Already a NinjaOne customer? Log in to view more guides and the latest updates.

End User Guide: BYOD Enrollment for Personal Devices with NinjaOne

reviewed by Ian Crego

This guide outlines the process for enrolling personally owned devices, including smartphones, tablets, and macOS laptops, into your organization’s Bring Your Own Device (BYOD) program using NinjaOne.

BYOD enrollment with NinjaOne enables secure, policy-driven access to corporate resources while maintaining a clear separation between personal and work data. Once enrolled, IT administrators can deploy approved business applications, apply baseline security controls, and enforce compliance requirements without gaining visibility into personal content, activity, or private applications.

Note: NinjaOne MDM does not have access to any personal files, photos, or private app data, regardless of whether the device is company or personally owned.

What is a Work Profile?

On Android, a work profile creates a secure, isolated container for work-related apps, email, and configurations. This prevents corporate data from mixing with personal data. IT administrators can only manage this container, delivering security while protecting user privacy.

Part 1: Android Device Enrollment

Method: Personal Device with Existing Data (Standard)

Use this method if you are using a personal phone you already own.

Before You Begin:

  • Ensure your device is connected to Wi-Fi.
  • Confirm your device runs Android 8.0 or later (minimum supported version).
  • Have your enrollment QR code or link ready (provided by IT).

Step-by-Step Enrollment:

  1. Install Android Device Policy: Open the Google Play Store on your device and install Android Device Policy (published by Google LLC).

You can also install it directly from the Google Play Store using the following link:
https://play.google.com/store/apps/details?id=com.google.android.apps.work.clouddpc

A screenshot showing the Android Device Policy app

This app is required to create and manage your secure work profile.

  1. Open the App & Scan: Open the Android Device Policy app. When prompted, tap to scan the QR code provided by your IT team.
    • Note: If you cannot scan, you may enter the code manually by selecting Enter code manually.

A screenshot showing the Enroll device

  1. Setup Work Profile: The screen will display “Let’s set up your work profile.” Tap Accept & Continue to proceed.

A screenshot showing the set up work profile

  1. Install Work Apps: You will see a “Your work checklist” screen. Tap Install to begin installing the work apps assigned to your device.

A screenshot showing the Work apps checklist

  1. Complete Enrollment: Once the required apps are installed, tap Set up or Next. The NinjaOne Assist app (and other company apps) will be installed, and you may see a confirmation that “Application setup is complete”.

A screenshot showing the NinjaOne Assist app installed

  1. Finalize: You can now exit the setup. Your device is enrolled, and you will see your work apps marked with a small briefcase icon to distinguish them from personal apps.

Part 2: iOS/iPadOS Device Enrollment

Important Considerations for Personal iOS Devices

Unlike corporate-owned devices, enrollment on personal Apple devices uses the Unsupervised status.

  • Unsupervised Status: Your device will be enrolled as “unsupervised.” This means only a limited set of privacy-respecting settings and policies designed for personal devices will be applied.
  • App Deployment: Apple iOS. Apps can be deployed, but all requests to install or manage apps will need to be approved by the end user of the device.
  • App Deployment Warning: If the Apple ID is not set up under your device’s Settings (for iCloud and iTunes/App Store), the device will be enrolled, but no managed company apps will successfully deploy. Ensure your personal Apple ID is active in Settings before starting enrollment.

Step-by-Step Enrollment:

(Note: These steps assume you have received a QR code or link from IT)

  1. Scan QR Code: Open your device’s Camera app and scan the QR code provided by IT. A notification will appear at the top of the screen; tap it to open the link in Safari.

QR Code

  1. Download Profile: A popup will ask, “This website is trying to download a configuration profile. Do you want to allow this?” Tap Allow.

Download profile pop-up

  1. Confirm Download: Once you see the “Profile Downloaded” confirmation, tap Close.
  2. Install Profile:
    • Open the Settings app on your device.
    • Tap the Profile Downloaded option near the top (under your Apple ID info).
    • Tap Install in the top right corner.

Profile downloaded

  1. Trust Remote Management:
    • If prompted, enter your device passcode.
    • You will see a “Warning” page about Mobile Device Management. Tap Install again.
    • A “Remote Management” popup will ask if you trust this profile’s source. Tap Trust.

Trust Remote Management

  1. Finish: When the screen says “Profile Installed,” tap Done. Your device is now enrolled.

Part 3: macOS Device Enrollment

For macOS devices, the enrollment is completed by manually installing a management profile.

Enrollment Method: Manually Install the Enrollment Profile

Before You Begin:

  • Ensure your Mac is connected to the internet.
  • Obtain the Enrollment Profile link or file from your IT team.

Step-by-Step Enrollment:

  1. Download the Profile: Click the link provided by IT to download the enrollment profile (.mobileconfig file) to your Mac.
  2. Install the Profile: Locate the downloaded file (usually in your Downloads folder) and double-click it.
  3. Follow System Prompts: A notification will open System Settings and guide you through the installation.
    • Follow the on-screen prompts.
    • You will likely be asked to enter your Mac’s administrator password to authorize the installation.
  4. Verification (Optional):Once installed, you can verify the profile is active. Go to System Settings → General → Device Management. The NinjaOne management profile will be listed there.

Post-Enrollment Summary

Once the enrollment steps are complete, the following actions will occur automatically:

  • Agent Installation (macOS): For macOS devices, once the MDM profile is successfully registered, the NinjaOne companion software will automatically be deployed and installed into your Mac. The software is essential for device health monitoring and management.
  • App Installation: Your IT team will begin pushing required applications to your device. On mobile devices, these will appear in your work folder or on your home screen. Apple app installs on mobile devices will ask for approval before install.
  • Security Policies: Corporate security settings (such as password complexity requirements) may be enforced immediately upon enrollment.
  • Privacy Maintained: Your personal apps, photos, messages, and files remain private and inaccessible to IT.

 

Additional Resources

For deeper insight into mobile device management (MDM), device supervision, and BYOD enrollment with NinjaOne, refer to the resources below:

Understanding Device Management

Learn the key differences between Supervised and Unsupervised device modes, including how each impacts management capabilities, security enforcement, and end-user privacy.
Supervised vs. Unsupervised Devices: What’s the Difference?

Detailed Technical Guide

Access a comprehensive, administrator-focused resource for enrolling Android devices, including support for multiple device ownership models and enrollment scenarios.
Enrolling Android Mobile Devices

Video Overviews

Watch concise videos that explain the business value, security benefits, and strategic role of Mobile Device Management (MDM) in modern IT environments.
Why Your Business Needs MDM
Mobile Device Management Strategy: Steps & Tips

FAQ

No. IT management is strictly limited to the work profile or managed apps. Your personal apps, photos, messages, browsing history, and any files outside the work container remain private and inaccessible to IT.

Your IT team can remotely remove the entire work profile or management configuration. This process cleanly deletes all company apps, data, and configurations without affecting any of your personal content.

The work profile and managed apps use some storage space, similar to installing any other apps. Performance impact is minimal because the work profile runs in a separate, optimized container.

Yes. You can remove the work profile or management profile from your device settings at any time. Keep in mind that doing so will instantly remove access to all company resources and applications.

The work profile creates a secure, isolated container for corporate apps and data. IT can only manage this container—not your personal apps or files—ensuring both enterprise security and user privacy.

Next Steps