Skip to main content

June 10, 2026

Enroll Android Device into Work Profile Mode

This page walks you through the steps to enroll Android devices by either Custom DPC or Workspace ONE Intelligent Hub or Android Device Management (AMAPI). For more information on the differences between Custom DPC and Android Management API, see Understanding Android Device Management Types.

Enrolling Work Profile with Using Custom DPC

The enrollment process secures a connection between Android devices and your Workspace ONE Environment environment . The Workspace ONE Intelligent Hub facilitates enrollment and allows for real-time management and access to relevant device information. To enroll, end users can provide a Server URL or email address. To allow users to use an email address, you must first configure email autodiscovery. For more information, please see Autodiscovery Enrollment.

To find the Server URL:

  1. Navigate to Groups & Settings > All Settings > System > Advanced > Site URLs
  2. Find the Device Service URL field
  3. Copy the hostname for this value. This hostname is what users can input in Intelligent Hub as the Server URL.

If using Server URL, end users must also provide a Group ID, which identifies the Organization Group the device will enroll into. To find the Group ID for an Organization Group:

  1. In the Workspace ONE UEM Console, switch to the Organization Group
  2. Navigate to Groups & Settings > Groups > OG Details.
  3. Copy the Group ID field.

Use the following instructions to install the Workspace ONE Intelligent Hub and authenticate users based on the enrollment flow:

  1. Download and install the Workspace ONE Intelligent Hub from the Google Play Store.

  2. Launch the Workspace ONE Intelligent Hub.

  3. Enter your email address or enrollment Server URL.

  4. If you entered a Server URL, enter a Group ID.

  5. Enter Username and Password and tap Continue.

  6. Accept the Terms of Use.

  7. Tap Set Up to configure the Work Profile that will be associated with the device.

  8. Tap OK on the Privacy Policy. Depending on how users are being created, the remaining screens for enrollment will vary.The enterprise settings from the Workspace ONE UEM console will be pushed to the device. This ends enrolling devices for managed Google Play Accounts.

  9. For Google Accounts only, tap Get Started to create the Work Profile and connect the Managed Google Account to the device. These steps differ based on authentication method:To proceed with User-defined enrollment:

  10. Create the Password with your user credentials and tap Next.

  11. Enter the Managed Google Account Password and tap Next.

  12. To continue with Directory Service Sync:

    1. Enter your Password and tap Next.
    2. Select Continue.
    3. Select Exit.
  13. To follow the SAML enrollment flow:

    1. Enter the User Name and Password and tap Login. The user will be redirected to the Workspace ONE Intelligent Hub.

If successful, the Work Profile is configured for the device and displays the Workspace ONE Intelligent Hub settings page. The device is ready for use according to Android settings for the Work Profile.

Enroll Work Profile Using Android Management (AMAPI)

For Work Profile devices using AMAPI, users can start enrollment using any of the following methods. The experience is similar regardless of which method is used:

  • Launch an AMAPI Enrollment URL
  • Use the AMAPI Sign Up Token
  • Workspace ONE Intelligent Hub

Note: Organizations that meet all of the following criteria should not use the Intelligent Hub method:

  • AMAPI enrollment for new devices is not enabled at the Customer-type Organization Group. In cloud-hosted Workspace ONE UEM environments, this is the highest organization group in most cases.
  • User Group Mapping is used to automatically place devices into specific Organization Groups based on the user that is enrolling the device. This is configured by setting Groups & Settings > All Settings > Devices & Users > Enrollment > Grouping > Group Assignment Mode to Automatically Select Based on User Group.

Launch an AMAPI Enrollment URL

Administrators can share an Enrollment URL in the form of a QR code or as a link. Users can start enrollment by scanning the QR code or opening the link.

For the admin

Before you begin, you can retrieve the AMAPI Enrollment URL from the Android EMM Registration Configuration page. To retrieve the Android Management API Enrollment URL, navigate to Devices > Devices Settings > Devices & Users > Android > Android EMM Registration > Configuration tab and select the Copy URL button. You can distribute the link through text or email, post it in an internal website, or use it to generate a QR code that users can scan from their devices.

For end users

  1. Scan the QR code or open the link provided by the admin to set up your Work Profile and follow the prompts on the screen to move through enrollment.
  2. Enter your Group ID to begin enrollment. Alternatively, you can select to enter your email address.
  3. Authenticate with your Username and Password and tap Next. The Intelligent Hub still pushes to the device to in order to apply internal apps and certificates, Product Provisioning, and Freestyle Orchestrator.
  4. Accept the Terms of Use.
  5. When prompted, install and launch Intelligent Hub.

Upon success, the Work Profile is configured for the device, and your device exits the setup wizard displays the Workspace ONE Intelligent Hub settings page. The device is ready for use according to Android settings for the Work Profile.

Using the AMAPI Sign Up Token

Administrators can share a Sign Up token that users can use to launch enrollment from the native Android Settings application.

For the admin

Before you begin, you can retrieve the AMAPI Sign Up Token from the Android EMM Registration Configuration page. Navigate to Devices > Devices Settings > Devices & Users > Android > Android EMM Registration > Configuration tab and find the Android Management Sign Up Token.

For end users

  1. On your Android device, launch the Settings application.
  2. Navigate Google > Set up & restore > Set up your work profile.
  3. Select Next and opt to enter the code manually.
  4. Enter the AMAPI Sign Up Token obtained from your administrator.
  5. Enter your Group ID to begin enrollment. Alternatively, you can select to enter your email address.
  6. Authenticate with your Username and Password and tap Next.
  7. Accept the Terms of Use.
  8. When prompted, install and launch Intelligent Hub.

Upon success, the Work Profile is configured for the device, and your device exits the setup wizard. The device is ready for use according to Android settings for the Work Profile.

Intelligent Hub

Like with Custom DPC, users can install Intelligent Hub app from the Play Store and input their organization’s information and credentials.

For the admin

To enroll, end users can provide a Server URL or email address. To allow users to use an email address, you must first configure email autodiscovery. For more information, please see Autodiscovery Enrollment. To find the Server URL:

  1. Navigate to Groups & Settings > All Settings > System > Advanced > Site URLs
  2. Find the Device Service URL field
  3. Copy the hostname for this value. This hostname is what users can input in Intelligent Hub as the Server URL.

If using Server URL, end users must also provide a Group ID, which identifies the Organization Group the device will enroll into. To find the Group ID for an Organization Group:

  1. In the Workspace ONE UEM Console, switch to the Organization Group
  2. Navigate to Groups & Settings > Groups > OG Details
  3. Copy the Group ID field

For end users

Use the following instructions to install the Workspace ONE Intelligent Hub and authenticate users based on the enrollment flow.

  1. Download and install the Workspace ONE Intelligent Hub from the Google Play Store.
  2. Launch the Workspace ONE Intelligent Hub.
  3. Enter your email address or Server URL. If you entered a Server URL, enter a Group ID. Intelligent Hub will launch your default browser to continue enrollment.
  4. Authenticate with your Username and Password and tap Next.
  5. Accept the Terms of Use.
  6. When prompted, install and launch Intelligent Hub.

Upon success, the Work Profile is configured for the device, and your device exits the setup wizard. The device is ready for use according to Android settings for the Work Profile.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…