Glossary
Android device management
Android device management is the control of Android phones, tablets and rugged terminals through Android Enterprise, the management framework Google builds into every certified device, with a mode for each ownership model: work profile for personal phones, fully managed for company devices, dedicated for kiosks. For an IT team it means picking the right mode at enrollment, because that choice sets what you can enforce for the life of the device.
How it works
Google's first attempt, the device administrator API from 2010, gave apps a few device-wide powers and was deprecated in Android 9 and mostly disabled in Android 10. What replaced it is Android Enterprise, shipped with Android 5.0 in 2014 and mandatory on every device that carries Google Play. The MDM talks to Google's Android Management API, and a Google-supplied agent, Android Device Policy, applies the rules on the device.
The mode is set at provisioning and can't be changed without a factory reset:
- Work profile on a personal phone: a separate, encrypted container for work apps, with the personal side invisible to the company.
- Fully managed device (device owner mode) on company hardware: the whole device under policy.
- Work profile on a company-owned device, the COPE model redesigned in Android 11, where the device belongs to the company but the personal side keeps some privacy.
- Dedicated device for kiosks, scanners and shared terminals, locked to a set of apps.
Enrollment matches the mode. A QR code scanned at the welcome screen, a token entered instead of a Google account, Google zero-touch for devices bought through a partner, or Samsung Knox Mobile Enrollment for Galaxy devices. Manufacturer extras such as Zebra or Samsung settings reach the MDM through OEMConfig rather than a vendor agent.
Why it matters for a fleet
Android is where most field devices live: delivery handhelds, warehouse scanners, tablets on a production line. It's also where fragmentation bites. A fleet can mix Android 12 rugged units that will never see 14 with Pixel phones on Android 16, and the security patch date on each is the number that matters for compliance.
The ownership decision has legal weight in Europe. Putting a personal phone in fully managed mode gives the employer visibility over private apps, which GDPR and most works councils won't accept. The work profile exists for that case and should be the default for BYOD.
Google publishes an Android Enterprise Recommended list of devices with committed update windows. Buying from it is the simplest way to avoid a fleet stuck on an unpatched OS two years in.
How Appaloosa handles it
Appaloosa manages every Android Enterprise mode from one console: work profile for personal phones, fully managed and COPE for company devices, dedicated devices in kiosk mode. Enrollment runs by QR code, token, Google zero-touch or Knox Mobile Enrollment, apps come from Managed Google Play or your own APK uploads, and Samsung or Zebra settings are pushed through OEMConfig. Compliance is evaluated continuously on OS version, patch level and passcode, with remote wipe and selective wipe when needed. Each mode is described on the Android MDM page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo