# Check enrollment-time grouping before choosing Android work-profile staging

> Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:29+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Guide
- DSE priority: Information
- Topics: Business Continuity, IT
- Reading time: 2 minutes

## What you need to know

Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?

## Potentially affected

Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.

## DSE recommendation

Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens.

## Article

## Source facts

Intune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. [Microsoft Learn](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile).

## Applicability

Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.

## DSE recommendation

Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.

## Verification

Provision a representative device with the approved profile and follow it through the user’s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.

## Official references

[Microsoft Learn: Set up Android Enterprise work profile for corporate owned devices](https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile).

## Primary reference

- Name: Set up Android Enterprise work profile for corporate owned devices - Microsoft Intune | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/intune/device-enrollment/android/setup-corporate-work-profile
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Check enrollment-time grouping before choosing Android work-profile staging,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-567-check-enrollment-time-grouping-before-choosing-android-work-profile-staging/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
