Sophos Mobile: manage a personal Android device with a work profile
With Android Enterprise work profiles, Sophos Mobile manages apps, accounts, and data in the work area of a personal device. This procedure is only for Owner: Personal; it does not cover a company-owned device with a work profile (COPE), a fully managed company device, the standalone Mobile Threat Defense app, or the legacy Android Device Administrator method. Check the ownership and management mode of the specific device before taking any action.
Before enrollment
If ownership or management mode is unclear, first resolve the choice of mode for MDM and Threat Defense. Review location access, app inventory, and uploads as part of privacy and Data Lake approval; a work profile does not replace that decision.
- Android Enterprise must be configured in Sophos Mobile. The target device group and user must exist; depending on the Android Enterprise integration, the user is in Sophos Fusion or a Google Workspace/Cloud Identity account.
- The user first sets up the device with their personal Google account. Enrollment requires their participation on the device. Send the instructions and QR code only to the intended user.
- Agree with the user which business apps and data will go into the work profile. The organization can install or uninstall apps within the work profile without asking for confirmation again. Before removal, preserve business content through approved company channels; removing the profile deletes local work-profile data.
- Before obtaining consent on a personal device: In Setup > General > Privacy, check the actual settings for location access by administrators and users and for displaying installed apps, and discuss them with the user. Disabling location access hides the last location in Google Maps, but not in the Device location report; hidden installed apps may still appear in aggregated app reports. Hide installed apps also excludes the installed-app list from Sophos Mobile uploads to the Data Lake, if uploads are enabled. Sophos Mobile audits administrator and self-service location requests and changes to Privacy settings; confirm the actual tenant settings rather than assuming location or upload behavior. According to Sophos, Sophos Mobile Control does not request location permission when device finding is disabled in the Sophos Mobile privacy settings; otherwise, setup may request Allow all the time. It may also request permission to display over other apps and to run in the background. Do not present any permission as harmless by default: review the prompts shown, their purpose, and the agreed settings together on the device.
- Review Restrictions in the actually assigned work-profile policy with the user: allowing the work clipboard in personal apps and opening work links in a personal browser creates paths for data to cross between areas. Allowing work contacts for personal calls, on Bluetooth devices, and in personal-profile searches involves separate switches; the Sophos Outlook procedure below requires all three. This policy can also affect location services for work apps and Smart Lock (device lock). Test the effective settings and Android/device variant on a consenting test device before assigning the policy widely; do not assume either complete isolation or a particular tenant configuration.
- Do not treat separation as an absolute confidentiality guarantee: for example, if access to work contacts is enabled for personal apps, personal apps with contacts permission can look up work contacts. The documented Outlook feature does not automatically copy those contacts into the personal address book. Enable such access only after a privacy decision and testing on a device.
Set up the work profile
Prepare the policy, task bundle, and device record
- In Sophos Fusion > My Products > Mobile > Policies > Android, create a policy through Create > Android Enterprise work profile policy. On Edit policy, enter a name in Name; Description is optional. Open and review the automatically included Restrictions configuration, which cannot be deleted. Apply changes there with Apply, add and review any other configurations needed through Add configuration, then save the policy with Save. Do not enable access to work contacts for personal apps without a deliberate decision.
- Under Task bundles > Android > Create > Create task bundle, create a task bundle. On Edit task bundle, enter a name and, if needed, a description. Select Add task > Enroll. In the Select enrollment type wizard step, enter a name for the enrollment task in Task name, for example
Enroll, and select Work profile under Select enrollment type. Sophos Mobile shows this task name on Task details while processing it for a device. In the next step, Select policy, fill in that step’s own Task name field, for example withAssign policy, and choose the work-profile policy created earlier under Select policy. The two example names are freely chosen and help distinguish enrollment from policy assignment in the task view. Complete the wizard with Finish and save the bundle with Save. - Under Devices > Add > Add device wizard, choose Search for user in the User step. Enter search criteria in one or more of User name, First name, Last name, and Email address. In User selection, select the intended user from the results. In the Device details step, set Platform to Android and enter the device’s name in Sophos Mobile in Name. Description and Phone number are optional; enter any phone number in international format. Set Owner to Personal and select the target device group under Device group. Email address shows the selected user’s email as read-only. If the address is wrong, resolve the user assignment or user account rather than attempting to change it in this field. In the Enrollment type step, select Enroll device with task bundle under Select the enrollment type and choose the prepared bundle. Send the instructions displayed on Enrollment to the intended user, using Send to their email address if needed. Close the Add device wizard using X at the top right. Alternatively, wait until the device is enrolled, then select Finish. Closing the wizard does not replace the enrollment checks described below.
Enroll on the personal device
The user carries out the following steps on the device they have set up with their personal Google account. The English labels below follow the documented workflow. Pages may differ by device model and Android version; if a prompt is unclear, check with IT rather than choosing a different management mode.
- In personal Google Play, open Sophos Mobile Control and select Install.
- After installation, select Open.
- Use the enrollment details from the instructions provided for this device. Choose one of the two paths:
- For QR enrollment, select Scan QR code in the app, which is initially in the personal area. Deliberately approve the camera prompt for taking pictures with While using the app or Only this time, then scan the QR code from the enrollment instructions. This camera prompt belongs to the personal app during scanning, not to the later setup of the work app.
- For manual entry, open More, the three-dot icon at the top right, and select Enter manually. Enter the details from the enrollment instructions, select Create work profile, and choose Connect.
- Android starts the wizard to create the work profile and enroll Sophos Mobile Control. On Create work profile, select Next.
- Follow the Android wizard’s instructions. Carry out steps 6 to 8 only for managed Google domain device enrollment. For other enrollment types, go directly to step 9. For managed Google domain device enrollment, Google creates a token valid for one hour after the enrollment details are entered in step 3. According to Sophos, the following steps through step 9 must be completed within this window. Step 9 in the Sophos instructions is entering authentication details if requested; Enrollment completed follows only in step 10. The documented deadline therefore applies to step 9, not to this completion page.
- Only for managed Google domain device enrollment, Preparing enrollment appears after the work profile is created. This page may remain visible for several minutes. Do not close the app or switch off the device during this time. Otherwise, enrollment may fail and removing the work profile may be necessary before trying again. Do not initiate such removal without the approvals and data-loss checks described below.
- On Sign in with your work account, check the email address displayed for Google sign-in and select Next to open the sign-in page.
- On the sign-in page, select Next without changing the prefilled work email address. Changing it causes enrollment to fail; removing the work profile may be necessary before another attempt.
- If requested, enter the password or other authentication details.
- On Enrollment completed, select Next. Sophos Mobile Control then opens in the work profile. Complete its permissions wizard as described in the next section; the completion page alone does not replace this setup or subsequent verification.
Review and configure the work app’s permissions
Sophos describes the following paths for the Sophos Mobile Control app in the work profile. They may look different depending on the device and Android version. Before each confirmation, review the purpose, prompt shown, and privacy settings agreed above. If an expected option is missing or a prompt does not match the approval, check with IT rather than granting permissions across the board.
- In the Display over other apps message, select Allow. On the Work tab, open Sophos Mobile Control and enable Allow display over other apps. Go back several times until Sophos Mobile Control is displayed again.
- Configure Location only if the app actually requests this permission and location access has been approved. Sophos Mobile Control does not request it when device finding is disabled in the Sophos Mobile privacy settings. In the documented workflow, select Allow, then Open. Under Permissions > Location > Allow all the time, confirm continuous location access and go back several times until Sophos Mobile Control is displayed again. Do not grant this access simply because a work profile exists.
- For the requested background operation, select Stay protected in the Battery optimization message, then Allow. Afterwards, check the state of the work app; confirmation alone does not establish that the exception remains effective on every device.
After setup, there are initially two Sophos Mobile Control apps. Identify the work app by its briefcase icon. On Xiaomi devices, do not uninstall the original personal app for now. Sophos documents the known issue SMCAND-3244 for Android Enterprise work-profile enrollment. After the personal app is removed, the work-profile app may lose its battery optimization exception, with no way to add it again. Usage access can then no longer be enabled either. A previously working work app does not rule out this issue. Confirm the appropriate next steps with IT or Sophos Support, quoting SMCAND-3244 and KBA-000010171, even if the personal app has already been removed. Without a confirmed procedure, do not try reinstalling the app in the personal area as a blanket solution. For devices from other manufacturers, the rule still applies: Uninstall the original personal app only after the app in the work profile is working.
Check enrollment and compliance separately
In Sophos Mobile, open the device under Devices and check on the Tasks tab that all tasks have Successful status. Under Devices, Work profile mode and Managed status must be displayed. On the device, open the work app and check its server connection and status. If all tiles on its dashboard are green, the app reports the device as compliant, with no pending actions. Use the Management info tile to open the Sophos Mobile server details and check them against the intended server.
Green tiles show the app’s compliance state. They prove neither that all business apps have been deployed nor that privacy approval has been checked; task, mode, and device checks are still required. A failed or interrupted enrollment is not a reason to factory-reset the device; first investigate the task error and the actual profile state.
Check the personal area and work apps
For changes to data flows between the work and personal areas, review the work-profile policy and its Restrictions; the Outlook access described below is only a specific exception.
The user can find approved work apps in the Google Play Store with the briefcase icon. On the device, open this Play Store in the work profile, browse the apps approved for the device, and select the app you want to open its app page. There, select Install and follow the installation steps. The personal Play Store is not the same app catalog. The organization can also install or remove work apps itself; this does not automatically affect personal apps.
Looking up work contacts from personal apps is optional, not a standard feature of a work profile. For the Outlook procedure documented by Sophos on an Android Enterprise work-profile device:
- Add the Microsoft Outlook Android app to Sophos Mobile, then set up Outlook in the work profile with the business account.
- In Sophos Fusion > My Products > Mobile > Policies > Android, open the policy assigned to the device. Under Configurations, open the Restrictions configuration and, under Security, turn on all three switches: Allow work contact info for personal calls, Allow work contact info for Bluetooth devices, and Allow searches of work contacts in personal profile. Apply changes first with Apply, then with Save on Edit policy.
- Before making changes and saving: Complete the inventory check and approval under Android app configuration. The change applies to all devices where the app is already installed, not just the test device; obtain approval for the entire affected installed base beforehand. Under Apps > Android, open Microsoft Outlook on the Apps - Android Enterprise page. Make sure Use managed configuration is selected, then open Edit managed configuration. Turn on at least one of Contact sync enabled or Contact sync (user change allowed). Save changes with Save at the bottom right of the Managed configuration window, then close the window. Then also save with Save on Edit approved app.
- On the device, open the Sophos Mobile Control app in the work profile so the policy changes synchronize.
- Open Outlook in the work profile, tap the profile picture at the top left, then tap the gear icon at the bottom to open Settings. Select Contacts and turn on Sync contacts. If Android asks to let Outlook access contacts, deliberately approve the Contacts permission with Allow. Then return to Inbox.
- With the user’s consent, check search and caller ID on the device.
This allows personal apps with Contacts permission to look up Outlook work contacts; it does not automatically copy them into the personal address book. Work names can appear for personal calls or on connected Bluetooth devices. Discuss this disclosure with the user beforehand. If you are considering search alone, without caller ID or Bluetooth access, do not follow this three-switch procedure: whether that narrower variant works has not been validated and must be tested separately with consent before making any promises. Do not enable access without consent.
Do not confuse the locking actions: According to Sophos, Actions > Set container access with Auto mode links a compliance rule with Lock container to a lock on the work profile; its apps and notifications are then unavailable. The general Sophos table for the compliance action, however, describes a lock on “all apps” with specified exceptions, without clearly distinguishing the effect on personal apps on a BYOD work-profile device. Whether personal apps remain available under this action is therefore unresolved—do not promise either continued access to them or their complete lockout. Actions > Lock is a different action and locks the entire device; neither locking action removes the work profile. Before using Lock container in production, clarify the specific edition, ownership, management mode, rule, and effect with Sophos or through an authorized, representative test that includes a recovery path.
Remove the work profile and verify offboarding
Check mode-specific authorization, remote actions, and unenrollment after loss or during offboarding against the guide to lost devices and safe removal. If you use a task bundle instead of the individual action, review its order, management mode, and destructive tasks in the task-bundle lifecycle; a Wipe task is not a harmless test or proof of completed removal.
STOP before any Wipe action: With the user, match the exact physical device to its admin record and independently confirm Owner: Personal, Android Enterprise Work profile management mode, current profile state, last synchronization/connectivity, and explicit authorization in the admin view and on the device. A possibly stale console label alone is insufficient. If the device, mode, interface, or effect cannot be verified, do not click any Wipe action; escalate instead. An offline device cannot receive a remote removal task while disconnected; this means neither that the task has definitively failed nor that removal has already occurred. For devices still enrolled, the unenrollment instruction may only take effect at the next synchronization. A work profile already removed manually is a separate case: it can no longer synchronize or receive a removal task sent afterward; according to Sophos, that task fails. Handle each case separately below.
Warning: Removing the work profile cannot be undone. It removes all apps and local data in the work profile, including Sophos Mobile Control. On a personal Android device correctly managed as a work profile, this action does not delete personal apps or data. However, data deliberately transferred to the personal area beforehand is not automatically recalled. Assess Wipe by interface and management mode: Sophos Mobile Admin > Actions > Wipe (“Wipe device”, factory reset) is not available for Android Enterprise work-profile devices. By contrast, Sophos Fusion > My Environment > Mobile Devices > Actions > Wipe removes only the work profile in this mode; a Wipe task in an Android task bundle also removes only the work profile and managed Google Play apps in this mode. In other management modes, Wipe can factory-reset the entire device. For this personal work-profile device, continue to prefer Sophos Mobile > Devices > Actions > Wipe Android work profile once authorized; deleting a device record does not replace checking that the profile has actually been removed on the device.
- Confirm the device, ownership, and management mode with the user. Address protected business data, local drafts, and any necessary handover. Do not use this procedure for a fully managed device.
- Once authorized, open the relevant device under Sophos Mobile > Devices and select Actions > Wipe Android work profile. In the administrator confirmation dialog, select Yes only after rechecking the target device, management mode, and authorization. This starts the removal task; it does not confirm execution on the device. Alternatively, the authorized user can initiate work-profile removal in Sophos Central Self Service Portal > Mobile > device > Actions > Wipe Android work profile; the Yes dialog described here belongs to the administrator workflow. Contact IT first if there is any doubt.
- Verify the task outcome and the state on the device: work-profile apps and their briefcase icons must be gone, while personal apps and data must remain. After administrative removal, Sophos Mobile shows the device as Unenrolled. A task that has merely been created or an old status is not proof of removal.
If the user previously removed the profile in Android themselves: Sophos Mobile may not detect this and may still show Work profile; the device then no longer syncs. A removal task sent afterward fails because the work profile cannot receive it. Confirm the device and user status directly. Before re-enrollment, all record safeguards below must first be met. An authorized administrator must then delete the unambiguously matched stale Mobile device record and verify its deletion. Only after this deletion may the user repeat the enrollment steps in the Sophos Fusion Self Service Portal. If the actual permission to delete, the available interface, or the safe effect is unclear, stop and clarify with IT or Sophos Support; do not proceed with re-enrollment first. Rollback after removal means enrolling again and reprovisioning work data from approved sources, not restoring the deleted local work profile.
If the device can no longer reach the Sophos Mobile server: For this situation, such as after a trial expires, Sophos describes a separate local removal path through Google’s instructions. Here, it applies only to a physically accessible personal device with confirmed Owner: Personal and Android Enterprise Work profile. First carry out the same device, data-loss, and authorization checks above with the user, and preserve required work data through approved channels. Losing the server connection is not permission to bypass management restrictions.
- On the device, open Settings > Passwords and accounts > Work > Remove Work Profile (German interface: Einstellungen > Passwörter und Konten > Geschäftlich > Arbeitsprofil entfernen). Menus may differ by device and Android version. If the option is missing or blocked, or its effect is unclear, stop and consult IT; do not use a factory reset as a substitute.
- Only after authorization, confirm with Delete (German: Löschen). This irreversibly deletes all apps and local data in the work profile, not personal apps or data. It is a local deletion, not a task sent to the server, and offers no way to restore the profile.
- Verify that the work profile and its management app are actually gone; grayed-out or paused work apps are not enough. Google requires checking that the policy app it calls generically Device Policy is no longer present. Do not equate that label with a personal Sophos app or infer that the personal app should be uninstalled. For Sophos Mobile, in particular, the Sophos Mobile Control app in the work profile must be removed. Handle a potentially stale Mobile status and authorized reenrollment as described in the preceding paragraph; the record safeguards below still apply.
Only in Managed Google Play Account mode: After unenrollment, a Google account may remain on the device and still consume the limited enrollment quota. Before re-enrollment, have an authorized technician identify the exact residual account and verify that it belongs to the organization’s managed enrollment; follow the applicable Sophos/Google manual-removal instructions only for that verified account. Never remove the user’s personal Google account as a shortcut. Check the effective on-device profile state and whether re-enrollment actually succeeds before closing the case.
Record and privacy safeguards: Removing the local work profile does not purge cloud or audit data. Delete a stale Mobile device record only after confirming on that exact personal device that the work profile was already removed manually, the matching record and current work-profile mode, that no remaining managed profile can receive a task, and that required Mobile record and report evidence has been retained; require authorization and acknowledge that deletion cannot be undone. A report of missing synchronization alone does not authorize deletion. The deletion required for the re-enrollment described above applies only to this stale Mobile device record; a Wipe action, deleting the user, or changing management mode is not a substitute. An offline or still-enrolled device is not proven unenrolled by record deletion: it may only receive an unenrollment instruction at its next synchronization. If the management mode differs, stop and use the separate lost-device/offboarding procedure; fully managed Android deletion may factory-reset the device. Independently verify on-device state and completed task rather than console disappearance. If the device record is separately deleted, previously uploaded Data Lake information may remain until the applicable Sophos XDR retention ends; do not assume uploads were enabled or promise a retention period.