<
 
 

How to enroll your first Android device?

Enrolling your first android device in ME MDM

Device Enrollment is the process of registering and configuring a device for organizational use, which involves the setup of security policies, work applications, and management controls.

Understanding management of android enterprise devices

Android devices are managed in various management modes based on business needs, defined by Android Enterprise and integrated into the Android OS. Manage Engine supports all these management use cases, offering different enrollment techniques for device onboarding. Here's a brief overview:


Android Management Mode


Scenarios


Enrollment Methods



Work Profile (Profile Owner)
  • Used for employee-owned devices or BYOD
  • Secure container for work apps and policies
  • No control over personal apps and data
  1. Using a direct QR Code or Enrollment link
  2. Self Enrollment
  3. User invitations


Fully Managed (Device Owner)
  • Used for Company-owned devices
  • Devices deployed in kiosk mode;
    dedicated devices locked down to run only work applications



  1. Zero touch Enrollment
  2. Knox Mobile Enrollment
  3. QR Code (EMM Token) Enrollment

Fully Managed with a Work Profile
(Work Profile on Company-Owned Devices)

Company-owned devices with work and
personal profile separation, allowing employees
to use their devices for both work
and personal activities while maintaining security and privacy

To learn more about the different enrolment methods and additional options for enrolling rugged devices and AOSP devices, please refer to our Help Guide.

Evaluating android device management with work profile enrollment

In this guide, we will explore the process of enrolling the first Android device quickly using a QR Code, to begin your MDM evaluation. This creates a work profile on the device to manage work apps and data separately. If you would like to explore full device management features such as Kiosk, lockdown apps, you can start with other enrolment methods outlined in the above sections.

An enrollment option is accessible once you log in to the product at the beginning. An enrollment QR code is available in the Devices section of the Enrollment tab in the product.

Pre-requisites for MDM On-Premise edition

If you are using the MDM Cloud version then please Skip the below steps and proceed directly to the enrollment steps to register your first Android device.

For MDM On-Premise Version:

  1. Firewall and Proxy Rules: To ensure proper functionality, the MDM (Mobile Device Management) server needs to connect to essential services such as Google Cloud Messaging. If you are utilizing a proxy or firewall, it's imperative to configure these settings within the MDM console. 
  2. MDM server address: Devices need to access the server address even from the internet for remote management. You can configure NAT settings so your public domain directs to the MDM server and port. Alternatively, use the default address for evaluation. You can set up NAT settings later when you plan on enrolling more devices.

    Ensure the device is part of the server network during testing.

    To know more about the MDM On-Premise please visit our Help Guide.

Methods to enroll the first android device

  • Install ME MDM App:

    Scan the QR Code using the camera; the user will be presented with an Enrollment URL. Click on the URL to download the Manage Engine Mobile Device Management (ME MDM) app.

    Alternatively, users can open the Play Store, search for the ME MDM app, and install it directly on their Android device.

  • Enroll the Device Using ME MDM App:

    Launch the ME MDM app and either scan the QR Code or access the Enrollment URL to initiate the enrollment process. Follow the on-screen instructions provided by the app to complete the device enrollment successfully.

  • View and Manage Enrolled Device:

    Upon successful completion of device enrollment, the user will receive a notification confirming the setup of the work profile. Users can then access the Work Profile on the enrolled devices, which distinguishes between personal and work applications for convenient management and organization.

    User can access the enrolled devices by navigating to the Devices section within the Enrollment Tab in the MDM Console, where the status of each device will be displayed as "Enrolled."

    User can execute actions on the enrolled devices from the Devices section within the Enrollment Tab, as well as from the Inventory Tab and Management Tab.

What's Next?

Configure profile and policies:

User can configure profiles and policies to leverage the benefits of device enrollment, including creating passcode rules for the work profile, restricting data leakage from work apps, and enforcing Play Protect.

To learn more about Configuring Profiles and Policies, please refer to Device Restrictions and Configurations.

Distribute work applications:

User can enable silent distribution of work applications by configuring the apps in the app repository and distributing them to the enrolled devices.

To learn about App Distribution, please visit App Management.

If you are encountering errors, please refer to these troubleshooting documents.