What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
To manage Android devices with Microsoft Intune, first connect your Intune tenant to Managed Google Play, then choose an Android Enterprise enrollment mode that matches who owns and uses each device. For a first test, a personally owned work profile is usually the least intrusive option for BYOD; enroll one device, approve and assign a Managed Google Play app, and verify the result before expanding the rollout.
“Google Play for Work” and “Android for Work” are older terms. Current Microsoft instructions use Managed Google Play and Android Enterprise. The walkthrough below focuses on a personal work profile first, with separate paths for corporate-owned and dedicated devices.
What Intune, Android Enterprise, and Managed Google Play each do
- Microsoft Intune is the administration service for enrollment, device and app policies, assignments, compliance, and reporting.
- Android Enterprise is Google’s framework for managing Android devices. It defines options such as a work profile, a fully managed device, or a dedicated kiosk-style device.
- Managed Google Play is the enterprise app catalog and distribution connection. Administrators use it to approve public apps and manage private apps and web apps for Android Enterprise deployments.
- Microsoft Entra ID provides work identities and group targeting, and can be used with Conditional Access to control access to organizational resources.
- Company Portal and the Microsoft Intune app have different roles depending on the enrollment method and device type. Company Portal is not the only current way to enroll a personal Android device.
Managed Google Play is linked to the organization’s Intune tenant; it is not a consumer Google Play account that an administrator must create and manage separately for every employee. Intune’s Android Enterprise management options require this connection. Microsoft’s Managed Google Play connection guide explains the setup.
Terms you may see in older instructions
| Older or informal term | Current term or meaning |
|---|---|
| Google Play for Work | Managed Google Play |
| Android for Work | Android Enterprise |
| Work profile | A separate Android area for organizational apps and data |
| DPC | Device Policy Controller, software used to apply management |
| BYOD | A personally owned device, commonly enrolled with a work profile |
Choose the right Android enrollment mode
Choose the mode before building policies or enrolling devices. Ownership and intended use determine how much control the organization needs and what the user experience should be. Microsoft outlines the available modes in its Android enrollment guide and Android Enterprise overview.
#1 Best Overall
| Scenario | Mode | Best suited to | Management trade-off |
|---|---|---|---|
| Employee-owned phone | Personally owned work profile | BYOD where work apps and data need separation | Intune manages the work profile; it does not manage the personal side like a corporate-owned device. |
| Company-owned phone that allows personal use | Corporate-owned work profile (COPE) | Organizations that want stronger device authority while separating work and personal use | More organizational control and operational responsibility than BYOD. |
| Company-owned phone for work use | Fully managed (COBO) | Employee devices intended primarily for organizational use | The organization manages the entire device; personal-use flexibility is limited. |
| Kiosk, shared tablet, scanner, or point-of-sale device | Dedicated (COSU) | Single-purpose or limited-purpose deployments | Not intended as an ordinary employee productivity phone. App assignments, often Required, are central. |
| Android device without Google Mobile Services or standard Android Enterprise support | Potentially AOSP or another supported fallback | Specific devices that cannot use the standard Android Enterprise route | Capabilities and setup differ; these are not equivalent replacements for standard Android Enterprise. |
For an employee’s own phone, the work profile separates organizational apps and data from personal apps and data. The organization’s controls apply to the work profile, not in the same way to the personal side. Avoid promising that no device-level information is ever visible: review Microsoft’s current enrollment and privacy details for the chosen mode before communicating what administrators can see.
Check prerequisites before connecting or enrolling
- An active Intune tenant and appropriate Intune or Microsoft 365 licensing for the devices and capabilities you plan to use.
- Microsoft Entra accounts for administrators and users, plus groups for pilot targeting.
- Android Enterprise availability in your country or region.
- Android devices that support the selected management mode and, where standard Android Enterprise requires it, Google Mobile Services. Check Play Protect certification and device compatibility.
- An administrator with permission to configure Android enrollment and Managed Google Play.
- Microsoft Edge or Google Chrome for Intune administration and compatible browser support for web-based enrollment.
- A test user and device. Remove existing MDM enrollment from the test device if it prevents enrollment with Intune.
- A plan for compliance, Conditional Access, user communication, and support before production rollout.
Availability and device requirements can vary by region, model, and enrollment mode; do not infer a universal minimum Android version from this general checklist. See Microsoft’s personal work-profile setup guidance and Android Enterprise overview for current requirements.
Connect Intune to Managed Google Play
- Sign in to the Microsoft Intune admin center.
- Go to Devices > Enrollment > Android.
- Under prerequisites, select Managed Google Play.
- Select the option to connect the Intune organization to Managed Google Play.
- Complete the Google organization setup or sign-in when redirected, then accept the connection.
- Return to Intune and confirm that the connection is active.
Labels and navigation can change, so follow the current controls shown in your tenant if they differ from these paths. Connecting the service also adds several commonly used Android Enterprise apps to Intune, including Microsoft Intune, Microsoft Authenticator, Intune Company Portal, Managed Home Screen, and Microsoft Launcher. Their purpose and whether they are needed depend on the enrollment mode. See Microsoft’s connection instructions.
Rank #2
- Powerful Hardware Configurations - Comparing with the End-of-life tablet scanner X-927, this 2025Q1 launched upgraded version maintains the appearance & rugged construction, but totally upgraded hardware configuration. It adopts a superior Qualcomm 8 core CPU processor which brings 1.5x faster running speed, & comes with 8GB RAM+128GB ROM large memory. As an essential production tool for enterprise mobile work, you can expect the high reliability to perform mission-critical tasks in field, & run multiple tasks smoothly.
- Professional Barcode Data Capturing — This industrial tablet integrates Zebra SE4750 2D laser scan engine, can read any 1D & 2D QR barcodes in milliseconds. With exceptional motion tolerance for reading moving barcodes, it boosts scanning speed and productivity. And the picklist feature allows user to easily select a single barcode to capture on a field of bar codes, ideal for intensive scan environment in warehouse, logistics, manufacturing etc.
- Android-based Warehouse Management – This enterprise tablet is developed based on Android 14 OS. With certified Google Mobile Service, you can easily utilize Android-based inventory applications or develop customized warehouse management system. It supports mainstream MDM software and 3rd party inventory apps such as Zoho Inventory, Orca Scan etc. The pre-installed Scan Helper App make things simple - you can set different scan mode (trigger on press or continuous scan etc.), barcode output formats, add prefix/ suffix / check digits etc. And you can simply utilize excel or web-based applications.
- 10000mAH High Capacity Battery - With integrated 10000mAh Li-ion battery and extraordinary low power design, the tablet standby time is more than 900hours, allows full day work without worrying about work efficiency & productivity.
- Multiple Functions for Comprehensive Enterprise Applications – Except for barcode scanner, this tablet also comes with 16MP camera, 13.56MHz NFC reader, WiFi, Bluetooth and 4G LTE module etc. With the all-in-one design, it meets versatile enterprise field work.
Do not disconnect Managed Google Play as a routine troubleshooting step. Microsoft’s documented process requires retiring Android Enterprise devices first; disconnecting can unenroll them from Intune. Treat a disconnect as a tenant-wide change and review the impact before proceeding.
Recommended Free Tools
Set up a personally owned work profile
Microsoft is transitioning personal Android work-profile enrollment from the older Company Portal/custom-DPC flow to web-based enrollment using the Android Management API. Follow the enrollment option currently available and recommended for your tenant; app-based enrollment remains relevant during the transition and for some authentication configurations. See the Android Management API overview and personal work-profile setup guide.
Create or configure the enrollment profile
- In Intune, go to Devices > Device onboarding > Enrollment > Android.
- Under enrollment profiles, choose Personally owned devices with a work profile.
- For a new deployment, review the web-enrollment option and enable it only if it suits your tenant’s authentication setup.
- Save the profile, then configure enrollment restrictions and group targeting for the intended users.
Enabling web enrollment is a tenant-level setting that cannot be reversed through the normal setting. Microsoft advises caution if passkeys are the tenant’s only accepted authentication method; verify current compatibility before enabling it. A device enrollment manager account is not supported for personally owned Android Enterprise work-profile enrollment. Also, the Personally owned enrollment restriction does not reliably block every Android Management API device or some Android 12-and-later custom-DPC cases. Use group-based restrictions or a corporate-owned enrollment approach when personal enrollment must be limited.
Rank #3
- [Next-Generation Barcode Tablet] The MUNBYN IRT01Pro rugged tablet with barcode scanner comes equipped with the Android 14, and boasts a large memory capacity of 8GB RAM and 128GB ROM. It offers a faster operating speed and wider software compatibility compared to previous models. Additionally, it can handle multitasking without any lag.
- [99.99% Reading Accuracy] MUNBYN IRT01P tablet scanner works with Zebra 4710 scanner, which is using PRZM intelligent imaging technology, guaranteeing high-definition image capture with up to 99.99% accuracy. It boasts a rapid scanning rate of 50 times/s, allowing for swift and precise identification of both 1D and 2D barcodes. With the capability to scan barcodes within a range of 29.92 inches (76 cm), this scanner promises an efficient and dependable scanning solution
- [No Job is Too Rugged]: MUNBYN IRT01P android tablet barcode scanner offers superior durability and protection compared to standard commercial tablets, boasting an IP67 protection level and MIL-STD-810G certification. It is designed to withstand immersion in water up to a depth of 1 meter for a brief period of time, as well as drops from a height of 1.22 meters while operational, without sustaining any damage
- [700nit Sunlight Readable] MUNBYN 8-inch Android tablet with barcode scanner features a 700nit high-brightness screen designed to deliver optimal visibility even in direct sunlight. Paired with an HD resolution of 1280*800, it ensures precise information capture and readability
- [3 Charging Ways & Large Battery] This rugged tablet with barcode scanner boasts impressive battery longevity with its substantial 8500mAh capacity, offering up to 9 hours of uninterrupted usage suitable for a full workday. The device further supports three versatile charging options, including DC Jack, Type C, and optional cradle charging, providing users with a practical and convenient means to keep the device powered and productivity uninterrupted on the go
Enroll with the web-based flow
- The user opens the organization’s enrollment URL or follows a redirect from a Microsoft productivity app or Company Portal.
- They select Get started, then Accept & continue.
- They continue in Chrome or another supported browser and sign in with their work account.
- They install required management apps if prompted and register the device.
- They follow Android’s prompts to create the work profile and complete required security or compliance steps.
The finished device shows a distinct work profile and work-app icons. Personal apps and data remain on the personal side of the phone; the work profile is the area managed under this enrollment.
Use the app-based flow if that is what the tenant supports
- Install Intune Company Portal from Google Play.
- Open it and sign in with the work account.
- Follow the enrollment prompts and allow Android to create the work profile.
- Complete the security and compliance actions presented by the device and Company Portal.
Do not assume Company Portal is always the enrollment app: its role varies with the web-based or app-based route and with corporate-owned enrollment.
Approve and assign an app from Managed Google Play
Approval, synchronization, and assignment are separate steps. An app that is merely approved does not automatically become available to users.
Rank #4
- Designed for Enterprise Mobility - This Android barcode scanner is our main supply and the most recommended model for warehousing & logistics use. It is equipped with a powerful Qualcomm Octa-core processor, Android 13 OS (upgradable to Android 16), 5.5-inch touch screen & 4420mAH removeable battery, and it is AER (Android Enterprise Recommended) certified. With higher compatibility, stability & superior hardware platform, the device brings outstanding operating experience in android enterprise applications, as an essential production tool.
- Integrated Multiple Data Collection Modules - This handheld PDA integrates Zebra SE4710 2D bar code scan engine, 13MP camera, NFC, WiFi etc. It is particularly design for enterprise mobile applications. The device obtains Android Enterprise Recommended(AER), which is verified by Google against enterprise grade requirements for performance, consistency and security updates.
- Easy Configuration & Enhanced Compatibility - With the pre-installed Keyboard Emulator & Infowedge app, you can easily configure the scanner for web-based applications. Also the mobile device is optimized to support multiple MDM or 3rd party inventory software, such as SOTI Mobicontrol, Ivanti Wavelink, Scalefusion, WizyEMM, Odoo, Zoho etc.
- Upgraded Wi-Fi stability — The upgraded Wi-Fi 6 technology of the handheld device significantly improves the ability to connect to increased number of mobile devices, handle network congestion with lower latency. Therefore it brings fast & stable network connection, improves work efficiency.
- Outstanding Durability - With rugged design and protective rubber boot included in the package, this mobile computer can withstand 2.4 m / 7.87 ft. drops (at least 20 times) to the concrete. Based on IP65 rated sealing, it can handle tasks in rain, dirt, mud, sand & water. Perfect for tough working conditions that demand the most from their tools.
- In Intune, go to Apps > All apps > Create and select Managed Google Play app.
- Open the app-search control and find the public app in Managed Google Play.
- Approve the app in the Managed Google Play interface.
- Return to Intune and synchronize the Managed Google Play connection. If needed, use Apps > All apps > Create > Managed Google Play app > Sync.
- Open the synchronized app in Intune and assign it to the intended user or device group.
- Choose the assignment intent that matches the user experience you want.
- Check installation status after the device has checked in.
| Assignment intent | What it means |
|---|---|
| Required | Intune directs installation automatically where the mode, device, assignment, and app support it. It may not happen immediately. |
| Available | Users can install the app from the managed store when it is offered to them. |
| Uninstall | Intune directs removal from targeted devices where the platform and scenario support it. |
Only apps assigned through Intune appear for users in Managed Google Play. An Available app should be found in the managed store, not assumed to appear in Company Portal. Microsoft’s Managed Google Play app guidance covers app addition and assignment.
App types and deployment limits
- Public apps: Existing apps published in Google Play and approved for the organization.
- Private apps: Organization line-of-business apps published privately for the tenant.
- Web apps: Managed shortcuts or web applications distributed through the managed store.
- Direct APK deployment: Supported by Intune for certain fully managed and dedicated-device scenarios. Do not assume it is available for every Android Enterprise mode, particularly personal work profiles.
Managed Google Play does not mean that every APK can be uploaded and distributed through the same workflow. Choose the app type and deployment method for the device mode you selected.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Add configuration, compliance, and access controls
After the first app installs successfully, apply controls in a pilot before broad deployment. Avoid adding a Conditional Access requirement that blocks the enrollment process before the device can become compliant.
Best Value
- UNLOCKED ON THE GO —Compatible with Verizon, AT&T and T-Mobile Networks
- MILITARY-GRADE DESIGN (MIL STD 810H, IP68 S Pen plus Anti Shock): Conquer the elements and don’t sweat the accidents. Dust, dirt, sand and water won’t get in your way with the IP681 rated Galaxy Tab Active3 and it’s S Pen. It’s even MIL-STD-810H2 compliant, so you can drop it from a height of 1.5M and it’ll absorb the shock.
- LONG-LASTING, FAST-CHARGING and REPLACEABLE BATTERY plus NO BATTERY MODE: Power through any project thanks to a long-lasting battery that won’t stop until your day does. Need to work even longer. The battery is also fast charging and replaceable, so you won’t lose a second in the field. The Galaxy Tab Active3 works in No Battery Mode when it’s connected to a dedicated power source making it a great in vehicle or fixed kiosk solution.
- WIRELESS DeX: Do more with a single device. With Samsung Wireless DeX, you can boost productivity and use your Galaxy Tab Active3 like a PC — that way you save money and your team can bring important tools into tough environments without having to haul around multiple devices or even a cable.
- ENHANCED TOUCH CAPABILITY : The gloves don’t have to come off, so your team stays safe and dry while they get more done. With enhanced touch capabilities settings, they can take advantage of an intuitive touchscreen, even while wearing gloves at work.
- Device configuration: Set a screen-lock requirement, encryption expectations, Play Protect expectations, and a minimum Android version only after checking support for your fleet.
- Work-profile controls: Decide how work data may be shared, including copy-and-paste and movement between work and personal apps.
- Compliance: Define the conditions a device must meet, and test the user experience when it does not.
- App configuration: Configure supported apps where useful. Android managed configuration works only when the app developer has implemented configuration values; Intune cannot arbitrarily configure every app.
- App protection: Use app protection policies to protect organizational data inside supported Microsoft apps, including when a device is not fully enrolled, where that scenario fits your requirements.
- Conditional Access: Require compliant devices only after enrollment and compliance reporting work for the pilot. The effect of exclusions depends on the exact policy.
- Operations: Document notifications, support contacts, selective wipe, device retirement, and lost-device procedures before rollout.
For corporate-owned enrollment, a Conditional Access policy that blocks access or requires compliance too early can obstruct setup. Review Microsoft’s corporate enrollment guidance and the policy’s targeted cloud apps and exclusions; do not apply a blanket exclusion without evaluating the security impact.
Enroll corporate-owned or dedicated devices
For corporate-owned work-profile, fully managed, and dedicated devices, select the corresponding corporate-owned enrollment profile. Provisioning generally starts with a factory-reset device and uses a method suited to how devices are purchased and deployed: QR code, token, Google Zero Touch, Samsung Knox Mobile Enrollment, NFC, or the DPC identifier method. The available choices depend on the scenario; see Microsoft’s corporate-owned enrollment methods.
DPC identifier method
For the documented DPC identifier route, enter afw#setup at the Google sign-in screen of a factory-reset device. Android Device Policy is installed, after which enrollment continues using a QR code or token. Follow the current tenant-specific provisioning instructions rather than treating the identifier as a complete enrollment by itself.
Fully managed and dedicated deployment cautions
- Do not restart a fully managed or corporate-owned device in the middle of enrollment. Microsoft warns that it can appear enrolled without having received protection policies.
- For a dedicated device, assign the required apps as Required when they must install automatically.
- For multi-app kiosk scenarios, Managed Home Screen may be part of the design. Confirm app assignments and restrictions on a test device before staging devices in quantity.
See Microsoft’s dedicated-device setup guide for that scenario.
Quick Recap
Troubleshoot common setup failures
| Symptom | Likely causes | What to check or do |
|---|---|---|
| Managed Google Play connection option is missing or fails | Insufficient administrator permissions or an organization/tenant setup issue | Verify the Intune role and organization setup, then retry using the current connection steps. |
| Device cannot create a work profile | Unsupported device, missing Google Mobile Services, lack of Play Protect certification, or existing management | Check Android Enterprise and device compatibility, and resolve existing MDM enrollment through a planned migration. |
| Enrollment is blocked at sign-in | Conditional Access, enrollment restrictions, unsupported authentication configuration, or browser issue | Review the exact policy and restriction affecting the user; confirm browser and web-enrollment compatibility. For corporate-owned enrollment, check whether Conditional Access prevents setup. |
| App was approved but does not appear in Intune | Connection has not synchronized, app was approved in another organization, or app is unavailable for the target country/device | Force a Managed Google Play sync, confirm the correct organization, and check app availability. |
| App is in Intune but user cannot find it | App has no assignment, wrong group, or user is checking Company Portal instead of the managed store | Check group membership and assignment intent; for Available apps, direct the user to Managed Google Play. |
| App is assigned but does not install | Device has not checked in, incompatible Android version/device, insufficient storage, network issue, wrong mode, or assignment scope problem | Verify the target group, assignment, compatibility, storage, network, and device check-in. Required is an instruction to install, not a guarantee of immediate installation. |
| Work profile exists but policies seem absent | Enrollment may not be complete, device has not checked in, or the policy is not assigned to the user/device | Check enrollment and assignment status, then allow or initiate a sync before diagnosing the policy itself. |
| Personal enrollment still works after a restriction was added | The Personally owned restriction is not reliable for Android Management API devices and some Android 12-and-later custom-DPC cases | Use appropriate group-based restrictions or a corporate-owned enrollment method when required. |
| Company Portal behavior differs from instructions | Web versus app-based enrollment, or a different corporate-owned mode | Identify the enrollment method and ownership mode first; Company Portal’s role varies. |
Pilot before rolling out
- Test with an administrator and a standard user in a small pilot group.
- Test enrollment over Wi-Fi and cellular service.
- Confirm the expected work-profile indicators and that a selected Managed Google Play app installs.
- Test app removal, selective wipe, and device retirement so administrators understand each action’s effect.
- Test Conditional Access and compliance after enrollment succeeds.
- Confirm user instructions, support ownership, and lost-device escalation procedures.
- Communicate what is managed in the work profile and what remains personal before asking employees to enroll.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




