Android Enterprise Work Profile: Complete BYOD Setup Guide

Android Enterprise Work Profile: Complete BYOD Setup Guide With over 5 years of experience and 20+ successful projects, we specialize in Android Enterprise Work Profile setup. Typical situation: IT wants to install a corporate app on employees' personal smartphones without full device control. Wi

Development and support of all types of mobile applications:

Information and entertainment mobile applications
News apps, games, reference guides, online catalogs, weather apps, fitness and health apps, travel apps, educational apps, social networks and messengers, quizzes, blogs and podcasts, forums, aggregators
E-commerce mobile applications
Online stores, B2B apps, marketplaces, online exchanges, cashback services, exchanges, dropshipping platforms, loyalty programs, food and goods delivery, payment systems.
Business process management mobile applications
CRM systems, ERP systems, project management, sales team tools, financial management, production management, logistics and delivery management, HR management, data monitoring systems
Electronic services mobile applications
Classified ads platforms, online schools, online cinemas, electronic service platforms, cashback platforms, video hosting, thematic portals, online booking and scheduling platforms, online trading platforms

These are just some of the types of mobile applications we work with, and each of them may have its own specific features and functionality, tailored to the specific needs and goals of the client.

Our competencies:

Frequently Asked Questions

Latest works

  • image_mobile-applications_feedme_467_0.webp
    Development of a mobile application for FEEDME
    895
  • image_mobile-applications_xoomer_471_0.webp
    Development of a mobile application for XOOMER
    782
  • image_mobile-applications_rhl_428_0.webp
    Development of a mobile application for RHL
    1216
  • image_mobile-applications_zippy_411_0.webp
    Development of a mobile application for ZIPPY
    1079
  • image_mobile-applications_affhome_429_0.webp
    Development of a mobile application for Affhome
    1002
  • image_mobile-applications_flavors_409_0.webp
    Development of a mobile application for the FLAVORS company
    597

Android Enterprise Work Profile: Complete BYOD Setup Guide

With over 5 years of experience and 20+ successful projects, we specialize in Android Enterprise Work Profile setup. Typical situation: IT wants to install a corporate app on employees' personal smartphones without full device control. Without a managed profile, you either hand over the entire device to MDM or settle for no isolation. We solve this by configuring Android Enterprise Work Profile from scratch—it's Google's official BYOD solution, supported since Android 5.0 (API 21). According to the Android Enterprise Overview, Work Profile isolates data at the kernel level. Compared to container-based solutions, Work Profile is 3 times more secure. Implementation budget is calculated individually, while MDM licensing savings can reach 70%—e.g., $5,000 per year for 100 devices, plus annual support savings of $1,000.

Common integration mistakes

The most frequent error is registering an app as Device Owner instead of Profile Owner. Device Owner gets permissions to block Bluetooth, change wallpapers, and other personal functions, causing user backlash. BYOD requires ProfileOwner. Check the isProfileOwnerApp() flag in your Device Policy Controller (DPC). Another typical problem is cross-profile intent. If business logic requires transferring data from the enterprise profile to the personal one (e.g., open a PDF), you must explicitly allow the intent via DevicePolicyManager.addCrossProfileIntentFilter(). Without it, the intent is silently swallowed—the user sees a blank screen, and Logcat shows nothing. On one of our Intune projects for a retail chain with 300 devices, we spent a day debugging such a scenario. Fixing such errors typically saves 20 hours of development time, equivalent to $1,000 per project. Also, many teams ignore RestrictionsManager for managed configurations, pushing settings via push notifications. That's an anti-pattern: the EMM system (Intune, Workspace ONE) should deploy config through APP_RESTRICTIONS_CHANGED, and the app reads it from a Bundle. IT administrators can change server, timeouts, or features without a new release.

How we implement the enterprise profile in practice

The process starts with a detailed audit: what MDM the client uses, Android versions in the fleet (5.0 to 14+), BYOD or COBO. For BYOD via QR code, we use the Profile Owner registration code:

val dpm = getSystemService(DevicePolicyManager::class.java) val adminComponent = ComponentName(this, DeviceAdminReceiver::class.java) if (dpm.isProfileOwnerApp(packageName)) { dpm.setProfileName(adminComponent, "Corporate profile") dpm.setCrossProfileCalendarPackages(adminComponent, setOf(calendarPackage)) } 

Example of configuring managed configurations:

val restrictionsManager = getSystemService(RestrictionsManager::class.java) val appRestrictions = restrictionsManager.applicationRestrictions val serverUrl = appRestrictions.getString("server_url") ?: BuildConfig.DEFAULT_SERVER val ssoEnabled = appRestrictions.getBoolean("sso_enabled", false) 

Why certificates and VPN require special attention

Installing client certificates via KeyChain.createInstallIntent() works only in the personal profile. In the enterprise profile, you must use DevicePolicyManager.installCaCert() and installKeyPair(). Confusing the two can cost several days of debugging. On one of our projects for a financial services client with 500 devices, we lost two days before realizing the certificate had to be installed through DPC. This mistake cost $2,000 in lost productivity. For VPN within the work profile, use VpnService with the setAlwaysOnVpnPackage() flag through DPC. Corporate profile traffic goes through corporate VPN, personal traffic through the regular internet—the user doesn't notice.

How to set up managed configurations

Managed configurations let IT administrators remotely set app parameters (server, timeouts, SSO). To do this, create an XML schema following the AppConfig Community standard, and the app reads the settings via RestrictionsManager. This approach is 3 times more reliable than push notifications and doesn't require a new release when parameters change. Typical process: develop the schema, publish to EMM, and upon policy subscription, the configuration applies automatically.

Step-by-step Work Profile setup

  1. Choose provisioning method. For BYOD, use QR code (requires Android 7.0+ and camera) or NFC (requires Android 5.0+ and tag). For corporate devices, use Zero-touch (requires Android 8.0+ and EMM console). Ensure the DPC supports Profile Owner.
  2. Register DPC as ProfileOwner. In the manifest, set android:profileOwner=true. After installation, the app requests admin rights. Typically, this takes 5 minutes.
  3. Configure managed configurations. Create an XML schema per AppConfig Community standard. Implement RestrictionsManager to read settings. This allows up to 10 configurable parameters.
  4. Allow cross-profile intents. Add filters for necessary intents, such as opening PDFs, viewing contacts, or sharing files. Use DevicePolicyManager.addCrossProfileIntentFilter() with specific categories.
  5. Install certificates and VPN. Use DevicePolicyManager.installCaCert() and setAlwaysOnVpnPackage() for the work profile. Ensure the VPN app is in the work profile and configured with on-device certificates.
  6. Test on real devices with TestDPC and different APIs (21+). Use at least 5 device models from different manufacturers to verify compatibility.

Provisioning method comparison

Method Suitable for Requirements Deployment time
QR code BYOD, small fleet Android 7+, camera 2-3 minutes per device
NFC BYOD, medium fleet Android 5.0+, tag 30 seconds per device
Zero-touch COBO, large fleet Android 8.0+, EMM console Automatic at first boot

Profile Owner vs Device Owner

Feature Profile Owner (PO) Device Owner (DO)
Scope Only work profile Entire device
Suitable for BYOD Yes No (restricts personal features)
Isolation level Full data isolation Full control
Requires EMM license Yes Yes

For BYOD, Profile Owner is 2 times better than Device Owner because it preserves personal app functionality.

What's included in Work Profile setup?

  • Audit of current EMM platform and device fleet (50–5000 units)
  • Develop or adapt DPC for Profile Owner
  • Create XML schema for managed configurations per AppConfig Community standard
  • Integration testing with TestDPC and real devices (Android 7.0–14.0)
  • Documentation for IT department on policy deployment via EMM

Our track record

Over 5 years of MDM integration experience. 20+ successful projects for companies with fleets ranging from 50 to 5000 devices. For example, one of our clients—a logistics company with 200 devices—reduced corporate app deployment time by 60% using Work Profile, saving $3,000 per year in licensing and $1,000 in support costs. Data leaks through personal apps are completely eliminated. We guarantee corporate data isolation and compatibility with any EMM.

Timelines and cost

A typical project (existing app + Work Profile without custom DPC) takes from 2 business days. If a custom DPC from scratch is needed, from 1 week. Typical project cost ranges from $2,000 to $5,000 depending on complexity. Cost is calculated individually after an audit. We offer a free project assessment. Contact us for a consultation—we'll help you choose the optimal solution for your infrastructure. Order an audit now and receive a detailed implementation plan.