> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Android Enrollment

> Set up Android work profile enrollment in Iru Endpoint as part of initial setup. Connect Android Enterprise and enroll your first Android device.

<Callout icon="android" color="#4f46e5" iconType="regular">This guide applies to Android devices</Callout>

Set up work profile enrollment so you can add company-owned Android devices to Iru Endpoint and manage them with the right apps, settings, and security controls.

<Note>
  As of **April 8, 2026**, apps were updated from **Kandji** <img className="inline dark:hidden" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-light-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=3ac73eb9098c090ac2838a4902a70e35" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-light-icon.png" /><img className="hidden dark:inline" src="https://mintcdn.com/iru/20OhJ3wZmF4DKbOd/assets/media/images/kandji-bee-dark-icon.png?fit=max&auto=format&n=20OhJ3wZmF4DKbOd&q=85&s=1d4b643c8e1903aabdb072fdf211f2de" alt="" style={{ height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 0.05em' }} width="400" height="284" data-path="assets/media/images/kandji-bee-dark-icon.png" /> to **Iru** <img src="https://mintcdn.com/iru/8j4H0SpqtcKJ5JUM/assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg?fit=max&auto=format&n=8j4H0SpqtcKJ5JUM&q=85&s=befa6ce99e1df18d397deb65aec8edaf" alt="" style={{ display: 'inline', height: '1em', width: 'auto', maxHeight: '1em', verticalAlign: '-0.125em', margin: '0 -0.08em 0 0', padding: 0 }} width="14" height="15" data-path="assets/media/svgs/Iru-Logomark-OnLight-16-Dashboard.svg" /> branding. App names changed from **Kandji Self Service** to **Iru Self Service** and from **Kandji Agent** to **Iru Agent**. The manual enrollment portal now uses Iru branding. Please update **scripts, automations, and utilities** that still reference the old app names.
</Note>

### How It Works

You configure the enrollment portal, choose a Blueprint, and share the **Blueprint link** (which has the Enrollment code embedded) with users. Users open the Blueprint link on a secondary device (they can't use the device they're enrolling), sign in if you require authentication, and follow the instructions to scan the QR code. Android Enterprise creates a work profile on the device and it is managed according to your Blueprint.

## Prerequisites

Before enrolling Android devices, ensure you have:

* **Android Enterprise** configured in Iru Endpoint (see [Android Setup](/en/endpoint/getting-started/platform-setup/android-setup))
* **Company-owned devices** in factory reset state
* **Android 13 and higher**
* **Blueprint** configured for Android devices
* **(Recommended)** **Single sign-on (SSO)** configured for secure authentication

## Work Profile Enrollment Setup

<Steps>
  <Step title="Configure Enrollment Portal">
    a. Go to **Endpoint** → **Enrollment** → **Manual Enrollment** in Iru Endpoint.

    b. Ensure the **Enrollment Portal** is active.

    c. Under **Choose an enrollment method**, select **Android work profile** and locate the desired **Blueprint**. Copy the **Blueprint link** for that Blueprint. If **Require authentication** is enabled on the Blueprint, end users will need to authenticate to view the instructions.
  </Step>

  <Step title="Configure authentication">
    a. Click the **Blueprint** and select **Require authentication** if you want users to authenticate prior to enrollment. Optionally check **Assign user to device record** to match the authenticated user to a user in your directory integration.

    b. This integrates with your Single Sign-On (SSO) configuration for secure enrollment. If you see a banner that **No single sign-on connections are configured**, go to **Access** ([**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Access**) and configure Single sign-on. See [SSO Setup](/en/endpoint/getting-started/foundation/sso-setup) for setup steps.
  </Step>

  <Step title="Share enrollment information">
    a. Share the **Blueprint link** with end users to enroll company-owned Android devices with work profile.

    b. Provide clear instructions for the Android enrollment process, including the requirement for a secondary device to view the enrollment instructions and QR code.
  </Step>
</Steps>

## Android Enrollment Process

### User Enrollment Steps

When users open the Blueprint link on a different device (computer, tablet, or phone), they'll authenticate using SSO if you've enabled that option, then see enrollment instructions including a QR code. They'll scan the QR code with their Android device to set up a work profile. Once the work profile is created, the device gets enrolled and configured according to your Blueprint settings.

### Work Profile Setup

The enrollment process creates a work profile on the Android device and configures it according to your assigned Blueprint settings. The device is then registered with Iru Endpoint for management.

## Android Management Features

Once enrolled, you can manage work profiles for company-owned devices, deploy applications within the work profile, and enforce policies for compliance monitoring. Iru Endpoint provides security configuration, full device inventory, and reporting.

## Work Profile Benefits

The work profile approach provides clear separation between personal and work data, ensuring user privacy while maintaining work security. Personal data remains private and unmanaged, while work data can be managed and secured according to your company policies. This gives users the flexibility to use their personal device while maintaining work security.

## Best Practices

Devices must be in factory reset state for enrollment, so test your Blueprints on designated devices before enrolling production hardware. Enable SSO authentication for secure enrollment and provide clear instructions to users about the Android enrollment process. You can monitor enrollment success and troubleshoot issues using the [Activity Page](/en/endpoint/devices/activity-page).

## Troubleshooting

### Trial Tenant Device Limit

Trial tenants are limited to a total of 10 devices. Once this limit is reached, a banner will be displayed until the device count becomes less than 10 again.

### Common Issues

If enrollment fails, check your Android Enterprise configuration and device state. For authentication issues, ensure SSO is properly configured and users have the necessary access. Verify that work profiles can be created on the device and that Blueprint policies are applied after enrollment.

### Support Resources

Check the [Activity Page](/en/endpoint/devices/activity-page) for enrollment logs and errors, and review Device records for enrollment status. [Contact Support](/en/iru/iru-support/access-to-iru-support) if you need additional assistance.

## Related Articles

<CardGroup cols={2}>
  <Card title="Blueprint Routing" icon="route" href="/en/endpoint/enrollment/blueprint-routing">
    Configure dynamic Blueprint assignment during device enrollment using Assignment Rules
  </Card>

  <Card title="Configuring Android Enrollment" icon="android" href="/en/endpoint/enrollment/android/configuring-android-enrollment">
    Complete guide to Android device enrollment and work profile management
  </Card>

  <Card title="User Experience with Android Enrollment" icon="user" href="/en/endpoint/enrollment/android/user-experience-with-android-enrollment">
    What to expect when enrolling your Android devices and setting up a work profile
  </Card>

  <Card title="Configure Require Authentication for Enrollment" icon="shield" href="/en/endpoint/enrollment/configure-require-authentication-for-enrollment">
    Configure authentication requirements for device enrollment across Apple, Windows, and Android platforms
  </Card>
</CardGroup>

## Next Steps

After setting up Android enrollment:

<Steps>
  <Step title="Test enrollment">
    Test the process with a few Android devices and monitor compliance and policy enforcement on the [Activity Page](/en/endpoint/devices/activity-page).
  </Step>

  <Step title="Set up enrollment for other platforms (optional)">
    To enroll Apple or Windows devices as well, see [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment) or [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment).
  </Step>
</Steps>

If you missed a step or want to review the path, see [Getting Started](/en/endpoint/getting-started/getting-started) for the full guide.
