{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
        "slug": "dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/"
        },
        "title": "Treat the AOSP userless enrollment QR code as a credential-bearing artifact",
        "summary": "What remains at risk after an Android AOSP enrollment QR code is exposed?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "physical-security",
            "label": "Physical security",
            "alt": "Integrated video surveillance and controlled entry at a modern commercial facility.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/physical-security-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/physical-security-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:01+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 224,
        "potentially_affected": "Apply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.",
        "dse_recommendation": "Handle the QR code through the same controlled custody process as its embedded credentials.",
        "primary_source": {
            "name": "Set up Android (AOSP) device management in Intune for corporate-owned userless devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For Intune&#8217;s corporate-owned userless AOSP enrollment, the QR code contains the profile&#8217;s network credentials in readable form. Microsoft recommends considering a restricted staging network for provisioning, without corporate access. Revoking the enrollment token immediately makes it unusable, but does not affect devices already enrolled. Replacing an expiring token likewise leaves existing enrollments unchanged. <a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Apply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.</p>\n<h2>DSE recommendation</h2>\n<p>Handle the QR code through the same controlled custody process as its embedded credentials. Limit who can view, print, or export it, and avoid placing it in shared deployment instructions. If exposure occurs, have the enrollment owner revoke the token and separately assess the network credential and already-enrolled device inventory. Do not assume token revocation proves that every consequence of disclosure has been removed.</p>\n<h2>Verification</h2>\n<p>In a safe provisioning exercise, confirm that an authorized current token enrolls the intended device and a revoked test token no longer does. Reconcile the enrolled inventory against the staging record. Review access to the provisioning network independently, and record what was replaced, revoked, or investigated without attaching the QR code to the general incident ticket.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Set up Android (AOSP) device management in Intune for corporate-owned userless devices</a>.</p>",
        "content_text": "Source facts\nFor Intune’s corporate-owned userless AOSP enrollment, the QR code contains the profile’s network credentials in readable form. Microsoft recommends considering a restricted staging network for provisioning, without corporate access. Revoking the enrollment token immediately makes it unusable, but does not affect devices already enrolled. Replacing an expiring token likewise leaves existing enrollments unchanged. Microsoft Learn.\nApplicability\nApply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.\nDSE recommendation\nHandle the QR code through the same controlled custody process as its embedded credentials. Limit who can view, print, or export it, and avoid placing it in shared deployment instructions. If exposure occurs, have the enrollment owner revoke the token and separately assess the network credential and already-enrolled device inventory. Do not assume token revocation proves that every consequence of disclosure has been removed.\nVerification\nIn a safe provisioning exercise, confirm that an authorized current token enrolls the intended device and a revoked test token no longer does. Reconcile the enrolled inventory against the staging record. Review access to the provisioning network independently, and record what was replaced, revoked, or investigated without attaching the QR code to the general incident ticket.\nOfficial references\nMicrosoft Learn: Set up Android (AOSP) device management in Intune for corporate-owned userless devices.",
        "content_markdown": "## Source facts\n\nFor Intune’s corporate-owned userless AOSP enrollment, the QR code contains the profile’s network credentials in readable form. Microsoft recommends considering a restricted staging network for provisioning, without corporate access. Revoking the enrollment token immediately makes it unusable, but does not affect devices already enrolled. Replacing an expiring token likewise leaves existing enrollments unchanged. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless).\n\n## Applicability\n\nApply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.\n\n## DSE recommendation\n\nHandle the QR code through the same controlled custody process as its embedded credentials. Limit who can view, print, or export it, and avoid placing it in shared deployment instructions. If exposure occurs, have the enrollment owner revoke the token and separately assess the network credential and already-enrolled device inventory. Do not assume token revocation proves that every consequence of disclosure has been removed.\n\n## Verification\n\nIn a safe provisioning exercise, confirm that an authorized current token enrolls the intended device and a revoked test token no longer does. Reconcile the enrolled inventory against the staging record. Review access to the provisioning network independently, and record what was replaced, revoked, or investigated without attaching the QR code to the general incident ticket.\n\n## Official references\n\n[Microsoft Learn: Set up Android (AOSP) device management in Intune for corporate-owned userless devices](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Treat the AOSP userless enrollment QR code as a credential-bearing artifact",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/",
                "headline": "Treat the AOSP userless enrollment QR code as a credential-bearing artifact",
                "description": "What remains at risk after an Android AOSP enrollment QR code is exposed?",
                "abstract": "What remains at risk after an Android AOSP enrollment QR code is exposed?",
                "articleBody": "Source facts\nFor Intune’s corporate-owned userless AOSP enrollment, the QR code contains the profile’s network credentials in readable form. Microsoft recommends considering a restricted staging network for provisioning, without corporate access. Revoking the enrollment token immediately makes it unusable, but does not affect devices already enrolled. Replacing an expiring token likewise leaves existing enrollments unchanged. Microsoft Learn.\nApplicability\nApply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.\nDSE recommendation\nHandle the QR code through the same controlled custody process as its embedded credentials. Limit who can view, print, or export it, and avoid placing it in shared deployment instructions. If exposure occurs, have the enrollment owner revoke the token and separately assess the network credential and already-enrolled device inventory. Do not assume token revocation proves that every consequence of disclosure has been removed.\nVerification\nIn a safe provisioning exercise, confirm that an authorized current token enrolls the intended device and a revoked test token no longer does. Reconcile the enrolled inventory against the staging record. Review access to the provisioning network independently, and record what was replaced, revoked, or investigated without attaching the QR code to the general incident ticket.\nOfficial references\nMicrosoft Learn: Set up Android (AOSP) device management in Intune for corporate-owned userless devices.",
                "datePublished": "2026-09-10T00:25:01+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-415-treat-the-aosp-userless-enrollment-qr-code-as-a-credential-bearing-artifact/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/physical-security-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Treat the AOSP userless enrollment QR code as a credential-bearing artifact"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 224,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set up Android (AOSP) device management in Intune for corporate-owned userless devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-aosp-corporate-userless"
                }
            }
        ]
    }
}