Corporate-Owned, Personally Enabled (COPE) Enrollment
COPE enrollment is designed for organization-owned Android devices that are issued to employees for both work and personal use. This deployment model provides a balance between corporate security and user privacy by separating work data from personal data on the same device.
In COPE mode, the organization manages the work profile and corporate policies, while employees retain limited control over personal applications and personal content.
Prerequisite
Step 1: Configure a COPE device in the UEM console
- In the UEM admin console, go to Manage Devices → Devices → Android and click Enroll Android Device.
- In the Enroll Android Device panel, configure the following details:
- User: Search and select the user the device will be assigned to.
- Device Type: Select Corporate with Personal Container from the dropdown to enroll the device in COPE mode – a managed work profile on company-owned hardware with a personal side allowed.
- Assign to Group: Pick the device group whose policies should govern the work profile (restrictions, managed Google Play apps, compliance).
- Admin Device Approval: Enable this if you want an admin to approve the device and assign the actual policy after the user completes setup.
- Enrollment: Choose By User Invite to email the QR code and enrollment token to the user, or By Myself if the IT admin will provision the device directly.
- Enrollment Token Expiration: Set how long the generated token remains valid (e.g., 20 minutes).
- Click Send Enrollment Email. The user receives an email containing a QR code and an Enrollment Token.

Step 2: Complete COPE enrollment on the device
- Reset the device (if it is not already new / out of the box):
- Open Settings on the phone.
- Use the Settings search bar and type reset, or browse manually:
- On many phones: Settings → System → Reset options → Erase all data (factory reset).
- On many Samsung phones: Settings → General management → Reset → Factory data reset.
- Choose Erase all data / Factory data reset, read the warning, confirm with your PIN or password if asked, and tap Erase all data / Delete all. The device will wipe itself and reboot into the welcome / setup wizard (out-of-box experience).
- When the phone finishes rebooting, you will see the Android Welcome screen. Tap Start to begin setup.
- Connect the device to Wi‑Fi on the Choose a Wi-Fi network screen.
- After Wi‑Fi connects and the device finishes preparing, if you see Copy apps & data tap Don’t copy so setup continues without restoring from another device.
- On the Google Sign in screen, in the Email or phone field, type afw#setup exactly then tap Next. The device should begin installing Android Device Policy.
- Now, scan the QR code as shown in the below screen.
- On Let’s separate your work apps, tap Accept and continue to create the managed work profile on this device.
- Wait while the device sets up the work profile Separating work apps.
- Set a work profile screen lock (PIN, pattern, or password) when prompted. This lock applies to the work profile, not the personal side of the device.
- When you see Install work apps, tap Install so your organisation’s apps are installed in the work profile.
- After the work apps finish installing, review the list and tap Done to complete setup.
- You will see the screen below. Click Next to continue.
- On Sign in with your personal account, tap Skip.
- Wait while the device shows Getting your phone ready (or similar), then tap Next or Continue.
- Once setup is complete, you will see your organisation’s work apps in the work profile. The personal side of the device stays separate. You are now ready to go.
For more on COPE capabilities and use cases on the product side, see Android COPE MDM. For standard BYOD work profiles, see BYOD enrollment; for fully managed corporate devices, see Company owned device enrollment.