Android Enterprise Work Profile Deployment Verification Checklist
Validate MDM policies, managed configurations, and work profile boundary controls for consultant device fleets.
Use this checklist when deploying enterprise Android devices to management consultants or field auditors. It establishes clear criteria for validating zero-touch provisioning, container isolation, and corporate compliance.
Role: Senior Enterprise Mobility Architect specializing in professional services Android rollouts
Context
- Practice group: {{consulting_practice_area}}
- Fleet device portfolio: {{target_device_fleet}}
- Unified Endpoint Management platform: {{mdm_platform_name}}
- Deployed line-of-business suite: {{internal_app_suite}}
- Secure perimeter architecture: {{vpn_profile_type}}
- Deployment target milestone: {{compliance_deadline}}
Task
Generate a rigorous pre-flight validation checklist to confirm that {{target_device_fleet}} devices running {{internal_app_suite}} under {{mdm_platform_name}} maintain absolute work profile separation and zero data exfiltration prior to {{compliance_deadline}} for {{consulting_practice_area}}.
Method
- Verify zero-touch enrollment profiles, DPC (Device Policy Controller) binding, and initial enrollment payload integrity.
- Validate Work Profile data boundaries, disabling cross-profile copy-paste, screenshot sharing, and unmanaged intent forwarding.
- Audit runtime App Restrictions and Managed Configurations pushed to {{internal_app_suite}} via {{mdm_platform_name}}.
- Check per-app VPN and Always-On VPN tunnel establishment for {{vpn_profile_type}} across all managed business apps.
- Verify device passcode complexity rules, work challenge authentication timeouts, and remote-wipe operational triggers.
- Inspect managed Google Play deployment channels, sideloading restrictions, and unknown source installation blocking.
- Test certificate distribution, private CA installation inside the work container, and network isolation from the personal container.
Constraints
- MUST specify the exact Android Management API or DPC policy attribute for each verification task.
- MUST separate checks into 'Device Enrollment', 'Profile Isolation', 'Network Routing', and 'Operational Governance'.
- MUST NOT assume unmanaged personal apps have access to enterprise storage volumes.
- Checklist items MUST include measurable pass criteria rather than subjective descriptions.
Output format
- Fleet Readiness Summary block (Target: {{compliance_deadline}})
- 4 Categorized Checklist Sections containing 4 to 6 numbered verification items each
- Failover & Quarantine Protocol checklist (5 tactical items)
- Sign-off block for Enterprise Mobility and Security leads
Self-review
- Ensure every parameter ({{consulting_practice_area}}, {{target_device_fleet}}, {{mdm_platform_name}}, {{internal_app_suite}}, {{vpn_profile_type}}, {{compliance_deadline}}) is explicitly referenced.
- Confirm the method steps cover both initial enrollment and ongoing isolation enforcement.
- Verify all constraint conditions and formatting requirements are strictly fulfilled.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.