GuideInformationBusiness ContinuityIT

Verify cross-app sign-out separately from Android shared-device enrollment

Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 1 min read
Executive summary

What you need to know

Does enrolling an Android device for shared use automatically provide the intended cross-app sign-out experience?

Potentially affected

Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application's session design.

DSE recommendation

Require the application owner to identify how each app participates in shared-device sign-in and sign-out.

Source facts

For Android Enterprise dedicated devices, Microsoft Entra shared device mode is optional and separate from Intune shared-device enrollment. The mode supplies an app-and-identity sign-in and sign-out experience; Microsoft identifies app support for MSAL as necessary for the full experience. Microsoft Learn.

Applicability

Use this check for a shared Android Enterprise dedicated device passed between workers. List the actual work applications and the intended handoff behavior instead of treating the enrollment label as the application’s session design.

DSE recommendation

Require the application owner to identify how each app participates in shared-device sign-in and sign-out. Review the endpoint enrollment choice and identity mode as separate entries. Establish what a departing worker must do and what the next worker should observe, including any application that needs its own reviewed handling.

Verification

Use two test identities and harmless work data. Have the first user complete a representative task, perform the approved sign-out, and hand the device to the second user. Inspect each application for the expected identity and accessible data. Record application-specific exceptions and resolve them before treating the handoff as ready. Do not report a successful enrollment alone as proof of cross-app session isolation.

Official references

Microsoft Learn: Get started with Android frontline worker devices.

Primary reference

Review the official source

Get started with Android frontline worker devices - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE