Android zero-touch enrollment

Roll out corporate-owned Android devices at scale—no manual setup. With Codeproof + Android zero-touch, devices auto-provision on first boot and apply your apps, policies, and security in minutes.

What is zero-touch enrollment?

Zero-touch enrollment is Google’s streamlined provisioning flow for corporate-owned Android devices. When an employee powers on a zero-touch device for the first time, it automatically initiates enrollment, downloads the Codeproof MDM agent, and applies management profiles, required apps, and configuration—without user intervention.

Why teams choose Codeproof + zero-touch

  • Speed: Provision hundreds or thousands of devices in parallel—no QR codes, no manual steps.
  • Consistency: Every device receives the same baseline, apps, and restrictions from first boot.
  • Security: Enforce passcodes, encryption, Play Protect, app allow-lists/deny-lists, network/VPN, and more.
  • Resilience: Replacements and resets re-enroll automatically, reducing IT tickets and downtime.

Requirements & eligibility

  • Android 8.0 (Oreo) or later on supported, Google-certified devices.
  • Devices purchased through participating carriers/resellers and assigned in the zero-touch portal.
  • Network connectivity on first boot to reach Google enrollment and Codeproof services.

Supported deployment modes

  • Fully managed (work-only): Locked-down corporate device with full policy control.
  • Dedicated/Kiosk: Single-purpose or multi-app kiosk (POS, field device, digital signage).
  • Corporate-owned work profile (COPE): Corporate device with separate work/personal spaces (where supported).

How it works (end to end)

  1. Purchase: Order zero-touch-compatible devices from an authorized zero-touch reseller or carrier partner.
  2. Portal access: Codeproof (or your reseller/carrier) provisions your zero-touch customer portal and invites your admin users.
  3. Configure: In the portal, create/set the Codeproof MDM enrollment configuration (DPC) and default options (support info, network prompts, etc.).
  4. Assign: Apply that configuration to device IMEIs/serials (bulk upload or API).
  5. Unbox & power on: On first boot with Wi-Fi or cellular, the device detects its assignment and begins enrollment automatically.
  6. Auto-configure: Codeproof applies your policies, Wi-Fi/VPN, certificates, apps, and restrictions based on the assigned profile.
  7. Ready to work: The device appears in the Cyber Device Manager console, where you can push policies, apps, and manage it remotely.

Security highlights

  • Mandatory device passcode/biometric, encryption, and Play Integrity checks.
  • App allow-list/deny-list, Managed Google Play, silent installs/updates.
  • Network controls (Wi-Fi, APN/VPN), hotspot/Airdrop-like sharing restrictions, USB/debugging controls.
  • Lost/stolen workflows: remote lock, wipe, location (where enabled).
  • Factory Reset Protection (FRP) safeguards to prevent unauthorized reuse after reset.

Procurement & portal setup

Codeproof can work with your preferred reseller to set up the zero-touch portal, define default configurations, and associate devices at purchase so they’re ready to ship directly to end users.


Common use cases

  • Field services, logistics, public safety, healthcare, retail POS
  • Shared devices and kiosks with app pinning and usage restrictions
  • Rapid replacements—re-enroll automatically after a factory reset

What you’ll need to get started

  • List of IMEIs/serials for devices being purchased
  • Zero-touch portal access (via your reseller/Google account)
  • Codeproof tenant with Android policies, apps, and network profiles defined

FAQs

What is Android zero-touch?
Android zero-touch enrollment lets organizations preconfigure corporate-owned Android devices so they provision automatically on first boot with your chosen MDM/UEM and policies. It’s conceptually similar to Apple Business Manager’s Automated Device Enrollment (formerly DEP), Samsung Knox Mobile Enrollment (KME), and Windows Autopilot. Learn more.
What types of devices can be enrolled with Android zero-touch?
Devices must be Android 9.0+ (many Android 8.0 models and Pixel on 7.0 are also eligible) and purchased via an authorized zero-touch reseller from a participating manufacturer. The device must be GMS-certified with Google Play services enabled. Zero-touch supports fully managed (device owner), dedicated/kiosk, and work profile on company-owned devices. BYOD/personal devices aren’t eligible. Vendors and customers must comply with Google’s zero-touch Permissible Usage Policy.
Can I get access to the zero-touch portal?
Yes. Codeproof will create and configure your organization’s zero-touch customer portal and provide admin login access. We handle initial onboarding and can manage device assignments on your behalf.
What is the zero-touch customer portal?
The customer portal is Google’s web console for enterprise IT to view devices assigned to their company, set a default configuration (DPC/MDM app, options, support info), and apply or modify configurations that devices pull during setup. How it works.
What is the zero-touch vendor/reseller portal?
The reseller portal is used by authorized partners to upload device inventory (IMEIs/serials), assign devices to customer accounts, and create/invite customer admins. It also exposes APIs for automation. Reseller portal guide.
Who creates the customer portal account?
An authorized zero-touch device reseller such as Codeproof creates the customer account (and invites owner/admin emails) via the reseller portal or API (createCustomer). Customers then sign in with those invited Google accounts. API reference.
Does Codeproof offer Android zero-touch reseller/vendor accounts?
Yes. Codeproof is a Google-authorized Android Enterprise zero-touch reseller and can provide vendor/reseller sub-accounts to device partners. Vendors must comply with Google’s zero-touch Permissible Usage Policy. Learn more in our Android zero-touch enrollment guide.
Is enrollment over the air (OTA)?
Yes. Enrollment is OTA on first boot when the device has Wi-Fi or cellular connectivity and has been pre-assigned in the zero-touch portal.
What happens after a factory reset?
If the device remains assigned in the zero-touch portal, it will re-enroll automatically on first boot. Factory Reset Protection (FRP) can help prevent unauthorized reuse.
Does zero-touch work with BYOD?
Zero-touch is designed for corporate-owned devices. For BYOD, use an Android Work Profile to separate work and personal data.
Can we switch to kiosk mode?
Yes. After enrollment, the device appears in the Cyber Device Manager console. Open Policy Manager to enable single-app or multi-app kiosk mode and restrict system UI.

Maximize employee productivity through Codeproof