Microsoft 365 Endpoint AdministratorManage devices and apps (55-60%)Medium
A technician is configuring Microsoft Intune for a new set of corporate-owned Android Enterprise devices. The company policy requires that all applications installed on these devices must be approved by the IT department and come from a controlled source. Users should not be able to install apps directly from the public Google Play Store. Which enrollment type should the technician use to ensure this level of control?
- AAndroid Enterprise (fully managed)
- BAndroid Open Source Project (AOSP) management
- CAndroid Device Administrator
- DAndroid Enterprise (personally-owned work profile)
Show answer & explanationAnswer & explanation
Correct answer: A. Android Enterprise (fully managed)
Android Enterprise fully managed devices are designed for corporate-owned devices and provide the highest level of control, allowing IT to manage the entire device, enforce app installation from a managed Google Play Store, and prevent access to the public Play Store.
Why the other options are wrong
- B. AOSP management is for devices without Google Mobile Services, which is not typical for standard Android Enterprise deployments requiring Managed Google Play.
- C. Android Device Administrator is a deprecated management method with limited capabilities compared to Android Enterprise.
- D. Personally-owned work profile is for BYOD scenarios, creating a separate work profile while allowing personal use and public Play Store access outside the profile.
Android Enterprise Fully Managed
An Intune enrollment type for corporate-owned Android devices that provides full device control, separating work and personal data, and restricting app installations to approved sources.
- Designed for corporate-owned, single-purpose, or dedicated devices.
- IT has full control over the entire device.
- App installations are restricted to the Managed Google Play Store.
Memory trick: Fully managed locks down the whole device for the company.