# Verify cross-app sign-out separately from Android shared-device enrollment

> Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:56+00:00
- Modified: 2026-09-10T02:11:19+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 1 minutes

## What you need to know

Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?

## Potentially affected

Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application's session design.

## DSE recommendation

Require the application owner to identify how each app participates in shared-device sign-in and sign-out.

## Article

## Source facts

For Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android).

## Applicability

Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application’s session design.

## DSE recommendation

Require the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.

## Verification

Use two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.

## Official references

[Microsoft Learn: Get started with Android frontline worker devices](https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android).

## Primary reference

- Name: Get started with Android frontline worker devices - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/solutions/frontline-worker/android
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Verify cross-app sign-out separately from Android shared-device enrollment,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-540-verify-cross-app-sign-out-separately-from-android-shared-device-enrollment/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
