# How to enroll Android devices?

Enrolling Android devices into Hexnode UEM is the process of bringing smartphones and tablets under centralized management to enforce security policies and distribute apps. Hexnode supports multiple enrollment workflows categorized into **Android Enterprise (AE)** for advanced control and **Standard Enrollment** for basic management. The fastest manual method is **QR Code enrollment**, while **Zero-touch** and **Samsung KME** are used for automated, bulk deployments.

Enrollment Methodology Overview 
--------------------------------

Hexnode categorizes enrollment based on device ownership and management depth:

Enrollment TypeBest ForManagement Depth Android Enterprise (AE) Corporate & BYOD**High**: Separate work profiles or full device control. Standard EnrollmentBasic Security**Moderate**: Standard MDM features (lock, wipe, apps). Automated (ZTE/KME)Bulk Deployment**Total**: Out-of-the-box enrollment, non-removable MDM. Available Enrollment Methods 
-----------------------------

Choose the method that best fits your security requirements and device ownership model:

- **Standard Enrollment**:  
    - [Email/ SMS enrollment](#method-2-enroll-android-devices-with-authentication)
    - [Self enrollment](#method-3-self-enrollment-directory-credentials)
    - [QR Code Enrollment](#method-4-qr-code-enrollment)
- **Advanced & Enterprise Enrollment**: 
    - [ROM enrollment](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-android-devices-in-hexnode-mdm-by-configuring-rom/)
    - [Android Enterprise enrollment (a.k.a Android for Work)](https://www.hexnode.com/mobile-device-management/help/enroll-organization-and-devices-in-android-for-work-using-hexnode-mdm/)
    - [Non-Android Enterprise Enrollment as Device Owner.](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-in-non-android-enterprise-as-device-owner-using-hexnode/)
- **Automated (Zero-Touch) Enrollment**: 
    - [Zero Touch Enrollment](https://www.hexnode.com/mobile-device-management/help/zero-touch-enrollment/).
    - [Samsung Knox Enrollment](https://www.hexnode.com/mobile-device-management/help/samsung-knox-mobile-enrollment/).

Download the Hexnode UEM App 
-----------------------------

To begin enrollment, install the Hexnode UEM agent on your device:

- [Download the Hexnode UEM APK file](https://downloads.hexnode.com/HexnodeMDM.apk)
- [Download the Hexnode UEM store app in Play Store](https://play.google.com/store/apps/details?id=com.hexnode.hexnodemdm&hl=en)

Method 2: Enroll Android Devices With Authentication 
-----------------------------------------------------

This method requires the user to verify their identity using credentials sent to them via email or SMS.

**Steps to Enroll:**

1. Open the **Google Play Store** and install the **Hexnode UEM** application.
2. Launch the app and enter your server name (e.g., <portalname>.hexnodemdm.com).
3. Enter the **Username** and **Password** provided in your enrollment email or SMS.
4. Tap **Next**.
5. Grant the required system permissions: 
    1. **Device Administration**
    2. **Usage Access**
    3. **Draw Over Apps**
    4. **Write System Settings**
    5. **Notification Access**
    6. **App Installation**
6. Tap **Allow** on the pop-ups for **Location**, **Storage**, and **Phone** permissions.
7. The device is now enrolled and assigned to the authenticated user.

Here is the optimized content for the **Self Enrollment** and **QR Code Enrollment** sections.

Method 3: Self Enrollment (Directory Credentials) 
--------------------------------------------------

Self-enrollment allows users to enroll devices using their corporate credentials (Active Directory, Microsoft Entra ID, Google, Okta). For other users, the admin may create a default user and a dedicated password manually or assign a common password or individual passwords for the users and sends it to them as a bulk mail.

**Steps to Enroll:**

1. Open the **Google Play Store** and install the **Hexnode UEM** application.
2. Launch the app and enter your server name (e.g., <portalname>.hexnodemdm.com).
3. Choose your authentication method based on your organization’s setup: 
    1. **Local Users**: Tap **Authenticate with Hexnode**, select **Domain** as ‘Local’, and enter your username and password.
    2. **Active Directory (AD) Users**: Tap **Authenticate with Hexnode**, select your **AD Domain** from the dropdown, and enter your credentials. 
        1. **Note**: If the domain is not selected, use the format *NetBiosName\SAMAccountName*. If the domain is selected, just use *SAMAccountName*.
    3. **Microsoft Entra ID (Azure AD) Users**: Tap **Authenticate with Microsoft** and sign in with your Entra ID credentials.
    4. **Google Users**: Tap **Authenticate with Google** and sign in with your Google Workspace credentials.
    5. **Okta Users**: Tap **Authenticate with Okta** and complete the on-screen login procedure.
4. Tap **Next**.
5. Grant the required system permissions: 
    1. **Draw Over Apps**
    2. **Usage Access**
    3. **Device Administration**
6. Tap **Next** and then **Grant** for any additional permissions.
7. Tap **OK** and **Allow** on the pop-ups to grant access to **GPS**, **Storage**, and **Phone**.

Method 4: QR Code Enrollment 
-----------------------------

QR Code enrollment simplifies the process by removing the need to manually type server names or usernames. Hexnode supports both Open Enrollment (Generic QR) and Authenticated Enrollment (User-Specific QR).

### Option A: Open Enrollment (Generic QR Code)

This method uses a generic QR code available directly in the Hexnode console.

1. **Get the QR Code**: 
    1. Log in to your **Hexnode UEM portal**.
    2. Navigate to E**nroll > Platform-Specific > Android > Android TV & Standard Device**.
    
    [![On Screen QR Code](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2019/07/QR-Code-Enrollment.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2019/07/QR-Code-Enrollment.png)4. Keep this screen open.
2. **On the Device**: 
    1. Download and open the **Hexnode UEM app**.
    2. Tap the **QR Code** icon located at the bottom left of the screen.
3. **Scan & Enroll**: 
    1. Scan the QR code displayed on your portal screen.
    2. Follow the on-screen instructions to complete the enrollment.

**Note**: You can also send this QR code to users via email, or send the Server Name via email/SMS for them to enter manually.

#### Support for Virtual Devices 

Hexnode UEM also supports the enrollment and management of virtual Android devices (emulators). You can manage devices emulated using tools like **BlueStacks**, **Android Studio**, and **Samsung Remote Test Lab** using these enrollment methods.

### Option B: Authenticated Enrollment (User-Specific QR Code) 

In this method, a unique QR code is generated for a specific user and sent to them via email. This ensures that the device is automatically assigned to the correct user upon enrollment.

1. **Prerequisites**Before sending the request, ensure your portal is configured to support email authentication:
    
    
    1. Navigate to **Enroll > Settings**.
    2. Under **Request Modes**, check **Email**.
    3. Under **Authentication Modes**, check **Enforce authentication**.
    4. Click **Save**.
2. **Send the Enrollment Request**
    1. Log in to your **Hexnode UEM** portal.
    2. Navigate to **Enroll > Platform-Specific > Android TV & Standard Device**.
    3. Set the **Enrollment Request Mode** to **Email**.
    4. Select the target user(s) from the list and click Send. 
        
        1. The user will receive an email containing a unique QR code.

![](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2018/12/Email-enrollment-hexnodemdm.png)4. **Enroll the Device**
    1. On the device, download and install the **Hexnode UEM app** from the Google Play Store.
    2. Open the app and tap the **QR Code** icon located at the bottom left of the screen.
    3. Scan the QR code found in the enrollment email.
    4. Tap **Agree**.
    
    1. Grant the required permissions: 
        1. **Device Administration**
        2. **Usage Access**
        3. **Draw Over Apps**
        4. **Write System Settings**
        5. **Notification Access**
    
    6. Tap **Next** and **Grant/Allow** for any additional pop-ups.
    7. The device is now enrolled.

**Note**: This QR Code is for **one-time use only**. Once scanned and used for enrollment, it becomes invalid.

Device-Specific Warning: Xiaomi (MIUI) Devices 
-----------------------------------------------

**Critical Issue**: On Xiaomi devices running MIUI, clearing “Recent Applications” (swiping away the app) can kill the background process, stopping communication between the Hexnode app and the server. This breaks device sync, remote actions, and data management.

**The Fix**: Users **must** manually enable the “Autostart” permission for the Hexnode app to ensure it stays active:

- Go to **Settings > Apps > Permissions > Autostart**.
- Find **Hexnode UEM** and toggle the switch to **ON**.

Troubleshooting 
----------------

### 1. Error: “Certificate error occurred” 

**Problem**: After entering the server name in the Hexnode app and tapping **Next**, the enrollment fails with a “*Certificate error occurred*” message.

**Possible Causes**:

- **Incorrect Date/Time**: If the device clock is significantly out of sync, the SSL certificate validation will fail.
- **Incorrect Server Name**: A typo in the portal address.
- **Outdated OS**: The device lacks critical security root certificates.

**Solution**:

1. **Check Date & Time**: Go to **Settings > System > Date and time**. Ensure the date and time are correct (set to “Automatic” if possible). **Restart** the device to apply changes globally.
2. **Verify Server Name**: Double-check the URL entered (e.g., <portalname>.hexnodemdm.com) for typos.
3. **Update Device**: Go to **Settings > System > System updates** and install the latest security patches.

### 2. Error: “Device limit reached!” 

**Problem**: During the enrollment process, the device displays: “*Device limit reached! Please contact your administrator!*”

**Possible Causes**:

- **License Cap**: The organization has enrolled the maximum number of devices allowed by the current subscription plan.
- **Expired License**: The Hexnode UEM subscription has expired.

**Solution**:

- **Check License Count**: Log in to the Hexnode portal and navigate to **Admin > License**. Verify if the “Enrolled Devices” count matches your “Total Licenses”.
- **Resolve**: If the limit is reached, you must either purchase additional licenses or delete old/inactive devices from the portal to free up slots.

Need more help? 
----------------

Then you can check out Hexnode’s dedicated troubleshooting guide for enrollment:

- [Common issues in Android enrollment ](https://www.hexnode.com/mobile-device-management/help/common-issues-in-android-enrollment/)