A Microsoft 365 Endpoint Administrator needs to configure a new set of shared corporate-owned Android Enterprise devices that will be used by multiple employees for specific task-oriented work, such as inventory scanning. These devices should be locked down to only allow access to a few pre-approved applications and prevent users from accessing settings or browsing the web. Which Android Enterprise deployment scenario should the administrator choose in Microsoft Intune?
- AAndroid Enterprise personally-owned with work profile
- BAndroid Enterprise dedicated devices
- CAndroid Enterprise fully managed
- DAndroid Enterprise corporate-owned with work profile
Show answer & explanationAnswer & explanation
Correct answer: B. Android Enterprise dedicated devices
Android Enterprise dedicated devices (formerly known as COSU - Corporate-Owned, Single-Use) are specifically designed for shared, task-oriented devices that need to be locked down to a limited set of applications. This scenario best fits the requirement for inventory scanning devices with restricted access. Fully managed devices offer more control but aren't inherently single-purpose kiosk-like, and work profiles are for BYOD or corporate-owned personal use.
Why the other options are wrong
- A. This scenario is for personally-owned devices (BYOD) where a work profile separates corporate data, which does not match the corporate-owned, shared device requirement.
- C. While fully managed, this scenario allows for a wider range of user interaction and applications, not typically locked down to a few apps for shared use.
- D. This scenario is for corporate-owned devices used personally by an employee, providing a separation between work and personal data, not for shared, locked-down devices.
Android Enterprise Dedicated Devices
An Android Enterprise management scenario in Microsoft Intune designed for corporate-owned, single-purpose, or shared devices that need to be locked down to a limited set of applications (kiosk mode).
- Ideal for shared devices, kiosks, or task-oriented devices.
- Devices are fully managed by the organization.
- Users are restricted from accessing device settings or installing unauthorized apps.
- Can be configured for single-app or multi-app kiosk mode.
Memory trick: Match the owner and purpose to the profile type.