Corporate-Owned, Personally Enabled (COPE) Enrollment
COPE enrollment is designed for organization-owned Android devices that are issued to employees for both work and personal use. This deployment model provides a balance between corporate security and user privacy by separating work data from personal data on the same device.
In COPE mode, the organization manages the work profile and corporate policies, while employees retain limited control over personal applications and personal content.
Prerequisite
Step 1: Configure a COPE device in the UEM console
-
In the UEM admin console, navigate to Manage Devices → Devices → Android and click
Enroll Android Device.
-
In the Enrollment Settings tab, configure the enrollment options:
- Device Type: Select Corporate with Personal Container to enroll the device in COPE (Company-Owned, Personally Enabled) mode.
- Assign to Device Group: Choose the device group whose policies, apps, and compliance settings should be applied.
- Admin Device Approval: Enable this option if an administrator should manually approve the device before policies are assigned.
- Enrollment Token Expiration: Specify how long the enrollment token should remain valid (for example, 20 Minutes or 1 Day).
-
Click Next to open the Add Users step. Search for the required user, select the checkbox beside the user account, and click Next.
-
Review the enrollment summary, verify the selected user and enrollment configuration, then choose the enrollment delivery method:
- Send Email: Sends an enrollment invitation containing the QR code and enrollment token to the selected user's email address.
- Show Here: Displays the QR code and enrollment token directly on the screen for manual device provisioning.
Click Submit to generate the enrollment invitation.
-
If Send Email is selected, the user receives an enrollment email containing a QR code, Enrollment Token, and setup instructions for enrolling the COPE device.
Step 2: Complete COPE enrollment on the device
- Reset the device (if it is not already new / out of the box):
- Open Settings on the phone.
- Use the Settings search bar and type reset, or browse manually:
- On many phones: Settings → System → Reset options → Erase all data (factory reset).
- On many Samsung phones: Settings → General management → Reset → Factory data reset.
- Choose Erase all data / Factory data reset, read the warning, confirm with your PIN or password if asked, and tap Erase all data / Delete all. The device will wipe itself and reboot into the welcome / setup wizard (out-of-box experience).
- When the phone finishes rebooting, you will see the Android Welcome screen. Tap Start to begin setup.
- Connect the device to Wi‑Fi on the Choose a Wi-Fi network screen.
- After Wi‑Fi connects and the device finishes preparing, if you see Copy apps & data tap Don’t copy so setup continues without restoring from another device.
- On the Google Sign in screen, in the Email or phone field, type afw#setup exactly then tap Next. The device should begin installing Android Device Policy.
- Now, scan the QR code as shown in the below screen.
- On Let’s separate your work apps, tap Accept and continue to create the managed work profile on this device.
- Wait while the device sets up the work profile Separating work apps.
- Set a work profile screen lock (PIN, pattern, or password) when prompted. This lock applies to the work profile, not the personal side of the device.
- When you see Install work apps, tap Install so your organisation’s apps are installed in the work profile.
- After the work apps finish installing, review the list and tap Done to complete setup.
- You will see the screen below. Click Next to continue.
- On Sign in with your personal account, tap Skip.
- Wait while the device shows Getting your phone ready (or similar), then tap Next or Continue.
- Once setup is complete, you will see your organisation’s work apps in the work profile. The personal side of the device stays separate. You are now ready to go.
For more on COPE capabilities and use cases on the product side, see Android COPE MDM. For standard BYOD work profiles, see BYOD enrollment; for fully managed corporate devices, see Company owned device enrollment.