Close Menu
Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Facebook X (Twitter) Instagram
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    • Home
    • Intune
    • Windows
      • Modern Workplace
    • macOS
    • Android
    • iOS
    • Automation
      • Logic Apps
      • Intune Monitoring
      • GitHub
    • Security
      • Passwordless
      • Security
    • Speaking
    • About me
    Peter Klapwijk – In The Cloud 24-7Peter Klapwijk – In The Cloud 24-7
    Home»Android»Migrate Android devices from device administrator to work profile management
    Android

    Migrate Android devices from device administrator to work profile management

    Peter KlapwijkBy Peter KlapwijkMarch 22, 2020Updated:May 15, 202044 Mins Read

    Since Android version 2.2. Android Device Administrator was used to manage Android devices. If you`re using Microsoft Intune to manage Android devices, you might also use Device Admin to manage your devices. But Device Admin is marked as deprecated by Google and Google is decreasing Device Admin support on new Android releases.
    A new management solution was already introduced by Google in Android 5.0, Android Enterprise, with improved management functionality. Because of these changes it`s time to migrate Android devices from Device Administrator to Android Enterprise Work Profile (or Fully managed).

    In this blog post I show the steps to make the migration process for the end-user as easy as possible.

    Microsoft made a new setting available to mark an Android Device Admin device not compliant. As soon as the end-user device is marked as not compliant by this setting, this is shown in the Company Portal app like it always was, but when the user this time clicks on Resolve on the Update device settings page, a migration process is started to migrate the device to Android Enterprise Work Profile.
    Besides that, you can also automatically send the user an email notification with explanation about the migration proces and mention the migration URL (The URL will launch the Android Company Portal to the Update device settings page).

    Configure the Compliance Policy

    I assume you already have an existing Compliance policy for Android Device Admin, otherwise create one.

    • Sign-in to the Device Management Portal
    • Browse to Devices – Android
    • On the Compliance Policies tab open the Device Admin policy
    • Browse to Properties
    • Click Edit next to Compliance settings and open Device Health
    • Set Devices managed with device administrator to Block
    • Click Review + Save – click Save

    This is all to mark Device Admin devices as non-compliant and make the migration flow available for your end-users.

    Configure push notifications (optional)

    • Browse to Devices – Android
    • On the Compliance Policies tab open the Device Admin policy
    • Browse to Properties
    • Click Edit next to Actions for noncompliance
    • Choose Send push notification to end user from the drop-down list
    • Leave the schedule value 0 to mark the device non compliant immediately
    • Click Review + Save
    • Click Save

    Configure Email notifications (optional)

    Optional you can automatically send an email to the end-user by following these steps.

    • Browse to Devices – Compliance Policies
    • On the Notifications tab click Create notification
    • Enter a Name
    • Enter a Subject
    • Enter a Message and refer to the URL https://portal.manage.microsoft.com/UpdateSettings.aspx
    • Click Next
    • Click Create
    • Browse to Devices – Android
    • On the Compliance Policies tab open the Device Admin policy
    • Browse to Properties
    • Click Edit next to Actions for noncompliance
    • Choose Send email to end user from the drop-down list
    • Click None selected under Message template
    • Select the previous create Email notification
    • Click Select
    • Click Review + Save – Click Save

    The Compliance policy is set, everything is ready for the new migration flow.

    End-user experience

    My device is marked as compliant before changing the Compliance policy.

    As soon as I change the Compliance policy and my Android device is synced with Intune, it is marked as Not in compliance.
    A pop-up is shown if that option is set in the Compliance policy.

    If you also set an email notification in the policy, the user should also receive an email.

    If you click on the pop-up message on the Android device, the Company portal app is opened.
    Click on Resolve to start the migration process.

    The user is informed of the migration steps.
    Click Begin.

    Take note of the information and click Begin.

    The old management profile is removed.
    Click Continue.

    After these steps the enrollment to Android Enterprise Work Profile is started.
    Click Continue.
    Screens might be different for you, depending on policies set in your Intune tenant, differences per Android version and Android vendor.

    The Work profile is created, several different screens are shown.

    The Work profile is created, click Continue.

    The Work profile is activated, policies applied.
    Click Done.

    The end-result is an Android device managed with Android Enterprise Work Profile.

    If you`d like to read more about managing Android devices with as Work Profile devices, I suggest to read this post.

    Thank you for reading!

    Android EMS Intune MEM Microsoft 365 Microsoft Endpoint Manager
    Share. Facebook Twitter LinkedIn Email WhatsApp
    Peter Klapwijk
    • Website
    • X (Twitter)
    • LinkedIn

    Peter is a Security (Intune) MVP since 2020 and is working as Modern Workplace Engineer at Wortell in The Netherlands. He has more than 15 years of experience in IT, with a strong focus on Microsoft technologies like Microsoft Intune, Windows, and (low-code) automation.

    Related Posts

    Windows Autopilot lifecycle automation with Logic Apps

    March 8, 2021

    How to start with Android Enterprise Corporate owned dedicated devices in Microsoft Intune

    April 24, 2019

    Secure Outlook Mobile with App Protection Policies

    April 3, 2019
    View 4 Comments

    4 Comments

    1. David on April 16, 2020 14:04

      Hi Peter,

      It is possible to enroll a work profile on a fully managed device with intune?
      https://developer.android.com/work/dpc/work-profile-on-managed-device

      Reply
      • Peter Klapwijk on April 18, 2020 22:27

        Hi David,

        No at this moment that`s not possible with Intune.

        Reply
    2. stuart on May 7, 2020 17:20

      hi
      is it possible to move from corporate-owned devices with device administrator privileges to Corporate-owned, fully managed user devices. if so what type of groups need to be created

      Reply
      • Peter Klapwijk on May 7, 2020 20:13

        No that`s not possible. For (Android Enterprise) Corporate-owned, fully managed a factory reset is needed to start the enrollment.

        Reply
    Leave A Reply Cancel Reply

    Peter Klapwijk

    Hi! Welcome to my blog post.
    I hope you enjoy reading my articles.

    Hit the About Me button to get in contact with me or leave a comment.

    Awards
    Sponsor
    Latest Posts

    Hide the “Turn on an ad privacy feature” pop-up in Chrome with Microsoft Intune

    April 19, 2025

    How to set Google as default search provider with Microsoft Intune

    April 18, 2025

    Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs

    April 13, 2025

    Using Visual Studio with Microsoft Endpoint Privilege Management, some notes

    April 8, 2025
    follow me
    • Twitter 4.8K
    • LinkedIn 6.1K
    • YouTube
    Tags
    Administrative Templates Android Automation Autopilot Azure Azure AD Browser Conditional Access Edge EMS Exchange Online Feitian FIDO2 Flow Google Chrome Graph Graph API Identity Management Intune Intune Monitoring iOS KIOSK Logic Apps macOS MEM MEMMonitoring Microsoft 365 Microsoft Edge Microsoft Endpoint Manager Modern Workplace Office 365 OneDrive for Business Outlook Passwordless PowerApps Power Automate Security SharePoint Online Teams Windows Windows 10 Windows10 Windows 11 Windows Autopilot Windows Update
    Copy right

    This information is provided “AS IS” with no warranties, confers no rights and is not supported by the authors, or In The Cloud 24-7.

     

    Copyright © 2025 by In The Cloud 24-7/ Peter Klapwijk. All rights reserved, No part of the information on this web site may be reproduced or posted in any form or by any means without the prior written permission of the publisher.

    Shorthand; Don’t pass off my work as yours, it’s not nice.

    Recent Comments
    • Peter Klapwijk on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • John M on Using Windows Autopilot device preparation with Windows 365 Frontline shared cloud PCs
    • Christoffer Jakobsen on Connect to Azure file shares with Microsoft Entra Private Access
    • Ludo on How to block Bluetooth file transfer with Microsoft Intune
    • RCharles on Automatically configure the time zone (during Autopilot enrollment)
    most popular

    Application installation issues; Download pending

    October 1, 2024

    Restrict which users can logon into a Windows 10 device with Microsoft Intune

    April 11, 2020

    How to change the Windows 11 language with Intune

    November 11, 2022

    Update Microsoft Edge during Windows Autopilot enrollments

    July 9, 2024
    Peter Klapwijk – In The Cloud 24-7
    X (Twitter) LinkedIn YouTube RSS
    © 2025 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Cookie Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
    View preferences
    {title} {title} {title}