Close Menu
    Facebook X (Twitter) Instagram
    Saturday, October 11
    X (Twitter) LinkedIn Reddit RSS
    All about Endpoint Management
    • Home
    All about Endpoint Management
    Home»Office 365»EMS»Convert Android Devices from Device Admin to work profile (Enterprise Enrollment) using Microsoft Endpoint Manager

    Convert Android Devices from Device Admin to work profile (Enterprise Enrollment) using Microsoft Endpoint Manager

    Eswar KonetiBy Eswar KonetiNovember 04, 12:02 am3 Mins Read EMS 1,286 Views
    Share
    Facebook Twitter LinkedIn Reddit

    Google has already announced the depreciation of the android enrollment using device administrator, for more information, please refer to https://developers.google.com/android/work/device-admin-deprecation and is highly encouraged to use Android enterprise for devices where GMS available.

    There is still a need to fallback to device admin in countries where there are no GMS available such as mainland China. If you don't have GMS services available, the device cannot be managed by Microsoft Endpoint Manager using the work profile. I recently did a blog post on this, for more information, please refer to https://systemcenterdudes.com/endpoint-manager-android-china/

    In this blog post, we will see how to move android users from device administrator to work profile (enterprise enrollment).

    If you have created enrollment restrictions for users (due to other reasons such as no GMS etc) to use android device administrator, please remove the users from the enrollment group.

    You can verify that from the enrollment restrictions policy.

    image

    Once you validated the enrollment restrictions, we will verify the number of devices/users that are enrolled using device admin.

    image

    You can also do a quick filter based on android (device administrator).

    we will now configure the android compliance policy to move android devices from device administrator to work profile management with setting Block devices managed with device administrator.

    When we configure this setting, it makes the android device non-compliant and the user clicks on the non-compliant, resolve. This process will take them to remove the device admin and enroll using the work profile. (When this process happens, make sure the user is not a member of the device admin enrollment). If user is a member of both device admin enrollment and enterprise enrollment, the enterprise enrollment profile takes precedence.

    we will now go to the android compliance policy and edit the existing policy (if you have any) or create a new policy with platform: android device administrator.

    Go to the android device compliance policy https://endpoint.microsoft.com/#blade/Microsoft_Intune_DeviceSettings/DevicesAndroidMenu/compliancePolicies and edit/create policy.

    image

    Click on the  android device admin policy, the Compliance settings page, in the Device Health section, set Block devices managed with device administrator , save policy.

    image

    Click review and save.

    image

    You can also customise the Actions for noncompliance such as email to user, send push notification etc.

    image

    Once the configuration is done, assign the policy to group of users who have devices enrolled with device admin.

    once you save the changes, the device will be marked as non-compliant in the endpoint portal.

    image

    End-User Experience:

    Moving the device from device admin to work profile is straight forward and end-user can do it

    Based on the actions for non-compliance, user get notified and user can launch the company portal, click on device tab, select the android device, click on Resolve.

    Screenshot_20201103-233041_Company Portal     Screenshot_20201103-233058_Company Portal    Screenshot_20201103-233104_Company Portal      Screenshot_20201103-233224_Company Portal     Screenshot_20201103-233232_Company Portal     Screenshot_20201103-233404_Work Setup

    Screenshot_20201103-233410_Work Setup     Screenshot_20201103-233426_Company Portal       Screenshot_20201103-233442_Company Portal      Screenshot_20201103-233450_Company Portal     Screenshot_20201103-233601_Company Portal

    The process involves with the following steps.

    1. Remove current management

    2.Create work profile

    3.Activate work profile

    4.Update device settings.

    After the enrollment is completed, a device will appear in the endpoint portal with OS as ‘Android work profile’.

    The old entry for device admin still appears and it get removed as part of the device clean up (if you have configured) or you can perform clean up using script.

    image

    For troubleshooting, please refer https://docs.microsoft.com/en-us/mem/intune/enrollment/android-move-device-admin-work-profile#troubleshooting

    android enrollment android.move device admin to work profile Device administrator EMS enterprise enrollment GMS intune
    Share. Twitter LinkedIn Email Facebook Reddit

    Related Posts

    Export Microsoft Entra ID User Authentication Methods to CSV using PowerShell & Microsoft Graph API

    August 13, 2:08 pm

    Automating Intune Deployment Rings Using Entra ID Dynamic Groups and Regex

    July 01, 10:31 pm

    Exporting Intune Win32 Apps with All Properties Using PowerShell and Microsoft Graph

    June 30, 7:01 pm

    Leave a ReplyCancel reply

    This site uses Akismet to reduce spam. Learn how your comment data is processed.

    Sign Up

    Get email notifications for new posts.

    Author

    I’m Eswar Koneti ,a tech enthusiast, security advocate, and your guide to Microsoft Intune and Modern Device Management. My goal? To turn complex tech into actionable insights for a streamlined management experience. Let’s navigate this journey together!

    Support

    Awards

    Archives

    © Copyright 2009-2025 Eswar Koneti, All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.