We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Intune
  2. Android Enterprise
Android Enterprise management, UAE

Three of the five Android enrolment methods require a factory reset. Choose before you buy the phones.

Corporate-owned work profile, fully managed and dedicated device enrolment all require a factory reset. Only personally owned work profile does not. Getting that decision right before devices are distributed is the difference between a smooth rollout and wiping four hundred phones people are already using.

Book an Android enrolment reviewSee the enrolment methods
Android Enterprise management for UAE organisations
  • Factory resetRequired for three of the five methods
  • 15 devicesEnrolment limit for a standard account
  • 1,000 devicesLimit with a device enrolment manager
  • DeprecatedDevice administrator, on Google services devices
The decision that cannot be undone cheaply

Factory reset, and which methods require one.

Microsoft publishes this as a table, and it is the fact that should drive your enrolment decision before any device is purchased or distributed.

  • No reset required: Android Enterprise personally owned devices with a work profile, and the deprecated device administrator method. These can be enrolled on a phone somebody is already using, which is exactly why personally owned work profile is the practical answer for bring your own device.
  • Reset required: Android Enterprise corporate-owned work profile, fully managed, and dedicated devices. All three are corporate-owned methods, and all three mean any device already in somebody hands has to be wiped before it can be enrolled that way.
  • Microsoft adds a second point worth reading carefully: devices that do not require a reset begin installing Intune policies as soon as they enrol, and previously configured settings may remain on the device if you do not change them in Intune before enrolment. So a non-reset enrolment inherits whatever was there.
  • The practical consequence is that this decision belongs at procurement. Devices bought and distributed before the enrolment method was chosen frequently end up on the wrong method, because nobody is willing to wipe four hundred phones that people are already using and have personal data on.
Ask us to choose the method before you buy
The enrolment methods

Eight things about Android management that decide the rollout.

Microsoft recommends Android Enterprise enrolment solutions for personal and corporate-owned devices that use Google Mobile Services, and the Android Open Source Project methods for corporate-owned devices without them. All Android Enterprise options require Intune to be connected to a managed Google Play account.

The factory reset requirement, which shapes everything

Microsoft publishes it plainly: corporate-owned work profile, fully managed and dedicated device enrolment all require a factory reset. Personally owned work profile and the deprecated device administrator method do not. If devices are already distributed and in use, that is a very different project from devices still in boxes, and the decision has to happen before procurement rather than after.

Personally owned work profile, for devices you will never own

A separate work profile is created on the personal device so people can switch between their personal and work applications easily and securely, with the device owner enrolling through the Company Portal. You manage the applications and data in the work profile only. No factory reset is required, which is what makes this deployable on phones people already carry.

Corporate-owned work profile, for phones you own but people also use personally

Microsoft describes this as enrolling corporate-owned devices that are also approved for personal use, creating a separate work profile so the user can switch between personal and work applications. It is the right answer for company phones where insisting on work-only use would be unrealistic, and it is the enrolment type most UAE organisations should be using and are not.

Fully managed, for devices that are only for work

Enrolling corporate-owned devices exclusively for work and not personal use, with one user associated with the device. Microsoft notes you can manage the entire device and enforce policy controls not available with the work profile method. The trade-off is real: more control, and no room for the personal use that people will attempt anyway unless the culture supports it.

Dedicated devices, for the ones nobody personally owns

Corporate-owned single use or kiosk devices, and Microsoft names the use cases directly: digital signage, ticket printing and inventory management. You limit the applications and web links available and prevent people using the device outside its intended scope. In this market that covers a great deal of retail, hospitality, logistics and facilities equipment.

AOSP methods, for devices with no Google services at all

For corporate-owned devices built from the Android Open Source Project without Google Mobile Services, there are two options: userless devices with no associated user, intended to be shared like in a library or lab, and user-associated devices tied to a single person for exclusive work use. This is the route for rugged and purpose-built hardware, which is common on sites here.

Zero-touch, which Microsoft recommends for volume

Microsoft recommends zero-touch enrolment for bulk enrolments and to simplify enrolment for remote workers, describing it as preparing corporate-owned devices ahead of time so they automatically provision and enrol as fully managed devices when users turn them on. For any deployment of scale, this is the difference between a distribution exercise and a manual configuration marathon.

Device administrator is deprecated, and it is time to move

Microsoft states that Android device administrator management is deprecated and no longer available for devices with access to Google Mobile Services, and recommends switching to another Android management option. Support and documentation remain for some Android 15 and earlier devices without Google services. If your Android estate is still on device administrator, that is a migration to plan rather than defer.

How we approach it

Four things that decide whether an Android rollout goes well.

Android is the platform where the wrong early decision is most expensive to reverse, because three of the enrolment methods require wiping the device.

We choose the enrolment method before devices are bought

Corporate-owned work profile, fully managed and dedicated all require a factory reset. Making that decision at procurement means devices arrive and are enrolled correctly. Making it afterwards means either wiping phones people are already using, with the personal data conversation that follows, or settling for a method that gives you less than you paid for.

We usually recommend corporate-owned work profile for company phones

Microsoft describes it as for corporate-owned devices also approved for personal use, with a separate work profile the user switches between. In this market, insisting a company phone is used only for work is unrealistic and produces either resentment or a second personal phone. Corporate-owned work profile is the honest configuration and it still gives you real control.

We set up bulk enrolment properly, including the account limits

A standard non-administrator account can enrol fifteen devices. A device enrolment manager account can enrol up to a thousand. Discovering that at device sixteen, halfway through distributing a fleet, is a specific and avoidable frustration, and Microsoft recommends zero-touch for bulk enrolment and for remote workers where it is available.

We plan the migration off device administrator rather than deferring it

Microsoft states device administrator management is deprecated and no longer available for devices with Google Mobile Services, and recommends switching. Estates still on it are on a method that is not coming back. Planning the move to Android Enterprise deliberately is considerably better than being forced into it by a device refresh nobody scheduled.

Where this matters most

Six UAE situations where Android management decisions matter.

Android dominates the device mix in large parts of this market, particularly in operational and frontline roles, and it is consistently the less well managed half of the estate.

Logistics and delivery operations with rugged handsets

Scanners, delivery handsets and rugged devices, frequently without Google Mobile Services. The Android Open Source Project methods cover exactly these, either userless for shared devices or user-associated where one person keeps a device. Getting this right is the difference between a managed fleet and a set of devices nobody can update or lock.

Retail and hospitality with single-purpose devices

Digital signage, ticket printing, ordering terminals and inventory devices, which Microsoft names directly as dedicated device use cases. Limiting the applications and web links available and preventing use outside the intended scope is what stops a customer-facing tablet becoming a browser somebody uses for something else entirely.

A company phone fleet where personal use is a fact

Company-owned Android phones that people also use personally, because that is how company phones work in practice here. Corporate-owned work profile is designed for exactly this, keeping work applications and data separate and manageable while leaving personal use alone, and it avoids the pretence that a fully managed device would involve.

A regulated firm needing control over company devices

Where the requirement is genuine control over a corporate device, fully managed enrolment allows management of the entire device and policy controls not available with the work profile method. The trade-off is that personal use is out, which needs to be a stated policy rather than something people discover when their photos application disappears.

A large distribution of new devices to remote staff

Where hundreds of devices need to reach people across sites or emirates. Microsoft recommends zero-touch enrolment for bulk enrolments and to simplify enrolment for remote workers, preparing devices ahead so they provision and enrol as fully managed when the user turns them on. The alternative is somebody touching every device.

An estate still on Android device administrator

Deprecated and no longer available on devices with Google Mobile Services, with documentation remaining only for some Android 15 and earlier devices without Google services. This is a migration with a clear direction and no realistic alternative, and doing it deliberately alongside a refresh is far cheaper than doing it under pressure.

Three positions

How Android devices are actually managed in UAE organisations.

The middle column is the most common and the most awkward: company-owned phones enrolled with a personal work profile method because nobody wanted to wipe them, leaving the organisation with less control than it paid for.
Enrolment method matches device ownership
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorNo
Bulk enrolment through zero-touch
Right method, chosen firstYes
Whatever avoided a wipeRarely
Unmanaged or device administratorNo
Full device policy control where owned
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorPartly
Personal data separated from work data
Right method, chosen firstYes
Whatever avoided a wipeYes
Unmanaged or device administratorNo
Kiosk and single-use devices locked down
Right method, chosen firstYes
Whatever avoided a wipeNo
Unmanaged or device administratorNo
Devices without Google services supported
Right method, chosen firstYes, via AOSP
Whatever avoided a wipeNo
Unmanaged or device administratorNo
On a supported management method
Right method, chosen firstYes
Whatever avoided a wipeYes
Unmanaged or device administratorDeprecated
Enrolment restrictions configured
Right method, chosen firstYes
Whatever avoided a wipeRarely
Unmanaged or device administratorNo
Bulk enrolment limits understood
Right method, chosen firstYes
Whatever avoided a wipeDiscovered at device 16
Unmanaged or device administratorNot applicable
Frequency in the UAE market
Right method, chosen firstUncommon
Whatever avoided a wipeCommon
Unmanaged or device administratorCommon
Feature
Right method, chosen first
Whatever avoided a wipe
Unmanaged or device administrator
Enrolment method matches device ownership
YesNoNo
Bulk enrolment through zero-touch
YesRarelyNo
Full device policy control where owned
YesNoPartly
Personal data separated from work data
YesYesNo
Kiosk and single-use devices locked down
YesNoNo
Devices without Google services supported
Yes, via AOSPNoNo
On a supported management method
YesYesDeprecated
Enrolment restrictions configured
YesRarelyNo
Bulk enrolment limits understood
YesDiscovered at device 16Not applicable
Frequency in the UAE market
UncommonCommonCommon
The methods compared

Six enrolment methods, what each suits, and whether it wipes the device.

Reproduced from the published descriptions and the factory reset table. The reset column is the one that most often determines what is actually achievable.
MethodSuits, and whether a reset is required
Personally owned work profilePersonal devices in bring your own device scenarios. No reset required.
Corporate-owned work profileCompany devices also approved for personal use. Reset required.
Fully managedCompany devices for work only, one user each, fuller policy control. Reset required.
Dedicated deviceSingle use and kiosk devices, signage, ticket printing, inventory. Reset required.
AOSP userlessDevices without Google services, shared, no associated user. For rugged and purpose-built hardware.
AOSP user associatedDevices without Google services, one user, work only.
Zero-touch enrolmentRecommended for bulk enrolment and remote workers, provisioning as fully managed on first power on.
Device administratorDeprecated and unavailable on devices with Google Mobile Services. Plan a migration.
How a deployment runs

Five steps, and the first one determines the cost of the rest.

Typically three to six weeks depending on fleet size and whether devices are already distributed. The factory reset requirement is what makes the sequencing matter.
  1. 1

    Choose the enrolment method per population

    Personal devices, company phones with personal use, work-only devices, single-purpose devices and devices without Google services all have a different answer. Crucially this happens before devices are procured or distributed, because three of the methods require a factory reset and that is not negotiable afterwards.

  2. 2

    Connect managed Google Play and set restrictions

    Connecting Intune to a managed Google Play account is required for every Android Enterprise option. Then enrolment restrictions by platform, version, manufacturer or ownership type, device limit restrictions, and terms and conditions if you want them shown in the Company Portal before enrolment.

  3. 3

    Prepare bulk enrolment properly

    Zero-touch where your supplier supports it, since Microsoft recommends it for bulk enrolments and remote workers. Device enrolment manager accounts where devices are being prepared centrally, given that a standard non-administrator account can only enrol fifteen devices against a thousand for a device enrolment manager.

  4. 4

    Build the policy set for each method

    Configuration profiles, compliance policies and application assignments differ meaningfully between work profile, fully managed and dedicated device methods, because the available controls differ. A policy set written for one method and applied to another is the most common source of the it does not work complaint.

  5. 5

    Pilot, then distribute

    A small group first, covering each method in scope, testing the enrolment experience end to end including what the user sees in the Company Portal. Microsoft provides a report on incomplete and abandoned enrolments showing where users failed to complete the process, and it is worth watching during the pilot rather than after distribution.

Straight answers

What organisations ask about Android Enterprise.

It depends on ownership and on whether personal use is allowed. Personal devices use personally owned work profile. Company phones that people also use personally use corporate-owned work profile. Work-only company devices use fully managed. Single-purpose and kiosk devices use dedicated. Devices without Google Mobile Services use one of the two Android Open Source Project methods. Each has a different set of available controls.

For three of the five methods, yes. Microsoft publishes a table showing that corporate-owned work profile, fully managed and dedicated device enrolment all require a factory reset, while personally owned work profile and the deprecated device administrator method do not. This is the fact that should drive your decision, and it should be made before devices are distributed rather than after.

Yes, and that is what personally owned work profile is for. A separate work profile is created during enrolment so people can switch between personal and work applications easily and securely, the device owner enrols through the Company Portal, and you manage the applications and data in the work profile. Personal applications and data are outside your control by design.

Personal use. Corporate-owned work profile is for company devices that are also approved for personal use, keeping a separate work profile the user switches between. Fully managed is for company devices used exclusively for work, with one associated user, and Microsoft notes it lets you manage the entire device and enforce policy controls not available with the work profile method. More control, no personal use.

Use the Android Open Source Project methods, which exist precisely for corporate-owned devices built from AOSP without Google Mobile Services. There are two: corporate-owned userless devices, which have no associated user and are intended to be shared like in a library or lab, and corporate-owned user-associated devices, which are tied to a single user for exclusive work use. Rugged and purpose-built hardware frequently falls here.

No, on any device with Google services. Microsoft states device administrator management is deprecated and no longer available for devices with access to Google Mobile Services, and recommends switching to another Android management option. Support and documentation remain for some Android 15 and earlier devices without Google services. Estates still on device administrator should be planning the migration now.

Intune connected to your managed Google Play account, which Microsoft states is required for all Android Enterprise management options including personally owned work profile, corporate-owned work profile, fully managed and dedicated. Beyond that, devices currently enrolled in another mobile device management provider should be unenrolled from it before enrolling in Intune.

Two things. Zero-touch enrolment, which Microsoft recommends for bulk enrolments and to simplify enrolment for remote workers, preparing devices ahead of time so they automatically provision and enrol as fully managed when the user turns them on. And device enrolment manager accounts, because a standard non-administrator account can only enrol fifteen devices while a device enrolment manager can enrol up to a thousand.

Because a standard non-administrator account is limited to fifteen enrolled devices. This catches people out routinely during a bulk preparation exercise. The answer is a device enrolment manager account, which is a non-administrator Microsoft Entra user who can enrol up to a thousand corporate-owned devices and deploy role-specific applications, though some methods such as Apple automated device enrolment are not compatible with it.

Yes, through enrolment restrictions. Device platform restrictions can restrict devices based on platform, version, manufacturer or ownership type. Device limit restrictions cap how many devices a user can enrol. Both are configured before you create the enrolment policy, and both are commonly left at default, which is how estates end up with device types nobody intended to support.

Yes, using a Conditional Access policy with a multifactor authentication policy, which Microsoft notes requires Microsoft Entra ID P1 or P2. Microsoft describes it as a one-time conditional step ensuring the person enrolling is who they say they are. Given enrolment establishes a trusted device identity, requiring a second factor at that moment is a proportionate control.

Device categories. You create a category in Intune, and Intune automatically adds devices in that category to the corresponding device group. For an estate with several enrolment methods and several populations, this saves a great deal of manual group management, and it is available for all platforms except Linux.

Microsoft flags this specifically for the non-reset methods: devices that do not require a reset begin installing Intune policies as soon as they enrol, and previously configured settings may remain on the device if you do not change them in Intune before enrolment. So the device inherits whatever was there, which is worth checking rather than assuming enrolment produces a clean state.

There is a report tracking incomplete and abandoned user enrolments, which Microsoft describes as telling you where in the Company Portal users failed to complete the enrolment process. During a pilot and an early rollout this is the most useful report available, because it distinguishes people who could not complete enrolment from people who simply have not started.

We scope per organisation, driven by fleet size, how many enrolment methods are in scope and whether devices are already distributed, since that last point determines whether a factory reset is a plan or a problem. What we will tell you free in the first conversation is which enrolment method your situation actually calls for, because getting that wrong is the expensive mistake here.
Before enrolling anything

Fifteen questions worth answering first.

The first group decides the method. The second is the preparation most rollouts skip. The third is the practical limits, one of which stops bulk enrolments dead.

Choosing the method

  • Who owns the devices?
    That is the first branch in the decision.
  • Are the devices already in use?
    Three of the methods require a factory reset.
  • Is personal use allowed on company phones?
    Corporate-owned work profile versus fully managed.
  • Do the devices have Google Mobile Services?
    If not, the AOSP methods apply.
  • Are you still using device administrator?
    It is deprecated on Google services devices.

Preparation

  • Is Intune connected to managed Google Play?
    Required for every Android Enterprise option.
  • Are devices currently enrolled elsewhere?
    Unenrol from the existing platform first.
  • Have you set enrolment restrictions?
    By platform, version, manufacturer or ownership type.
  • Do you need terms and conditions shown?
    Displayed in the Company Portal before enrolment.
  • Should multifactor authentication apply at enrolment?
    Via Conditional Access, needs Entra ID P1 or P2.

The practical limits

  • How many devices is one person enrolling?
    A standard account is capped at 15 devices.
  • Do you need a device enrolment manager?
    That raises the limit to 1,000 devices.
  • Is zero-touch available from your supplier?
    Recommended for bulk and for remote workers.
  • Do you want devices auto-grouped by category?
    Device categories add them to matching groups.
  • Who reviews abandoned enrolments?
    A report shows where users failed to complete.
Related reading

The pages around this one.

Microsoft Intune

The platform this runs in, covering configuration, compliance and application deployment across every platform.

Learn more

App protection policies

The alternative for personal Android devices where even a work profile enrolment is unwelcome.

Learn more

MDM solutions

The wider device management picture across Windows, Apple and Android, and how to choose between approaches.

Learn more
Next step

Decide the enrolment method before the devices arrive.

Three of the five methods require a factory reset, and that is not something you can retrofit onto a fleet people are already using. Half an hour on this decision at procurement saves a genuinely painful conversation later.

Book an Android enrolment reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Kiosk and Shared Devices

Signage, terminals and handsets locked to the job they do

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

App Protection Policies

Protect company data on a phone you will never be allowed to manage

Learn more

MDM Solutions Dubai

Device management across Windows, Apple and Android

Learn more

Intune Compliance Policies

The default that lets unassessed devices through Conditional Access

Learn more

Intune Suite

Eight advanced capabilities, and one trial each per tenant

Learn more

Endpoint Security

Defender for Endpoint and Intune managed

Learn more

Apple Device Management

Mac and iPhone fleets, encryption, patching and the September cycle

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy