First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Microsoft Intune Initial Setup for Android Device Management
Security and Protection

Microsoft Intune Initial Setup for Android Device Management

Microsoft Intune Initial Setup for Android Device Management is a one-week, fixed-fee add-on that extends your Intune tenant to Android using Android Enterprise. IT Partner connects Managed Google Play, helps you choose the right Android Enterprise enrollment model for how your devices are owned and used, configures that model with baseline compliance and configuration policies and up to three managed applications, and proves it on a pilot of up to three devices. Windows is covered by Microsoft Intune Initial Setup for Windows Device Management; iPhone and iPad by Microsoft Intune Initial Setup for iPhone & iPad Management.

Timeline 1 weekService owner Roman SotnikOffice 365microsoft 365

What this engagement is

Android management succeeds or fails on one early decision: the Android Enterprise enrollment model. Each model — personally owned work profile, corporate-owned fully managed, corporate-owned work profile, and corporate-owned dedicated — behaves differently for privacy, applications, and policy control, and some choices are effectively permanent. This add-on gets that decision right, then implements it. IT Partner connects your Intune tenant to Managed Google Play, configures the selected enrollment model with its profile, token, QR code, or web enrollment flow, blocks legacy Android Device Administrator enrollment, builds one compliance baseline and one device configuration baseline, assigns up to three public Managed Google Play applications, and validates the whole flow on up to three pilot devices. Who this is for: US commercial organizations of roughly 100–500 seats on the Microsoft cloud that need company data managed on Android phones and tablets — whether corporate-owned or employees' own devices. Who it is not for: fleets needing several enrollment models at once, kiosk estates with custom launcher requirements, or organizations wanting a full-fleet hands-on rollout — each of those extends this foundation as separately scoped work. The engagement covers one enrollment model per implementation; adding a second model later is a separately quoted extension of the same foundation.

Success criteria

01The Intune tenant has an active Managed Google Play connection owned through a client-controlled account, and Managed Google Play application synchronization succeeds.
02The approved Android Enterprise enrollment model is configured with its required profile, token, QR code, or web enrollment flow, and the associated pilot access and policy-assignment controls are in place.
03Enrollment restrictions block legacy Android Device Administrator and, where applicable, unapproved personally owned enrollment. Profiles and credentials for other corporate-owned modes are not configured or distributed.
04Up to three eligible pilot devices enroll through the selected flow and appear in Intune with the expected ownership, user association, inventory, and management state.
05The pilot devices receive the approved compliance policy and device configuration profile, and report their resulting status without unresolved assignment conflicts caused by the implemented scope.
06Up to three approved public Managed Google Play applications synchronize to Intune, are assigned as documented, and install or become available as intended on the pilot devices.
07Your administrators can locate the pilot devices, review inventory and compliance status, initiate a synchronization, and follow the documented enrollment procedure.
08Your administrators receive and can follow the selected-model design, enrollment, troubleshooting, application, and operating procedures.

What you receive

Android Enterprise readiness assessment: device ownership, user association, personal-use requirements, supported devices and OS versions, Google Mobile Services availability, current MDM state, applications, licensing, network access, and identity-policy dependencies.
Enrollment-model decision record — which of the four Android Enterprise models fits your fleet and why, with the approved pilot population.
One active Managed Google Play connection using a client-controlled account, with documented tenant ownership and administrative procedure.
The configured enrollment model with its required profile, token, QR code, or web flow, pilot access and policy-assignment controls, and a documented credential-handling procedure.
Android enrollment restrictions that block legacy Device Administrator and, where applicable, unapproved personally owned enrollment.
One baseline Android Enterprise compliance policy and one baseline device configuration or restrictions profile, tailored to the selected model.
Approval, synchronization, and assignment of up to three public Managed Google Play applications.
Enrollment, policy, compliance, and application validation report for up to three client-provided pilot devices, including identified dependencies and unresolved items outside scope.
As-built configuration, pilot enrollment guide, administrator operations and troubleshooting runbook, rollout recommendations, and an administrator handoff session.

How the work unfolds

Day 1 — Kickoff, readiness, and model selection

Confirm the relationship to the core Intune service and how your devices are owned and used. Select the Android Enterprise enrollment model, and approve pilot devices, users, applications, policies, success measures, and client responsibilities.

Days 1–2 — Managed Google Play and tenant foundation

Verify the Intune foundation, connect the tenant to Managed Google Play with the client-controlled account, confirm application synchronization, and review enrollment-affecting identity and network policies.

Day 2 — Enrollment configuration and restrictions

Configure the profile, token, QR code, or web flow for the selected model. Establish pilot access and policy assignments, block legacy Device Administrator and unapproved personal enrollment where applicable, and withhold credentials for other corporate-owned modes.

Day 3 — Compliance, configuration, and applications

Configure the approved compliance baseline, the device configuration or restrictions baseline, and up to three public Managed Google Play application assignments.

Day 4 — Pilot enrollment and validation

Enroll up to three supported pilot devices. Validate ownership, user association, inventory, policy delivery, compliance evaluation, application delivery, and administrator visibility.

Day 5 — Remediation, documentation, and handoff

Correct in-scope configuration issues, finalize the design and runbooks, review phased-rollout recommendations and open dependencies, conduct the administrator handoff, and confirm acceptance criteria.

Prerequisites

An active Microsoft Intune tenant with MDM authority configured — through Microsoft Intune Initial Setup for Windows Device Management, an existing equivalent Intune foundation, or a concurrent implementation.
Assigned Microsoft Intune licensing for each benefiting user or eligible device. Device-only licensing for userless dedicated devices does not provide user-based capabilities such as Conditional Access or app protection.
Android Enterprise availability in your region, and supported devices with the OS version, Google Mobile Services connectivity, and Play Protect certification required for the selected model.
A client-controlled Microsoft Entra account with an active mailbox and the Intune permission required to establish and administer the Managed Google Play connection. You retain ownership of the associated Google administrator relationship after setup.
A client-approved choice of one Android Enterprise model: personally owned work profile, corporate-owned fully managed, corporate-owned work profile, or corporate-owned dedicated.
Between one and three representative pilot devices and any required pilot users. Corporate-owned models require new or factory-reset devices and your authorization to erase local data after backup.
An approved list of up to three public Managed Google Play applications, plus any application licenses, sign-in accounts, or testing credentials required for validation.
Reliable internet, DNS, firewall, proxy, and Wi-Fi access to the Google, Microsoft Entra, Microsoft Intune, Managed Google Play, and application-delivery endpoints the selected enrollment flow requires.
Disclosure of existing MDM, Conditional Access, Terms of Use, authentication, compliance, certificate, VPN, Wi-Fi, OEM, and application policies that could affect Android enrollment or management.
If existing Conditional Access policies require compliant Android devices or block cloud access during enrollment, a client-approved enrollment design or narrowly scoped exception that permits both pilot and production enrollment.
A client project owner and technical decision-maker who can provide administrative access, approve Google terms and data sharing, make devices and users available, provide decisions, and validate results within the one-week schedule.
Client-approved user communications, change records, device-reset authorization, data backups, and end-user or help-desk availability for the pilot.

Who does what

IT Partner

  • Lead Android discovery, readiness assessment, enrollment-model selection, implementation planning, pilot validation, and acceptance review.
  • Connect one Intune tenant to Managed Google Play using the client-controlled account, and document the connection and administrative ownership.
  • Configure the selected enrollment model with its required token, QR code, or web enrollment flow.
  • Configure pilot access and policy assignments, block legacy Device Administrator and unapproved personal enrollment where applicable, and withhold credentials for other corporate-owned modes.
  • Configure the baseline compliance policy, the baseline device configuration or restrictions profile, and up to three public Managed Google Play application assignments.
  • Assist with enrollment and validation of up to three client-provided pilot devices, and troubleshoot issues caused by the implemented configuration.
  • Validate the agreed device, policy, compliance, application, and administrative outcomes, and document dependencies that require separate remediation.
  • Provide the as-built configuration, enrollment guide, credential-handling and troubleshooting runbook, rollout recommendations, and administrator handoff.

Your team

  • Provide and maintain Microsoft Intune licenses, supported Android devices, application licenses, the client-controlled Managed Google Play connection account, and any third-party subscriptions.
  • Provide approved administrative access to Microsoft Intune, Microsoft Entra, Managed Google Play, and any client systems required for implementation and testing.
  • Select and approve the Android Enterprise ownership and enrollment model, the pilot population, compliance requirements, configuration settings, applications, and acceptable user experience.
  • Approve Google's terms and data sharing, retain long-term control of the Managed Google Play connection account, and manage account recovery and client-only Google tasks.
  • Provide between one and three eligible pilot devices, authorize any required factory resets, back up local data, make pilot users available, and perform required physical device steps.
  • Provide network access, application inputs, authentication and identity-policy decisions, change approvals, communications, and first-line end-user support.
  • Review testing results and deliverables, provide decisions and feedback within the one-week schedule, and approve acceptance against the published success criteria.
  • Own production rollout, device logistics, user support, ongoing application approvals, compliance remediation, monitoring, and policy maintenance after handoff unless separately contracted.

What's not included

Other platforms — Windows Intune configuration (provided by Microsoft Intune Initial Setup for Windows Device Management; Windows Autopilot zero-touch deployment is a further separate service), iPhone and iPad management (provided by Microsoft Intune Initial Setup for iPhone & iPad Management), endpoint detection and response (provided by Microsoft Defender for Endpoint Deployment for Intune-Managed Devices), and AOSP, ChromeOS, Teams-certified Android devices, or legacy Device Administrator management.
Other Android models and OEM integrations — any Android Enterprise enrollment model beyond the one selected for this engagement; Google zero-touch enrollment portal implementation and reseller coordination; Samsung Knox Mobile Enrollment; NFC provisioning; OEMConfig; custom kiosk workflows and Managed Home Screen customization; and Microsoft Entra shared-device-mode application integration. Zero-touch and Knox onboarding are available as separately scoped work — see the FAQ.
Migration and legacy management — migration from another MDM or UEM, mass unenrollment or factory reset, coexistence design, device backup or restoration, and decommissioning of legacy management.
Security and identity program work — tenant-wide Conditional Access, MFA redesign, identity federation, Zero Trust architecture, Microsoft Defender for Endpoint and mobile threat defense, threat-based compliance, DLP, SIEM/SOC integration, PKI and certificate services (SCEP, NDES, Cloud PKI), custom VPN or Wi-Fi engineering, and network access control. Mobile application management without enrollment (MAM-only app protection) is its own design and separately scoped.
Commercial and logistics items — Microsoft and Google licenses, paid applications, devices, accessories and carrier services, private or line-of-business app publishing and APK packaging, organization-wide enrollment beyond the three-device pilot, physical staging or shipping, formal end-user training, ongoing administration and support after acceptance, travel, and taxes.

Limitations & technical notes

!What partners most often get wrong on Android — three warnings worth reading before anything else: (1) personally owned work-profile web enrollment is a tenant-wide setting and effectively irreversible, so it is enabled only after a documented readiness decision; (2) an Intune compliance policy only evaluates and reports — actually blocking access to Microsoft 365 requires separately licensed Microsoft Entra Conditional Access; (3) disconnecting the Managed Google Play account breaks Android Enterprise management for every enrolled device, so that account must stay under your control permanently.
!The engagement implements one Android Enterprise enrollment model. The four models differ materially in enrollment, privacy, application, and policy behavior, and a second model is a separately quoted extension rather than a settings change.
!Corporate-owned modes generally require a new or factory-reset device. Users should not restart a device mid-enrollment: an interrupted enrollment can leave the device registered without its intended protection.
!Dedicated devices without Microsoft Entra shared device mode are userless. They are not suitable for ordinary user-based applications or for resources protected by user Conditional Access.
!Enrollment, application and policy delivery, synchronization, and compliance reporting are not instant. Timing depends on Microsoft and Google service availability, connectivity, device state, Android version, OEM behavior, and policy conflicts.
!The one-week schedule assumes a ready Intune foundation, an eligible Managed Google Play connection account, an enrollment model approved at kickoff, supported pilot devices, available public applications, working network access, and timely client decisions and testing.
!The fixed fee covers one Intune tenant, one Android Enterprise enrollment model, up to three pilot devices, and up to three public Managed Google Play applications. Additional models, devices, applications, platforms, or remediation require a written, approved change in scope.
!Intune management improves consistency and administrative control, but no management platform can guarantee prevention of every data-loss event, security incident, service outage, enrollment failure, or compliance issue.
!Technical content reviewed August 2026.

Frequently asked questions

Which Android Enterprise enrollment model should we choose?

There are four, and the right one follows from who owns the device and who controls the personal side. Personally owned work profile: the employee owns the phone, work data lives in a separate encrypted profile, IT manages only that profile, and the personal side stays private — no device reset needed. Corporate-owned fully managed: the company owns the device and IT manages all of it; requires a new or factory-reset device; typical for knowledge-worker fleets. Corporate-owned work profile (COPE): the company owns the device but the employee also uses it personally; IT manages the work profile with limited device-level control; requires a reset; balances control with personal privacy. Corporate-owned dedicated: kiosk-style devices with no single user — scanners, signage, shared floor devices; requires a reset; unsuitable for user-based apps unless Microsoft Entra shared device mode is added. Choosing the model is the first working session of this engagement, and IT Partner documents the decision and its trade-offs before anything is configured.

What do partners most often get wrong on Android — and how does this service avoid it?

Three mistakes account for most Android Enterprise rework. First, enabling personally owned work-profile web enrollment casually: it is tenant-wide and effectively irreversible, so this service treats it as a formal readiness decision. Second, assuming a compliance policy blocks anything: it only reports status — enforcement needs separately licensed Microsoft Entra Conditional Access, which we design for but do not silently enable. Third, losing the Managed Google Play connection account: disconnecting it breaks management of every enrolled device, so the connection is created under a client-controlled account with a documented ownership procedure.

Who is this service for — and who is it not for?

It fits US commercial organizations of roughly 100–500 seats on the Microsoft cloud that need company data managed on Android devices — corporate-owned or personal. It is not the right shape for fleets that need several enrollment models at once, custom kiosk launchers, or a hands-on rollout of hundreds of devices; each of those builds on this foundation as separately scoped work.

What is included in Microsoft Intune Initial Setup for Android Device Management?

The service connects one Intune tenant to Managed Google Play, configures the selected Android Enterprise enrollment model, sets pilot access and policy assignments, blocks legacy Device Administrator enrollment, builds one compliance baseline and one device configuration baseline, assigns up to three public applications, validates up to three pilot devices, and delivers documentation and an administrator handoff.

How does this add-on relate to the other Intune services?

Microsoft Intune Initial Setup for Windows Device Management provides the core foundation every add-on builds on. This service is the Android add-on; the sibling mobile add-on is Microsoft Intune Initial Setup for iPhone & iPad Management; and Microsoft Defender for Endpoint Deployment for Intune-Managed Devices layers endpoint detection and response onto the managed Windows fleet. Windows Autopilot zero-touch deployment is a further separate engagement on the same foundation. Together they cover a complete, defended multi-platform estate.

How much does the Android setup cost?

The fee is fixed — see the price on this page. It covers one Intune tenant, one Android Enterprise enrollment model, up to three pilot devices, and up to three public Managed Google Play applications. Licensing, hardware, full-fleet deployment, and additional enrollment models are not included, and no out-of-scope work is performed without your written approval.

How long does implementation take?

One week. That assumes the Intune foundation is ready, the Managed Google Play connection account is available, the enrollment model is approved at kickoff, supported pilot devices and public applications are ready, and decisions and testing arrive on time. Client-side delays move the completion date rather than the scope.

Do you support Google zero-touch enrollment or Samsung Knox Mobile Enrollment?

Yes — as separately scoped work. Zero-touch enrollment and Knox Mobile Enrollment are the Android equivalents of Windows Autopilot: the reseller or OEM registers corporate-owned devices so they enroll automatically on first boot, which is the right production model for larger fleets. This one-week engagement establishes the Android Enterprise foundation those programs plug into; the portal setup and reseller coordination are quoted separately once your device supplier is known.

Why is Managed Google Play required?

Managed Google Play is the required bridge between Intune and Android Enterprise for enrollment and managed application distribution. You supply and keep control of the connection account, approve Google's terms, and keep the connection active after handoff — because disconnecting it breaks management of every enrolled device.

Can this service manage both corporate-owned and personal Android devices?

In one engagement, one model is implemented. A personally owned work profile manages the work area while leaving the personal side outside Intune's control; corporate-owned models manage more of the device. Many organizations run both — the second model is added as a separately quoted extension on the same foundation.

Are all Android applications included?

The service includes up to three client-selected public applications from Managed Google Play. Private or line-of-business app publishing, APK packaging, custom managed configurations, developer-account work, and vendor troubleshooting are separately scoped.

Does an Intune compliance policy automatically block access?

No. The compliance policy evaluates and reports whether a device meets the approved rules. Blocking access to Microsoft 365 based on that status requires Microsoft Entra Conditional Access — separate licensing, design, and testing, which we can scope as follow-on identity work.

What happens after implementation?

You receive the validated configuration, pilot results, as-built document, enrollment and troubleshooting runbook, rollout recommendations, and an administrator handoff. Natural next steps, each separately scoped: the production rollout, a second enrollment model, zero-touch or Knox onboarding for your device supplier, and the multi-platform bundle completing Windows, iPhone/iPad, and Android under one management design.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$1,950 per project
1 week
Book an Android scoping call