Overview
When managing mobile devices in an organization, it’s important to understand the different management modes available. These modes determine the level of control IT administrators have and the degree of privacy afforded to the user.
Learn more at How Android Enrollment Works.
1. Full Managed
Full Managed (also known as "Fully Managed Device") refers to a device owned by the organization and fully controlled by IT administrators. This mode is typically used for company-issued devices where personal use is not permitted.
Ownership: Company-owned.
Control: The organization has complete authority over the entire device.
Capabilities: IT can enforce global security policies, install/remove any app, and restrict hardware features (e.g., camera, Bluetooth).
Use Case: Best for employees who require a dedicated business device for high-security tasks.
2. Work Profile
A Work Profile separates work data and apps from personal data on a single device. Within our Android EMM (Enterprise Mobility Management) framework, this is further categorized into two distinct ownership models: COPE and Full BYOD.
COPE (Corporate-Owned, Personally Enabled)
COPE allows an organization to maintain ownership of the hardware while providing employees with a private space for personal use.
Ownership: Company-owned.
Setup: The device is enrolled after a factory wipe using the
PERSONAL_USAGE_ALLOWEDflag.Control: The organization has full management authority over the device but allows a "Work Profile" to coexist with personal applications.
Privacy: Employees have privacy for personal apps, while the organization maintains high security for the work container.
Full BYOD (Bring Your Own Device)
In a Full BYOD model, the employee retains ownership of the device, and the organization only manages a secure container for work-related data.
Ownership: Employee-owned (Personal).
Setup: A Work Profile is created directly on an active device (via
Settings > Google > Set up work profile) using an Allowed Personal Usage QR code without requiring a factory wipe.Control: The organization manages only the Work Profile container. IT cannot view personal apps or personal data, track personal location, or factory reset the physical handset.
Capabilities: IT can only wipe or manage work-related data inside the Work Profile container; they cannot perform a full device wipe.
Technical Considerations & Limitations
Based on current testing and Google Android Management API behavior, please note the following device-control statuses:
Remote Wiping
COPE & Fully Managed: Verified; executes a full factory reset of the hardware.
Full BYOD: Verified; triggering a remote Wipe removes only the enterprise Work Profile container from the device. All personal data, personal apps, photos, and personal accounts remain intact.
Remote Locking
Full BYOD: Triggering a remote Lock command from the Swif portal will show a status of
Successin the portal, but will not lock the physical handset (the device remains unlocked). This is by design in Android BYOD architecture to prevent enterprise interference with personal hardware access.COPE: Remote device-level lock commands may report as queued or sent, but physical lock enforcement depends on device synchronization state with Google Services.
BYOD Enrollment by Android Version
Android 14, 15, 16+: Seamless enrollment out of the box via
Settings > Google > Set up work profile.Android 13: If an error occurs during initial Work Profile setup, reboot the device and scan the QR code again. Enrollment succeeds upon restart without needing to re-generate the QR code.
Command Queueing & Delays
Commands (such as app updates or policy syncs) are processed via Google Services and may experience slight delays depending on the device's synchronization state.
Summary Table
Mode | Device Ownership | IT Control Level | Personal Privacy | Remote Wipe Scope | Remote Lock Behavior | Typical Use Case |
Full Managed | Company | Full Device | Limited / None | Full Factory Reset | Locks device | Company-only devices |
Work Profile (COPE) | Company | Full Device + Work Profile | Yes (Isolated personal area) | Full Factory Reset | Varies by sync state | Corporate devices with personal use |
Work Profile (BYOD) | Personal | Work Profile Only | Full Privacy (Zero personal visibility) | Work Profile Only (Selective) | Success in portal; leaves physical handset unlocked | Employee-owned devices |