Flamingo Raises $4.5M Seed Round

Skip to content

A warehouse scanner, a sales rep's Pixel and a contractor's personal Samsung all need the same Wi-Fi, the same apps and the same wipe button, but they can't be managed the same way. Android splits that problem into four management modes, and the mode you pick at enrollment decides what IT can see, lock and erase for the life of the device. This guide covers Android MDM end to end: the modes, how devices get enrolled, the policies worth setting on day one, and how the tools group so you can shortlist two or three.

TL;DR

  • Android MDM today means Android Enterprise. The old device admin API lost its enterprise policies in Android 10, and Microsoft Intune no longer offers device administrator management for devices with Google Mobile Services.
  • There are four modes: work profile on a personal phone, work profile on a company-owned phone, fully managed, and dedicated. Pick per device group, not per company.
  • Company devices should enroll themselves. Zero-touch (and Knox Mobile Enrollment on Samsung) makes a factory-reset device re-enroll on its own. QR code and afw#setup cover everything bought outside a reseller.
  • Apps flow through managed Google Play. Private apps, web apps and app config all live there, so app policy is the same whichever tool you choose.
  • The tools group into suite-bundled MDM, OEM tools, specialist cross-platform MDM and self-hosted open source. The mode support is similar across them. Multi-tenancy, kiosk depth and price are what separate them.

What Android MDM Does Now

Android mobile device management is the set of policies, enrollment flows and remote actions IT uses to control company data on Android phones and tablets. The management layer lives inside Android itself. Your MDM tool sends policy, and an app on the device (Google calls it a device policy controller, or DPC) applies it.

For most of Android's history that app used the device admin API. It could enforce a password and wipe a phone, and not much else. It had no clean way to separate work data from personal data, so a BYOD enrollment meant handing IT the whole phone.

Google replaced it with Android Enterprise. The device admin policies for camera, keyguard and password rules were marked deprecated in Android 9 and stopped working for apps targeting Android 10. The password reset call stopped working in Android 11. Google's own guidance is blunt: device admin "isn't well suited to support today's enterprise requirements."

The MDM vendors followed. Microsoft's Intune deployment guide now states that Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services. If a client's fleet still enrolls through device admin, that's the first thing to fix, because each new Android release removes a little more of what it can do.

Everything below assumes Android Enterprise. When a vendor says "Android MDM" in 2026, that's what they should mean. Ask if it isn't clear.

The Four Android Enterprise Modes

Android Enterprise gives you four ways to manage a device. The difference between them is who owns the phone and how much of it IT controls.

Work profile on a personal device. This is the BYOD mode. Android creates a separate, self-contained space for work apps and data, marked with a briefcase badge. IT manages the work profile only. Personal apps, photos and messages stay out of reach, and an unenrollment removes the profile, not the owner's data. It works on Android 5.1 and later.

Work profile on a company-owned device. The company buys the phone, the employee gets a personal side. Google's documentation is explicit that the personal profile's apps, data and usage aren't visible to the organization. IT does get some device-level controls it wouldn't have on a personal phone, and it can wipe the whole device when it's returned. This is the mode for a company phone that people will inevitably use for WhatsApp and banking.

Fully managed. A work-only company device. IT can apply the full range of Android's management policies, including device-level controls that work profiles can't touch. Sales reps, field techs and executives whose phones hold client data usually land here.

Dedicated. A fully managed device locked to one app or a small set of apps. Scanners, point-of-sale tablets, check-in kiosks and digital signage. IT controls the lock screen, status bar, keyboard and system buttons, and the device often has no named user at all.

ModeWho owns itWhat IT controlsWhat IT can't seeTypical device
Work profile (personal)EmployeeWork apps and data onlyPersonal apps, data, usageContractor's own phone
Work profile (company-owned)CompanyWork profile plus some device controlsThe personal profileCompany phone with personal use allowed
Fully managedCompanyThe whole deviceNothing is carved outField tech, sales, execs
DedicatedCompanyThe whole device, locked to set appsNothing is carved outScanner, kiosk, POS tablet

The mode is chosen at enrollment. You can't flip a personal work profile into a fully managed device later without a factory reset, so settle it before the first phone ships.

How to Pick a Mode for Each Device Group

Choose modes per device group, not per company. A single client can easily need three of the four.

Start with ownership. If the employee owns the phone, the only mode is a personal work profile. Anything more invasive won't survive the first conversation with a privacy-minded employee, and in some regions it won't survive legal review either. Our BYOD policy template covers the paperwork side of that conversation.

If the company owns the phone, ask whether personal use is allowed. If it is, a company-owned work profile keeps the personal side private and still lets IT wipe everything when someone leaves. If it isn't, fully managed gives you the full policy set with no personal side to worry about.

Then ask whether a person uses the device at all. A tablet bolted to a reception desk or a scanner that moves between shifts is a dedicated device. It needs kiosk lockdown, not a user profile.

Three edge cases come up again and again. Devices shared between shifts are dedicated, often with a shared sign-in app on top so each worker signs in and out without IT resetting anything. Executives who refuse a work profile get a fully managed company phone they carry alongside their own, and the second phone ends the argument faster than any policy. Contractors get a personal work profile, or app protection with no enrollment at all if the only company data is email and Teams.

App protection without enrollment deserves a note. Intune, for example, can protect data inside Outlook, Teams and Office apps without the phone being enrolled. That's enough for a contractor who reads email. It isn't device management, so there's no Wi-Fi profile, no certificate and no wipe of the device.

This r/sysadmin thread asks the question every Android rollout starts with, and the replies are worth skimming for which tools admins already run.

Tool recommendations are the easy half. Decide the modes first, then check each tool supports them the way you need.

Enrollment Methods: Zero-Touch, QR, NFC and More

Enrollment is where Android MDM saves or burns technician hours. The method you use depends on who owns the device and where it was bought.

Zero-touch enrollment. The device is registered to your organization by the reseller at purchase. On first boot it checks in, finds its configuration, and provisions itself as a fully managed or company-owned work profile device, downloading the right management app. Google's help page notes that it repeats the process after a factory reset and shows a "Your device at work" screen. That's the part that matters: a stolen phone that gets wiped comes back up managed. Zero-touch needs Android 9 or later (or a compatible Android 8 device, or a Pixel on Android 7), a purchase through an authorized zero-touch reseller, and a zero-touch account the reseller creates for you.

Google's own overview walks through the reseller, portal and first-boot flow:

Knox Mobile Enrollment. Samsung's equivalent for Samsung devices. Resellers upload device IDs through the Knox Reseller Portal, you approve the upload and assign a profile, and the device enrolls at boot. Samsung lists it as free to use. An MDM that supports both zero-touch and Knox Mobile Enrollment lets a mixed fleet use each where it fits.

QR code. Tap the welcome screen six times during setup, scan a QR code from your MDM console, and the device provisions itself. It works on Android 7.0 and later for company-owned devices, and it's the default for phones bought at retail.

afw#setup. Type afw#setup into the Google account field during setup, and the device downloads the management app and walks through enrollment. Useful when the camera is broken or a QR code isn't to hand.

NFC. Bump a provisioning device against the new one. It supports fully managed and dedicated provisioning on Android 6.0 and later, but Google's documentation notes it can't provision a company-owned work profile on Android 11. It's handy for rugged fleets where devices sit side by side on a bench.

Personal devices. For BYOD, the user adds a work profile from Settings, installs the management app from Play, or opens an enrollment link your MDM generates.

Enrollment tokens have a default life too. In the Android Management API, a token expires after one hour unless you set a longer duration. A QR code printed for a rollout day can be dead by lunch, so generate them with an expiry that matches the job.

MethodOwnershipModesNeeds
Zero-touchCompanyFully managed, company-owned work profileAuthorized reseller, Android 9+ (or compatible 8)
Knox Mobile EnrollmentCompanySame, Samsung onlySamsung reseller upload
QR codeCompanyFully managed, dedicated, company-owned work profileAndroid 7.0+, tap setup screen
afw#setupCompanySame as QRGoogle account field at setup
NFCCompanyFully managed, dedicatedAndroid 6.0+, not company-owned work profile on 11
Settings, Play or linkPersonalWork profileAndroid 5.1+

The rule for a client fleet is simple. Buy company devices through a zero-touch or Knox reseller whenever you can, and reserve QR codes for the phones that came from somewhere else.

Apps Through Managed Google Play

Android MDM tools all deliver apps the same way: managed Google Play. When you connect an MDM to your organization's managed Google Play account, you approve apps there and the MDM assigns them to devices or users.

Three kinds of app live there. Public apps appear in the work Play Store only after you approve them, so users can't install random tools into the work profile. Private apps are line-of-business apps published only to your organization, with no public listing. Web apps are links packaged as an app icon, handy for an intranet or a ticket portal.

App configuration rides along. Apps that support managed configuration, like Outlook, Chrome or a VPN client, can be pre-filled with server addresses, account names and restrictions, so users open them already set up. OEM-specific settings on devices like Zebra and Samsung arrive through OEMConfig apps, also delivered through managed Google Play.

This is also why Android MDM tools feel similar in daily use. App delivery, app config and the work Play Store come from Google. Where tools differ is the console on top: how you group devices, how policy inheritance works across clients, and how fast you can find a device when someone calls.

Policies Worth Setting on Day One

A new Android MDM rollout doesn't need every policy on the list. It needs the dozen that close the obvious gaps, set before the first user enrolls.

#PolicyWhat to setWhy it matters
1Screen lockPIN or stronger, auto-lock at 5 minutes or lessThe only barrier on a lost phone
2EncryptionRequired (on by default on modern Android)Protects data at rest
3OS versionMinimum supported version in a compliance ruleBlocks phones that stopped getting patches
4Security patch levelMaximum age in a compliance ruleCatches devices a manufacturer abandoned
5Play ProtectOn, with apps from unknown sources blockedStops sideloaded malware
6Developer options and USB debuggingOff on company devicesRemoves an easy path around policy
7Copy and pasteBlocked from work to personal appsKeeps client data in the work profile
8Wi-Fi and VPN profilesPushed from the MDM, certificates where possibleEnds password sharing on sticky notes
9Factory reset protectionCompany account set on company devicesA wiped stolen phone stays useless
10System updatesAutomatic or a maintenance windowUpdates install before users can defer forever
11Compliance actionBlock email and files when noncompliantMakes the rules above mean something
12Lost deviceTest remote lock and wipe on one device firstYou find the gap before a real loss does

Patch level deserves its own mention. Google's Android Enterprise Recommended program requires listed manufacturers to ship Android security updates within 90 days of Google releasing them, and rugged devices in the program get that commitment for five years from their ship date. Devices outside the program may stop getting patches much sooner. A compliance rule on patch age turns that from a buying note into something you enforce.

Identity sits alongside all of this. Conditional access that checks MDM compliance before granting email or file access is where device policy stops being advisory, and our IAM solutions guide covers that side.

Dedicated Devices and Kiosk Mode

Dedicated devices are where Android MDM earns its keep. A tablet at a front desk or a handheld in a warehouse has one job, and anything else it can do is a support ticket waiting to happen.

Android's lock task mode pins the device to an allowlist of apps. Single-app kiosk mode launches one app and hides everything else. Multi-app kiosk mode swaps the home screen for a managed launcher that shows only the approved apps; Microsoft's Managed Home Screen is one example, and every kiosk-capable MDM has its own.

The settings that make a kiosk hold are small and specific:

  • Hide or lock the status bar so users can't pull down quick settings.
  • Disable the home, recent apps and power menu buttons.
  • Block Settings, or expose only Wi-Fi and brightness through the launcher.
  • Set an exit PIN for technicians and keep it out of the kiosk's line of sight.
  • Schedule reboots and app updates for the hours the device is idle.

Rugged fleets add OEM settings on top. Zebra's Mobility Extensions and Samsung Knox settings reach things generic Android policy can't, like scanner configuration and hardware button mapping, delivered through OEMConfig.

Test every kiosk with the most curious person you know. If they can reach a browser in two minutes, a bored shift worker will find it in one.

Android MDM Tools: How the Options Group

A shortlist is easier when you stop comparing twenty tools and compare four kinds. Android Enterprise support is broadly similar across serious tools because Google supplies the modes, enrollment and app delivery. The differences sit in who the tool is built for.

Suite-bundled MDM. Microsoft Intune comes with Microsoft 365 plans that include it, and Google's endpoint management comes with Google Workspace. Workspace's basic mobile management covers passwords, managed apps and remote wipe across its Business, Enterprise and Frontline editions; advanced management adds app management and device audits. If a client already pays for one of these suites, start there and only move off it if it can't do something you need.

OEM tools. Samsung Knox Manage and similar tools go deepest on one manufacturer's hardware. They fit fleets that are all Samsung or all Zebra, and they lose appeal as soon as the fleet mixes brands.

Specialist cross-platform MDM. Tools like ManageEngine MDM Plus, Scalefusion, Hexnode and Miradore manage Android alongside iOS, Windows and macOS from one console, and several include kiosk depth that suite tools lack. Our MDM solutions comparison covers this group across platforms.

For the iPhones in the same fleet, the Apple MDM guide compares the options for multi-tenant MSPs.

Self-hosted open source. Headwind MDM is an Apache-2.0 licensed Android MDM with a web control panel you run yourself. It suits teams that want Android management without a per-device subscription and are comfortable owning the server.

Five questions narrow the list fast:

  1. Does it support all four modes you picked, including company-owned work profile?
  2. Does it support zero-touch and Knox Mobile Enrollment, not just QR codes?
  3. For MSPs, is it multi-tenant, with separate policies and billing per client?
  4. How deep is kiosk mode: single-app, multi-app, custom launcher, scheduled reboots?
  5. Does it sit in the same console as the rest of the fleet, or add another tab?

For admins weighing the same trade-off, this r/sysadmin thread on MDM and Android is a quick read.

There's no wrong answer, only a cost to each. One more tab means one more place policy drifts. One suite means living with its kiosk and multi-tenant limits.

Rolling Out Android MDM Across Client Fleets

For an MSP, Android MDM is less a tool choice than a repeatable rollout. The same six steps work for a ten-phone office and a two-hundred-device warehouse.

1. Inventory what exists. Count devices by owner, model and Android version, and flag anything still on device admin. Anything below your minimum OS version goes on a replacement list before enrollment starts.

2. Assign modes per group. Use the decision flow above and write it down per client. The mode map becomes the policy map.

3. Connect the plumbing. Bind managed Google Play, set up the zero-touch or Knox portal with each client's reseller, and create enrollment profiles per mode.

4. Build a baseline policy set. The day-one table above, cloned per client with only the Wi-Fi, VPN and app list changing. Resist per-client custom policies unless a contract demands them.

5. Pilot on three devices. One per mode you're deploying. Enroll, apply policy, test email, test a remote lock and a wipe, then factory reset one company device and confirm it re-enrolls.

6. Enroll the rest and set a review date. Compliance reports show you which devices fall behind on patches. Review them monthly with the client, alongside everything else in the RMM report.

The CLOUDINFRA demo below walks through a fully managed enrollment step by step, useful for training the tech who'll run step 5:

Mobile devices are one part of the fleet, and the laptops and servers next to them need the same visibility. OpenFrame, Flamingo's open, AI-native infrastructure layer for IT and security, keeps a device inventory across a client's endpoints and can run scripts across them with the output collected in one place.

The Short Version

Android MDM means Android Enterprise now, and anything still on device admin belongs on the migration list. Choose one of four modes per device group based on who owns the phone and whether a person uses it. Buy company devices through a zero-touch or Knox reseller so they enroll and re-enroll on their own. Set a dozen day-one policies, make compliance block access, and test a wipe before you need one. Then pick a tool by the modes, enrollment, tenancy and kiosk depth you need. For the cross-platform view, read our unified endpoint management guide next.

Aliaska Varieva

Aliaska Varieva

Head of Platform

Hi! I’m Aliaska, and I’ve been working as a software engineer (mostly Java + a bit Kotlin) for over 8 years now. I mostly spend my time building backend services, integrating systems, fixing bugs (the fun part 🙃), and making sure things don’t fall apart behind the scenes.

Related Content

Blog Posts

Product Releases

Podcasts

Webinars

Case Studies

Events

Onboarding Guides

Frequently Asked Questions

About OpenFrame

OpenFrame isn't built to plug into your stack. It replaces it. Instead of duct-taping a dozen tools together (RMM, MDM, SIEM, patching, remote access, each its own login and bill), we bundle it into one unified platform: RMM, MDM, monitoring, automation, remote access, patch management, security monitoring, and ticketing, plus built-in AI copilots. So "does it integrate with X?" usually means: you won't need X anymore.
Most platforms give you one piece and expect you to bolt the rest on. OpenFrame unifies the whole stack in one place, with AI copilots built in. Fewer logins, fewer bills, less duct tape.

MSP AI Agents

On a five-person desk, reported deployments show $78,000 to $130,000 in annual direct labor savings, roughly 30% fewer escalations, and 15% to 20% better SLA compliance. Broader MSP adoption data adds ticket handling time cut by 45% and five to 12 points of margin, all from reclaimed capacity rather than headcount cuts.
Yes. In production MSP shops today, 10% to 25% of tickets close before a human opens them. Thread alone has processed 173 million tickets across 750-plus MSP partners at 96% triage accuracy, handing back 490,000-plus technician hours. Agents own the low-risk, high-volume work (password resets, MFA enrollment, known installs, onboarding and offboarding) and flag anything that touches production data or needs judgment for a human to take.
Android MDM is the set of policies, enrollment flows and remote actions IT uses to manage company data on Android phones and tablets. Today it runs on Android Enterprise: your MDM tool sends policy and a management app on the device applies it, in one of four modes (personal work profile, company-owned work profile, fully managed or dedicated).
A work profile is a separate, self-contained space for work apps and data, and IT manages only that space while personal apps and data stay private. A fully managed device is a work-only company phone where IT can apply the full range of Android policies, including device-level controls that work profiles can't touch.
No, not for enterprise use. Google deprecated the device admin policies in Android 9, they stopped working for apps targeting Android 10, and password reset stopped in Android 11. Microsoft Intune no longer offers device administrator management on devices with Google Mobile Services, so fleets still on device admin should move to Android Enterprise.
The reseller registers the device to your organization at purchase. On first boot it checks for an assigned configuration, downloads the management app and provisions itself, and it repeats this after a factory reset. It needs Android 9 or later (or a compatible Android 8 device, or a Pixel on Android 7), an authorized zero-touch reseller and a zero-touch account.
No. With a work profile, IT manages the work apps and data only. Google's documentation states that the personal profile's apps, data and usage aren't visible to the organization, on personal phones and on company-owned phones that allow personal use.
Start from the modes and enrollment methods you need, then check each tool against five questions: support for all four Android Enterprise modes, zero-touch and Knox Mobile Enrollment, multi-tenancy per client, kiosk depth, and whether it runs in the same console as the rest of the fleet. Suite-bundled, OEM, specialist cross-platform and self-hosted open-source tools each fit different fleets.