Overview
Factorial IT uses Fleet as the MDM agent on Android. Android 13 and later is supported; anything below cannot enrol.
Unlike Windows and Linux, Android needs one piece of setup first: linking a Managed Google Play account. That registers your organisation with Android Enterprise and is what allows apps to be deployed and policies enforced.
Android version |
Can be managed |
|---|---|
13+ |
Yes |
12 and below |
No |
How to use — connect Managed Google Play
- Go to MDM > Android.
- Connect your Managed Google Play account. Follow the prompts to link your organisation's account. This registers you with Android Enterprise and authorises device management.
- Confirm the connection. Android MDM is now active: devices can enrol and apps can be deployed from the Play Store.
Enrolment modes
Both modes are available everywhere you can enrol — MDM settings, the employee enrolment stepper and invite emails. Pick the one that matches who owns the device.
Personal (work profile) |
Company-owned (fully managed) |
|
|---|---|---|
Use it for |
A phone the employee already owns |
A new or factory-reset company device |
What is managed |
A separate work profile only |
The whole device |
Personal data |
Stays private and invisible to IT |
No separate personal profile |
Who does it |
The employee, on their own |
IT, with the device in hand |
How to use — personal device (work profile)
The employee does this themselves:
- Open the enrolment link on the Android device, or scan the QR code shown next to it.
- Tap Enrol and follow the steps to create the work profile.
Company apps and data live inside the work profile. Personal apps, photos and accounts stay outside it and are not visible to IT.
How to use — company-owned (fully managed)
This is an IT staging flow, not self-service. You need the device in hand and a second screen:
- On a computer or tablet, open the fully-managed enrolment link. A provisioning QR code appears. Leave the page open.
- Power on the Android device so it sits on its welcome screen. If it has already been set up, factory-reset it first.
- Tap the welcome screen six times to open the QR scanner, then scan the code from step 1.
The device provisions itself and appears in the dashboard once enrolment finishes.
The provisioning QR code is generated on demand and expires about an hour after the link is opened. Open the link immediately before scanning, not in advance.
Tips and Best Practices
- Open the QR link right before you scan it. The code expires in roughly an hour, and a stale code is the most common reason a fully-managed enrolment fails.
- Use work profile for anything the employee owns. It keeps personal data out of your visibility, which is a much easier conversation than asking for full control of someone's phone.
- Batch fully-managed enrolments. They need the device and a second screen, so doing ten in one sitting is far quicker than one at a time.
- Remember Android has no remote wipe. Plan offboarding for these devices differently from laptops.
Troubleshooting and FAQ
Troubleshooting
- The provisioning QR code does not work. It has almost certainly expired — codes last about an hour from when the link is opened. Reload the link to generate a fresh one and scan it straight away.
- Tapping the welcome screen does not open a scanner. The device has already been set up, so it is past the welcome screen. Factory-reset it and start again.
- A device on Android 12 will not enrol. Android 13 is the minimum. There is no workaround other than updating the device.
- Apps will not deploy. Managed Google Play is not connected, or the connection did not complete. Go to MDM > Android and confirm it.
FAQ
-
Can we see an employee's personal apps and photos on a work profile device?
No. Personal apps, photos and accounts sit outside the work profile and are not visible.
-
Can we convert a personal enrolment into a fully managed one?
Not in place. Fully-managed provisioning starts from the welcome screen, so the device has to be factory-reset.
-
Do we need Managed Google Play even if we deploy no apps?
Yes. It is what registers your organisation with Android Enterprise and enables policy enforcement.