Microsoft Intune Initial Setup for Android Device Management
Microsoft Intune Initial Setup for Android Device Management is a one-week, fixed-fee add-on that extends your Intune tenant to Android using Android Enterprise. IT Partner connects Managed Google Play, helps you choose the right Android Enterprise enrollment model for how your devices are owned and used, configures that model with baseline compliance and configuration policies and up to three managed applications, and proves it on a pilot of up to three devices. Windows is covered by Microsoft Intune Initial Setup for Windows Device Management; iPhone and iPad by Microsoft Intune Initial Setup for iPhone & iPad Management.
What this engagement is
Android management succeeds or fails on one early decision: the Android Enterprise enrollment model. Each model — personally owned work profile, corporate-owned fully managed, corporate-owned work profile, and corporate-owned dedicated — behaves differently for privacy, applications, and policy control, and some choices are effectively permanent. This add-on gets that decision right, then implements it. IT Partner connects your Intune tenant to Managed Google Play, configures the selected enrollment model with its profile, token, QR code, or web enrollment flow, blocks legacy Android Device Administrator enrollment, builds one compliance baseline and one device configuration baseline, assigns up to three public Managed Google Play applications, and validates the whole flow on up to three pilot devices. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud that need company data managed on Android phones and tablets — whether corporate-owned or employees' own devices. Who it is not for: fleets needing several enrollment models at once, kiosk estates with custom launcher requirements, or organizations wanting a full-fleet hands-on rollout — each of those extends this foundation as separately scoped work. The engagement covers one enrollment model per implementation; adding a second model later is a separately quoted extension of the same foundation.
Success criteria
What you receive
How the work unfolds
Confirm the relationship to the core Intune service and how your devices are owned and used. Select the Android Enterprise enrollment model, and approve pilot devices, users, applications, policies, success measures, and client responsibilities.
Verify the Intune foundation, connect the tenant to Managed Google Play with the client-controlled account, confirm application synchronization, and review enrollment-affecting identity and network policies.
Configure the profile, token, QR code, or web flow for the selected model. Establish pilot access and policy assignments, block legacy Device Administrator and unapproved personal enrollment where applicable, and withhold credentials for other corporate-owned modes.
Configure the approved compliance baseline, the device configuration or restrictions baseline, and up to three public Managed Google Play application assignments.
Enroll up to three supported pilot devices. Validate ownership, user association, inventory, policy delivery, compliance evaluation, application delivery, and administrator visibility.
Correct in-scope configuration issues, finalize the design and runbooks, review phased-rollout recommendations and open dependencies, conduct the administrator handoff, and confirm acceptance criteria.
Prerequisites
Who does what
IT Partner
- Lead Android discovery, readiness assessment, enrollment-model selection, implementation planning, pilot validation, and acceptance review.
- Connect one Intune tenant to Managed Google Play using the client-controlled account, and document the connection and administrative ownership.
- Configure the selected enrollment model with its required token, QR code, or web enrollment flow.
- Configure pilot access and policy assignments, block legacy Device Administrator and unapproved personal enrollment where applicable, and withhold credentials for other corporate-owned modes.
- Configure the baseline compliance policy, the baseline device configuration or restrictions profile, and up to three public Managed Google Play application assignments.
- Assist with enrollment and validation of up to three client-provided pilot devices, and troubleshoot issues caused by the implemented configuration.
- Validate the agreed device, policy, compliance, application, and administrative outcomes, and document dependencies that require separate remediation.
- Provide the as-built configuration, enrollment guide, credential-handling and troubleshooting runbook, rollout recommendations, and administrator handoff.
Your team
- Provide and maintain Microsoft Intune licenses, supported Android devices, application licenses, the client-controlled Managed Google Play connection account, and any third-party subscriptions.
- Provide approved administrative access to Microsoft Intune, Microsoft Entra, Managed Google Play, and any client systems required for implementation and testing.
- Select and approve the Android Enterprise ownership and enrollment model, the pilot population, compliance requirements, configuration settings, applications, and acceptable user experience.
- Approve Google's terms and data sharing, retain long-term control of the Managed Google Play connection account, and manage account recovery and client-only Google tasks.
- Provide between one and three eligible pilot devices, authorize any required factory resets, back up local data, make pilot users available, and perform required physical device steps.
- Provide network access, application inputs, authentication and identity-policy decisions, change approvals, communications, and first-line end-user support.
- Review testing results and deliverables, provide decisions and feedback within the one-week schedule, and approve acceptance against the published success criteria.
- Own production rollout, device logistics, user support, ongoing application approvals, compliance remediation, monitoring, and policy maintenance after handoff unless separately contracted.
What's not included
Limitations & technical notes
Frequently asked questions
Which Android Enterprise enrollment model should we choose?
There are four, and the right one follows from who owns the device and who controls the personal side. Personally owned work profile: the employee owns the phone, work data lives in a separate encrypted profile, IT manages only that profile, and the personal side stays private — no device reset needed. Corporate-owned fully managed: the company owns the device and IT manages all of it; requires a new or factory-reset device; typical for knowledge-worker fleets. Corporate-owned work profile (COPE): the company owns the device but the employee also uses it personally; IT manages the work profile with limited device-level control; requires a reset; balances control with personal privacy. Corporate-owned dedicated: kiosk-style devices with no single user — scanners, signage, shared floor devices; requires a reset; unsuitable for user-based apps unless Microsoft Entra shared device mode is added. Choosing the model is the first working session of this engagement, and IT Partner documents the decision and its trade-offs before anything is configured.
What do partners most often get wrong on Android — and how does this service avoid it?
Three mistakes account for most Android Enterprise rework. First, enabling personally owned work-profile web enrollment casually: it is tenant-wide and effectively irreversible, so this service treats it as a formal readiness decision. Second, assuming a compliance policy blocks anything: it only reports status — enforcement needs separately licensed Microsoft Entra Conditional Access, which we design for but do not silently enable. Third, losing the Managed Google Play connection account: disconnecting it breaks management of every enrolled device, so the connection is created under a client-controlled account with a documented ownership procedure.
Who is this service for — and who is it not for?
It fits US commercial organizations of roughly 100–500 seats on the Microsoft cloud that need company data managed on Android devices — corporate-owned or personal. It is not the right shape for fleets that need several enrollment models at once, custom kiosk launchers, or a hands-on rollout of hundreds of devices; each of those builds on this foundation as separately scoped work.
What is included in Microsoft Intune Initial Setup for Android Device Management?
The service connects one Intune tenant to Managed Google Play, configures the selected Android Enterprise enrollment model, sets pilot access and policy assignments, blocks legacy Device Administrator enrollment, builds one compliance baseline and one device configuration baseline, assigns up to three public applications, validates up to three pilot devices, and delivers documentation and an administrator handoff.
How does this add-on relate to the other Intune services?
Microsoft Intune Initial Setup for Windows Device Management provides the core foundation every add-on builds on. This service is the Android add-on; the sibling mobile add-on is Microsoft Intune Initial Setup for iPhone & iPad Management; and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices layers endpoint detection and response onto the managed Windows fleet. Windows Autopilot zero-touch deployment is a further separate engagement on the same foundation. Together they cover a complete, defended multi-platform estate.
How much does the Android setup cost?
The fee is fixed — see the price on this page. It covers one Intune tenant, one Android Enterprise enrollment model, up to three pilot devices, and up to three public Managed Google Play applications. Licensing, hardware, full-fleet deployment, and additional enrollment models are not included, and no out-of-scope work is performed without your written approval.
How long does implementation take?
One week. That assumes the Intune foundation is ready, the Managed Google Play connection account is available, the enrollment model is approved at kickoff, supported pilot devices and public applications are ready, and decisions and testing arrive on time. Client-side delays move the completion date rather than the scope.
Do you support Google zero-touch enrollment or Samsung Knox Mobile Enrollment?
Yes — as separately scoped work. Zero-touch enrollment and Knox Mobile Enrollment are the Android equivalents of Windows Autopilot: the reseller or OEM registers corporate-owned devices so they enroll automatically on first boot, which is the right production model for larger fleets. This one-week engagement establishes the Android Enterprise foundation those programs plug into; the portal setup and reseller coordination are quoted separately once your device supplier is known.
Why is Managed Google Play required?
Managed Google Play is the required bridge between Intune and Android Enterprise for enrollment and managed application distribution. You supply and keep control of the connection account, approve Google's terms, and keep the connection active after handoff — because disconnecting it breaks management of every enrolled device.
Can this service manage both corporate-owned and personal Android devices?
In one engagement, one model is implemented. A personally owned work profile manages the work area while leaving the personal side outside Intune's control; corporate-owned models manage more of the device. Many organizations run both — the second model is added as a separately quoted extension on the same foundation.
Are all Android applications included?
The service includes up to three client-selected public applications from Managed Google Play. Private or line-of-business app publishing, APK packaging, custom managed configurations, developer-account work, and vendor troubleshooting are separately scoped.
Does an Intune compliance policy automatically block access?
No. The compliance policy evaluates and reports whether a device meets the approved rules. Blocking access to Microsoft 365 based on that status requires Microsoft Entra Conditional Access — separate licensing, design, and testing, which we can scope as follow-on identity work.
What happens after implementation?
You receive the validated configuration, pilot results, as-built document, enrollment and troubleshooting runbook, rollout recommendations, and an administrator handoff. Natural next steps, each separately scoped: the production rollout, a second enrollment model, zero-touch or Knox onboarding for your device supplier, and the multi-platform bundle completing Windows, iPhone/iPad, and Android under one management design.