How AirWatch handles Android Enterprise work profiles
AirWatch, now operating as part of the VMware family, sits at the centre of enterprise mobility for thousands of Australian organisations, from mining operators in the Pilbara to financial firms in Sydney's Barangaroo precinct. Android remains the dominant mobile operating system across the local market, so the way an EMM platform handles work profiles often determines whether a strategy succeeds. Understanding how AirWatch interprets and enforces the Android Enterprise framework gives administrators a clear path to balancing user freedom with corporate governance.
Work profiles are the cornerstone of bring-your-own-device programs and many company-owned schemes alike, and AirWatch has built deep tooling around them. From the moment a device enrolls, the console begins separating personal apps from managed resources, applying policies, and pushing the configuration that keeps regulated data inside a controlled boundary. The platform's maturity in this area is one reason IT teams in Brisbane, Melbourne, and Adelaide continue to standardise on it.
What Android Enterprise work profiles actually do
A work profile is a separate, encrypted container on a supported Android device that isolates business apps, data, and accounts from the personal side. Google introduced the framework to replace the older device administrator model, and today it underpins most modern BYOD rollouts. Within that container, the EMM console enforces app whitelists, restricts copy-paste between work and personal apps, blocks screenshots in sensitive flows, and routes traffic through corporate proxies when required.
AirWatch treats the work profile as a first-class managed object. The console exposes a dedicated payload group with toggles for required apps, system updates, and the badge that visually distinguishes work icons. Administrators can choose whether the profile is set up on employee-owned hardware, on a corporate device in dual-persona mode, or alongside a fully managed device, with each scenario generating a different set of restrictions.
Because Australian employers frequently ask staff to use their own phones for work email, rosters, and clinical tools, the work profile answer is usually more palatable than issuing a second handset. The container approach aligns with guidance from the Office of the Australian Information Commissioner, which expects organisations to apply least-privilege controls when personal and work data coexist on a single device.
Enrollment paths and identity binding
AirWatch supports several Android Enterprise enrollment flows, each affecting how the work profile behaves. For BYOD, the user installs the Intelligent Hub, authenticates with corporate credentials, and accepts the work profile creation in a single guided flow. For company-owned devices, AirWatch can use a QR code, zero-touch enrollment, or Knox Mobile Enrollment to provision a device straight out of the box, then apply the work profile on top of a fully managed container.
Identity binding sits at the heart of this process. The console ties each work profile to a directory object in Active Directory, Entra ID, or Workspace ONE Access, so when an employee leaves or changes role in a Sydney law firm, for example, the removal of that directory entry instantly triggers de-provisioning. Certificates are issued for Wi-Fi, VPN, and single sign-on, and the same identity is reused across iOS, Windows, and ChromeOS without reconfiguration.
For field staff working in regional Queensland or Western Australia where connectivity is patchy, AirWatch supports offline enrollment via staged bundles. The agent caches the configuration, applies it when the device next syncs, and reconciles any drift once back online, which is critical for utilities and local councils that rotate between metro and remote sites.
Securing corporate data in the container
Security is where the work profile pays for itself, and AirWatch layers its own defences on top of Android's native isolation. The Data Loss Prevention module can block the forwarding of work email to personal accounts, prevent the saving of attachments to local storage, and force work files to open only in managed applications such as Workspace ONE Boxer or Content. DLP rules can be tailored by compliance posture, device health, or geofence, useful for legal teams under Australian privacy law.
The console also exposes network and access controls that apply only inside the profile. Administrators can route work traffic through an internal gateway, mandate per-app VPN tunnels, and require screen lock to a defined timeout. When a device is lost in transit, whether on a flight into Perth or in a rideshare across the Inner West, a selective wipe removes the work profile and its contents while leaving personal photos, contacts, and messages untouched.
For regulated industries, AirWatch integrates with VMware's compliance engine to assess device posture continuously. Jailbroken or rooted devices, outdated security patches, and USB debugging flags all generate compliance events that can quarantine the profile or revoke access to sensitive resources. The platform's reporting feeds into SIEM tools that many Australian SOCs already operate, making it easier to demonstrate accountability under the Notifiable Data Breaches scheme.
Supporting the BYOD culture in Australia
BYOD uptake in Australia is well above the global average, partly because employees value the choice of handset and partly because the technology sector, healthcare networks, and professional services have normalised the practice. AirWatch accommodates this cultural reality by keeping the work profile footprint small and unobtrusive. A worker in a Melbourne hospital can use their personal device for podcasts and family chats while the same device quietly runs clinical messaging, rostering, and electronic medical record apps inside a hardened container.
The platform also addresses the financial reality of reimbursing mobile costs. AirWatch can split billing telemetry into work and personal buckets, allowing payroll teams to reimburse the corporate portion without scrutinising personal usage. This single feature often determines whether BYOD policies are accepted, particularly in unionised environments governed by enterprise agreements.
Crucially, AirWatch's privacy notices and consent flows are translatable, and the console respects the worker's right to remove the profile at any time. When that happens, the personal device is left intact and the corporate wipe only touches managed data, which mirrors the protective stance expected under the Privacy Act 1988 and helps HR teams in Perth, Canberra, and Hobart defend the program to staff.
App management and the Managed Google Play store
Distributing software inside a work profile without handing over full device control is a fine art, and AirWatch has refined its approach over several Android Enterprise releases. Administrators curate a private app catalogue through the Managed Google Play iframe embedded directly in the Workspace ONE console, and they can approve public apps, push private line-of-business apps, and synchronise licensing through the same view.
App configuration policies replace the older SDK wrapping approach, and AirWatch generates per-app delivery records that simplify audits. For example, a Brisbane retail chain can deploy a point-of-sale app, push its store-specific configuration through a single payload, and revoke access instantly if a tablet is reassigned between stores. A national logistics operator can distribute a driver workflow app with maps, signature capture, and barcode scanning, configured to launch when a user signs in.
Updates flow through the same console, and administrators can defer non-critical upgrades or force critical security patches when a vulnerability is disclosed. This balance of autonomy and control is particularly valuable in industries such as aged care, where a missed update can disrupt medication rounds and trigger a clinical incident.
Compliance, reporting, and integration
AirWatch surfaces work profile telemetry in dashboards that map neatly to the controls an Australian CIO or CISO needs to evidence. The console shows enrollment counts, compliance status, OS patch levels, app inventory, and DLP events, all exportable for board reports or regulator requests. Pre-built report templates cover frameworks such as the Australian Government Information Security Manual, which many public sector bodies and contractors reference.
Integration with the wider VMware ecosystem extends the value of the work profile considerably. Identity federation through Workspace ONE Access means the same login used for a Windows virtual desktop works for an Android work profile app. VMware SD-WAN lets Adelaide or Townsville branch offices steer work traffic without re-tunnelling through head office. And the Carbon Black security stack can inspect work profile traffic for malware, giving SOC analysts a single pane of glass across endpoints and workloads.
For organisations pursuing a unified endpoint strategy, AirWatch also coordinates with Apple Business Manager, Windows Autopilot, and ChromeOS enrollment, so the work profile on Android sits alongside equivalent constructs elsewhere. The result is a consistent management grammar that simplifies life for stretched IT teams in fast-growing mid-market firms across the country.
Comparing work profile deployment modes
The comparison below summarises the main deployment shapes that AirWatch supports for Android Enterprise, and where each is most useful in an Australian context.
| Deployment mode | Device ownership | Profile boundary | Typical Australian use case | Wipe behaviour on exit |
|---|---|---|---|---|
| Work profile only | BYOD | Single container, badge visible | Professional services, healthcare, education | Removes work profile only |
| Work profile on company-owned device | Corporate, light personal use | Work container on managed device | Retail, hospitality, field sales | Removes work profile, device stays managed |
| Fully managed device | Corporate | Whole device under IT control | Mining, transport, frontline operations | Full device wipe |
| Dedicated device / kiosk | Corporate, single purpose | Single app or app group locked down | Warehousing, logistics, clinical carts | Full device wipe or app restart |
Administrators usually start with work profile only for BYOD populations, add the company-owned variant for shared kit, and reserve fully managed and dedicated modes for frontline roles where the device is effectively a tool of the trade.
Put a work profile strategy into practice with a fully functional 30-day free trial of AirWatch, compare the available packages side by side, or speak with the local sales team to map a rollout to the realities of your Australian workforce.