Glossary
Work profile
A work profile is a separate, encrypted container that Android Enterprise creates on a device to hold company apps and data apart from personal ones. The MDM manages only what's inside the profile: it can configure, restrict or wipe the work side without seeing the user's photos, messages or personal apps.
How it works
Technically, the work profile is a second Android user running on the same device, with its own storage, its own copies of apps and its own encryption key. Google introduced it with Android 5.0 in 2014, and it has been the standard answer to BYOD on Android ever since.
Once the profile exists, the launcher shows two tabs or two sets of icons: work apps carry a small briefcase badge. Gmail in the personal tab and Gmail in the work tab are two separate installs that don't share data. The MDM decides what goes into the work side: apps from Managed Google Play, a mail account, Wi-Fi and VPN settings, a passcode policy for the profile itself.
Data doesn't cross the wall unless the admin allows it. Copy and paste, file sharing, contact lookup for caller ID, screenshots: each one is a switch. The user can pause the work profile in the evening with one tap, which suspends work notifications until the next morning.
There are two flavours. On a personal device, the user creates the profile from the Android Device Policy app or a link, and can delete it whenever they like. On a company-owned device enrolled since Android 11, the profile is set up during provisioning and the admin keeps a few device-wide controls (OS update policy, some restrictions) on top of it.
Why it matters for a fleet
Without a work profile, you have two bad options for a personal phone: manage nothing and hope, or take over the whole device and deal with the privacy complaints. The profile gives you a third path that HR and the works council will actually sign.
The admin gets what the security policy requires: encrypted company data, an enforced work passcode, apps pinned to the right version, and a selective wipe on the day someone leaves. The employee keeps a phone that still feels like theirs. In practice, that's the difference between 90% of staff enrolling and a shadow-IT fleet of unmanaged WhatsApp groups.
How Appaloosa handles it
Appaloosa enrolls personal Android devices in work profile mode, and company-owned devices with a work profile when you want the COPE setup. From the console you assign Managed Google Play apps and private APKs to the profile, set passcode and data-sharing rules, and wipe the profile alone when needed. The device's personal side stays out of reach. Details on the Android MDM page.
Explore
See the full platform
Enrollment, apps, security, remote support: all in one place.
Explore Appaloosa →See Appaloosa run on your fleet Book a demo