When a user can't get a work profile on their personal Android phone, the message on screen rarely tells you which of half a dozen dependencies is missing. In this post I'll go through the checklist in the order I'd work it, covering both the newer web-based enrollment and the older Company Portal flow, and finish with how to collect logs before you escalate.
Symptoms#
- Enrollment stops because a work profile can't be created on the device.
- The user is told the device isn't allowed to enroll, or sees
DeviceCapReachedor Company Portal Temporarily Unavailable. - Browser-based enrollment stalls, or users land in the old Company Portal flow when you expected web enrollment.
- Re-enrolling a device that already has a work profile ends in an error.
Why it happens#
A personally owned work profile enrollment only succeeds when the tenant, the user and the device all line up: the tenant is connected to Managed Google Play, the enrollment profile and restrictions allow it, the user is licensed, and the device is supported and doesn't already carry a conflicting profile.
The enrollment method itself changed in 2026. Intune is moving personally owned work profiles to Google's Android Management API, which brings a browser-based flow:
| Method | How users start | Status |
|---|---|---|
| Web-based enrollment (Android Management API) | aka.ms/enrollmyandroid, a prompt in Teams or Outlook, or the Company Portal app | Default for new tenants; Company Portal isn't needed to enroll |
| Company Portal app (custom DPC) | Install Company Portal from Google Play and sign in | Being phased out |
How to fix it#
1. Confirm the Managed Google Play connection#
In the Microsoft Intune admin center, go to Devices › Device onboarding › Enrollment, select the Android tab and open Managed Google Play under Prerequisites. It should show an active connection; without it, no Android Enterprise enrollment works. A Last sync time that hasn't moved for days is expected, because you trigger that sync manually.
2. Review the enrollment profile#
On the same tab, open Personally owned devices with a work profile. When Use web enrollment for all users enrolling into Android personally owned work profile management is selected, users get the browser flow. Before you tick it, know three things: it's tenant-wide and can't be reversed, tenants where passkeys are the only accepted sign-in method shouldn't enable it yet, and Company Portal versions older than 2604.x still send users into app-based enrollment.
3. Check device platform restrictions#
Go to Devices › Device onboarding › Enrollment › Device platform restriction and select Android restrictions. For the restriction that actually applies to the user, confirm:
- Android Enterprise (work profile) platform is set to Allow.
- Personally owned is set to Allow.
- Any minimum or maximum OS version uses the
major.minor.rev.buildformat and doesn't exclude the device. Version limits are only enforced for Company Portal enrollments. - The manufacturer isn't in the blocked manufacturers list.
If the error is DeviceCapReached, check the device limit restriction too (1 to 15 devices per user).
Watch out: setting Personally owned to Block doesn't apply to Android Management API devices and isn't reliable on Android 12 and later with custom DPC. To control who can enroll, block work profile enrollment for everyone and add a higher-priority restriction that allows an approved group.
4. Check the licence and group membership#
Open Troubleshooting + support › Troubleshoot, select the user and confirm the Intune licence shows a green check. If you only just added the user to a group used by a restriction, wait 15 minutes or so; group and filter processing isn't instant.
5. Check the device#
- Intune supports Android 10 and later for personally owned work profiles. The device needs Google Mobile Services, Play Protect certification, and a country or region where Android Enterprise is available.
- Enrollment must happen in the primary user account, not a secondary user. Android 15's private space isn't supported.
- Google Play services should be up to date.
- Look for an existing work profile under Settings › Passwords & accounts › Work (the location varies by manufacturer). Remove a leftover profile from another MDM first. If it's from an earlier Intune enrollment, retiring the old device record removes the work profile and leaves the phone ready to enroll again.
- Still suspect the hardware? Install Google's Test DPC app and try to create a sample work profile. If that fails too, the manufacturer has to answer for work profile support.
Encryption being enforced during setup is normal: Google requires it to create a work profile.
6. Use a supported browser or app#
Web enrollment needs Chrome, Edge or Samsung's browser, and users should skip the browser's offer to add their work account. For app-based enrollment, Company Portal should come from Google Play and be current. Users who already have an older work profile and get a re-enroll prompt should open Outlook or Teams inside the work profile instead.
7. Collect logs if it still fails#
- Company Portal: turn on verbose logging, then open the menu and go to Help › Send logs (or tap HELP on the error) and choose SEND LOGS, THEN EMAIL. The email subject carries the incident ID.
- Microsoft Intune app on web-enrolled devices: Menu › Help › Get Support › UPLOAD LOGS, then EMAIL.
Keep the incident ID; Microsoft Support can use it to find the uploaded logs if you open a case.
Verify the fix#
- The device appears under Devices › All devices with ownership Personal.
- On the phone, work apps carry a briefcase badge. Web-enrolled devices show both the Microsoft Intune app and Company Portal inside the work profile.
- If you're migrating existing devices to the Android Management API, the Personal Devices on Android Management API report shows them reaching the AMAPI state.
Prevent it next time#
- Pilot web enrollment in a test tenant first, because switching it on is a one-way change.
- Control enrollment with group-based restrictions rather than the personally owned toggle.
- Enforce OS minimums with a compliance policy as well, since enrollment version limits only cover Company Portal enrollments.
- Give users one clear entry point, such as
aka.ms/enrollmyandroid, and update your helpdesk notes.