imPC@ndo IT

Guides / intune

Android Enterprise enrollment in Microsoft Intune

Fully managed, work profile and dedicated devices: which enrollment mode fits which case, and how to connect the Managed Google Play account.

Managing Android devices in an enterprise environment requires a balance between security, user experience, and administrative control. Android Enterprise, integrated with Microsoft Intune, provides a modern and secure framework to manage both corporate-owned and personal (BYOD) Android devices. This guide walks through the complete end-to-end configuration of Android Enterprise enrollment in Microsoft Intune.

Prerequisites

Before starting, ensure the following requirements are met:

  • Microsoft Intune subscription (included in Microsoft 365)
  • Global Administrator or Intune Administrator permissions
  • Dedicated Google account to bind Android Enterprise
  • Android devices running Android 9.0 or later
  • Network access to Google and Microsoft services

Enable Android Enterprise in Intune

The first step is to connect your Microsoft Intune tenant to the Android Enterprise program via Managed Google Play.

  1. Sign in to the Microsoft Intune Admin Center (intune.microsoft.com).
  2. Navigate to Devices → Enrollment → Android.
  3. Select Managed Google Play.
  4. Select the “I agree” option.
  5. Click “Connect to Google now” to open the Google Play Android Enterprise portal.

Sign in with the Google account that will be used to bind Intune with Android Enterprise.

  1. Select “Sign up”, enter the Gmail account password, and click Next.
  2. Select the “Sign in” option.
  3. Provide your organization information (Business name) and click Next.
  4. Enter Data Protection Officer and EU Representative details (optional), then click Confirm.
  5. Check “I have read and agree to the Managed Google Play agreement”, then click Confirm.
  6. After completing registration, click “Complete registration”.

Choose a Management Scenario

Once Android Enterprise is enabled, Intune supports multiple enrollment scenarios. The right choice depends on device ownership and company policy.

  • Fully Managed — Company-owned devices used exclusively for work. IT has full control over the entire device.
  • Work ProfilePersonally owned devices. A clear separation between personal and corporate data via a work profile container.
  • Corporate Work Profile — Company-owned devices that allow personal use. Balances IT control with user privacy.
  • Dedicated / Kiosk — Devices assigned to a specific task, often without a signed-in user. Ideal for kiosks and warehouses.

Create the Enrollment Profile

After choosing a scenario, create the enrollment profile that will be assigned to devices.

  1. Open the Intune admin portal: https://intune.microsoft.com/
  2. Go to DevicesEnrollmentAndroid.
  3. From the available profiles list, select Fully Managed — Corporate-owned, fully managed user devices.
  4. Click “Create policy”.
  5. Fill in: Profile name, Description, Token type, and optionally a Device name template.
  6. Select the Entra ID Group to associate with this profile, then click Next.
  7. Click Create to finish.

Enroll a New Android Device

There are several enrollment methods (Company Portal app, QR code, NFC token, etc.). This guide uses the QR code scan method — the fastest and most practical.

Get the QR Code

  1. Open the enrollment profile you just created.
  2. Select the Token menu.
  3. The QR code is displayed — this will be used to configure the device.

Configure the Device

  1. On the Android device (after factory reset), on the startup screen, tap the screen 6 times to launch the QR code reader.
  2. The QR reader appears — scan the code from the Token section of the enrollment profile.
  3. Select a Wi-Fi network and enter the password to connect to the internet.
  4. Device configuration begins automatically — click Continue.
  5. Accept the terms and conditions by clicking “Accept & Continue”.
  6. Sign in with the user’s Microsoft 365 account (email, password, and MFA).
  7. The app installation window opens. By default, Chrome, Intune Company Portal, and Microsoft Authenticator are installed.
  8. Select “Register your device” to start device registration.
  9. Click Next, then Agree.

Summary

In this guide we covered how to: connect Intune to Android Enterprise via Managed Google Play, choose the right management scenario, create an enrollment profile with a QR token, and enroll an Android device via QR code scan after a factory reset.

This configuration is the foundation for a complete enterprise Android device management strategy. From here you can deploy apps, enforce compliance policies, and configure Conditional Access.

Original source:cloudsecop.com — Original author: Aymen EL JAZIRI (Microsoft MVP)