Intune set up for Android mobile builds

JW 0 Reputation points
2025-02-06T13:50:16.65+00:00

Good Afternoon,

I work in a large organization and am looking for a better solution for setting up user Android mobile devices. Currently, we use fully managed device enrollment through Intune, which requires either resetting user passwords or asking users for their passwords during setup. This approach raises security concerns.

We have attempted a "bring your own device" setup, but this does not provide the level of management we need.

I would appreciate any guidance or solutions you can provide that would allow us to implement a secure, user-friendly, and fully managed device setup process. This information will be used to propose a better approach to our management team.

TIA JW

Microsoft Intune Android
Microsoft Intune Android
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Android: An open-source mobile platform based on the Linux kernel, developed by Google, and maintained by the Open Handset Alliance.
342 questions
Microsoft Intune Enrollment
Microsoft Intune Enrollment
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Enrollment: The process of requesting, receiving, and installing a certificate.
1,420 questions
Microsoft Intune
Microsoft Intune
A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.
5,554 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. ZhoumingDuan-MSFT 15,810 Reputation points Microsoft Vendor
    2025-02-07T02:46:48.43+00:00

    @JW,Thanks for posting in Q&A.

    Based on the official document, there are some Android device enrollment methods you can refer to.

    BYOD: Android Enterprise personally owned devices with a work profile

    Android Enterprise corporate owned dedicated devices (COSU)

    Android Enterprise corporate owned fully managed (COBO)

    Android Enterprise corporate owned work profile (COPE)

    Android Open Source Project (AOSP)

    Android device administrator (DA)(deprecated)

    https://learn.microsoft.com/en-us/mem/intune/fundamentals/deployment-guide-enrollment-android

    And after the research, Android Enterprise fully managed, Android Open Source Project and Android Enterprise corporate owned work profile are both requires either resetting user passwords or asking users for their passwords during setup.

    Android Enterprise corporate owned dedicated devices, the only purpose is to be a kiosk-style device. They aren't associated with a single or specific user. These devices are commonly used to scan items, print tickets, get digital signatures, manage inventory, and more.

    So, it is suggested that you consider Android Enterprise corporate owned fully managed or Android Enterprise corporate owned work profile, although these two methods require a password during the setup process, they are still more convenient and secure than other registration methods.

    Hope above information can help you.

    If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".

    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.