Separate Android Enterprise Corp Owned Fully Managed from Work Profile

%3CLINGO-SUB%20id%3D%22lingo-sub-1121309%22%20slang%3D%22en-US%22%3ESeparate%20Android%20Enterprise%20Corp%20Owned%20Fully%20Managed%20from%20Work%20Profile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1121309%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20All%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ETesting%20some%20policies%20etc%20for%20both%20Android%20Enterprise%20Corp%20Owned%20Fully%20Managed%20and%20Work%20Profiles.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20user%20may%20have%20BOTH%20device%20types.%20Now%20for%20obvious%20reasons%20I%20cannot%20assign%20these%20to%20the%20same%20group%2C%20so%20what's%20the%20best%20way%20to%20assign%20both%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESeparate%20user%20groups%20or%20dynamic%20device%20groups%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EInfo%20appreciated%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1121309%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EIntune%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EMobile%20Device%20Management%20(MDM)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1122568%22%20slang%3D%22en-US%22%3ERe%3A%20Separate%20Android%20Enterprise%20Corp%20Owned%20Fully%20Managed%20from%20Work%20Profile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1122568%22%20slang%3D%22en-US%22%3EHmmm%2C%20last%20time%20I%20checked%20the%20Work%20Profile%20was%20deploying%20to%20Device%20Owner%20%2F%20COFM%20device%3CBR%20%2F%3E%3CBR%20%2F%3EBut%20I%20see%20this%20has%20been%20separated%20out%20better%20in%20the%20Portal%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1122534%22%20slang%3D%22en-US%22%3ERe%3A%20Separate%20Android%20Enterprise%20Corp%20Owned%20Fully%20Managed%20from%20Work%20Profile%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1122534%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F131657%22%20target%3D%22_blank%22%3E%40Stuart%20King%3C%2FA%3E%26nbsp%3B%20You%20can%20assign%20both%20policy%20types%20to%20the%20same%20user%20groups.%20The%20configurations%20will%20only%20be%20deployed%20and%20take%20effect%20for%20the%20enrollment%20type%20defined%20in%20each%20of%20the%20profiles.%20(Device%20Owner%20Only%20vs%20Work%20Profile%20Only)%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Regular Contributor

Hi All

 

Testing some policies etc for both Android Enterprise Corp Owned Fully Managed and Work Profiles.

 

A user may have BOTH device types. Now for obvious reasons I cannot assign these to the same group, so what's the best way to assign both? 

 

Separate user groups or dynamic device groups? 

 

Info appreciated

3 Replies
Highlighted

@Stuart King  You can assign both policy types to the same user groups. The configurations will only be deployed and take effect for the enrollment type defined in each of the profiles. (Device Owner Only vs Work Profile Only)

Highlighted
Hmmm, last time I checked the Work Profile was deploying to Device Owner / COFM device

But I see this has been separated out better in the Portal
Highlighted

@Stuart King  You'll still see both sets of config policies listed in the Device Configuration section of a device enrollment record, with the invalid policy states set to "Pending". Hopefully Microsoft will fix this so it's less confusing to look at, since those additional policies listed are invalid for the selected device.