints by using Intune, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.

Amazon.co.ukKindle: coming soonPaperback: coming soon
Amazon.comKindle: coming soonPaperback: coming soon

Due on Amazon in December 2026, in Kindle and paperback editions.

About the book · MD-102 terms in the glossary · All MD-102 study notes

More MD-102 study notes