Step-by-Step Guide to Setting Up AirWatch for Android Devices

Managing Android smartphones and tablets across a business can become difficult when staff work from offices, warehouses, hospitals, shops and home networks. AirWatch, commonly associated with VMware Workspace ONE UEM, gives IT teams a central console for enrolling devices, applying security rules, distributing apps and protecting corporate information.

A well-planned Android deployment begins before anyone scans an enrolment code. The organisation needs to decide which employees, devices and applications belong in the initial rollout, then match the management mode to the way each device is used. A personal phone requires a different configuration from a company-owned warehouse scanner or delivery tablet.

Australian organisations also need to consider the Privacy Act, Australian Privacy Principles and industry-specific obligations. A business operating in Sydney may have different requirements from a regional Queensland service provider with intermittent connectivity. Clear policies help employees understand what the organisation can see and what remains private.

The steps below cover the main process, from preparing the AirWatch console to testing compliance and supporting users. Menu names can vary between AirWatch and Workspace ONE UEM releases, so use the terminology displayed in your tenant when following the workflow.

Prepare The AirWatch Environment

Start by confirming access to the AirWatch administration console and identifying the administrators who will manage Android endpoints. Create separate console roles where appropriate. A help-desk employee may need to troubleshoot devices, while a security administrator may need permission to change compliance policies. Limiting administrator rights reduces the risk of accidental changes.

Set up the organisation groups, smart groups and user accounts before enrolment begins. Organisation groups can separate business units, subsidiaries or locations, while smart groups allow profiles and applications to target users based on attributes such as department, ownership type or operating system version. For example, devices used by a Melbourne sales team can receive different applications from tablets assigned to a Brisbane warehouse.

Connect the identity service your organisation uses, such as Microsoft Entra ID or another directory platform. Configure authentication, conditional access and, where required, multi-factor authentication. Confirm that employee usernames and email addresses match the records used by AirWatch. Inconsistent identities often cause failed enrolments and duplicate user accounts.

Decide whether Android devices will use Android Enterprise. Modern deployments should generally use Android Enterprise work profiles, fully managed devices or corporate-owned work profile modes instead of older device administrator methods. Android Enterprise provides a clearer separation between business and personal information and supports stronger controls on company-owned hardware.

Choose Ownership And Enrolment Methods

The management mode should reflect device ownership and its business purpose. A work profile is suitable for a personally owned Android phone because it creates a managed container for business apps and data. The employee’s personal photos, messages and applications remain outside the work profile.

A fully managed configuration is designed for a company-owned device used exclusively for work. It allows the organisation to enforce settings across the entire device, block unapproved applications and control factory resets. Corporate-owned work profile mode is useful when the business owns the phone but permits some personal use.

Select an enrolment method that fits the scale of the rollout:

Before enrolling a fleet, verify that the reseller can associate zero-touch devices with the correct configuration and that the handsets support the required Android Enterprise features. Check coverage and logistics for staff in places such as regional Western Australia or the Northern Territory, where replacement devices may take longer to arrive.

Configure Profiles, Apps And Security

Create device profiles for password requirements, encryption, screen-lock timers, camera access, Bluetooth, Wi-Fi and mobile network settings. Avoid applying every available restriction immediately. A staged policy lets the IT team identify whether a setting interferes with essential work, such as barcode scanning, contactless payments or field-service software.

Configure Wi-Fi profiles with the correct network name, authentication type and certificate settings. For corporate networks, certificate-based authentication is preferable to distributing a shared password. Include mobile connectivity guidance for employees who regularly travel between metropolitan areas and regional sites, where network performance may vary across Telstra, Optus and Vodafone coverage areas.

Add required applications through managed Google Play. Approve business tools such as Microsoft 365, Teams, VPN clients, expense systems, line-of-business applications and secure browsers. Assign applications to smart groups rather than pushing every app to every user. This keeps the catalogue relevant and reduces mobile data consumption.

Security policies should include encryption, a screen lock, minimum Android versions and a response to compromised devices. Configure compliance rules to detect missing encryption, disabled security settings, outdated operating systems or signs of rooting. Decide whether a non-compliant device should receive a warning, lose access to corporate applications or be enterprise-wiped.

Deployment choice Suitable use Main control Australian workplace example
Work profile Personally owned phones Manages business data in a separate profile Staff using their own phones in a Sydney office
Fully managed Company-owned devices for work only Controls the complete device Tablets used for stocktake in a Melbourne warehouse
Corporate-owned work profile Company-owned phones with limited personal use Separates work and personal activity Phones issued to field technicians in regional Queensland
Dedicated device Single-purpose kiosk or frontline hardware Locks the device to approved apps Check-in tablets at a Perth clinic or reception desk
Zero-touch enrolment Large or remote deployments Automates initial provisioning Devices shipped directly to employees around Australia

Enrol And Test Android Devices

For a manual setup, reset the Android device if it has already been configured, connect it to a reliable Wi-Fi network and start the enrolment process. During the setup wizard, scan the AirWatch QR code or enter the supplied enrolment token. The device should install the Workspace ONE Intelligent Hub, contact the UEM console and apply the assigned profiles.

The exact sequence depends on the management mode. A work profile prompts the user to accept business management and creates a separate work area. A fully managed device applies organisation-wide settings during provisioning. Read each prompt carefully and confirm that the device is assigned to the correct user, organisation group and smart group.

After enrolment, check the console for the device record, ownership classification, operating system version, compliance state and last-seen time. On the handset, confirm that the work badge appears on managed applications and that the Intelligent Hub reports a healthy connection. Test app installation, Wi-Fi authentication, VPN access, email, printing and any specialist software used by the employee.

Use a small pilot group before a broad deployment. Include different handset models, Android versions and network conditions. A test group might contain office staff in Sydney, a travelling sales employee in Adelaide and a worker in regional New South Wales. This exposes compatibility and connectivity issues that a single office-based test may miss.

Protect Data And Support Users

Configure application security settings to control copy and paste, screenshots, data sharing and access from unmanaged applications. App-level protections can help prevent corporate files from moving into personal storage or consumer messaging apps. Balance these controls against genuine work requirements, especially for teams that need to share photos, documents or location information.

Create compliance actions that are easy to understand. An employee should receive a useful notification explaining what needs attention, such as an expired passcode or missing update. Escalation can then occur if the issue remains unresolved. Keep an audit record of policy changes, enrolment events, device wipes and administrator actions.

Privacy communication is essential for bring-your-own-device programmes. Explain what AirWatch can manage, which business details are visible to administrators and what information is excluded from monitoring. Under Australian privacy expectations, employees should receive a clear collection notice and know how device information is used. Personal devices should generally use a work profile rather than full-device management.

Prepare support procedures for lost or stolen devices. Administrators may need to lock a device, enterprise-wipe the work profile, revoke certificates or remove access tokens. A full factory reset should be reserved for company-owned hardware when authorised. Document the process and provide a simple reporting channel for employees, including staff working outside standard office hours.

Validate Compliance And Expand The Rollout

Review the pilot results in the AirWatch console before enrolling the wider fleet. Look for repeated errors involving Google Play, certificates, application licensing, battery usage or network access. Check whether compliance rules are creating false alerts and whether users can complete their daily work without bypassing security controls.

Create dashboards or reports for enrolment status, compliance, application versions and inactive devices. Schedule operating system updates where the business can tolerate them, while allowing time to test major Android releases. Some organisations may need to delay updates on specialist hardware until vendors certify compatibility.

Train administrators and employees with short, practical instructions. Show users how to open the work profile, install approved applications, report a lost phone and distinguish work notifications from personal ones. Plain language is especially helpful for a distributed workforce, from a Canberra office to a construction crew in Far North Queensland.

Once the deployment is stable, expand by department or location rather than enrolling every device at once. Review access rules, application assignments and privacy notices regularly. AirWatch can then become part of a broader endpoint management programme covering Android phones, rugged devices, tablets and other business endpoints.

A controlled setup gives Australian organisations stronger security without making everyday work unnecessarily difficult. Begin with the AirWatch or Workspace ONE UEM trial, define a small pilot group, configure Android Enterprise profiles and measure the results before scaling. A careful rollout protects company data, supports flexible working and gives employees a reliable way to use approved business services wherever they work.