Android Enterprise has four management modes and you probably want two
Work profile, fully managed, fully managed with work profile, dedicated. Which one applies decides what you can enforce and what you can never see.
Android device management is frequently described as more complicated than iOS. It is not more complicated — it just makes you choose up front, where Apple lets you drift.
The choice is the management mode, it is made at enrolment, and changing it later means wiping the device. So it is worth ten minutes.
The four modes
Work profile (BYOD). The device is personally owned. A cryptographically separated container holds work apps and data. You manage the profile completely and have no visibility into or control over anything outside it — not the personal apps, not the photos, not the location, not the device serial number.
Fully managed. The device is corporate-owned and managed in its entirety from first boot. Full policy control, full inventory, and the ability to enforce or block anything the platform exposes. No personal separation.
Fully managed with a work profile. Corporate-owned, fully managed, and carrying a work profile for the corporate applications and data. This is the COPE mode: the organisation controls the device, and the personal use that happens on it sits outside the work container. It is the mode most government fleets should be using and the one most often overlooked.
Dedicated (kiosk / COSU). Corporate-owned, single-purpose. The device is locked to one application or a small set, with the launcher, status bar and settings restricted. This is the mode for shared frontline devices, scanners, ruggedised field units and anything mounted in a vehicle.
Which one applies
If the user owns the device: work profile. There is no other defensible option. Full management on a personally owned phone gives you a wipe capability over somebody’s personal data that you do not want and will eventually use by accident.
If the organisation owns it and the user carries it personally too: fully managed with a work profile. You get the enforcement that ownership entitles you to — minimum OS version, security agent, disallowed applications, factory reset protection — while work data lives in a container that can be removed on its own. It is also the mode that lets you make a truthful privacy statement to staff.
If the organisation owns it and it is a work-only device: fully managed. Simpler, and appropriate where there is genuinely no personal use.
If it is shared, mounted or single-purpose: dedicated. Trying to run a shared frontline device as a fully managed personal-style device produces a support queue immediately.
Most organisations need two of these: fully managed with a work profile for staff, and dedicated for the frontline units. Adding work profile as a third covers a contractor or volunteer population.
The things that catch people
The mode is set at enrolment and cannot be changed. Moving a device from work profile to fully managed is a factory reset. Decide before the devices are provisioned, not after the pilot.
Zero-touch enrolment is a purchasing decision. Android zero-touch and Samsung Knox Mobile Enrolment both require the device to be registered to your organisation by the reseller at the point of supply. A device bought retail cannot be retroactively made corporate-owned without a wipe — the same trap as Apple’s Carrier DEP.
Factory reset protection needs planning. On corporate-owned devices, FRP stops a wiped handset being usable by anyone who does not have the original account. This is the point of it, and it also means a device returned from a departed staff member can be permanently bricked if the account association was not managed. Set the FRP account to an organisational one before you need it.
Work profile visibility is genuinely zero. This surprises administrators who expect to see at least an inventory. You cannot see personal applications, you cannot get the serial number, and you cannot enforce a device passcode — only a work challenge. Those are deliberate design decisions, and they are what makes the mode acceptable to users.
OEM variation is real. Samsung Knox, and to a lesser extent other OEM layers, expose controls beyond the Android Enterprise baseline. Useful, and worth confirming that your fleet is actually homogeneous before you depend on one.
The short version
Pick the mode from who owns the device and how it is used, then buy the devices in a way that supports it. Both halves have to be right, and the purchasing half is the one that is expensive to fix afterwards.
More on how we design and run mobile fleets, and on choosing an ownership model.