Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. These devices will be used in a retail store for point-of-sale (POS) transactions and should only run the POS application, with no access to other apps or device settings. Which Android Enterprise deployment scenario should the administrator choose?

  1. AAndroid Enterprise personally-owned work profile
  2. BAndroid Enterprise fully managed
  3. CAndroid Enterprise dedicated devices
  4. DAndroid Open Source Project (AOSP) user-associated
Show answer & explanation

Correct answer: C. Android Enterprise dedicated devices

Android Enterprise dedicated devices (formerly 'kiosk mode' or 'corporate-owned single-use') are specifically designed for scenarios where devices are single-purpose, such as POS terminals, digital signage, or inventory scanners, restricting them to a limited set of apps and functionalities.

Why the other options are wrong

  • A. This scenario is for BYOD (Bring Your Own Device) and creates a separate work profile, allowing personal use alongside work apps.
  • B. Fully managed devices are corporate-owned but allow for a broader range of apps and device settings, suitable for general-purpose corporate phones.
  • D. AOSP management is for devices without Google Mobile Services and is not the standard Intune Android Enterprise scenario for corporate-owned devices with specific app restrictions.

Android Enterprise Dedicated Devices

A Microsoft Intune Android Enterprise deployment mode for corporate-owned, single-purpose devices, often used in kiosk, digital signage, or task-worker scenarios.

  • Locks down devices to a predefined set of applications.
  • Users cannot access other apps, settings, or perform factory resets.
  • Enrollment typically uses QR code, NFC, or Zero-touch.

Memory trick: Android's Enterprise Deals Protect Devices.

More Manage devices and apps (55-60%) questions