Decide who owns and manages the phone

Start by recording whether each phone is company owned, personally owned or shared. The answer affects privacy, acceptable use, who pays for it, what can be remotely removed and what happens when somebody leaves.

Android Enterprise supports different management approaches. A Work Profile separates business applications and data from personal content. Fully managed devices are intended for company owned business use, while dedicated device management is intended for equipment restricted to a small number of tasks.

Check Android and security updates

Open Settings, then Security and privacy, and review the system update and security update status. Menu names vary between manufacturers and Android versions.

Install supported updates promptly and replace phones that no longer receive security fixes. The National Cyber Security Centre recommends keeping devices and software updated and using mobile device management to enforce updates where appropriate.

When buying work phones, check the manufacturer's published support period rather than assuming a new handset will receive updates for the expected lifetime of the contract.

Use a strong screen lock

Require a PIN, password or another approved screen lock. Fingerprint or face unlock can make daily use easier, but a secure fallback credential is still required. Avoid sharing the same unlock code across a team.

Set the phone to lock automatically after a short period and hide sensitive notification content from the lock screen. Android Work Profile settings can also apply a separate work credential and hide work notification details.

Review applications and permissions

Use Google Play Protect and install work applications from approved sources. Review warnings in Security and privacy rather than ignoring them. Remove applications that are no longer required and check access to the camera, microphone, location, contacts and files.

An application should receive only the access needed for its purpose. Staff should not install an unknown application merely because a text message or website instructs them to do so. Organisations using mobile management can distribute approved applications through managed Google Play.

Prepare for a lost or stolen phone

Google's Find Hub can locate, secure or erase a lost Android device where it has been configured and the required account conditions are met. Check the setting before the phone is lost and make sure the organisation knows which account controls it.

Create a simple reporting process. Staff should know who to contact immediately, even outside normal office hours, and should not wait until the next working day if the phone can open business email or files.

  • Record the telephone number, device model, serial number and assigned user.
  • Confirm Find Hub or the organisation's management service is active.
  • Know how to suspend the SIM and business accounts.
  • Revoke active sessions and reset exposed credentials where necessary.
  • Record the incident and consider whether personal data may have been exposed.

Use a Work Profile for personal phones

A Work Profile stores work applications and data in a separate managed area. Work applications display a briefcase symbol, and the organisation can apply controls to that area without taking control of an employee's personal photographs, messages or applications.

Android Enterprise allows an organisation to enforce work passcodes, distribute approved applications, check compliance and remotely remove work data. This is a clearer arrangement than adding a company mailbox to an unmanaged personal phone and hoping that it remains secure.

Protect business accounts as well as the device

A locked telephone does not protect an account if an attacker has obtained its password. Enable suitable multifactor authentication or passkeys for Microsoft 365, Google and other important services. Keep administrator accounts separate from ordinary mobile use.

Check that recovery telephone numbers and email addresses are current. Do not use one employee's personal account as the only recovery route for a shared business service.

Android work phone checklist

  • Record ownership, assigned user and support dates.
  • Install the latest Android and security updates.
  • Replace devices that no longer receive security fixes.
  • Require a PIN, password or approved biometric lock.
  • Hide sensitive information from the lock screen.
  • Keep Google Play Protect enabled.
  • Remove unused applications and review permissions.
  • Configure Find Hub or mobile device management.
  • Separate work data with a Work Profile where appropriate.
  • Use multifactor authentication or passkeys for business accounts.
  • Document the lost phone and staff departure procedures.
  • Back up business information to an approved service rather than only the handset.

How Bury I.T. Support can help

Bury I.T. Support Ltd can review mobile access to Microsoft 365 and other business services, help choose a suitable management approach and document secure setup, lost device and staff departure procedures.

Official sources and further reading

These primary sources were checked when this article was last reviewed.

Written by

Christopher Lomax

Director of Bury I.T. Support Ltd, with more than 20 years of hands-on experience supporting business IT, Microsoft 365, networks, servers and cyber security.

About the team