Glossary
Device owner mode
Device owner mode is the Android Enterprise provisioning mode in which the management app owns the whole device, from the lock screen to the app list, with no personal space left for the user. For an IT team it's the mode for company-owned hardware: the only one that allows silent app installs, factory reset protection, kiosk lockdown and a full remote wipe.
How it works
Android has two levels of management authority. A profile owner controls one work profile on a device somebody else owns. A device owner controls the device itself. Google introduced both with Android 5.0 in 2014, and the console vocabulary followed: device owner mode became "fully managed device", and with Android 11 Google reworked the company-owned variant with a work profile into what it now calls a work profile on a company-owned device.
Device owner can only be set on a device with no accounts and no user data, which in practice means at first boot after a factory reset. The paths are the ones you'd expect: tap the welcome screen six times to scan a QR code, type a token such as afw#appaloosa instead of a Google account, let Google zero-touch enroll a device bought through a partner, or use Samsung Knox Mobile Enrollment on Galaxy devices. NFC bump provisioning existed too and Google removed it in Android 10.
Once the device policy controller (Android Device Policy on modern fleets) is the device owner, the OS grants it powers a profile owner never gets: install and uninstall apps silently, disable the factory reset menu, enforce factory reset protection with a company account, lock the device into a single app or a set of apps, set global network and Wi-Fi settings, read device identifiers such as the serial number and IMEI, and wipe the whole device.
Why it matters for a fleet
Device owner mode is what makes an Android fleet behave like a fleet. Scanners in a warehouse, delivery handhelds, tablets on a truck: none of them should have a personal Google account, a browser open to anything, or a user able to remove management. Fully managed is the mode that guarantees it.
It's also the wrong mode for a personal phone. A device owner sees every app on the device and can wipe it entirely, which no employee should accept on hardware they paid for, and which European privacy rules don't allow without a very good reason. The work profile exists for that case.
A practical warning: because the mode is fixed at provisioning, a company device enrolled by hand in a work profile stays a second-class citizen until someone factory resets it. Get the enrollment path right on day one, ideally through zero-touch so nobody has to touch the box.
How Appaloosa handles it
Appaloosa provisions company-owned Android devices as fully managed (device owner) through QR code, token, Google zero-touch or Knox Mobile Enrollment, then applies the controls that mode unlocks: silent installs from Managed Google Play or private APKs, kiosk mode for dedicated devices, factory reset protection, compliance rules evaluated continuously, lost mode and full remote wipe. Personal phones go through the work profile instead, and the console keeps both populations apart. The enrollment paths are listed on the Android MDM page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo