GuideInformationBusiness ContinuityIT

Treat the AOSP userless enrollment QR code as a credential-bearing artifact

What remains at risk after an Android AOSP enrollment QR code is exposed?

Integrated video surveillance and controlled entry at a modern commercial facility.
DSE visual intelligencePhysical securityGuide · 2 min read
Executive summary

What you need to know

What remains at risk after an Android AOSP enrollment QR code is exposed?

Potentially affected

Apply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.

DSE recommendation

Handle the QR code through the same controlled custody process as its embedded credentials.

Source facts

For Intune’s corporate-owned userless AOSP enrollment, the QR code contains the profile’s network credentials in readable form. Microsoft recommends considering a restricted staging network for provisioning, without corporate access. Revoking the enrollment token immediately makes it unusable, but does not affect devices already enrolled. Replacing an expiring token likewise leaves existing enrollments unchanged. Microsoft Learn.

Applicability

Apply this review to the documented AOSP userless provisioning profile, including RealWear staging. Identify both the enrollment token and any network credential carried by the QR code.

DSE recommendation

Handle the QR code through the same controlled custody process as its embedded credentials. Limit who can view, print, or export it, and avoid placing it in shared deployment instructions. If exposure occurs, have the enrollment owner revoke the token and separately assess the network credential and already-enrolled device inventory. Do not assume token revocation proves that every consequence of disclosure has been removed.

Verification

In a safe provisioning exercise, confirm that an authorized current token enrolls the intended device and a revoked test token no longer does. Reconcile the enrolled inventory against the staging record. Review access to the provisioning network independently, and record what was replaced, revoked, or investigated without attaching the QR code to the general incident ticket.

Official references

Microsoft Learn: Set up Android (AOSP) device management in Intune for corporate-owned userless devices.

Primary reference

Review the official source

Set up Android (AOSP) device management in Intune for corporate-owned userless devices - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE