Skip to main content

Glossary

Fully managed device

A fully managed device is an Android Enterprise mode in which the company owns the device and the MDM controls all of it: apps, settings, updates, security and the option to wipe it entirely. There's no personal space. It's the corporate-owned, business-only (COBO) setup, typical for field terminals, shared phones and any device that never leaves work.

How it works

The mode has to be chosen at the very first boot. A device that has already been set up as a personal phone can't be converted: you factory reset it, then provision it from the setup wizard with a QR code, the afw# identifier in the Google sign-in screen, or zero-touch if it was bought from a zero-touch reseller. The MDM's device policy controller becomes the device owner, a privilege Android grants only once and only at that moment.

From then on the MDM decides what the device is. It installs apps silently from Managed Google Play or as private APKs, pins system settings, forces a passcode, disables the camera or USB file transfer, sets the OS update window, and can lock, locate or wipe the device from the console. The user can't remove management without a factory reset, and Factory Reset Protection can be configured so that even a reset brings the device back into the fleet.

Google introduced device owner mode in Android 5.0, then reworked it in Android 8 with the fully managed naming and, in Android 11, added the company-owned work profile as a softer alternative when staff also use the device privately.

Why it matters for a fleet

This is the mode that makes a phone behave like a piece of company equipment rather than a consumer gadget. For a delivery driver's terminal or a nurse's shared handset, that's exactly what you want: nothing personal on it, every setting known, replacement in ten minutes because the configuration lives in the MDM and not on the device.

It's also the mode auditors like. Encryption is enforced, app inventory is exact, and a lost device is wiped remotely without arguing about whose photos were on it.

The trade-off is obvious. Full control means full responsibility: if you push a broken app version to 800 devices at 8 a.m., you'll hear about it by 8:05. Staged rollouts and a test group aren't optional in this mode.

How Appaloosa handles it

Appaloosa enrolls company devices as fully managed through QR code, afw# identifier or zero-touch, then applies your policy set: apps from Managed Google Play, private APKs, passcode and restriction rules, kiosk lockdown when needed, OEMConfig settings for Samsung, Zebra or Honeywell hardware, and remote wipe. Everything is driven from the console described on the Android MDM page.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

See Appaloosa run on your fleet Book a demo

Frequently asked questions

Can I switch a device from fully managed to work profile mode later?
Not without a factory reset. The management mode is fixed when the device policy controller becomes device owner during setup. To change mode you wipe the device and provision it again, so decide the mode per device category before enrollment rather than after.
Can a user still add a personal Google account on a fully managed device?
Only if you allow it. The admin controls account addition through a restriction, and most fleets block it so that only the managed account exists. If staff need private use, the company-owned device with a work profile is the better mode.
What does the user see if they try to factory reset a fully managed device?
The admin can block the reset entirely from the settings menu. If a reset still happens through recovery mode, Factory Reset Protection asks for the authorized account the MDM configured, so the device can't be reused outside the company.