Overview
Android enrollment allows your organization to manage and configure Android devices for work. The enrollment process depends on whether the device is personally owned or company-owned.
Swif supports:
BYOD enrollment with a separate work profile
Fully managed enrollment for company-owned devices
Android zero-touch enrollment for eligible company-owned devices
Important: Choose the device’s current setup state carefully. An existing personal device can be enrolled without a factory reset only in BYOD mode. Fully managed company-owned enrollment must begin during initial device setup.
Learn more at Understanding Android Device Management (MDM) Modes: Full Managed, Work Profile, and BYOD.
Prerequisites
Before enrolling a device:
Your Swif team must be registered with Android Enterprise. Personal gmail can be used to sign up as well. It doesn't have to be a company email address.
The device must run Android 9 or later.
The device must have a stable internet connection.
The administrator must generate an Android enrollment QR code or enrollment code from Swif.
If Android Enterprise registration has not been completed, Swif will prompt an administrator to register before generating enrollment details.
Choose an Enrollment Type
Swif supports two primary Android enrollment modes.
Device use | Personal Usage setting | Swif enrollment option | Factory reset required |
Personally owned device with personal apps and data | Allowed | Existing device | No |
Company-owned, fully managed device | Disallowed | New device | Yes |
New company-owned device that has not completed setup | Disallowed | New device | No additional reset is needed |
Existing device being converted to fully managed | Disallowed | New device | Yes |
Device owner auto assigned
When generating QR code, the work identity email will be used to auto assign the enrolled device to the right device employee owner.
BYOD Enrollment — Personal Usage Allowed
Use BYOD enrollment when an employee wants to enroll an existing personal device without deleting personal applications, photos, messages, accounts, or other data.
When Personal Usage is set to Allowed, Android creates a separate work profile.
The organization can manage the work profile, including its:
Work applications
Work accounts
Work data
Security requirements
Application permissions
Data-sharing controls
Personal applications and data remain outside the work profile and are not converted into managed company data.
Management capabilities are more limited than on a fully managed device because Swif manages the work profile instead of the entire device.
Learn more about Android BYOD limitation.
Enroll an Existing Personal Device
In the Swif Admin Dashboard:
Generate the Android enrollment details.
Select the Existing device tab.
Display the QR code or copy the enrollment code.
On the Android device:
Open Settings.
Go to Google > Set up & restore.
Select Set up your work profile.
Scan the enrollment QR code or enter the enrollment code.
Follow the on-screen instructions to create the work profile and complete enrollment.
Menu names can vary slightly depending on the Android version and device manufacturer. Search Settings for work profile if the option is not displayed under Set up & restore.
Important: Do not scan the BYOD enrollment QR code directly with the regular Camera application. The QR code must be scanned from Android’s Set up your work profile enrollment flow. Scanning it with the Camera application can produce an error or fail to start enrollment.
After enrollment, Swif displays the device as BYOD. The device will have separate personal and work profiles.
Company-Owned Enrollment — Personal Usage Disallowed
Use fully managed enrollment for company-owned devices on which the organization requires management of the entire device.
When Personal Usage is set to Disallowed:
The entire device is managed.
Android does not create a separate personal profile.
The organization can apply the full set of supported device restrictions and security policies.
Existing personal applications and data cannot be preserved during conversion to fully managed mode.
Is a Factory Reset Required?
Yes. Android requires fully managed enrollment to begin during the initial setup of a new or factory-reset device.
A device that has already completed Android Setup cannot be converted to fully managed mode using a QR code or enrollment code. It must first be factory reset.
A separate reset is not required when the device is new and still displays its initial welcome screen.
Warning: A factory reset deletes applications, accounts, settings, and locally stored data. Back up any required information before resetting the device.
Enroll a New or Factory-Reset Company-Owned Device
In the Swif Admin Dashboard:
Generate the Android enrollment details.
Select the New device tab.
Display the enrollment QR code.
On the Android device:
Turn on the new or factory-reset device.
On the initial Android welcome screen, tap the same empty area six times.
Connect the device to Wi-Fi if prompted.
Wait for Android to open or download the QR-code scanner.
Scan the enrollment QR code displayed in Swif.
Follow the on-screen instructions to complete device setup.
Allow Android Device Policy to apply the organization’s configurations and policies.
Do not complete the normal Android Setup flow before starting enrollment. Fully managed enrollment cannot be initiated after the device reaches its normal Home screen.
Enroll a Company-Owned Device Without Scanning the QR Code
If the new or factory-reset device cannot scan the QR code:
Begin Android Setup normally.
Connect the device to Wi-Fi.
At the Google sign-in screen, enter the following instead of an email address:
afw#setup
The device will automatically download and install the necessary Swif enrollment application.
In the Swif web app, select Generate Enrollment Code. The manual enrollment token will be displayed alongside the QR code.
Enter the enrollment code displayed in Swif.
Follow the on-screen instructions to complete fully managed enrollment.
The afw#setup method is intended for new or factory-reset company-owned devices. Do not use it to create a BYOD work profile on an existing personal device.
Enroll a BYOD Device Without Scanning the QR Code
If the BYOD QR code cannot be scanned:
Open Settings.
Go to Google > Set up & restore.
Select Set up your work profile.
Choose the option to enter an enrollment code.
Enter the code displayed under the Existing device tab in Swif.
Follow the on-screen instructions.
Do not enter afw#setup on an existing personal device. That provisioning method is for device setup and fully managed enrollment.
Zero-Touch Enrollment
Android zero-touch enrollment allows eligible company-owned devices to enroll automatically during initial setup without manually scanning a QR code.
Zero-touch enrollment requires:
A supported Android device
Purchase from an authorized zero-touch reseller
Assignment of the device to your organization
A zero-touch configuration associated with Swif
Contact your IT administrator or device reseller to determine whether zero-touch enrollment is available.
Bulk Invite for Android Enrollment
Admins can now use the bulk invite flow to enroll multiple Android devices simultaneously. This feature supports unique QR code generation per employee identity and provides flexible personal usage options to streamline the onboarding process.
Key Features
Personal Usage Options: When initiating a bulk invite, admins must select a Personal Usage setting (Allowed, Disallowed, or Userless). The "Invite" button will remain disabled until an option is selected to ensure the correct instructions are sent.
Unique QR Codes: For BYOD enrollment (Personal Usage: Allowed), Swif generates a unique QR code for each recipient based on their work email identity. This ensures that the enrolled device is automatically assigned to the correct employee in the dashboard.
Bulk Notice: When multiple employees are selected, the dashboard displays a notice confirming that unique QR codes will be generated and sent to each individual recipient.
Comprehensive Instructions: The enrollment email sent to employees includes specific instructions for both new and existing devices when personal usage is allowed, guiding them through the Work Profile setup.
How to Use Bulk Invite
In the Swif Admin Dashboard, navigate to the Device Enrollment or Bulk Invite section.
Select the employees you wish to invite using the Identity combobox selector.
Choose Android QR Code as the installation method.
Select the appropriate Personal Usage option based on your organization's policy.
Click Invite to send the unique enrollment instructions and QR codes to all selected employees.
Automatic App Deployment
Upon successful enrollment, the Swif Mobile Security for Android app is automatically deployed to the device to ensure real-time security and compliance monitoring.
Fully Managed Devices: The app is default-deployed and installed automatically during the initial setup.
BYOD (Work Profile): The app is automatically deployed and installed within the work profile.
BYOD (Personal Profile): For personal profiles, the app can be manually installed from the Google Play Store after enrollment.
Verify Enrollment
After enrollment, follow these steps to ensure the device is correctly managed:
Confirm that the device appears in the Swif Admin Dashboard.
Verify that the expected ownership type is displayed.
Confirm that the Swif Mobile app has been installed.
Open the Swif Mobile app and navigate to "Device Diagnostics" to verify Managed Configuration, Android ID, Enterprise ID, FCM Token, and Location data.
On a BYOD device, confirm that work applications (including Swif Mobile) display the work-profile badge.
Allow time for Android Device Policy to synchronize all assigned configurations.
For more details on the app's features, you can refer to the Introducing Swif Mobile Security for Android article.
Troubleshooting
The BYOD QR Code Fails or Displays an Error
Confirm that the QR code is being scanned from the correct location.
For a personal device, use:
Settings > Google > Set up & restore > Set up your work profile
Do not use the regular Camera application. The Camera application can read the QR code visually but cannot initiate the required Android Enterprise work-profile provisioning flow.
Also confirm that:
You selected Existing device in Swif.
Personal Usage is set to Allowed.
The enrollment QR code has not expired.
The device runs a supported Android version.
The device has a stable internet connection.
The device does not already have a work profile from another organization.
If scanning still fails, enter the enrollment code manually from the same work-profile setup flow.
The Work-Profile Option Is Not Displayed
Search Android Settings for work profile.
Confirm that the device supports Android Enterprise.
Check whether a work profile already exists.
Remove any work profile belonging to a previous organization before retrying.
Confirm that the device manufacturer has not moved the option to another Settings location.
Restart the device and check again.
Do not factory reset a personal device unless the user has backed up their data and a reset is specifically required for another reason.
Company-Owned Enrollment Fails on an Existing Device
Fully managed enrollment cannot be added after normal Android Setup has been completed.
Back up the required data, factory reset the device, and begin enrollment from the first welcome screen after the reset.
Neither scanning the company-owned QR code with the Camera application nor manually entering the enrollment code from the normal Android interface can bypass this requirement.
Can I Preserve Personal Applications and Data?
Yes, but only when enrolling the device as BYOD with Personal Usage set to Allowed.
A device cannot preserve its existing personal environment while being converted to fully managed, company-owned mode. Fully managed enrollment requires a new or factory-reset device.
Tapping the Welcome Screen Does Not Open the Scanner
Confirm that the device is new or has been factory reset.
Make sure you are still on the first welcome screen.
Tap the same empty area six times.
Avoid tapping buttons, accessibility controls, or emergency-call controls.
Confirm that the device supports QR-code provisioning.
Try the
afw#setupenrollment method if QR scanning is unavailable.
afw#setup Does Not Work
Confirm that the device is new or factory reset.
Enter
afw#setupin the email or Google Account field during Setup.Do not add spaces.
Confirm that the device is connected to the internet.
Verify that Google Play services are available.
Confirm that the generated enrollment code is valid.
afw#setup is not the fallback enrollment method for an existing BYOD device.
The Enrollment Code Is Rejected
Generate a new enrollment code in Swif.
Confirm that the code is being entered in Android Device Policy.
Verify that the correct New device or Existing device option was selected.
Confirm that the selected Personal Usage setting matches the intended enrollment type.
Check whether the token has expired or has already reached its allowed usage limit.
Confirm that the device is not already managed by another organization.
What happened after re-enroll previous unenrolled device
It showed up as a new device instead of updating the enrollment status of the same device.
Google assigns a new device ID with each enrollment. Therefore, it appears as a separate device. The old one is being unenrolled.
Summary
Use the following enrollment path:
Personal device with existing apps and data: Set Personal Usage to Allowed, select Existing device, and create a work profile without resetting the device.
Company-owned device requiring full management: Set Personal Usage to Disallowed, select New device, and enroll during initial setup.
Existing device being converted to fully managed: Back up the data, factory reset the device, and enroll from the first welcome screen.
BYOD QR-code scanning: Open Set up your work profile in Android Settings; do not scan the code with the regular Camera application.
Company-owned QR-code scanning: Open the provisioning scanner by tapping the initial welcome screen six times.
Company-owned enrollment without QR scanning: Enter
afw#setupduring the initial Android Setup flow.









