A warehouse scanner, a sales rep's Pixel and a contractor's personal Samsung all need the same Wi-Fi, the same apps and the same wipe button, but they can't be managed the same way. Android splits that problem into four management modes, and the mode you pick at enrollment decides what IT can see, lock and erase for the life of the device. This guide covers Android MDM end to end: the modes, how devices get enrolled, the policies worth setting on day one, and how the tools group so you can shortlist two or three.
TL;DR
- Android MDM today means Android Enterprise. The old device admin API lost its enterprise policies in Android 10, and Microsoft Intune no longer offers device administrator management for devices with Google Mobile Services.
- There are four modes: work profile on a personal phone, work profile on a company-owned phone, fully managed, and dedicated. Pick per device group, not per company.
- Company devices should enroll themselves. Zero-touch (and Knox Mobile Enrollment on Samsung) makes a factory-reset device re-enroll on its own. QR code and afw#setup cover everything bought outside a reseller.
- Apps flow through managed Google Play. Private apps, web apps and app config all live there, so app policy is the same whichever tool you choose.
- The tools group into suite-bundled MDM, OEM tools, specialist cross-platform MDM and self-hosted open source. The mode support is similar across them. Multi-tenancy, kiosk depth and price are what separate them.
What Android MDM Does Now
Android mobile device management is the set of policies, enrollment flows and remote actions IT uses to control company data on Android phones and tablets. The management layer lives inside Android itself. Your MDM tool sends policy, and an app on the device (Google calls it a device policy controller, or DPC) applies it.
For most of Android's history that app used the device admin API. It could enforce a password and wipe a phone, and not much else. It had no clean way to separate work data from personal data, so a BYOD enrollment meant handing IT the whole phone.
Google replaced it with Android Enterprise. The device admin policies for camera, keyguard and password rules were marked deprecated in Android 9 and stopped working for apps targeting Android 10. The password reset call stopped working in Android 11. Google's own guidance is blunt: device admin "isn't well suited to support today's enterprise requirements."
The MDM vendors followed. Microsoft's Intune deployment guide now states that Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services. If a client's fleet still enrolls through device admin, that's the first thing to fix, because each new Android release removes a little more of what it can do.
Everything below assumes Android Enterprise. When a vendor says "Android MDM" in 2026, that's what they should mean. Ask if it isn't clear.
The Four Android Enterprise Modes
Android Enterprise gives you four ways to manage a device. The difference between them is who owns the phone and how much of it IT controls.
Work profile on a personal device. This is the BYOD mode. Android creates a separate, self-contained space for work apps and data, marked with a briefcase badge. IT manages the work profile only. Personal apps, photos and messages stay out of reach, and an unenrollment removes the profile, not the owner's data. It works on Android 5.1 and later.
Work profile on a company-owned device. The company buys the phone, the employee gets a personal side. Google's documentation is explicit that the personal profile's apps, data and usage aren't visible to the organization. IT does get some device-level controls it wouldn't have on a personal phone, and it can wipe the whole device when it's returned. This is the mode for a company phone that people will inevitably use for WhatsApp and banking.
Fully managed. A work-only company device. IT can apply the full range of Android's management policies, including device-level controls that work profiles can't touch. Sales reps, field techs and executives whose phones hold client data usually land here.
Dedicated. A fully managed device locked to one app or a small set of apps. Scanners, point-of-sale tablets, check-in kiosks and digital signage. IT controls the lock screen, status bar, keyboard and system buttons, and the device often has no named user at all.
| Mode | Who owns it | What IT controls | What IT can't see | Typical device |
|---|---|---|---|---|
| Work profile (personal) | Employee | Work apps and data only | Personal apps, data, usage | Contractor's own phone |
| Work profile (company-owned) | Company | Work profile plus some device controls | The personal profile | Company phone with personal use allowed |
| Fully managed | Company | The whole device | Nothing is carved out | Field tech, sales, execs |
| Dedicated | Company | The whole device, locked to set apps | Nothing is carved out | Scanner, kiosk, POS tablet |
The mode is chosen at enrollment. You can't flip a personal work profile into a fully managed device later without a factory reset, so settle it before the first phone ships.
How to Pick a Mode for Each Device Group
Choose modes per device group, not per company. A single client can easily need three of the four.
Start with ownership. If the employee owns the phone, the only mode is a personal work profile. Anything more invasive won't survive the first conversation with a privacy-minded employee, and in some regions it won't survive legal review either. Our BYOD policy template covers the paperwork side of that conversation.
If the company owns the phone, ask whether personal use is allowed. If it is, a company-owned work profile keeps the personal side private and still lets IT wipe everything when someone leaves. If it isn't, fully managed gives you the full policy set with no personal side to worry about.
Then ask whether a person uses the device at all. A tablet bolted to a reception desk or a scanner that moves between shifts is a dedicated device. It needs kiosk lockdown, not a user profile.
Three edge cases come up again and again. Devices shared between shifts are dedicated, often with a shared sign-in app on top so each worker signs in and out without IT resetting anything. Executives who refuse a work profile get a fully managed company phone they carry alongside their own, and the second phone ends the argument faster than any policy. Contractors get a personal work profile, or app protection with no enrollment at all if the only company data is email and Teams.
App protection without enrollment deserves a note. Intune, for example, can protect data inside Outlook, Teams and Office apps without the phone being enrolled. That's enough for a contractor who reads email. It isn't device management, so there's no Wi-Fi profile, no certificate and no wipe of the device.
This r/sysadmin thread asks the question every Android rollout starts with, and the replies are worth skimming for which tools admins already run.
Tool recommendations are the easy half. Decide the modes first, then check each tool supports them the way you need.
Enrollment Methods: Zero-Touch, QR, NFC and More
Enrollment is where Android MDM saves or burns technician hours. The method you use depends on who owns the device and where it was bought.
Zero-touch enrollment. The device is registered to your organization by the reseller at purchase. On first boot it checks in, finds its configuration, and provisions itself as a fully managed or company-owned work profile device, downloading the right management app. Google's help page notes that it repeats the process after a factory reset and shows a "Your device at work" screen. That's the part that matters: a stolen phone that gets wiped comes back up managed. Zero-touch needs Android 9 or later (or a compatible Android 8 device, or a Pixel on Android 7), a purchase through an authorized zero-touch reseller, and a zero-touch account the reseller creates for you.
Google's own overview walks through the reseller, portal and first-boot flow:
Knox Mobile Enrollment. Samsung's equivalent for Samsung devices. Resellers upload device IDs through the Knox Reseller Portal, you approve the upload and assign a profile, and the device enrolls at boot. Samsung lists it as free to use. An MDM that supports both zero-touch and Knox Mobile Enrollment lets a mixed fleet use each where it fits.
QR code. Tap the welcome screen six times during setup, scan a QR code from your MDM console, and the device provisions itself. It works on Android 7.0 and later for company-owned devices, and it's the default for phones bought at retail.
afw#setup. Type afw#setup into the Google account field during setup, and the device downloads the management app and walks through enrollment. Useful when the camera is broken or a QR code isn't to hand.
NFC. Bump a provisioning device against the new one. It supports fully managed and dedicated provisioning on Android 6.0 and later, but Google's documentation notes it can't provision a company-owned work profile on Android 11. It's handy for rugged fleets where devices sit side by side on a bench.
Personal devices. For BYOD, the user adds a work profile from Settings, installs the management app from Play, or opens an enrollment link your MDM generates.
Enrollment tokens have a default life too. In the Android Management API, a token expires after one hour unless you set a longer duration. A QR code printed for a rollout day can be dead by lunch, so generate them with an expiry that matches the job.
| Method | Ownership | Modes | Needs |
|---|---|---|---|
| Zero-touch | Company | Fully managed, company-owned work profile | Authorized reseller, Android 9+ (or compatible 8) |
| Knox Mobile Enrollment | Company | Same, Samsung only | Samsung reseller upload |
| QR code | Company | Fully managed, dedicated, company-owned work profile | Android 7.0+, tap setup screen |
| afw#setup | Company | Same as QR | Google account field at setup |
| NFC | Company | Fully managed, dedicated | Android 6.0+, not company-owned work profile on 11 |
| Settings, Play or link | Personal | Work profile | Android 5.1+ |
The rule for a client fleet is simple. Buy company devices through a zero-touch or Knox reseller whenever you can, and reserve QR codes for the phones that came from somewhere else.
Apps Through Managed Google Play
Android MDM tools all deliver apps the same way: managed Google Play. When you connect an MDM to your organization's managed Google Play account, you approve apps there and the MDM assigns them to devices or users.
Three kinds of app live there. Public apps appear in the work Play Store only after you approve them, so users can't install random tools into the work profile. Private apps are line-of-business apps published only to your organization, with no public listing. Web apps are links packaged as an app icon, handy for an intranet or a ticket portal.
App configuration rides along. Apps that support managed configuration, like Outlook, Chrome or a VPN client, can be pre-filled with server addresses, account names and restrictions, so users open them already set up. OEM-specific settings on devices like Zebra and Samsung arrive through OEMConfig apps, also delivered through managed Google Play.
This is also why Android MDM tools feel similar in daily use. App delivery, app config and the work Play Store come from Google. Where tools differ is the console on top: how you group devices, how policy inheritance works across clients, and how fast you can find a device when someone calls.
Policies Worth Setting on Day One
A new Android MDM rollout doesn't need every policy on the list. It needs the dozen that close the obvious gaps, set before the first user enrolls.
| # | Policy | What to set | Why it matters |
|---|---|---|---|
| 1 | Screen lock | PIN or stronger, auto-lock at 5 minutes or less | The only barrier on a lost phone |
| 2 | Encryption | Required (on by default on modern Android) | Protects data at rest |
| 3 | OS version | Minimum supported version in a compliance rule | Blocks phones that stopped getting patches |
| 4 | Security patch level | Maximum age in a compliance rule | Catches devices a manufacturer abandoned |
| 5 | Play Protect | On, with apps from unknown sources blocked | Stops sideloaded malware |
| 6 | Developer options and USB debugging | Off on company devices | Removes an easy path around policy |
| 7 | Copy and paste | Blocked from work to personal apps | Keeps client data in the work profile |
| 8 | Wi-Fi and VPN profiles | Pushed from the MDM, certificates where possible | Ends password sharing on sticky notes |
| 9 | Factory reset protection | Company account set on company devices | A wiped stolen phone stays useless |
| 10 | System updates | Automatic or a maintenance window | Updates install before users can defer forever |
| 11 | Compliance action | Block email and files when noncompliant | Makes the rules above mean something |
| 12 | Lost device | Test remote lock and wipe on one device first | You find the gap before a real loss does |
Patch level deserves its own mention. Google's Android Enterprise Recommended program requires listed manufacturers to ship Android security updates within 90 days of Google releasing them, and rugged devices in the program get that commitment for five years from their ship date. Devices outside the program may stop getting patches much sooner. A compliance rule on patch age turns that from a buying note into something you enforce.
Identity sits alongside all of this. Conditional access that checks MDM compliance before granting email or file access is where device policy stops being advisory, and our IAM solutions guide covers that side.
Dedicated Devices and Kiosk Mode
Dedicated devices are where Android MDM earns its keep. A tablet at a front desk or a handheld in a warehouse has one job, and anything else it can do is a support ticket waiting to happen.
Android's lock task mode pins the device to an allowlist of apps. Single-app kiosk mode launches one app and hides everything else. Multi-app kiosk mode swaps the home screen for a managed launcher that shows only the approved apps; Microsoft's Managed Home Screen is one example, and every kiosk-capable MDM has its own.
The settings that make a kiosk hold are small and specific:
- Hide or lock the status bar so users can't pull down quick settings.
- Disable the home, recent apps and power menu buttons.
- Block Settings, or expose only Wi-Fi and brightness through the launcher.
- Set an exit PIN for technicians and keep it out of the kiosk's line of sight.
- Schedule reboots and app updates for the hours the device is idle.
Rugged fleets add OEM settings on top. Zebra's Mobility Extensions and Samsung Knox settings reach things generic Android policy can't, like scanner configuration and hardware button mapping, delivered through OEMConfig.
Test every kiosk with the most curious person you know. If they can reach a browser in two minutes, a bored shift worker will find it in one.
Android MDM Tools: How the Options Group
A shortlist is easier when you stop comparing twenty tools and compare four kinds. Android Enterprise support is broadly similar across serious tools because Google supplies the modes, enrollment and app delivery. The differences sit in who the tool is built for.
Suite-bundled MDM. Microsoft Intune comes with Microsoft 365 plans that include it, and Google's endpoint management comes with Google Workspace. Workspace's basic mobile management covers passwords, managed apps and remote wipe across its Business, Enterprise and Frontline editions; advanced management adds app management and device audits. If a client already pays for one of these suites, start there and only move off it if it can't do something you need.
OEM tools. Samsung Knox Manage and similar tools go deepest on one manufacturer's hardware. They fit fleets that are all Samsung or all Zebra, and they lose appeal as soon as the fleet mixes brands.
Specialist cross-platform MDM. Tools like ManageEngine MDM Plus, Scalefusion, Hexnode and Miradore manage Android alongside iOS, Windows and macOS from one console, and several include kiosk depth that suite tools lack. Our MDM solutions comparison covers this group across platforms.
For the iPhones in the same fleet, the Apple MDM guide compares the options for multi-tenant MSPs.
Self-hosted open source. Headwind MDM is an Apache-2.0 licensed Android MDM with a web control panel you run yourself. It suits teams that want Android management without a per-device subscription and are comfortable owning the server.
Five questions narrow the list fast:
- Does it support all four modes you picked, including company-owned work profile?
- Does it support zero-touch and Knox Mobile Enrollment, not just QR codes?
- For MSPs, is it multi-tenant, with separate policies and billing per client?
- How deep is kiosk mode: single-app, multi-app, custom launcher, scheduled reboots?
- Does it sit in the same console as the rest of the fleet, or add another tab?
For admins weighing the same trade-off, this r/sysadmin thread on MDM and Android is a quick read.
There's no wrong answer, only a cost to each. One more tab means one more place policy drifts. One suite means living with its kiosk and multi-tenant limits.
Rolling Out Android MDM Across Client Fleets
For an MSP, Android MDM is less a tool choice than a repeatable rollout. The same six steps work for a ten-phone office and a two-hundred-device warehouse.
1. Inventory what exists. Count devices by owner, model and Android version, and flag anything still on device admin. Anything below your minimum OS version goes on a replacement list before enrollment starts.
2. Assign modes per group. Use the decision flow above and write it down per client. The mode map becomes the policy map.
3. Connect the plumbing. Bind managed Google Play, set up the zero-touch or Knox portal with each client's reseller, and create enrollment profiles per mode.
4. Build a baseline policy set. The day-one table above, cloned per client with only the Wi-Fi, VPN and app list changing. Resist per-client custom policies unless a contract demands them.
5. Pilot on three devices. One per mode you're deploying. Enroll, apply policy, test email, test a remote lock and a wipe, then factory reset one company device and confirm it re-enrolls.
6. Enroll the rest and set a review date. Compliance reports show you which devices fall behind on patches. Review them monthly with the client, alongside everything else in the RMM report.
The CLOUDINFRA demo below walks through a fully managed enrollment step by step, useful for training the tech who'll run step 5:
Mobile devices are one part of the fleet, and the laptops and servers next to them need the same visibility. OpenFrame, Flamingo's open, AI-native infrastructure layer for IT and security, keeps a device inventory across a client's endpoints and can run scripts across them with the output collected in one place.
The Short Version
Android MDM means Android Enterprise now, and anything still on device admin belongs on the migration list. Choose one of four modes per device group based on who owns the phone and whether a person uses it. Buy company devices through a zero-touch or Knox reseller so they enroll and re-enroll on their own. Set a dozen day-one policies, make compliance block access, and test a wipe before you need one. Then pick a tool by the modes, enrollment, tenancy and kiosk depth you need. For the cross-platform view, read our unified endpoint management guide next.

Aliaska Varieva
Head of Platform
Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.
