Work profiles on fully managed devices (COPE) debuted with Android Oreo on the 21st of August, 2017. In the extortionate amount of time since then (highlighted above) there are still only a minute number of EMMs in the market which support this perfect middle-ground between the loss of control on work profile devices, and lack of support for personal use on fully managed devices.
With advancements in Android Enterprise solutions to date, in particular OEMConfig, the workload for EMM vendors today has in theory shrunk. OEMs like Samsung and Zebra have fully embraced OEMConfig, with the former recommending the adoption of Android Enterprise over legacy DA-period SAFE APIs.
Yet EMMs continue to lag behind, implementing Android’s universal APIs in dribs and drabs across the ecosystem, and providing a rather fragmented management experience for customers. COPE is just one such example.
MobileIron was the first to launch support for work profiles on fully managed devices with MobileIron Core 9.7 in early 2018. It would be several months before their other UEM, MobileIron Cloud, gained support in late 2018 with R58.
MobileIron’s implementation isn’t bad, but their approach in deciding how admins should be able to manage the parent profile (by limiting available restrictions) has been a point of contention from the beginning.
In late 2018 VMware also introduced support for COPE with version 1810.
VMware equally uniquely provision managed Google Play accounts in both the work and parent profiles, leading to the possibility in future of deploying applications to both profiles as opposed to the work profile only.
BlackBerry introduced COPE support with BlackBerry UEM 12.11, though if you thought work profiles on fully managed devices was a mouthful, BlackBerry opted bizarrely to call their’s Work and personal – full control activations for Android Enterprise devices.
Samsung introduced COPE support back in May-time 2019 for their Knox Manage EMM solution. Despite the name for anyone who is unfamiliar, Knox Manage supports Android (including non-Samsung), iOS and more.
Citrix introduced COPE support with Endpoint Management 20.1.0 and became the first UEM to declare support in 2020.
A particularly nice capability which all EMMs should support is the ability to Enterprise Wipe a COPE device without factory reset. Citrix supports this:
You can use the selective wipe security action to remove the work profile of a COPE device. After the selective wipe, you can either perform a full wipe on the device or re-enroll the device with the same user name. Re-enrolling the device recreates the work profile.
Other EMM/UEM vendors are working on supporting the solution – IBM, SOTI being two of the larger vendors. Intune and other vendors who rely on Google’s Android Management API are effectively stuck until Google support the deployment scenario.
As more vendors eventually support this two-year-old deployment scenario it will be updated here.