# Android Enrollment

> Enroll Android devices in CapaOne through Android Enterprise, from linking your account to getting devices managed.

Source: https://docs.capaone.com/capaone/enrollment/android-enrollment/  
Product: CapaOne — a separate CapaSystems product; do not apply this page to any other.

Android devices are managed through **Android Enterprise**. If you just want to get devices
enrolled, this article guides you through everything you need. If you want a deeper understanding
of what Android Enterprise is, how the account settings work, and what the GDPR contact fields
mean, see [Android Enterprise Setup](/capaone/mobile-manager/android/android-enterprise-setup/).

## Link your Android Enterprise account

The first time you open **Android → Enrollment**, CapaOne guides you through a one-time setup that
registers your organization with Managed Google Play:

![Android Enterprise setup](/attachments/capaone/android-enterprise-setup.png)

1. Click **Link to Google account**.
2. Sign in with a company Google account.
3. Click **Get started** on the **Bring Android to Work** page.
4. Enter a business name and details about your key contacts.
5. Read and agree to the Managed Google Play agreement, then confirm and complete registration.

## Management modes

An Android enrollment configuration defines how the device is managed:

- **Fully managed device** — company-owned devices used exclusively for work. The device must be
  factory reset or fresh out of the box, and is enrolled during initial device setup.
- **Managed work profile** — for personally owned devices (BYOD). Corporate apps and data live in a
  separate work profile; the user's personal apps and data stay private.

## Enrollment methods

Open a configuration with **View** to access the enrollment methods, shown as tabs:

- **QR code** — on a company-owned device, tap the welcome screen six times to launch the QR
  reader and scan the code. On a personally owned device, install the
  [Android Device Policy](https://play.google.com/store/apps/details?id=com.google.android.apps.work.clouddpc)
  app and scan the code from there.
- **Token** — on a company-owned device, enter `afw#setup` on the Google sign-in screen during
  setup, then enter the enrollment token manually. On a personally owned device, enter the token in
  the Android Device Policy app.
- **Zero Touch** — for zero-touch compatible devices: create a configuration in the
  [zero-touch portal](https://partner.android.com/zerotouch) with **Android Device Policy** as the
  EMM DPC, and paste the JSON snippet from CapaOne into the **DPC extras** field. Assigned devices
  enroll automatically out of the box.
- **Samsung Knox** — create a profile in the
  [Knox Mobile Enrollment portal](https://central.samsungknox.com/itadmin/kme/profiles) using the
  same JSON snippet, and assign it to your Samsung devices.

:::note
Enrollment configurations can have an expiration date and can be marked **one-time only** (the QR
code or token works for a single device, which rules out Zero Touch and Samsung Knox). A
configuration can also enforce **Microsoft** or **Google** user authentication during enrollment;
Microsoft authentication requires the
[Entra ID integration](/capaone/integrations/integrate-capaone-with-entra-id/).
:::

Once enrolled, the device appears under **Android → Endpoints** with the groups, configurations,
and applications from the enrollment configuration applied. See
[Mobile Manager](/capaone/mobile-manager/) for app and configuration management.
