Guide · RubusNode

Android Enterprise Explained

Google's enterprise mobility program breaks down into a few core management modes. Here's what each one means and where it applies.

What Android Enterprise actually is

Android Enterprise is Google's official program for managing Android devices in an organizational context. It isn't a single feature — it's a set of management APIs, provisioning flows, and a dedicated managed Google Play instance that an MDM platform integrates with to apply enterprise controls to a device. Devices enrolled through Android Enterprise run apps and policy through this managed layer rather than a personal Google account.

An MDM platform doesn't build Android Enterprise itself; it becomes a Device Policy Controller (DPC) that talks to Android Enterprise's APIs on Google's behalf, requesting configuration changes, apps, and restrictions, and reading back device state.

The main management modes

Android Enterprise supports a few distinct ownership and management models, and picking the right one is the first real decision in an Android deployment:

  • Fully managed device — the entire device is under organizational control, typically for company-owned, company-issued hardware
  • Work profile — a separated, encrypted profile for organizational apps and data on an otherwise personal device (bring-your-own-device scenarios)
  • Dedicated device (COSU) — a fully managed device locked to one purpose, the mode kiosk and single-use deployments build on

Managed Google Play and app distribution

Android Enterprise devices get apps through managed Google Play, a private instance of the Play Store scoped to the organization. This is how private, internally built APKs get distributed without ever going through the public store, and how public apps can be approved, restricted, or configured centrally before they reach a device.

This distinction matters operationally: app approval, version control, and configuration push are managed-layer decisions, not something end users control on the device itself.

How RubusNode uses Android Enterprise

RubusNode manages GMS devices through the full Android Enterprise policy surface — fully managed and dedicated-device modes, managed app distribution, and policy baselines that map to Android Enterprise's own configuration model. Private APK distribution, staged app updates, and certificate and VPN profile delivery all run through this managed layer, alongside kiosk configuration for dedicated-device deployments.

Because Android Enterprise coverage depends on GMS being present on the device, RubusNode also manages Non-GMS and AOSP devices through a separate Device Owner path — so a mixed fleet doesn't have to choose one integration model for every device.

Why this distinction matters when evaluating a platform

A platform that says it "supports Android Enterprise" is really saying it implements some subset of fully managed, work profile, and dedicated-device modes through managed Google Play. Worth asking which modes, and what happens to devices that fall outside GMS availability — that's usually where Android Enterprise coverage alone stops being enough.

See RubusNode manage this in practice.

Book a walkthrough of the platform this guide describes.