Lenovo Idea Tab Plus device

JO 0 Reputation points
2026-05-28T17:59:40.6833333+00:00

Unable to enroll "Lenovo Idea Tab Plus" tablet into Microsoft Intune. Steps I completed:

  1. Created a Corporate-owned, fully managed device profile.
  2. Factory reset device.
  3. Scanned QR code, it did not automatically enroll.

I copied the URL into Chrome...App downloaded and installed, but will not launch.

Message: Can’t set up work profile.  Your IT admin doesn’t allow a work profile on this device.

Can you suggest troubleshooting steps?

Microsoft Security | Intune | Microsoft Intune Android
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-05-28T18:00:05.7933333+00:00

    The error indicates that the current enrollment method and profile type are not allowed for this device scenario.

    Key points from the scenario and context:

    1. The profile created is Corporate-owned, fully managed (COBO).
    2. The error on the device is “Can’t set up work profile. Your IT admin doesn’t allow a work profile on this device.”
    3. Fully managed and corporate-owned with work profile (COPE) devices use Android Enterprise corporate enrollment methods (QR code, Zero Touch, Knox, NFC, token) and require the device to be in a supported, factory-reset state.

    Based on the provided documentation, use these checks and steps:

    1. Confirm the correct Android Enterprise enrollment type
      • Fully managed (COBO), dedicated (COSU), and corporate-owned with work profile (COPE) all use the Android Enterprise corporate enrollment flow (QR code, Zero Touch, etc.).
      • BYOD work profile enrollment (via Company Portal from Google Play) is different and uses a personally owned work profile flow.
      • Ensure the Lenovo tablet is being enrolled using the corporate-owned fully managed method (QR code at setup) and not the BYOD work profile method.
    2. Verify the device is in a supported and clean state
      • For Android Enterprise corporate-owned scenarios, the device must be factory reset before enrollment. This was done, but verify that enrollment is started immediately from the out-of-box setup using the QR code method, not after completing setup and then installing Company Portal.
      • Do not restart the device during enrollment. The documentation notes that restarting fully managed or corporate-owned devices with work profile during enrollment can cause devices to appear enrolled but not properly register with Intune.
    3. Use the correct enrollment flow for the scenario
      • For corporate-owned fully managed devices: start from the factory-reset screen and use one of the supported methods (QR code, Zero Touch, Knox, NFC, or token entry) as described for Android Enterprise dedicated/fully managed/corporate-owned with work profile devices.
      • Avoid manually copying the URL into Chrome and trying to launch the app outside the guided setup; the Android setup process uses a Chrome tab to authenticate during enrollment and must follow the designed flow.
    4. Check Conditional Access configuration
      • If there is a Microsoft Entra Conditional Access policy that:
        • Requires devices to be marked as compliant, or
        • Blocks access,
        • And applies to All cloud apps, Android, and Browsers, then exclude the Microsoft Intune cloud app from this policy. The Android setup process uses a Chrome tab for user authentication during enrollment, and blocking this can prevent proper work profile or fully managed setup.
    5. If using BYOD work profile instead of corporate-owned
      • If the intent is to enroll the Lenovo tablet as a personally owned device with a work profile, then:
        • Install the Company Portal app from Google Play.
        • Sign in with organization credentials.
        • Follow the BYOD work profile enrollment steps.
      • In that case, ensure that Android Enterprise personally owned work profile enrollment is allowed in Intune platform restrictions and that no policy is blocking work profiles on Android.
    6. General troubleshooting
      • Confirm that Android enrollment is enabled in Intune and that the tenant is configured according to the Android enrollment guide.
      • If the device appears partially enrolled or stuck, perform another factory reset and repeat the correct enrollment flow from the beginning, ensuring no restarts during enrollment.

    If the problem persists after confirming the correct enrollment type, supported state, and Conditional Access configuration, collect logs from the Intune/Company Portal app and use Troubleshooting + Support in the Intune admin center to investigate further.


    References:

    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.