Android device enrolment in ProVconnect

Android device enrolment in ProVconnect

1 - Choose the enrollment type

Android enrollment types

Four enrollment options exist for Android devices. The option you choose depends on your use case and affects how the device can be managed.

  • Work profile (BYOD : bring your own device)
    The device belongs to the user, who also uses it for work purposes. The company can manage only the work profile.
    Corporate apps, data, and management policies are restricted to the work profile. With a work profile, the same device can be used securely and privately for work and personal purposes.

  • Work Profile (COPE : Company‑Owned, Personally Enabled)
    The device belongs to the company, and the user is allowed to use it for personal purposes. As with BYOD, the device has two profiles: personal and work. The company manages only the apps and data in the work profile. However, because the device belongs to the company, it can also perform global actions: enable lost mode, lock the device, reset it, or enforce a global password policy. All of this is done without access to the personal profile’s data or apps, in order to preserve the user’s privacy.

  • Fully managed device
    The device belongs to the company and is for work use only. The company has full management of the device. Provides full MDM and app management for granular control over company-owned devices. Choose from 80+ settings to enforce and benefit from Android’s full suite of app management features. This option is designed for devices intended primarily for corporate use.

  • Dedicated Device
    The device belongs to the company and is dedicated to one or more specific tasks (kiosk, point of sale, digital signage, logistics, scanning, etc.). The company fully manages it and can lock it to an approved application.

How to choose enrollment type

Enrollment type

Device ownership

Factory reset required at enrollment

Personal use

Remote wipe

Lost mode / full lock

App deployment

Enrollment type

Device ownership

Factory reset required at enrollment

Personal use

Remote wipe

Lost mode / full lock

App deployment

BYOD Work profile
Bring Your Own Device

Employee

No

Yes
(separate personal space)

Work profile wipe only

No

Silent within the work profile

COPE Work Profile
Company‑Owned, Personally Enabled

Company

Yes

Yes
(separate personal space)

Work profile wipe or full wipe of the device

Yes

Silent within the work profile

Fully Managed Device

Company

Yes

No
(100% corporate)

Full wipe (factory reset)

Yes

Silent, system and corporate apps

Dedicated Device

Not available yet in ProVconnect.

Company

Yes

No
(100% corporate)

Full wipe (factory reset)

Yes

Silent, system and corporate apps

2 - Generate an enrollment token

After you create an enterprise, a default policy is automatically created. To enroll a device, you must generate an enrollment token that is linked to a policy. During enrollment, that policy will be applied to the device. You can later modify the policy or assign a different one to the device.

Steps:

  • Go to: https://[your-server-url]/#/AndroidDevicesManagement/Policies

  • On the policy you want to use for enrollment, click Actions > Create enrollment token.

Important choice: “Allow personal usage.”

When creating an enrollment token, whether you enable “Allow personal usage” depends on the enrollment type:

  • For BYOD Work Profile or COPE Work Profile, you must check this option.

  • For Fully Managed Device, you must leave this option unchecked.

enrollment 1.png
enrollment 2.png
enrollment 3.png
enrollment 4.png

3 - Enroll your devices

BYOD Work profile case

This enrollment type does not require a factory reset.

  1. Install Android Device Policy

Open Google Play and install the EMM Agent : Android Device Policy https://play.google.com/store/apps/details?id=com.google.android.apps.work.clouddpc

  1. Open the application and scan the enrollment QR code.

  2. Policy application
    Follow the prompts: create a PIN for work profile, accept the terms, install required apps, etc.
    The work profile will progressively lock down according to the policy you configured in ProVconnect.

  3. Approve the device enrollment in the ProVconnect console
    To finalize enrollment, return to the ProVconnect console. Go to the “Enrollment” tab, then in the submenu select “Device Enrollment.” You should see the device(s) on which you used the enrollment token. You still need to approve their enrollment by selecting them and clicking the “Enroll XX device(s)”

    button.

 

Fully managed device or COPE Work Profile case

These enrollment types do require a factory reset.

“Allow personal use” option : The enrollment method is exactly the same for both Fully Managed Device and COPE Work Profile modes. The difference occurs when generating the enrollment token (QR code): if the “Allow personal usage” option is selected, the device will be enrolled in COPE Work Profile mode. Conversely, if you want to enroll your device(s) in Fully Managed Device mode, you must clear the “Allow personal usage” option when creating the enrollment token.

  1. Power on the factory‑reset device
    You should land on the “Welcome” screen (the word “Welcome” typically scrolls through several languages).

 

  1. Start “QR scan” mode
    On the “Welcome” screen, tap the same spot 6 times quickly.
    A prompt saying “Scan a QR code to set up” appears. Confirm.

 

20240902_131302 (1).mp4
  1. Connect the device to a network
    The system will ask you to connect to Wi‑Fi to download the QR scanner if needed.

 

  1. Scan the enrollment QR code
    Point the device at the QR code provided by the ProVconnect console.
    Confirm the prompts (date/time, etc.).

 

  1. Download and install the DPC
    The device downloads the management agent (Device Policy Controller) specified by the QR code and sets ProVconnect as the device owner for management.

 

  1. Policy application
    Follow the prompts: create a PIN, accept the terms, install required apps, certificates, Wi‑Fi/VPN, etc.
    The device will progressively lock down according to the policy you configured in ProVconnect (system apps hidden, managed Google Play, restrictions, etc.).

 

  1. Approve the device enrollment in the ProVconnect console
    To finalize enrollment, return to the ProVconnect console. Go to the “Enrollment” tab, then in the submenu select “Device Enrollment.” You should see the device(s) on which you used the enrollment token. You still need to approve their enrollment by selecting them and clicking the “Enroll XX device(s)”

    button.

 

4 - Enrollment FAQ

Can I change the policy after enrollment?

Yes. You can update the assigned policy at any time; changes will be pushed to the device.

Do I need a factory reset?

It depends on the management mode chosen during enrollment:

  • In BYOD Work Profile mode, a factory reset is not required, because the work profile is added alongside personal use of the device.

  • In COPE Work Profile and Fully Managed modes, a factory reset is mandatory before enrollment. There is no alternative, and this behavior is not specific to ProVconnect; it’s the same for all Android EMMs.

Can I manage devices enrolled using different enrollment types on the same ProVconnect server?

Yes, for example, you can manage fully managed devices and BYOD devices on the same ProVconnect server.