data separation

Three basic approaches are available for separating business and private data on Android devices: full device management of an organization-owned device, the managed device with a personal profile (COPE) as an organization-owned device with a separate private area, or the Work Profile as a separate container on a private device.


Full device management (Device Owner, from Android 9)

Since Relution 5 at the latest, Android Enterprise enrollment as a fully managed device (Device Owner) has become increasingly common for managing Android devices in Relution. The MDM functions are integrated into the operating system and standardized. This enables a largely vendor-independent, uniform MDM functionality on the Android platform. The Android Enterprise functions are only available for certified devices. Samsung devices can be managed and secured even more extensively with the KNOX functions. The Relution Client App is no longer mandatory for Android Enterprise Enrollment.

Additionally, the classic enrollment as device administrator is still available. In this case, the Relution Client App is provided with special rights on the device to be able to execute the MDM functions. However, with this type of enrollment, the options for MDM intervention are highly dependent on the Android device used.

A wide range of configurations and functions are available when managing Android devices:

  • Installation and configuration of apps (e.g. Exchange client)
  • Managed Google Play Store
  • WiFi and VPN configuration
  • Fully automated device enrollment (KNOX Mobile Enrollment)

Managed device with a personal profile (COPE)

With the enrollment type Set up managed device with a personal profile (Company Owned, Personally Enabled – COPE), an organization-owned device is issued to users who may also use it privately. In addition to the managed area, a personal profile is available to which administrators have neither insight nor access. Relution manages the entire device and can, for example, perform a factory reset, which also deletes all private data.

Personal profile →


Work Profile Enrollment

Android Enterprise additionally offers the so-called Work Profile, which is intended for private devices and sets up a container Work on the device that can be managed by Relution. This container contains a Managed Play Store, which only makes approved apps available for installation. Installing apps from the Managed Google Play Store is possible without a local Google account. Additionally, the apps can be configured via Relution if a Managed App Configuration is supported by the respective app (e.g. an email app with a predefined server address and user ID). The container can also contain its own address book to separate business and private contacts.

Relution cannot affect anything outside the container (Personal), e.g. the device cannot be reset to factory settings. However, the container can be removed via Relution, which deletes all the data it contains. The Lock device action is also available for devices with a work profile. Whether only the work profile or the entire device is locked depends on Android and the lock settings on the device.

Relution supports the work profile in an organization in parallel with the full device management of Android Enterprise and the classic enrollment as Device Administrator. Thus, mixed operation with different devices is possible in Relution.

Functional limitations

In addition, the following functions in the Work container can also be disabled by restriction:

  • App Block/Allowlisting
  • Creation of new users and profiles
  • Adding and removing accounts
  • Install apps
  • Uninstalling apps
  • Using the camera
  • Taking screenshots
  • Configuring and using Bluetooth
  • Sharing contacts via Bluetooth
  • Configure mobile network
  • Configure VPN
  • Using Android Beam (NFC) to share app data
  • Mount external physical media

Configuring Wi-Fi networks and transferring files via USB can only be restricted on managed devices and devices with a personal profile (COPE), not in the work profile of private devices.

Top