Android device enrolment in ProVconnect
1 - Choose the enrollment type
Android enrollment types
Four enrollment options exist for Android devices. The option you choose depends on your use case and affects how the device can be managed.
Work profile (BYOD : bring your own device)
The device belongs to the user, who also uses it for work purposes. The company can manage only the work profile.
Corporate apps, data, and management policies are restricted to the work profile. With a work profile, the same device can be used securely and privately for work and personal purposes.Work Profile (COPE : Company‑Owned, Personally Enabled)
The device belongs to the company, and the user is allowed to use it for personal purposes. As with BYOD, the device has two profiles: personal and work. The company manages only the apps and data in the work profile. However, because the device belongs to the company, it can also perform global actions: enable lost mode, lock the device, reset it, or enforce a global password policy. All of this is done without access to the personal profile’s data or apps, in order to preserve the user’s privacy.Fully managed device
The device belongs to the company and is for work use only. The company has full management of the device. Provides full MDM and app management for granular control over company-owned devices. Choose from 80+ settings to enforce and benefit from Android’s full suite of app management features. This option is designed for devices intended primarily for corporate use.Dedicated Device
The device belongs to the company and is dedicated to one or more specific tasks (kiosk, point of sale, digital signage, logistics, scanning, etc.). The company fully manages it and can lock it to an approved application.
How to choose enrollment type
Enrollment type | Device ownership | Factory reset required at enrollment | Personal use | Remote wipe | Lost mode / full lock | App deployment |
|---|---|---|---|---|---|---|
BYOD Work profile | Employee | No | Yes | Work profile wipe only | No | Silent within the work profile |
COPE Work Profile | Company | Yes | Yes | Work profile wipe or full wipe of the device | Yes | Silent within the work profile |
Fully Managed Device | Company | Yes | No | Full wipe (factory reset) | Yes | Silent, system and corporate apps |
Dedicated Device Not available yet in ProVconnect. | Company | Yes | No | Full wipe (factory reset) | Yes | Silent, system and corporate apps |
2 - Generate an enrollment token
After you create an enterprise, a default policy is automatically created. To enroll a device, you must generate an enrollment token that is linked to a policy. During enrollment, that policy will be applied to the device. You can later modify the policy or assign a different one to the device.
Steps:
Go to: https://[your-server-url]/#/AndroidDevicesManagement/Policies
On the policy you want to use for enrollment, click Actions > Create enrollment token.
Important choice: “Allow personal usage.”
When creating an enrollment token, whether you enable “Allow personal usage” depends on the enrollment type:
For BYOD Work Profile or COPE Work Profile, you must check this option.
For Fully Managed Device, you must leave this option unchecked.
3 - Enroll your devices
BYOD Work profile case
Fully managed device or COPE Work Profile case
These enrollment types do require a factory reset.
“Allow personal use” option : The enrollment method is exactly the same for both Fully Managed Device and COPE Work Profile modes. The difference occurs when generating the enrollment token (QR code): if the “Allow personal usage” option is selected, the device will be enrolled in COPE Work Profile mode. Conversely, if you want to enroll your device(s) in Fully Managed Device mode, you must clear the “Allow personal usage” option when creating the enrollment token.
4 - Enrollment FAQ
Can I change the policy after enrollment?
Yes. You can update the assigned policy at any time; changes will be pushed to the device.
Do I need a factory reset?
It depends on the management mode chosen during enrollment:
In BYOD Work Profile mode, a factory reset is not required, because the work profile is added alongside personal use of the device.
In COPE Work Profile and Fully Managed modes, a factory reset is mandatory before enrollment. There is no alternative, and this behavior is not specific to ProVconnect; it’s the same for all Android EMMs.
Can I manage devices enrolled using different enrollment types on the same ProVconnect server?
Yes, for example, you can manage fully managed devices and BYOD devices on the same ProVconnect server.