IntuneTroubleshooting

Android Enterprise work profile enrollment failures: what to check

A practical checklist for failed Android personally owned work profile enrollments: Managed Google Play, restrictions, licences, device requirements, existing profiles and logs.

When a user can't get a work profile on their personal Android phone, the message on screen rarely tells you which of half a dozen dependencies is missing. In this post I'll go through the checklist in the order I'd work it, covering both the newer web-based enrollment and the older Company Portal flow, and finish with how to collect logs before you escalate.

How this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Confirm the Managed Google Play connection; Review the enrollment profile; Check device platform restrictions; Check the licence and group membership; Check the device; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: Device onboarding › Enrollment, Help › Send logs, DeviceCapReached, aka.ms/enrollmyandroid, major.minor.rev.build.1Symptoms2Why it happens3How to fix it4Verify the fix5Prevent it nexttime1Confirm theManaged Goo…2Review theenrollment pr…3Check deviceplatform rest…4Check thelicence and gr…5Check thedevice+2 moreTOOLBOXDevice onboarding › EnrollmentHelp › Send logsDeviceCapReachedaka.ms/enrollmyandroidmajor.minor.rev.buildHow this guide is organised: Symptoms → Why it happens → How to fix it → Verify the fix → Prevent it next timeFlow diagram of the article's sections in reading order: 1. Symptoms. 2. Why it happens. 3. How to fix it (7 steps: Confirm the Managed Google Play connection; Review the enrollment profile; Check device platform restrictions; Check the licence and group membership; Check the device; and 2 more). 4. Verify the fix. 5. Prevent it next time. Toolbox: Device onboarding › Enrollment, Help › Send logs, DeviceCapReached, aka.ms/enrollmyandroid, major.minor.rev.build.1Symptoms2Why it happens3How to fix it1Confirm the Managed Google Play connection2Review the enrollment profile3Check device platform restrictions4Check the licence and group membership5Check the device+2 more4Verify the fix5Prevent it next timeTOOLBOXDevice onboarding › EnrollmentHelp › Send logsDeviceCapReachedaka.ms/enrollmyandroidmajor.minor.rev.build
At a glance: how this guide is organised · 7 fix steps · 5 key tools

Symptoms#

  • Enrollment stops because a work profile can't be created on the device.
  • The user is told the device isn't allowed to enroll, or sees DeviceCapReached or Company Portal Temporarily Unavailable.
  • Browser-based enrollment stalls, or users land in the old Company Portal flow when you expected web enrollment.
  • Re-enrolling a device that already has a work profile ends in an error.

Why it happens#

A personally owned work profile enrollment only succeeds when the tenant, the user and the device all line up: the tenant is connected to Managed Google Play, the enrollment profile and restrictions allow it, the user is licensed, and the device is supported and doesn't already carry a conflicting profile.

The enrollment method itself changed in 2026. Intune is moving personally owned work profiles to Google's Android Management API, which brings a browser-based flow:

MethodHow users startStatus
Web-based enrollment (Android Management API)aka.ms/enrollmyandroid, a prompt in Teams or Outlook, or the Company Portal appDefault for new tenants; Company Portal isn't needed to enroll
Company Portal app (custom DPC)Install Company Portal from Google Play and sign inBeing phased out

How to fix it#

1. Confirm the Managed Google Play connection#

In the Microsoft Intune admin center, go to Devices › Device onboarding › Enrollment, select the Android tab and open Managed Google Play under Prerequisites. It should show an active connection; without it, no Android Enterprise enrollment works. A Last sync time that hasn't moved for days is expected, because you trigger that sync manually.

2. Review the enrollment profile#

On the same tab, open Personally owned devices with a work profile. When Use web enrollment for all users enrolling into Android personally owned work profile management is selected, users get the browser flow. Before you tick it, know three things: it's tenant-wide and can't be reversed, tenants where passkeys are the only accepted sign-in method shouldn't enable it yet, and Company Portal versions older than 2604.x still send users into app-based enrollment.

3. Check device platform restrictions#

Go to Devices › Device onboarding › Enrollment › Device platform restriction and select Android restrictions. For the restriction that actually applies to the user, confirm:

  • Android Enterprise (work profile) platform is set to Allow.
  • Personally owned is set to Allow.
  • Any minimum or maximum OS version uses the major.minor.rev.build format and doesn't exclude the device. Version limits are only enforced for Company Portal enrollments.
  • The manufacturer isn't in the blocked manufacturers list.

If the error is DeviceCapReached, check the device limit restriction too (1 to 15 devices per user).

Watch out: setting Personally owned to Block doesn't apply to Android Management API devices and isn't reliable on Android 12 and later with custom DPC. To control who can enroll, block work profile enrollment for everyone and add a higher-priority restriction that allows an approved group.

4. Check the licence and group membership#

Open Troubleshooting + support › Troubleshoot, select the user and confirm the Intune licence shows a green check. If you only just added the user to a group used by a restriction, wait 15 minutes or so; group and filter processing isn't instant.

5. Check the device#

  • Intune supports Android 10 and later for personally owned work profiles. The device needs Google Mobile Services, Play Protect certification, and a country or region where Android Enterprise is available.
  • Enrollment must happen in the primary user account, not a secondary user. Android 15's private space isn't supported.
  • Google Play services should be up to date.
  • Look for an existing work profile under Settings › Passwords & accounts › Work (the location varies by manufacturer). Remove a leftover profile from another MDM first. If it's from an earlier Intune enrollment, retiring the old device record removes the work profile and leaves the phone ready to enroll again.
  • Still suspect the hardware? Install Google's Test DPC app and try to create a sample work profile. If that fails too, the manufacturer has to answer for work profile support.

Encryption being enforced during setup is normal: Google requires it to create a work profile.

6. Use a supported browser or app#

Web enrollment needs Chrome, Edge or Samsung's browser, and users should skip the browser's offer to add their work account. For app-based enrollment, Company Portal should come from Google Play and be current. Users who already have an older work profile and get a re-enroll prompt should open Outlook or Teams inside the work profile instead.

7. Collect logs if it still fails#

  • Company Portal: turn on verbose logging, then open the menu and go to Help › Send logs (or tap HELP on the error) and choose SEND LOGS, THEN EMAIL. The email subject carries the incident ID.
  • Microsoft Intune app on web-enrolled devices: Menu › Help › Get Support › UPLOAD LOGS, then EMAIL.

Keep the incident ID; Microsoft Support can use it to find the uploaded logs if you open a case.

Verify the fix#

  • The device appears under Devices › All devices with ownership Personal.
  • On the phone, work apps carry a briefcase badge. Web-enrolled devices show both the Microsoft Intune app and Company Portal inside the work profile.
  • If you're migrating existing devices to the Android Management API, the Personal Devices on Android Management API report shows them reaching the AMAPI state.

Prevent it next time#

  • Pilot web enrollment in a test tenant first, because switching it on is a one-way change.
  • Control enrollment with group-based restrictions rather than the personally owned toggle.
  • Enforce OS minimums with a compliance policy as well, since enrollment version limits only cover Company Portal enrollments.
  • Give users one clear entry point, such as aka.ms/enrollmyandroid, and update your helpdesk notes.

References#

Written and checked against current Microsoft Learn documentation. Test changes with a pilot group before rolling them out to everyone, and if an admin center path has moved since, search for the setting name instead.

Spotted a mistake, or did this fix work differently for you? Email me or message me on LinkedIn — corrections are credited in the article.

OE
Written by

Omer Eltayeb

Independent Microsoft Intune consultant in Cairo, Egypt, former Microsoft Cloud Solutions Architect, Microsoft Certified Trainer and Microsoft Innovative Educator Expert (2024–26) and Microsoft Elevate Educator Expert (2026–27). I share practical, step-by-step guides, study plans, scripts and toolkits for Microsoft Intune, Microsoft Entra ID, Microsoft Defender and Exchange Online with the community.

Microsoft Certified Trainer (MCT) 2026Microsoft Innovative Educator Expert 2025–2026Microsoft Elevate Educator Expert 2026–2027ISC2 Certified Information Systems Security Professional (CISSP)Microsoft 365 Certified: Enterprise Administrator Expert (MS-102)