GuideInformationBusiness ContinuityIT

Check enrollment-time grouping before choosing Android work-profile staging

Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?

Paired infrastructure paths converging on a stable recovered service.
DSE visual intelligenceContinuity & recoveryGuide · 2 min read
Executive summary

What you need to know

Can a corporate-owned Android work-profile staging token also use enrollment-time grouping?

Potentially affected

Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.

DSE recommendation

Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens.

Source facts

Intune offers separate standard and staging tokens for corporate-owned Android work-profile enrollment. The staging token lets an administrator or vendor finish pre-provisioning, leaving the user to complete provisioning by signing in to the Intune app. Enrollment-time grouping is not supported with that staging token. Microsoft directs profiles that need enrollment-time grouping to use the standard corporate-owned work-profile token instead. Microsoft Learn.

Applicability

Use this choice for Android Enterprise corporate-owned devices with a work profile. Establish whether the deployment specifically requires enrollment-time grouping, rather than grouping at an unspecified later point.

DSE recommendation

Resolve the staging-versus-enrollment-grouping requirement before issuing provisioning tokens. Ask the staging partner and endpoint administrator to agree on which preparation work belongs before handoff and which assignment timing is essential. If the design depends on enrollment-time grouping, do not silently choose the incompatible staging flow. Document the chosen token and intended group behavior in the deployment record so different staging teams do not select inconsistent paths.

Verification

Provision a representative device with the approved profile and follow it through the user’s final sign-in. Check the resulting enrollment profile, expected grouping, and delivery of required work apps. Record when each assignment becomes effective rather than accepting eventual membership as proof of enrollment-time behavior. Stop distribution if the observed sequence does not meet the agreed readiness requirement.

Official references

Microsoft Learn: Set up Android Enterprise work profile for corporate owned devices.

Primary reference

Review the official source

Set up Android Enterprise work profile for corporate owned devices - Microsoft Intune | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE