User-less Android devices
With the QR code and Zero-touch enrollment methods, you can enroll user-less Android Enterprise devices such as kiosk devices.
Requirements
- You registered your organization with Android Enterprise.
- If you registered your organization with Android Enterprise in managed Google domain mode before April 9, 2024, you must turn on Use managed Google domain device enrollment in your Android Enterprise settings. See Managed Google domain device enrollment.
- For user-less QR code enrollment, you created a task bundle for QR code enrollment. The task bundle must have an Assign policy task for an Android Enterprise device policy and must not have an Enroll task.
User-less devices are Android Enterprise fully managed devices that you don't connect to an email account during enrollment. Sophos Mobile doesn't assign a user to the device. If required, you can manually assign a user later. See Assign a user to a device.
Although there's no email account connected to the device, Google assigns an internal user account. You see the account ID on the device's Internal properties tab.
The name of the property depends on the device's enrollment mode:
- Managed Google domain:
android.enterprise.bte.userless-device.account-id - Managed Google Play Account:
afw_play_emm_managed_device_account_user_id
For general information on internal device properties, see Internal properties.
See the sections below for configuring user-less device enrollment.
QR code enrollment
QR code enrollment lets you create different QR codes for user-assigned and user-less devices. To configure user-less QR code enrollment, go to Setup > Google setup > QR code enrollment (user-less). For details, see User-less QR code enrollment.
Zero-touch enrollment
When setting up Zero-touch enrollment, you must decide whether to enroll user-assigned or user-less devices. You do this with the User authentication checkbox on the Zero-touch tab. For details, see Set up zero-touch enrollment.