Cybersecurity 101back-iconWhat is Corporate-owned, business-only (COBO)?

What is Corporate-owned, business-only (COBO)?

Corporate-owned business-only is a device deployment model where an organization owns an endpoint and limits it to approved work use only.

In enterprise mobility, COBO is commonly associated with Android Enterprise fully managed devices. IT manages the whole device, not just a work container, making it useful for regulated teams, field operations, shared fleets, and roles where personal use should be excluded.

How does it work?

COBO starts during enrollment, often through zero-touch, QR-code, or reseller-assisted provisioning. The device is assigned to the organization before setup, allowing a UEM or EMM platform to apply baseline configuration, identity requirements, Wi-Fi, certificates, apps, restrictions, and security controls.

After enrollment, IT can enforce passcodes, block unmanaged app installation, control settings, push updates, monitor compliance, and remotely lock or wipe the device. Corporate-owned business-only works best when users need a reliable work tool rather than a personalizable device.

COBO element Purpose
Ownership model Confirms the organization owns the device and defines it as a business-only asset.
Provisioning Enrolls the endpoint into full-device management before normal user access begins.
Policy control Applies restrictions, app rules, security settings, compliance checks, and remote actions.

Corporate-owned business-only vs COPE

COBO and COPE both involve corporate-owned devices, but they solve different needs. COBO gives the organization full-device control for business use only. COPE, or corporate-owned personally enabled, allows personal use while separating work data and personal space.

Choose COBO when privacy expectations are simple because the device is a work asset. Choose COPE when employees need a company phone that also supports approved personal use with clear separation.

How Hexnode supports Corporate-owned business-only

Hexnode supports COBO deployments by helping IT teams enroll devices, assign policies, enforce restrictions, manage applications, track compliance, and take remote actions from a central console. For Android Enterprise devices, Hexnode can support endpoint visibility, app controls, kiosk-style restrictions, patch workflows, and device lifecycle operations.

This helps organizations keep fully managed devices aligned with mobile device security goals: work apps stay available, risky settings stay restricted, and lost or non-compliant endpoints can be acted on quickly.

When should organizations use it?

Organizations should use COBO for devices issued to delivery workers, healthcare staff, retail associates, warehouse teams, contractors, and other users who need controlled access to business apps and data. It is also appropriate for enterprise-managed mobile devices in compliance-heavy or high-turnover environments.

Avoid COBO when employee privacy or personal flexibility is a requirement. In those cases, BYOD or COPE is usually a better fit because it separates work management from personal activity.

FAQs

In Android Enterprise, COBO is usually implemented through fully managed or device owner mode, where the management app controls the whole device.

Usually no. IT can restrict app installation to approved business apps or managed app stores, depending on policy.

IT can wipe and redeploy it with standard policies so the next user receives a clean, compliant work device.