HomeSetup guides › Enrol a test Android device (fully managed QR + BYOD work profile)
Setup guide · from scratch

Enrol a test Android device (fully managed QR + BYOD work profile)

Prove your Android enrolment actually works by putting one device through each path: a factory-reset corporate phone provisioned fully managed by tapping the first setup screen several times to open the QR scanner, and a personal phone self-enrolled through the Company Portal app. The trap: fully managed DEMANDS a genuine factory-reset, out-of-box device, and you must NOT restart it mid-provisioning — do either and it can look enrolled in Intune while being completely unmanaged.

A factory-reset Android device + Company Portalassisted guide — Decolla walks you through this
≈ 40 min
Google — Android · step 5 of 5 · ≈ 40 min‹ Previous
Do these first — this guide assumes you already have:
The Decolla way — skip the clicks.

Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.

⏱ By hand: about 40 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
0 of 10 done
Step 1. Start with the corporate path. In Intune, open the fully managed enrolment profile you created and reveal its enrolment token: Devices > Enrollment > Android tab > under 'Android Enterprise > Enrollment Profiles' open 'Corporate-owned, fully managed user devices' > your profile > Token (in newer tenants Enrollment sits under Devices > Device onboarding). Leave that QR code on your screen — the device will scan it straight off your monitor.
Screenshot: The enrolment profile's Token pane in Intune showing the QR code and the numeric token string (captured during a live customer build — coming to this page)
Why: The QR carries the enrolment token that tells the device which tenant and profile to join; nothing on the device side works without it.
Watch for: Microsoft has shuffled this navigation more than once — it may read Devices > Enrollment > Android or Devices > By platform > Android > Device onboarding > Enrollment. If you can't see corporate profiles, confirm Managed Google Play is connected first.
Step 2. Factory-reset the test phone (Settings > System > Reset options > Erase all data / factory reset), or take a brand-new device out of the box. Then power it on and stop at the very first setup screen — do not tap through the wizard.
Screenshot: The device's first-boot Welcome / 'Hi there' / language-selection setup screen (captured during a live customer build — coming to this page)
Why: Fully managed (device-owner) provisioning can ONLY be applied to a device in its clean, first-boot state.
Watch for: Factory Reset Protection: if the phone was previously tied to a Google account, Android may demand that same account after the reset before you can continue. Have it ready, or you will be locked out at this screen.
Don’t: Do NOT try this on a phone you have already signed into or set up — you cannot convert an in-use device to fully managed. It must be reset.
Step 3. On that first setup screen, tap the same spot on the screen several times in quick succession to bring up the QR-code enrolment flow.
Screenshot: The setup screen mid-tap, with the QR-scan / camera prompt just appearing (captured during a live customer build — coming to this page)
Watch for: The exact number of taps varies by manufacturer and Android version — Microsoft's own documentation only says to tap the screen 'repeatedly'. In practice it is usually around six taps in the same place. Keep tapping until a QR scanner, a camera permission, or a Wi-Fi prompt appears; if nothing happens after a dozen taps, the device isn't at a true first-boot state — reset it again.
Step 4. If prompted, connect to Wi-Fi and allow the device to download a QR reader (phones on Android 9.0 and later already have one built in; note the fully managed path itself needs Android 10.0 or later). Then scan the enrolment-profile QR code off your monitor.
Screenshot: The device scanning the on-screen QR code, or the 'downloading QR reader / connecting' progress screen (captured during a live customer build — coming to this page)
Watch for: Browser zoom can stop the scan working. If the camera won't lock onto the code, zoom the Intune page in or out a step and try again.
Step 5. Let the device provision. It downloads the Android Device Policy / management app, applies your profile, and sets itself up as a fully managed device — accept any Google or OEM terms it shows and follow the on-screen prompts through to the home screen.
Screenshot: The 'Setting up your device / This device is managed by your organisation' provisioning progress screen (captured during a live customer build — coming to this page)
Why: The provisioning stage is where the device registers with Intune; interrupt it and the registration silently fails even though setup looks finished.
Don’t: Do NOT restart, power off, or let the battery die while it provisions. A mid-provisioning restart can leave the device appearing enrolled in Intune while it is actually NOT under management or policy.
Step 6. If the profile uses user affinity, sign in with the test user's work account when asked, and let setup finish. The corporate device is now fully managed — its entire storage is company-controlled, with no separate personal space.
Screenshot: The work-account sign-in screen during setup, then the finished managed home screen (captured during a live customer build — coming to this page)
Watch for: If enrolment stalls in a sign-in loop here, that is usually a Conditional Access policy catching the setup browser — the Microsoft Intune cloud app must be excluded from any 'require compliant device' / block policy that targets Android.
Step 7. Now switch to the BYOD path on a SEPARATE personal phone — no factory reset needed. On new tenants the default is now web-based enrolment (the Android Management API): open the Microsoft Intune app - or tap the prompt in a Microsoft 365 app like Teams or Outlook, or browse to https://aka.ms/enrollmyandroid in Chrome or Edge - and sign in with the test user's work or school account. (Legacy app-based path, only while web enrolment is off: install 'Intune Company Portal' from Google Play and sign in there instead.)
Screenshot: The Intune Company Portal listing in Google Play with the Install button, or its sign-in screen (captured during a live customer build — coming to this page)
Watch for: The Microsoft Intune app has replaced Company Portal as the Android enrolment app on new tenants. The older Company Portal app-based flow still works only while web-based enrolment is off (and needs a Company Portal build newer than about 2604); Microsoft is phasing app-based BYOD enrolment out.
Step 8. Complete the on-screen work-profile setup and sign-in. Web-based flow: accept the Google work-profile terms, let the work profile create, and finish the prompts. Legacy Company Portal app flow: tap BEGIN, CONTINUE, then Accept & continue, wait while the work profile is created, CONTINUE / Next, let it register, then CONFIRM DEVICE SETTINGS and DONE.
Screenshot: The Company Access Setup checklist with green ticks against 'Create work profile' and 'Activate work profile', ending on the Done button (captured during a live customer build — coming to this page)
Why: This creates a walled work profile that holds only company apps and data; the user's personal apps, photos and accounts stay in a separate space Intune cannot see or wipe.
Watch for: On a Samsung device you'll also get a Knox privacy prompt — tap Agree. If the profile won't create at all, check Devices > Enrolment restrictions isn't blocking personally-owned Android work profile (policies created before July 2019 default to Block), and that Google Play services on the phone is up to date.
Step 9. Verify the corporate device in Intune. Go to Devices > All devices and open the phone you QR-enrolled. Confirm Ownership = Corporate, that Managed by shows Intune/MDM, and that it reads as an Android (fully managed) enrolment.
Screenshot: The corporate device's Overview in Intune showing Ownership: Corporate and an Android fully managed enrolment (captured during a live customer build — coming to this page)
Why: Ownership 'Corporate' plus a fully managed enrolment type is the proof the QR path did what it should — it is the one field that distinguishes a truly device-owned phone from a work-profile one.
Watch for: A newly enrolled device can take a few minutes to surface — that is normal sync latency, not a failure, so refresh rather than re-enrolling. If Ownership reads Personal, you scanned a BYOD/work-profile profile by mistake, not the fully managed one.
Step 10. Verify the BYOD device the same way: Devices > All devices > the personal phone. Confirm Ownership = Personal and that it appears as an Android (work profile) enrolment. Two devices, two different ownership types, both showing as managed — that is the whole test passed.
Screenshot: Devices > All devices listing both phones side by side: one Corporate / fully managed, one Personal / work profile (captured during a live customer build — coming to this page)
Why: Seeing both records with the correct, contrasting ownership confirms each enrolment path is wired end to end — the device side AND the Intune side agree.
Watch for: If the personal device shows up TWICE (once as work profile, once as device administrator), someone tried to enrol an Android 15 private space or hit the DA fallback — remove the stray device-administrator record and re-check the work-profile one is the live enrolment.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access