Laptop and Android smartphone connected through cloud icons representing web-based enrollment and secure work profile setup with Microsoft Intune on a modern workspace background.

Simplifying Android Enrollment: Web-Based Enrollment for Personally Owned Work Profiles in Microsoft Intune

Introduction

Last week, Microsoft introduced key capabilities as part of the General Availability of Android Management API support for personally-owned work profiles in Microsoft Intune. What does this mean?

Organisations can now opt in to use web-based enrollment for all newly enrolled personally-owned Android devices with Work Profile. This new approach enables a simplified, browser-driven enrollment experience that aligns with Android Enterprise best practices. This marks a significant shift away from the traditional enrollment experience and lays the foundation for a fully modern onboarding process.

Microsoft also introduced the first step in transitioning existing devices. Administrators can now configure policies to migrate groups of already enrolled devices to the Android Management API. This approach enables a controlled and phased transition, allowing organisations to manage the change in a structured way. Instead of a forced switch, organisations now have the flexibility to pilot, validate, and gradually move their devices to the new management model.

With this General Availability release, Microsoft Intune fully aligns the management of personally owned Android work profile devices with Google’s Android Management API. This transition marks a move away from custom Device Policy Controller (DPC) implementations and adopts a more standardised, platform-native approach.
As a result, organisations can benefit from more consistent behaviour across all Android Enterprise management scenarios, regardless of device ownership or deployment model.

This announcement transforms how organisations manage Android devices in Microsoft Intune; it’s a foundational shift, not just another feature update. It gives:

  • Consistency: One API and one model across all Android scenarios
  • Simplicity: A cleaner, web-based enrollment experience
  • Future-proofing: Faster access to new Android Enterprise capabilities
  • Control: Flexible migration options before full enforcement later in 2026

What is Google’s Android Management API?

The Android Management API (AMAPI) is a Google-provided API that allows enterprise mobility management (EMM) solutions, like Microsoft Intune, to manage Android devices using a policy-based model. Instead of relying on custom device management components, it provides a standardised, native way to control Android devices directly through the Android platform.

How it works

When using Microsoft Intune, the Android Management API acts as the underlying engine that enables modern Android device management. Intune integrates directly with this API to define policies, manage devices, and control the overall lifecycle of Android Enterprise deployments.

Administrators manage configurations in the Microsoft Intune admin centre, where Microsoft Intune translates those settings into policy-based instructions for Google’s Android Management API.

During enrollment, organisations associate devices using an enrollment method (such as web-based enrollment), and the Android Device Policy app installs on the device to automatically enforce Microsoft Intune policies.

In practice, this means:

  • Administrators configure compliance, configuration, and app policies in Microsoft Intune
  • Microsoft Intune communicates these settings to the Android Management API
  • The Android Device Policy app enforces those settings on the device

This model ensures that device management is policy-driven, consistent, and fully aligned with Android Enterprise standards, rather than depending on custom implementations.

How this relates to Microsoft Intune

Microsoft Intune uses the Android Management API under the hood, especially for Android Enterprise scenarios, including personally owned work profiles.

Microsoft is shifting everything to the Android Management API because it provides consistent behaviour across all Android device types, enables modern features such as web-based enrollment, and removes the dependency on older custom components like the Company Portal acting as a device policy controller.

Timeline

Limitations before migrating

There are certain limitations when migrating to AMAPI, such as the use of passkeys and Wi-Fi authentication.

Passkey support

Currently, web-based enrollment does not support passkeys. If administrators configure passkeys as the only allowed authentication method, users cannot complete the enrollment process using the new web-based flow.

Microsoft recognises this as a known limitation and plans to introduce passkey support before web-based enrollment becomes the default for all personally owned work profile enrollments, currently targeted for Q4 2026.

IMPORTANT: If your organisation relies exclusively on passkeys for authentication, you should not enable web-based enrollment until passkey support becomes available, as enrollment attempts will fail.

Certificate authentication for Wi-Fi

If your organisation uses username and password authentication for Wi‑Fi policies, you should transition to certificate-based authentication.

When organisations migrate devices to AMAPI, devices that rely on username and password authentication for corporate Wi‑Fi may lose connectivity and require manual reconnection. In contrast, devices using certificate-based authentication will maintain seamless access to corporate Wi-Fi during and after the transition.

Beyond improving the user experience, certificate-based authentication also provides a more secure method of network access.

Microsoft Intune – Configuration

Enrollment Profile

Start by enabling web-based enrolment in your tenant. To do this, go to the Microsoft Intune admin center | Devices | Android | Enrollment and select Personally owned devices with work profile.

You’ll see a new option called Web-based Enrollment. Select the Use web enrollment for all users enrolling in Android personally owned work profile management option and confirm with Yes.

Confirm by choosing Ok.

Web-based enrollment for your tenant is now permanently active. You’ll notice that disabling the option is now greyed out.

INFORMATION: Enabling this option is permanent. Enable this feature first in a test environment, and document the enrollment flow for the end-user. As of Q4 2026, Microsoft Intune will automatically configure all Personally Owned Work Profile devices for web enrollment.

Platform restrictions

In enrollment restrictions, administrators can allow or block personally owned Android Enterprise (work profile) devices, but Intune does not apply this setting to AMAPI devices and will remove it once all devices migrate. Because this setting is unreliable on Android 12 and later, Microsoft does not recommend blocking personal devices. Instead, use alternative controls, such as corporate-owned work profile enrollment or user-based restriction groups.

Migrate existing devices

If you already have Android devices enrolled through the Company Portal app, you can use a simple configuration profile to seamlessly migrate your devices to web-based enrollment.

Go to the Microsoft Intune admin center | Devices | Android | Configuration, and create a new policy with the following:

  • Platform: Android Enterprise
  • Profile types: Templates

Now choose Move to Android Management API under Personally-Owned Work Profile, then choose Create.

Give your policy a name and description, and choose Next.

  • Name: AND – BYOD – Migrate to Android Management API
  • Description: This policy will migrate existing Personally-Owned with Work Profile devices to Android Management API.

In the Configuration settings blade, read the limitations or actions you need to take before migrating. If you are ok to go, choose Next.

Assign to your device group with all Personally-Owned with Work Profile enrolled devices, and choose Next.

INFORMATION: I created an Entra ID Dynamic Device group with the following Dynamic membership rules syntax: (device.deviceOwnership -eq “Personal”)

Review your settings and then choose Create.

Monitoring

In Microsoft, you also have the option to monitor enrollment and migration. The available statuses are AMAPI, Error, Move pending, and Not targeted to move.

Go to Microsoft Intune admin center | Devices | Monitor and choose the Personal devices on Android Management API report.

When you open the report, you’ll see an overview of devices and their status.

End User Experience

Now, how does this look for our end users when enrolling their device?

On your Android device, open a browser and go to https://aka.ms/enrollmyandroid. This will redirect you to https://portal.manage.microsoft.com/enrollment/webenrollment/android and a Microsoft Sign-in page. Sign-in with your corporate Entra ID account. In the How to set up your device screen, choose Get started.

In the Set up your work profile screen, choose Next. Your device will start setting up your work profile. Choose Next.

This will start updating the device and will open Google Chrome. Choose Continue, and sign in with your Corporate Entra ID account again. Setting up device will start.

This will start the registration, on the Your work checklist screen, choose Install underneath Install work apps, and wait till the required apps are installed, then choose Done.

In the Register your device screen, choose Set up. This will redirect you to the Microsoft Intune app, choose Sign In. Fill in your password (your username should be known) and choose Sign in. Next, choose Register on the Help us keep your device secure screen to get started.

The first step is to Register the device, so choose Next. After the register device part, choose Next to Check device settings. Choose Next.

Once the checks are done, your device is ready to go! Choose Got it in the overview message, then choose Done in the Device is ready to go screen!. You’ll notice the Work profile is now active on the device.

So this is how the new web-based enrollment for Personally-owned with Work Profile devices will work for your end-users.

Conclusion

The move to the Android Management API marks an important evolution in Android management within Microsoft Intune. As demonstrated throughout this post, and especially during the enrollment walkthrough, the new web-based enrollment experience significantly simplifies the process for end users while providing IT administrators with a more consistent and modern foundation for device management.

Although there are still a few limitations to consider and some preparation required, the direction is clear. By aligning with Google’s Android Management API and introducing a streamlined enrollment flow, Intune is moving towards a more unified, predictable, and future-proof approach. Now is the right time to start exploring the new experience, validate it within your environment, and prepare for the broader rollout later this year.