Android Enterprise Self Service QR Code Enrollment

Android Enterprise Self Service QR Code Enrollment

Introduction
As of Android 10, device administrator management (legacy) is no longer possible due to Google depreciating the usage of this on the OS. Android Enterprise device management is Google's new initiative to allow companies to manage Android devices within the workplace.

In our Recommended Reads, we have two different management modes covered:
Android Enterprise Full Device management - https://community.sophos.com/sophos-mobile/f/recommended-reads/132167/sophos-mobile---android-enterprise-full-device-management-enrollment
Android Enterprise Work Profile management - https://community.sophos.com/sophos-mobile/f/recommended-reads/132235/sophos-mobile---android-enterprise-work-profile-enrollment

An alternative enrollment method is available for “Android Enterprise Full Device” management where an end-user is able to set up a Self Service Portal account to enroll their mobile device. An External LDAP connection can also be used instead, as a way to associated your users with their respective devices.

Prerequisites

Goals

  • Understand how to prepare Android Enterprise Self Service QR Enrollment for the Full Device management mode.
  • Understand how to successfully enroll a device into Sophos Mobile using this method.

Set up Self Service Portal access
From Sophos Central, ensure that all users that you wish to enroll with SMC have an e-mail address applied to their user entry.

Note: If you have enabled "User access" settings, your users may have already received this setup email. An LDAP connection can be used instead of the SSP account, as a means to associate your devices to their respective users.

  1. From the "People" page in Sophos Central, highlight all users you'd like to set up and click the "Email Setup Link" button

  2. Check "Sophos Central Self Service Welcome/Setup Email" and click "Send".


  3. Click “Set up my password” in the email received.


  4. Enter your email address and click “Send Verification Code.”


  5. A new e-mail will be sent to you containing a code.



  6. Enter the code you received and click "Verify Code"


  7. Enter the desired password to your “Self Service Portal” account.

Create the Android Enterprise Policy and Task bundle
Create the Android Enterprise Full Device policy in the SMC portal, or use an existing one.

  1. Policies > Android > Create > Android Enterprise device Policy


  2. Define the configuration you wish to apply within the Policy
  3. Save the Policy

Create a Task Bundle to strictly assign the policy

  1. Task Bundles > Android > Create > Create task bundle


  2. Select “Add Task”
  3. Specify “Assign policy” and select the Android Enterprise Device Policy created in the previous step.

  4. Save

Create the enrollment QR code

  1. Go to: Setup > Google Setup > QR code enrollment > Configure Android Enterprise QR code enrollment
  2. Enable/Disable system applications, specify Wi-Fi settings if needed and click Next.
  3. Use the drop-down menu next to “Task bundle” to specify the task bundle we created in the previous step to strictly assign the policy.
  4. Specify a Device Group you’d like to associate these QR enrolled devices to.
  5. Click Finish

Note: The enrollment QR Code will be displayed. You may want to print out this code so that you can post it in the office or send this QR Code to all users via e-mail.

Enroll the device

  1. Start by performing a factory reset on the device you wish to enroll.
  2. On the startup/welcome screen tap on the screen 6 times.
  3. The screen will change to state "QR code setup," press Next.

  4. Connect to a wireless network.
  5. A QR scanner will begin downloading. Once completed, the camera will open.

  6. Scan the QR code you created.
    Note: If your Android Enterprise policy requires the device to be encrypted, the device will prompt to begin encrypting.


  7. Press “OK” on the following page advising “Your admin has the ability to monitor…”


  8. The following will now occur automatically:
    - The mobile device will download the Sophos Mobile Control application
    - Updates to the Google Play store will be installed




  9. An auto-enrollment screen will be displayed after which you will need to authenticate with your SSP account.


  10. As a final step after the device returns to the home screen, open the Sophos Mobile Control app to approve battery optimization and you’re all set.

In Sophos Mobile, the device will be shown as "Android Enterprise #####," which is not very descriptive. I suggest renaming the device to something more easily identifiable using the "Edit" button as shown below. 

Thanks for reading. If you have any questions, feel free to post them using the reply button below.



Edited spacing
[edited by: Qoosh at 9:58 PM (GMT -8) on 9 Feb 2022]