New article with version: 2.0.0
Einleitung
Bring your own Device - Personal device with business use:
- Every employee uses his or her private device
- Apps and data for work purposes are stored in a work container
Hint:This app does not appear on the Home screen or in the App Launcher.
The app is launched from the list of installed apps in the Google Play Store
Eine Übersicht über die Betriebsarten von Android Enterprise sind im Wiki-Artikel Ersteinrichtung Android Enterprise zu finden.
Flow chart
The steps required to connect Android devices are described here:
Prerequisite:
- Securepoint Mobile Device Management (MDM) must be linked to a Google account as Android Enterprise account
- In Securepoint Unified Security Portal configured Android Enterprise Profile
Enrollment:
- Securepoint Mobile Device Management (MDM) must be linked to a Google account as Android Enterprise account
- In Securepoint Unified Security Portal configured Android Enterprise Profile
Enrollment:
- Securepoint Mobile Device Management (MDM) must be linked to a Google account as Android Enterprise account
- In Securepoint Unified Security Portal configured Android Enterprise Profile
Enrollment:
- Securepoint Mobile Device Management (MDM) must be linked to a Google account as Android Enterprise account
- In Securepoint Unified Security Portal configured Android Enterprise Profile
Enrollment:
Preparation
There must be a connection from the Securepoint Mobile Security Portal to an Android Enterprise account.
BYOD: Link Google Enterprise with Securepoint Mobile Security
| In order to be able to use Google Enterprise for companies and administer it via Securepoint Mobile Security, a link must be established between the Mobile Security account and a Google account for EMM. It is important to note that there is only one Google Enterprise account for all devices of a tenant (customer with own mobile security account). Without EMM, every device has its own Google account. |
![]() | ||||||||||||||||||
| notempty A Google Account may only be associated with one tenant at a time ! Otherwise, all devices assigned to a tenant – and thus to a Google Account – will appear in all other tenants linked to the same Google Account! | |||||||||||||||||||
|
Associating in the menu
| |||||||||||||||||||
| → Android Enterprise → Add/Link | |||||||||||||||||||
| A Google account is enabled as an enterprise account by linking Securepoint Mobile Security as EMM provider | |||||||||||||||||||
| The communication of the Securepoint Mobile Security Portal runs completely via this Google account. | |||||||||||||||||||
| notempty To avoid unwanted side effects, a new account should definitely be created. | |||||||||||||||||||
![]() Email address, for linking with Android Enterprise
![]() If an e-mail address with a domain of your own organisation is used (e.g. mdm@anyideas.de), this must be confirmed ![]() If an e-mail address with a domain of a mail provider is used (e.g. mdm.anyideas@gmail.com), the option Register for Android only must be selected. ![]() Forwarding to https://play.google.com/work ![]() Data Protection Officer and EU authorized details required ![]() You will be redirected back to the Securepoint Mobile Security Portal. The e-mail address with which the link was created should now be saved to enable later assignment. The setup must be completed with save. ![]() If this message appears when calling https://play.google.com/work, the registration in the Securepoint Mobile Security Portal has not yet been completed and no token linked! | |||||||||||||||||||
There must be an Android profile that can be assigned to the device.
BYOD: Android Profile
Under you can Add profile or Import profile or edit an existing profile (click on profile tile or → Edit )
Various configurations are made here, e.g:
- Install and configure Apps
- Password policies
- Security settings
- Control of the app store for private applications
- Release of professional address books for private use (e.g. for incoming calls).
- WiFi configurations
- Restrictions
- Password policies
- Security settings
Device enrollment
BYOD: Registration Token for a Profile
Under it is possible to Register new device
| Caption | Option | Description | ![]() |
![]() |
![]() |
![]() | ||
|---|---|---|---|---|---|---|---|---|
| Would you like to use an existing registration token? | Create a new registration token | If a registration token has already been created that has not yet expired, it can be selected and displayed here. (Fig. see below) | ||||||
| Profile | Android Enterprise Profil | This profile is to be applied to the device to be registered. | ||||||
| License | TTT-Point AG | MDM [0/10] (aaaa) | Select the license to be used for new enrolled devices. It is possible to assign devices to a new License after a runtime license expires. | ||||||
| Use code |
Determines whether or not a code is required during enrollment at the end of device registration notempty Should be enabled to prevent devices that have fallen into unauthorized hands from being registered with configured credentials or other company secrets For security reasons for ZeroTouch Enrolment, only enrolment tokens that have been provided with a PIN can be selected. | |||||||
| More options | ||||||||
| Duration | 30 days | Specifies how long this token can be used After this, device registration with this token is no longer possible. Possible values: 30 minutes Technically, it is a limit of 10,000 years | ||||||
| Additional data | Any data associated with the registration token. Displayed under in the device overview | |||||||
| Only once | Specifies whether the registration token may only be used once. | |||||||
| Allow private use | Private use is permitted | Determines whether private use is allowed on a device logged in with this registration token. For private devices: A work profile is set up on the device. |
Private use is permitted | Determines whether private use is allowed on a device logged in with this registration token. For corporate devices: A working profile is set up on the device. |
Private use is not permitted | Determines whether private use is allowed on a device logged in with this registration token. Disabling private use prevents the creation of a work container. |
Private use is not permitted | Determines whether private use is allowed on a device logged in with this registration token. Disabling private use prevents the creation of a work container. |
| Create registration token | Creates a registration token with QR code and a value that can be entered using the keyboard. The name of the associated profile is displayed, as well as the date on which it expires and can no longer be used. |
![]() | ||||||
BYOD: Register device
Private devices with additional work profile (BYOD)
In order to be able to distinguish private from business apps, the app Android Device Policy is required.
On private devices in which only the work profile is managed by an organisation - and thus by the Securepoint Mobile Security Profile - this app must be installed manually from the Android App Store.
With this app the registration token is scanned or entered via the keyboard and the devices can be registered and configured in the portal.
- Installing the app Android Device Policy from the Google App Store
- Scanning the QR code or entering the registration token via the keyboard
- A work profile is created on the device for the Enterprise profile.
- All configured applications, restrictions etc. are created and applied within the work profile.
| 1. | 2. | 3. |
| Abb.1 | Abb.2 | Abb.3 |
| Abbildungen | ||

- Switching on for the first time or device reset (factory settings)
- Country settings selection
- Tapping the display 7 times quickly opens a QR code scanner
- Scanning of the profile QR code (see above)
- A work profile is created on the device
- All configured apps, restrictions, etc. are created and applied within the work profile.
- Apps are displayed in the "Business area and marked with a suitcase icon
- A private Google account can be stored additionally
This step can also be done later- A private profile is created
- There is a separate area Private with its own playstore
Fully managed devices (COPE, Company Owned personal enabled) are connected directly to the Android Enterprise profile during initial setup or after a device reset. The link to a Google account and thus to an app store is defined by the assigned profile.
- Initial power-up or device reset (factory settings)
- Selection of regional settings
- Tap the display 7 times quickly to open a QR code scanner
- Scanning the profile QR code (see above)
- The device is configured as a fully managed device.
- All policies, apss and restrictions stored in the profile will be applied directly to the device
This process may take a few minutes during the initial installation!
- All policies, apss and restrictions stored in the profile will be applied directly to the device
| 1. | 2. | 3. |
| Abb.1 | Abb.2 | Abb.3 |
| Abbildungen | ||

7 quick taps on the display opens a QR code scanner
Devices with Android ≤ 9 (Pie) already require a temporary WLAN connection to load a QR code scanner.

Remove devices from Mobile Security management
Devices with working profile (BYOD)
Under / Delete in the respective device tile the administration can be removed from the devices:
- All apps and data within the work profile are wiped.
- The work profile on these devices is removed.
































































