Skip to main content

10 de junio de 2026

How to Configure Android Profiles

Android profiles ensure proper use of devices and protection of sensitive data. Profiles serve many different purposes, from letting you enforce corporate rules and procedures to tailoring and preparing Android devices for how they are used.

Custom DPC versus Android Management (AMAPI)

When deploying profiles, you will first select the Android management type which determine which profile and functions can be configured in each profile. For AMAPI configurations, most profiles are sent to AMAPI and are applied to the device by Android Device Policy. For Custom DPC, most profiles are sent through the Workspace ONE Intelligent Hub, which applies them to the device. In many cases, the capabilities of AMAPI and Custom DPC profiles are similar, but the profile settings are organized differently.

Work Profile vs. Work Managed Device Mode

A Work Profile is a special type of administrator tailored primarily for a BYOD use case. When the user already has a personal device configured with their own Google account, Workspace ONE UEM enrollment creates a Work Profile, where it installs the Workspace ONE Intelligent Hub. Workspace ONE UEM only controls the Work Profile. Managed apps install inside the Work Profile and display an orange briefcase badge to differentiate them from personal apps.

Work Managed device applies to devices enrolled from an unprovisioned or factory reset state. This mode is recommended for corporate owned devices. Workspace ONE Intelligent Hub is installed during the setup process and set as the device owner, meaning Workspace ONE UEM will have full control of the entire device.

Android profiles display the following tags: Work Profile and Work Managed Device.

Profile options with the Work Profile tag only apply to the Work Profile settings and apps, and do not affect the user's personal apps or settings. For example, certain restrictions turn off access to the Camera or taking screen capture. These restrictions only affect the Android badged apps inside the Work Profile and will not impact personal apps. Profile options configured for Work Managed Device apply to the entire device. Each profile discussed in this section indicates which device type the profile affects.

Configure Profile

In the Workspace ONE UEM console, you follow the same navigation path for each profile. The Preview section shows you Total Assigned Devices with a list view. You can see the added profiles on the Summary tab.

!!! Important !!! "Profiles Behavior: There are times when more than one profile needs to be implemented for various reasons. When duplicate profiles are deployed, the most restrictive policy takes priority. Therefore, if two profiles are installed, and one says to block camera and another says to allow camera, Workspace ONE UEM combines the profiles and blocks the camera to choose the more secure option."

To configure profiles:

  1. Navigate to Resources > Profiles & Baselines > Profiles > Add > Add Profile > Android.

  2. Select your Management Type: as Custom DPC or Android Management API. While you will see the same profile options for either type, how they are configured can differ.

  3. Configure the settings:

    SettingsDescription
    NameSet the name for your profile and add a description that would be easily recognizable to you.
    Profile ScopeSet how the profile is used in your environment either on Production, Staging, or Both.
    OEM Settings (Custom DPC Only)Turn on OEM settings to configure specific settings for Samsung or Zebra devices. Once you select the OEM, you will see additional profiles and settings display that are unique to either OEM.
  4. Select the Add button for the desired profile and configure the settings as desired. You can use the drop-down and preview profile settings before selecting add.

  5. Select Next to configure the general Assignment and Deployment profile settings as appropriate. Configure the following settings:

    SettingsDescription
    Smart GroupThe group this profile should be assigned to.
    Allow ExclusionWhen turned on, a new text box Exclude Group displays. You can then select those groups you want to exclude from the assignment of the device profile.
    Assignment TypeDetermines how the profile is deployed to devices: Auto – The profile is deployed to all devices. Optional – An end user can optionally install the profile from the Self-Service Portal (SSP), or it can be deployed to individual devices at the administrator's discretion. End users can also install profiles representing Web applications, using a Web Clip or a Bookmark payload. And if you configure the payload to show in the App Catalog, then you can install it from the App Catalog. Compliance – The profile is applied to the device by the Compliance Engine when the user fails to take corrective action toward making their device compliant.
    Managed ByThe organization group with administrative access to the profile.
    Install Area Only (Custom DPC only)Turn on to display geofencing option: Install only on devices inside selected areas: Enter an address anywhere in the world and a radius in kilometers or miles to make a 'perimeter of profile installation'.
    Schedule Install Time (Custom DPC only)Turn on to configure time schedule settings: Turn on Scheduling and install only during selected time periods:Specify a configured time schedule in which devices receive the profile only within that timeframe.
  6. Select Save & Publish.

¿Le resultó útil esta página?

Enviar comentarios sobre este tema

¿Le resultó útil este tema?

No incluya información personal ni confidencial.

Generando el enlace…