> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Configuring Android Enrollment

> Configure Android device enrollment in Iru Endpoint. Set up Android Enterprise, connect Google Workspace, and enable work profile management.

<Callout icon="android" color="#B84A7A" iconType="regular">This guide applies to Android devices</Callout>

Android devices in Iru Endpoint use the Android Management API with work profile management for secure enterprise device management. This approach provides complete separation between work and personal data while giving organizations full control over work-related applications and policies. For enabling the Android platform and a quick enrollment overview, see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) and [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment).

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names.
</Note>

## How Android Enrollment Works

Android enrollment in Iru Endpoint uses Google's Android Management API to create and manage work profiles on Android devices. When users enroll their devices, a work profile is created that completely isolates work applications and data from personal content. Blueprints can use Assignment Maps to apply conditional logic based on device attributes, user information, or other organizational criteria.

The enrollment process establishes a secure connection between the Android device and Iru Endpoint through Google's Android Management API, providing enterprise-grade security and management capabilities while maintaining user privacy for personal data.

## Prerequisites

Before configuring Android enrollment, ensure you have:

* **Android Enterprise** configured in Iru Endpoint (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup))
* **Super admin** access to your organization's Google Admin console ([learn more about super admin roles](https://support.google.com/a/answer/2405986?hl=en\&sjid=10473235341862195521-NA))
* **Third-party Android mobile Management** enabled in Google Workspace (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup))
* **Company-owned Android devices** in factory reset state (Android 13 and higher required)
* **Blueprint** configured for Android devices
* **(Recommended)** **Single sign-on (SSO)** configured for secure authentication

## Configure Android Enterprise

Complete Android platform enablement and Android Enterprise integration before configuring enrollment. See [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup) for enabling the Android platform in Organization settings.

## Configure Android Enrollment

<Steps>
  <Step title="Configure Enrollment Portal">
    a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint.

    b. Ensure the **Enrollment Portal** is active.

    c. Under **Choose an enrollment method**, select **Android work profile** and locate the desired **Blueprint**. Copy the **Blueprint link** for that Blueprint. If **Require authentication** is enabled on the Blueprint, end users will need to authenticate to view the instructions.
  </Step>

  <Step title="Configure authentication">
    a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment. Optionally check the box to **Assign user to device record** to match the authenticated user to a user in your directory integration.

    b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps.
  </Step>

  <Step title="Share enrollment information">
    a. Share the **Blueprint link** with end users to enroll company-owned Android devices with work profile.

    b. Provide clear instructions for the Android enrollment process, including the requirement for a secondary device to view the enrollment instructions and QR code.

    c. Consider creating a dedicated email or help article with the Blueprint link and these instructions for consistency.

    <Warning>
      Each QR code can only be used once. If a user needs to enroll multiple devices, they must refresh the enrollment instructions page after each enrollment to generate a new QR code.
    </Warning>
  </Step>
</Steps>

## Verify Enrollment

<Steps>
  <Step title="Check devices">
    In Iru Endpoint, open **Devices**
  </Step>

  <Step title="Locate device">
    Locate the newly enrolled Android device (search by user email, device name, or serial number)
  </Step>

  <Step title="Verify work profile">
    Confirm the device shows as enrolled with work profile management
  </Step>

  <Step title="Check applications">
    Verify that work applications are being deployed to the work profile
  </Step>
</Steps>

## Android-Specific Considerations

### Device Requirements

Devices must be in a factory restored state to enroll and need to be compatible with most modern Android versions. The device must have Google Play Services installed and needs internet connectivity for enrollment.

## Best Practices

<CardGroup cols={2}>
  <Card title="Test with Pilot Group" icon="users">
    Test Android enrollment with a small pilot group before full deployment
  </Card>

  <Card title="Clear Communication" icon="message">
    Provide clear instructions to users about work profile setup and usage
  </Card>

  <Card title="Monitor Enrollment" icon="eye">
    Monitor enrollment success rates and address any issues promptly
  </Card>

  <Card title="Require Authentication" icon="lock">
    Require authentication for enrollment and link Blueprints to your identity provider. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for configuration.
  </Card>

  <Card title="User Training" icon="book">
    Provide training on work profile features and benefits. See [User Experience with Android Enrollment](/en/endpoint/enrollment/android/user-experience-with-android-enrollment) for end-user guidance.
  </Card>

  <Card title="Pre-stage Items" icon="box">
    Pre-stage Wi-Fi, certificates, SCEP, and password policies in the Blueprint so devices come online with required trust and connectivity.
  </Card>
</CardGroup>

## Troubleshooting

<AccordionGroup>
  <Accordion title="Enrollment fails on device">
    **Possible causes:**

    * Device not in factory restored state
    * Network connectivity issues
    * Google Play Services not available

    **Solutions:**

    * Ensure device is factory reset before attempting enrollment
    * Check internet connectivity
    * Verify Google Play Services is installed and updated
  </Accordion>

  <Accordion title="Work profile not created">
    **Possible causes:**

    * Android Enterprise not properly configured
    * Device compatibility issues
    * User permissions problems

    **Solutions:**

    * Verify Android Enterprise integration is working
    * Check device compatibility with Android Enterprise
    * Ensure the user has proper permissions for work profile creation
  </Accordion>

  <Accordion title="Apps not installing in work profile">
    **Possible causes:**

    * Work profile not properly set up
    * App compatibility issues
    * Policy restrictions

    **Solutions:**

    * Verify work profile is active and properly configured
    * Check app compatibility with work profile
    * Review policy settings for app installation
  </Accordion>

  <Accordion title="User can't access Blueprint link">
    **Possible causes:**

    * Authentication required but user not authenticated
    * Incorrect Blueprint link
    * Network access issues

    **Solutions:**

    * Verify user authentication if required
    * Check Blueprint link is correct
    * Ensure user has network access to open the Blueprint link
  </Accordion>
</AccordionGroup>

## Android Management API Features

### Security Capabilities

The Android Management API provides streamlined device setup through QR code enrollment, built-in security features, and work profile management capabilities. For company-owned work profile devices, Google provides some EMM reach into personal settings.

### Application Management

You can deploy work applications to work profiles, manage application updates centrally, remove work applications when needed, and control which apps can be installed in both work and personal profiles.

### Policy Enforcement

Iru Endpoint can enforce security settings on work profiles and some personal settings including:

* Require passcodes
* Block specific personal apps
* Block camera and screenshot on personal side
* Disable apps from unknown sources
* Disallow developer mode
* Deploy and configure work apps

### Device Management

Iru Endpoint can also wipe the entire device when needed for security purposes.

<Note>
  For more information about Android Management API capabilities, see [Google's Android Management API documentation](https://developers.google.com/android/management).
</Note>

## Related Articles

<CardGroup cols={2}>
  <Card title="User Experience with Android Enrollment" icon="user" href="/en/endpoint/enrollment/android/user-experience-with-android-enrollment">
    What to expect when enrolling your Android devices and setting up a work profile
  </Card>

  <Card title="Android Enrollment" icon="android" href="/en/endpoint/getting-started/enrollment/android-enrollment">
    Set up work profile enrollment for Android devices
  </Card>

  <Card title="Configuring Apple Enrollment" icon="apple" href="/en/endpoint/enrollment/apple/configuring-apple-enrollment">
    Configure Apple device enrollment with Automated Device Enrollment (ADE)
  </Card>

  <Card title="Configuring Windows Enrollment" icon="microsoft" href="/en/endpoint/enrollment/windows/configuring-windows-enrollment">
    Complete guide to Windows device enrollment and management setup
  </Card>
</CardGroup>
