Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium

A Microsoft 365 Endpoint Administrator needs to configure a new set of shared corporate-owned Android Enterprise devices that will be used by multiple employees for specific task-oriented work, such as inventory scanning. These devices should be locked down to only allow access to a few pre-approved applications and prevent users from accessing settings or browsing the web. Which Android Enterprise deployment scenario should the administrator choose in Microsoft Intune?

  1. AAndroid Enterprise personally-owned with work profile
  2. BAndroid Enterprise dedicated devices
  3. CAndroid Enterprise fully managed
  4. DAndroid Enterprise corporate-owned with work profile
Show answer & explanation

Correct answer: B. Android Enterprise dedicated devices

Android Enterprise dedicated devices (formerly known as COSU - Corporate-Owned, Single-Use) are specifically designed for shared, task-oriented devices that need to be locked down to a limited set of applications. This scenario best fits the requirement for inventory scanning devices with restricted access. Fully managed devices offer more control but aren't inherently single-purpose kiosk-like, and work profiles are for BYOD or corporate-owned personal use.

Why the other options are wrong

  • A. This scenario is for personally-owned devices (BYOD) where a work profile separates corporate data, which does not match the corporate-owned, shared device requirement.
  • C. While fully managed, this scenario allows for a wider range of user interaction and applications, not typically locked down to a few apps for shared use.
  • D. This scenario is for corporate-owned devices used personally by an employee, providing a separation between work and personal data, not for shared, locked-down devices.

Android Enterprise Dedicated Devices

An Android Enterprise management scenario in Microsoft Intune designed for corporate-owned, single-purpose, or shared devices that need to be locked down to a limited set of applications (kiosk mode).

  • Ideal for shared devices, kiosks, or task-oriented devices.
  • Devices are fully managed by the organization.
  • Users are restricted from accessing device settings or installing unauthorized apps.
  • Can be configured for single-app or multi-app kiosk mode.

Memory trick: Match the owner and purpose to the profile type.

More Manage devices and apps (55-60%) questions