Managing Android devices using Microsoft Intune
The error indicates that the current enrollment method and profile type are not allowed for this device scenario.
Key points from the scenario and context:
- The profile created is Corporate-owned, fully managed (COBO).
- The error on the device is “Can’t set up work profile. Your IT admin doesn’t allow a work profile on this device.”
- Fully managed and corporate-owned with work profile (COPE) devices use Android Enterprise corporate enrollment methods (QR code, Zero Touch, Knox, NFC, token) and require the device to be in a supported, factory-reset state.
Based on the provided documentation, use these checks and steps:
- Confirm the correct Android Enterprise enrollment type
- Fully managed (COBO), dedicated (COSU), and corporate-owned with work profile (COPE) all use the Android Enterprise corporate enrollment flow (QR code, Zero Touch, etc.).
- BYOD work profile enrollment (via Company Portal from Google Play) is different and uses a personally owned work profile flow.
- Ensure the Lenovo tablet is being enrolled using the corporate-owned fully managed method (QR code at setup) and not the BYOD work profile method.
- Verify the device is in a supported and clean state
- For Android Enterprise corporate-owned scenarios, the device must be factory reset before enrollment. This was done, but verify that enrollment is started immediately from the out-of-box setup using the QR code method, not after completing setup and then installing Company Portal.
- Do not restart the device during enrollment. The documentation notes that restarting fully managed or corporate-owned devices with work profile during enrollment can cause devices to appear enrolled but not properly register with Intune.
- Use the correct enrollment flow for the scenario
- For corporate-owned fully managed devices: start from the factory-reset screen and use one of the supported methods (QR code, Zero Touch, Knox, NFC, or token entry) as described for Android Enterprise dedicated/fully managed/corporate-owned with work profile devices.
- Avoid manually copying the URL into Chrome and trying to launch the app outside the guided setup; the Android setup process uses a Chrome tab to authenticate during enrollment and must follow the designed flow.
- Check Conditional Access configuration
- If there is a Microsoft Entra Conditional Access policy that:
- Requires devices to be marked as compliant, or
- Blocks access,
- And applies to All cloud apps, Android, and Browsers, then exclude the Microsoft Intune cloud app from this policy. The Android setup process uses a Chrome tab for user authentication during enrollment, and blocking this can prevent proper work profile or fully managed setup.
- If there is a Microsoft Entra Conditional Access policy that:
- If using BYOD work profile instead of corporate-owned
- If the intent is to enroll the Lenovo tablet as a personally owned device with a work profile, then:
- Install the Company Portal app from Google Play.
- Sign in with organization credentials.
- Follow the BYOD work profile enrollment steps.
- In that case, ensure that Android Enterprise personally owned work profile enrollment is allowed in Intune platform restrictions and that no policy is blocking work profiles on Android.
- If the intent is to enroll the Lenovo tablet as a personally owned device with a work profile, then:
- General troubleshooting
- Confirm that Android enrollment is enabled in Intune and that the tenant is configured according to the Android enrollment guide.
- If the device appears partially enrolled or stuck, perform another factory reset and repeat the correct enrollment flow from the beginning, ensuring no restarts during enrollment.
If the problem persists after confirming the correct enrollment type, supported state, and Conditional Access configuration, collect logs from the Intune/Company Portal app and use Troubleshooting + Support in the Intune admin center to investigate further.
References: