Enterprise Android Fleet Security Matrix
Assess Android enterprise mobility deployment, device provisioning, and Zero-Trust posture for client consulting.
Use this template when advising corporate clients on securing distributed Android device fleets. It creates an actionable security evaluation matrix covering management modes, enrollment workflows, and hardware-backed credential safeguards.
Role: Staff Android Security & Enterprise Mobility Consultant advising Fortune 500 professional services clients.
Context
- Fleet Deployment Model: {{enterprise_deployment_model}}
- Managed OEM Hardware Fleet: {{target_oem_fleet}}
- Identity & Access Management Provider: {{identity_provider_stack}}
- Enterprise Threat Model Priorities: {{threat_model_priorities}}
- Regulatory Governance Mandates: {{regulatory_mandates}}
- Offline Field Policy Requirements: {{offline_policy_requirements}}
Task
Develop an enterprise-grade Android Security & Provisioning Matrix evaluating device ownership models, policy enforcement mechanisms, and Zero-Trust endpoint posture tailored to the client's operational environment.
Method
- Assess {{enterprise_deployment_model}} (BYOD, COPE, COBO, COSU) against enterprise data isolation boundaries.
- Evaluate hardware security module capabilities (StrongBox Keymaster, TEE, attestation APIs) across {{target_oem_fleet}}.
- Analyze Android Enterprise Management APIs (Device Owner vs. Profile Owner) against {{threat_model_priorities}}.
- Map integration hooks between {{identity_provider_stack}}, Android KeyStore, and mutual TLS token binding.
- Audit local data-at-rest encryption, biometric authentication policies, and network isolation for {{offline_policy_requirements}}.
- Align MDM/UEM policy configurations with legal and compliance directives defined in {{regulatory_mandates}}.
- Synthesize findings into a comparative security matrix scoring implementation complexity against residual vulnerability surface.
- Produce a prioritized remediation and rollout roadmap for client engineering leadership.
Constraints
- MUST structure the core evaluation as a comparative matrix table.
- MUST specify Android Enterprise enrollment methods (Zero-Touch, QR code, Knox Mobile Enrollment, DPC token).
- MUST NOT recommend unmanaged or root-permissive fallback configurations.
- Recommendations MUST explicitly account for hardware fragmentation within {{target_oem_fleet}}.
Output format
- Executive Security Assessment (under 250 words)
- Android Enterprise Provisioning Matrix (Columns: Management Mode, Key Isolation, Attestation Support, Identity Hook, Fleet Compatibility, Residual Risk)
- Zero-Trust Policy Control Matrix (Policy Area, DPC Implementation, Fail-Closed Behavior, Offline Behavior)
- Implementation Recommendations & Prioritized Next Steps
Self-review
- Ensure both requested matrix tables contain explicit, non-generic security controls.
- Confirm that {{identity_provider_stack}} and {{regulatory_mandates}} are fully mapped in the control matrix.
- Check that offline edge cases from {{offline_policy_requirements}} have defined fail-closed behaviors.
Explicit role, a named task, and discrete steps the model can follow.
Background, inputs and variables the model needs before it starts.
Hard boundaries — what the model must and must not do.
A named, field-level shape for the response.
Ordered work items that force analysis before an answer.
Length and structure that travel across frontier models.
Signal density — instruction weight without padding.
Documented variables so the scaffold adapts to new inputs.
Quality bar, assumptions and behaviour when inputs are thin.
How much real usage the template has behind it.