Skip to main content

Understanding Android Device Management (MDM) Modes: Full Managed, Work Profile, and BYOD

Overview

When managing mobile devices in an organization, it’s important to understand the different management modes available. These modes determine the level of control IT administrators have and the degree of privacy afforded to the user.


1. Full Managed

Full Managed (also known as "Fully Managed Device") refers to a device owned by the organization and fully controlled by IT administrators. This mode is typically used for company-issued devices where personal use is not permitted.

  • Ownership: Company-owned.

  • Control: The organization has complete authority over the entire device.

  • Capabilities: IT can enforce global security policies, install/remove any app, and restrict hardware features (e.g., camera, Bluetooth).

  • Use Case: Best for employees who require a dedicated business device for high-security tasks.

2. Work Profile

A Work Profile separates work data and apps from personal data on a single device. Within our Android EMM (Enterprise Mobility Management) framework, this is further categorized into two distinct ownership models: COPE and Full BYOD.

COPE (Corporate-Owned, Personally Enabled)

COPE allows an organization to maintain ownership of the hardware while providing employees with a private space for personal use.

  • Ownership: Company-owned.

  • Setup: The device is enrolled after a factory wipe using the PERSONAL_USAGE_ALLOWED flag.

  • Control: The organization has full management authority over the device but allows a "Work Profile" to coexist with personal applications.

  • Privacy: Employees have privacy for personal apps, while the organization maintains high security for the work container.

Full BYOD (Bring Your Own Device)

In a Full BYOD model, the employee retains ownership of the device, and the organization only manages a secure container for work-related data.

  • Ownership: Employee-owned (Personal).

  • Setup: A Work Profile is created directly on an active device (via Settings > Google > Set up work profile) using an Allowed Personal Usage QR code without requiring a factory wipe.

  • Control: The organization manages only the Work Profile container. IT cannot view personal apps or personal data, track personal location, or factory reset the physical handset.

  • Capabilities: IT can only wipe or manage work-related data inside the Work Profile container; they cannot perform a full device wipe.

Technical Considerations & Limitations

Based on current testing and Google Android Management API behavior, please note the following device-control statuses:

Remote Wiping

  • COPE & Fully Managed: Verified; executes a full factory reset of the hardware.

  • Full BYOD: Verified; triggering a remote Wipe removes only the enterprise Work Profile container from the device. All personal data, personal apps, photos, and personal accounts remain intact.

Remote Locking

  • Full BYOD: Triggering a remote Lock command from the Swif portal will show a status of Success in the portal, but will not lock the physical handset (the device remains unlocked). This is by design in Android BYOD architecture to prevent enterprise interference with personal hardware access.

  • COPE: Remote device-level lock commands may report as queued or sent, but physical lock enforcement depends on device synchronization state with Google Services.

BYOD Enrollment by Android Version

  • Android 14, 15, 16+: Seamless enrollment out of the box via Settings > Google > Set up work profile.

  • Android 13: If an error occurs during initial Work Profile setup, reboot the device and scan the QR code again. Enrollment succeeds upon restart without needing to re-generate the QR code.

Command Queueing & Delays

  • Commands (such as app updates or policy syncs) are processed via Google Services and may experience slight delays depending on the device's synchronization state.


Summary Table

Mode

Device Ownership

IT Control Level

Personal Privacy

Remote Wipe Scope

Remote Lock Behavior

Typical Use Case

Full Managed

Company

Full Device

Limited / None

Full Factory Reset

Locks device

Company-only devices

Work Profile (COPE)

Company

Full Device + Work Profile

Yes (Isolated personal area)

Full Factory Reset

Varies by sync state

Corporate devices with personal use

Work Profile (BYOD)

Personal

Work Profile Only

Full Privacy (Zero personal visibility)

Work Profile Only (Selective)

Success in portal; leaves physical handset unlocked

Employee-owned devices

Did this answer your question?