{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
        "slug": "dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/"
        },
        "title": "Check enrollment-time grouping before choosing Android work-profile staging",
        "summary": "Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "continuity-recovery",
            "label": "Continuity & recovery",
            "alt": "Paired infrastructure paths converging on a stable recovered service.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "business-continuity",
                "name": "Business Continuity",
                "url": "https://update.dsesecurity.com/topic/business-continuity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:29+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 233,
        "potentially_affected": "Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.",
        "dse_recommendation": "Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens.",
        "primary_source": {
            "name": "Set up Android Enterprise work profile for corporate owned devices - Microsoft Intune | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Intune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. <a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.</p>\n<h2>DSE recommendation</h2>\n<p>Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.</p>\n<h2>Verification</h2>\n<p>Provision a representative device with the approved profile and follow it through the user&#8217;s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Set up Android Enterprise work profile for corporate owned devices</a>.</p>",
        "content_text": "Source facts\nIntune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. Microsoft Learn.\nApplicability\nUse this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.\nDSE recommendation\nResolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.\nVerification\nProvision a representative device with the approved profile and follow it through the user’s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.\nOfficial references\nMicrosoft Learn: Set up Android Enterprise work profile for corporate owned devices.",
        "content_markdown": "## Source facts\n\nIntune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile).\n\n## Applicability\n\nUse this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.\n\n## DSE recommendation\n\nResolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.\n\n## Verification\n\nProvision a representative device with the approved profile and follow it through the user’s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.\n\n## Official references\n\n[Microsoft Learn: Set up Android Enterprise work profile for corporate owned devices](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Check enrollment-time grouping before choosing Android work-profile staging",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/",
                "headline": "Check enrollment-time grouping before choosing Android work-profile staging",
                "description": "Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?",
                "abstract": "Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?",
                "articleBody": "Source facts\nIntune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. Microsoft Learn.\nApplicability\nUse this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.\nDSE recommendation\nResolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.\nVerification\nProvision a representative device with the approved profile and follow it through the user’s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.\nOfficial references\nMicrosoft Learn: Set up Android Enterprise work profile for corporate owned devices.",
                "datePublished": "2026-09-10T00:22:29+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/continuity-recovery-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Check enrollment-time grouping before choosing Android work-profile staging"
                },
                "articleSection": [
                    "Business Continuity",
                    "IT"
                ],
                "keywords": [
                    "Business Continuity",
                    "IT",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Business Continuity",
                        "url": "https://update.dsesecurity.com/topic/business-continuity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 233,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Set up Android Enterprise work profile for corporate owned devices - Microsoft Intune | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile"
                }
            }
        ]
    }
}