Skip to content

QR code enrollment

You can enroll Android Enterprise fully managed devices by scanning a QR code during the device setup. Use this, for example, to prepare devices before deploying them to your users.

You can create different QR codes for user-assigned and user-less devices. User-less devices are Android Enterprise fully managed devices that you don't connect to an email account during enrollment. For details on user-less Android devices, see User-less Android devices.

Requirements

  • Create a task bundle for QR code enrollment. The task bundle must have an Assign policy task for an Android Enterprise device policy and must not have an Enroll task.
  • Turn on Use managed Google domain device enrollment in your Android Enterprise settings if any of the following conditions apply:

    • You registered your organization with Android Enterprise in managed Google domain mode before April 9, 2024.
    • You use federated sign-in as the Sophos Fusion sign-in method. See Sophos sign-in settings.

    For information on the Use managed Google domain device enrollment setting, see Managed Google domain device enrollment.

Set up QR code enrollment

Select the tab for the enrollment method you want to set up.

To set up QR code enrollment, do as follows:

  1. On the menu sidebar, select Setup > Google setup, and then select the QR code enrollment tab.
  2. Select Configure Android Enterprise QR code enrollment.
  3. Under Configure QR code, configure the settings for the device setup:

    • Enable system apps: On Android Enterprise fully managed devices, system apps with a launcher icon are disabled by default. Select this setting to keep all system apps enabled.
    • Language: The language of the Android user interface.
    • Wi-Fi settings: Select the security type of the Wi-Fi connection or select Don't configure Wi-Fi to configure no network in the QR code. In this case, users must manually connect to a Wi-Fi network when they set up the device.
    • Wi-Fi SSID: The ID of the Wi-Fi network.
    • SSID is hidden: Select this if the Wi-Fi network is hidden.
    • Wi-Fi password: The password for the Wi-Fi network.
    • Use cellular network: If the Wi-Fi connection is unavailable or you selected Don't configure Wi-Fi, the device uses its cellular data connection for enrollment.
  4. Under Configure enrollment, configure how Sophos Mobile manages the device:

    • Task bundle: The task bundle transferred to the device.
    • Device group: The device group devices are assigned to.
  5. Optionally, click Print to print the QR code. This lets you enroll devices when you don't have access to Sophos Mobile Admin.

To set up QR code enrollment for user-less devices, do as follows:

  1. On the menu sidebar, select Setup > Google setup, and then select the QR code enrollment (user-less) tab.
  2. Select Configure Android Enterprise QR code enrollment for user-less devices.
  3. Under Configure QR code, configure the settings for the device setup:

    • Enable system apps: On Android Enterprise fully managed devices, system apps with a launcher icon are disabled by default. Select this setting to keep all system apps enabled.
    • Language: The language of the Android user interface.
    • Wi-Fi settings: Select the security type of the Wi-Fi connection or select Don't configure Wi-Fi to configure no network in the QR code. In this case, users must manually connect to a Wi-Fi network when they set up the device.
    • Wi-Fi SSID: The ID of the Wi-Fi network.
    • SSID is hidden: Select this if the Wi-Fi network is hidden.
    • Wi-Fi password: The password for the Wi-Fi network.
    • Use cellular network: If the Wi-Fi connection is unavailable or you selected Don't configure Wi-Fi, the device uses its cellular data connection for enrollment.
  4. Under Configure enrollment, configure how Sophos Mobile manages the device:

    • Task bundle: The task bundle transferred to the device.
    • Device group: The device group devices are assigned to.
  5. Optionally, click Print to print the QR code. This lets you enroll devices when you don't have access to Sophos Mobile Admin.

You can enroll all devices with the same QR code.

You can revoke the QR code to prevent future enrollments. The code is also revoked when you create a new one.