Android Enterprise EMM COPE support

The future of COPE

How Android Enterprise implements COPE is changing, requiring all of the below EMMs who’ve worked to bring support for the solution set to market to rework COPE support once more from Android 11. Read more

Work profiles on fully managed devices (COPE) debuted with Android Oreo on the 21st of August, 2017. In the extortionate amount of time since then there are still a number of EMMs in the market which do not support this perfect middle-ground between the loss of control on work profile devices, and lack of support for personal use on fully managed devices.

With advancements in Android Enterprise solutions to date, in particular OEMConfig, the workload for EMM vendors today has in theory shrunk. OEMs like Samsung and Zebra have fully embraced OEMConfig, with the former recommending the adoption of Android Enterprise over legacy DA-period SAFE APIs.

Yet EMMs continue to lag behind, implementing Android’s universal APIs in dribs and drabs across the ecosystem, and providing a rather fragmented management experience for customers. COPE is just one such example.

Who supports COPE today?

MobileIron – 2018

MobileIron was the first to launch support for work profiles on fully managed devices with MobileIron Core 9.7 in early 2018. It would be several months before their other UEM, MobileIron Cloud, gained support in late 2018 with R58.

MobileIron’s implementation isn’t bad, but their approach in deciding how admins should be able to manage the parent profile (by limiting available restrictions) has been a point of contention from the beginning.

VMware Workspace ONE UEM (AirWatch) – 2018

In late 2018 VMware also introduced support for COPE with version 1810.

VMware equally uniquely provision managed Google Play accounts in both the work and parent profiles, leading to the possibility in future of deploying applications to both profiles as opposed to the work profile only.

BlackBerry UEM – 2019

BlackBerry introduced COPE support with BlackBerry UEM 12.11, though if you thought work profiles on fully managed devices was a mouthful, BlackBerry opted bizarrely to call their’s Work and personal – full control activations for Android Enterprise devices.

Samsung Knox Manage – 2019

Samsung introduced COPE support back in May-time 2019 for their Knox Manage EMM solution. Despite the name for anyone who is unfamiliar, Knox Manage supports Android (including non-Samsung), iOS and more.

Citrix Endpoint Management – 2020

Citrix introduced COPE support with Endpoint Management 20.1.0 and became the first UEM to declare support in 2020.

A particularly nice capability which all EMMs should support is the ability to Enterprise Wipe a COPE device without factory reset. Citrix supports this:

You can use the selective wipe security action to remove the work profile of a COPE device. After the selective wipe, you can either perform a full wipe on the device or re-enroll the device with the same user name. Re-enrolling the device recreates the work profile.

And everyone else?

Other EMM/UEM vendors are working on supporting the solution – IBM, SOTI being two of the larger vendors. Intune and other vendors who rely on Google’s Android Management API are effectively stuck until Google support the deployment scenario.

As more vendors eventually support this two-year-old deployment scenario it will be updated here.

Comments

There are no comments on Discuss yet, click below to leave one:

Comment