Three of the five Android enrolment methods require a factory reset. Choose before you buy the phones.
Corporate-owned work profile, fully managed and dedicated device enrolment all require a factory reset. Only personally owned work profile does not. Getting that decision right before devices are distributed is the difference between a smooth rollout and wiping four hundred phones people are already using.

- Factory resetRequired for three of the five methods
- 15 devicesEnrolment limit for a standard account
- 1,000 devicesLimit with a device enrolment manager
- DeprecatedDevice administrator, on Google services devices
Factory reset, and which methods require one.
Microsoft publishes this as a table, and it is the fact that should drive your enrolment decision before any device is purchased or distributed.
- No reset required: Android Enterprise personally owned devices with a work profile, and the deprecated device administrator method. These can be enrolled on a phone somebody is already using, which is exactly why personally owned work profile is the practical answer for bring your own device.
- Reset required: Android Enterprise corporate-owned work profile, fully managed, and dedicated devices. All three are corporate-owned methods, and all three mean any device already in somebody hands has to be wiped before it can be enrolled that way.
- Microsoft adds a second point worth reading carefully: devices that do not require a reset begin installing Intune policies as soon as they enrol, and previously configured settings may remain on the device if you do not change them in Intune before enrolment. So a non-reset enrolment inherits whatever was there.
- The practical consequence is that this decision belongs at procurement. Devices bought and distributed before the enrolment method was chosen frequently end up on the wrong method, because nobody is willing to wipe four hundred phones that people are already using and have personal data on.
Eight things about Android management that decide the rollout.
The factory reset requirement, which shapes everything
Microsoft publishes it plainly: corporate-owned work profile, fully managed and dedicated device enrolment all require a factory reset. Personally owned work profile and the deprecated device administrator method do not. If devices are already distributed and in use, that is a very different project from devices still in boxes, and the decision has to happen before procurement rather than after.
Personally owned work profile, for devices you will never own
A separate work profile is created on the personal device so people can switch between their personal and work applications easily and securely, with the device owner enrolling through the Company Portal. You manage the applications and data in the work profile only. No factory reset is required, which is what makes this deployable on phones people already carry.
Corporate-owned work profile, for phones you own but people also use personally
Microsoft describes this as enrolling corporate-owned devices that are also approved for personal use, creating a separate work profile so the user can switch between personal and work applications. It is the right answer for company phones where insisting on work-only use would be unrealistic, and it is the enrolment type most UAE organisations should be using and are not.
Fully managed, for devices that are only for work
Enrolling corporate-owned devices exclusively for work and not personal use, with one user associated with the device. Microsoft notes you can manage the entire device and enforce policy controls not available with the work profile method. The trade-off is real: more control, and no room for the personal use that people will attempt anyway unless the culture supports it.
Dedicated devices, for the ones nobody personally owns
Corporate-owned single use or kiosk devices, and Microsoft names the use cases directly: digital signage, ticket printing and inventory management. You limit the applications and web links available and prevent people using the device outside its intended scope. In this market that covers a great deal of retail, hospitality, logistics and facilities equipment.
AOSP methods, for devices with no Google services at all
For corporate-owned devices built from the Android Open Source Project without Google Mobile Services, there are two options: userless devices with no associated user, intended to be shared like in a library or lab, and user-associated devices tied to a single person for exclusive work use. This is the route for rugged and purpose-built hardware, which is common on sites here.
Zero-touch, which Microsoft recommends for volume
Microsoft recommends zero-touch enrolment for bulk enrolments and to simplify enrolment for remote workers, describing it as preparing corporate-owned devices ahead of time so they automatically provision and enrol as fully managed devices when users turn them on. For any deployment of scale, this is the difference between a distribution exercise and a manual configuration marathon.
Device administrator is deprecated, and it is time to move
Microsoft states that Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services, and recommends switching to another Android management option. Support and documentation remain for some Android 15 and earlier devices without Google services. If your Android estate is still on device administrator, that is a migration to plan rather than defer.
Four things that decide whether an Android rollout goes well.
We choose the enrolment method before devices are bought
Corporate-owned work profile, fully managed and dedicated all require a factory reset. Making that decision at procurement means devices arrive and are enrolled correctly. Making it afterwards means either wiping phones people are already using, with the personal data conversation that follows, or settling for a method that gives you less than you paid for.
We usually recommend corporate-owned work profile for company phones
Microsoft describes it as for corporate-owned devices also approved for personal use, with a separate work profile the user switches between. In this market, insisting a company phone is used only for work is unrealistic and produces either resentment or a second personal phone. Corporate-owned work profile is the honest configuration and it still gives you real control.
We set up bulk enrolment properly, including the account limits
A standard non-administrator account can enrol fifteen devices. A device enrolment manager account can enrol up to a thousand. Discovering that at device sixteen, halfway through distributing a fleet, is a specific and avoidable frustration, and Microsoft recommends zero-touch for bulk enrolment and for remote workers where it is available.
We plan the migration off device administrator rather than deferring it
Microsoft states device administrator management is deprecated and no longer available for devices with Google Mobile Services, and recommends switching. Estates still on it are on a method that is not coming back. Planning the move to Android Enterprise deliberately is considerably better than being forced into it by a device refresh nobody scheduled.
Six UAE situations where Android management decisions matter.
Logistics and delivery operations with rugged handsets
Scanners, delivery handsets and rugged devices, frequently without Google Mobile Services. The Android Open Source Project methods cover exactly these, either userless for shared devices or user-associated where one person keeps a device. Getting this right is the difference between a managed fleet and a set of devices nobody can update or lock.
Retail and hospitality with single-purpose devices
Digital signage, ticket printing, ordering terminals and inventory devices, which Microsoft names directly as dedicated device use cases. Limiting the applications and web links available and preventing use outside the intended scope is what stops a customer-facing tablet becoming a browser somebody uses for something else entirely.
A company phone fleet where personal use is a fact
Company-owned Android phones that people also use personally, because that is how company phones work in practice here. Corporate-owned work profile is designed for exactly this, keeping work applications and data separate and manageable while leaving personal use alone, and it avoids the pretence that a fully managed device would involve.
A regulated firm needing control over company devices
Where the requirement is genuine control over a corporate device, fully managed enrolment allows management of the entire device and policy controls not available with the work profile method. The trade-off is that personal use is out, which needs to be a stated policy rather than something people discover when their photos application disappears.
A large distribution of new devices to remote staff
Where hundreds of devices need to reach people across sites or emirates. Microsoft recommends zero-touch enrolment for bulk enrolments and to simplify enrolment for remote workers, preparing devices ahead so they provision and enrol as fully managed when the user turns them on. The alternative is somebody touching every device.
An estate still on Android device administrator
Deprecated and no longer available on devices with Google Mobile Services, with documentation remaining only for some Android 15 and earlier devices without Google services. This is a migration with a clear direction and no realistic alternative, and doing it deliberately alongside a refresh is far cheaper than doing it under pressure.
How Android devices are actually managed in UAE organisations.
| Feature | Right method, chosen first | Whatever avoided a wipe | Unmanaged or device administrator |
|---|---|---|---|
Enrolment method matches device ownership | Yes | No | No |
Bulk enrolment through zero-touch | Yes | Rarely | No |
Full device policy control where owned | Yes | No | Partly |
Personal data separated from work data | Yes | Yes | No |
Kiosk and single-use devices locked down | Yes | No | No |
Devices without Google services supported | Yes, via AOSP | No | No |
On a supported management method | Yes | Yes | Deprecated |
Enrolment restrictions configured | Yes | Rarely | No |
Bulk enrolment limits understood | Yes | Discovered at device 16 | Not applicable |
Frequency in the UAE market | Uncommon | Common | Common |
Six enrolment methods, what each suits, and whether it wipes the device.
| Method | Suits, and whether a reset is required | |
|---|---|---|
| Personally owned work profile | Personal devices in bring your own device scenarios. No reset required. | |
| Corporate-owned work profile | Company devices also approved for personal use. Reset required. | |
| Fully managed | Company devices for work only, one user each, fuller policy control. Reset required. | |
| Dedicated device | Single use and kiosk devices, signage, ticket printing, inventory. Reset required. | |
| AOSP userless | Devices without Google services, shared, no associated user. For rugged and purpose-built hardware. | |
| AOSP user associated | Devices without Google services, one user, work only. | |
| Zero-touch enrolment | Recommended for bulk enrolment and remote workers, provisioning as fully managed on first power on. | |
| Device administrator | Deprecated and unavailable on devices with Google Mobile Services. Plan a migration. |
Five steps, and the first one determines the cost of the rest.
- 1
Choose the enrolment method per population
Personal devices, company phones with personal use, work-only devices, single-purpose devices and devices without Google services all have a different answer. Crucially this happens before devices are procured or distributed, because three of the methods require a factory reset and that is not negotiable afterwards.
- 2
Connect managed Google Play and set restrictions
Connecting Intune to a managed Google Play account is required for every Android Enterprise option. Then enrolment restrictions by platform, version, manufacturer or ownership type, device limit restrictions, and terms and conditions if you want them shown in the Company Portal before enrolment.
- 3
Prepare bulk enrolment properly
Zero-touch where your supplier supports it, since Microsoft recommends it for bulk enrolments and remote workers. Device enrolment manager accounts where devices are being prepared centrally, given that a standard non-administrator account can only enrol fifteen devices against a thousand for a device enrolment manager.
- 4
Build the policy set for each method
Configuration profiles, compliance policies and application assignments differ meaningfully between work profile, fully managed and dedicated device methods, because the available controls differ. A policy set written for one method and applied to another is the most common source of the it does not work complaint.
- 5
Pilot, then distribute
A small group first, covering each method in scope, testing the enrolment experience end to end including what the user sees in the Company Portal. Microsoft provides a report on incomplete and abandoned enrolments showing where users failed to complete the process, and it is worth watching during the pilot rather than after distribution.
What organisations ask about Android Enterprise.
Fifteen questions worth answering first.
Choosing the method
- Who owns the devices?That is the first branch in the decision.
- Are the devices already in use?Three of the methods require a factory reset.
- Is personal use allowed on company phones?Corporate-owned work profile versus fully managed.
- Do the devices have Google Mobile Services?If not, the AOSP methods apply.
- Are you still using device administrator?It is deprecated on Google services devices.
Preparation
- Is Intune connected to managed Google Play?Required for every Android Enterprise option.
- Are devices currently enrolled elsewhere?Unenrol from the existing platform first.
- Have you set enrolment restrictions?By platform, version, manufacturer or ownership type.
- Do you need terms and conditions shown?Displayed in the Company Portal before enrolment.
- Should multifactor authentication apply at enrolment?Via Conditional Access, needs Entra ID P1 or P2.
The practical limits
- How many devices is one person enrolling?A standard account is capped at 15 devices.
- Do you need a device enrolment manager?That raises the limit to 1,000 devices.
- Is zero-touch available from your supplier?Recommended for bulk and for remote workers.
- Do you want devices auto-grouped by category?Device categories add them to matching groups.
- Who reviews abandoned enrolments?A report shows where users failed to complete.
The pages around this one.
Microsoft Intune
The platform this runs in, covering configuration, compliance and application deployment across every platform.
App protection policies
The alternative for personal Android devices where even a work profile enrolment is unwelcome.
MDM solutions
The wider device management picture across Windows, Apple and Android, and how to choose between approaches.
Decide the enrolment method before the devices arrive.
Three of the five methods require a factory reset, and that is not something you can retrofit onto a fleet people are already using. Half an hour on this decision at procurement saves a genuinely painful conversation later.
Related Services
Explore more solutions that work great with this service
Kiosk and Shared Devices
Signage, terminals and handsets locked to the job they do
Microsoft Intune
Device management and endpoint security
App Protection Policies
Protect company data on a phone you will never be allowed to manage
MDM Solutions Dubai
Device management across Windows, Apple and Android
Intune Compliance Policies
The default that lets unassessed devices through Conditional Access
Intune Suite
Eight advanced capabilities, and one trial each per tenant
Endpoint Security
Defender for Endpoint and Intune managed
Apple Device Management
Mac and iPhone fleets, encryption, patching and the September cycle