Enrollment types

There are three different types of enrollment available for Android Enterprise. Each has special functionalities suitable for specific use cases.

Enrollment typeFactory reset requiredPersonal useAdministrator access
Managed Device →requirednot possiblefull access to the entire device
Personal profile (COPE) →requiredpossible in the personal profilefull access to the device, no insight into the personal profile
Work profile / BYOD →not requiredpossible on the rest of the deviceno access to private areas of the device

Managed Device

The Managed Device enrollment type is suitable, for example, for organizations or schools to hand over devices to users who use them exclusively for official or school activities.

  • Administrator access: full access to the device, including insight into the list of installed apps and the ability to reset the device to factory settings.
  • Requirement: the device must be reset to factory settings before it is commissioned.
  • Restriction: enrolling a private GoogleID is not possible.

Details on setup: Managed Device →


Managed Device with Personal Profile (Company Owned, Personally Enabled COPE)

The enrollment type is the counterpart to the work profile and allows devices of an organization to be issued to users who may also use them for private purposes.

  • Personal profile: users register their private GoogleID there and install their own apps; private and company-related data are strictly separated.
  • Administrator access: full access to the device, but no insight into the personal profile (e.g. no view of installed apps or activated settings).
  • Factory reset: required before the device is commissioned; a later factory reset performed by administrators deletes both private and company-related data completely.

Details on setup: Personal profile →


Work Profile / BYOD

The Work Profile enrollment type is the right choice for the Bring Your Own Device (BYOD) approach: users provide their private device, on which the organization sets up a work profile.

  • Requirement: no reset of the device is necessary.
  • Usage: the mail app or other apps of the organization can, for example, be made available within the work profile; private and organization-related data are strictly separated.
  • Administrator access: no insight into installed private apps, no access rights to functions or settings of the private device.
  • Removal: if the work profile is removed, only the organization-related data is deleted — private data is retained.

Details on setup: Work profile / BYOD →

Top