Android
AuraScore 83/100

Enterprise Android Fleet Security Matrix

Assess Android enterprise mobility deployment, device provisioning, and Zero-Trust posture for client consulting.

Use this template when advising corporate clients on securing distributed Android device fleets. It creates an actionable security evaluation matrix covering management modes, enrollment workflows, and hardware-backed credential safeguards.

Template

Role: Staff Android Security & Enterprise Mobility Consultant advising Fortune 500 professional services clients.

Context

  • Fleet Deployment Model: {{enterprise_deployment_model}}
  • Managed OEM Hardware Fleet: {{target_oem_fleet}}
  • Identity & Access Management Provider: {{identity_provider_stack}}
  • Enterprise Threat Model Priorities: {{threat_model_priorities}}
  • Regulatory Governance Mandates: {{regulatory_mandates}}
  • Offline Field Policy Requirements: {{offline_policy_requirements}}

Task

Develop an enterprise-grade Android Security & Provisioning Matrix evaluating device ownership models, policy enforcement mechanisms, and Zero-Trust endpoint posture tailored to the client's operational environment.

Method

  1. Assess {{enterprise_deployment_model}} (BYOD, COPE, COBO, COSU) against enterprise data isolation boundaries.
  2. Evaluate hardware security module capabilities (StrongBox Keymaster, TEE, attestation APIs) across {{target_oem_fleet}}.
  3. Analyze Android Enterprise Management APIs (Device Owner vs. Profile Owner) against {{threat_model_priorities}}.
  4. Map integration hooks between {{identity_provider_stack}}, Android KeyStore, and mutual TLS token binding.
  5. Audit local data-at-rest encryption, biometric authentication policies, and network isolation for {{offline_policy_requirements}}.
  6. Align MDM/UEM policy configurations with legal and compliance directives defined in {{regulatory_mandates}}.
  7. Synthesize findings into a comparative security matrix scoring implementation complexity against residual vulnerability surface.
  8. Produce a prioritized remediation and rollout roadmap for client engineering leadership.

Constraints

  • MUST structure the core evaluation as a comparative matrix table.
  • MUST specify Android Enterprise enrollment methods (Zero-Touch, QR code, Knox Mobile Enrollment, DPC token).
  • MUST NOT recommend unmanaged or root-permissive fallback configurations.
  • Recommendations MUST explicitly account for hardware fragmentation within {{target_oem_fleet}}.

Output format

  • Executive Security Assessment (under 250 words)
  • Android Enterprise Provisioning Matrix (Columns: Management Mode, Key Isolation, Attestation Support, Identity Hook, Fleet Compatibility, Residual Risk)
  • Zero-Trust Policy Control Matrix (Policy Area, DPC Implementation, Fail-Closed Behavior, Offline Behavior)
  • Implementation Recommendations & Prioritized Next Steps

Self-review

  • Ensure both requested matrix tables contain explicit, non-generic security controls.
  • Confirm that {{identity_provider_stack}} and {{regulatory_mandates}} are fully mapped in the control matrix.
  • Check that offline edge cases from {{offline_policy_requirements}} have defined fail-closed behaviors.
AuraScore breakdown
83/100Provisional
Instruction clarity15/15 · Strong

Explicit role, a named task, and discrete steps the model can follow.

Context architecture12/12 · Strong

Background, inputs and variables the model needs before it starts.

Constraint engineering12/12 · Strong

Hard boundaries — what the model must and must not do.

Output specification6/14 · Thin

A named, field-level shape for the response.

Reasoning structure10/10 · Strong

Ordered work items that force analysis before an answer.

Model compatibility10/10 · Strong

Length and structure that travel across frontier models.

Token efficiency5/10 · Thin

Signal density — instruction weight without padding.

Reusability7/7 · Strong

Documented variables so the scaffold adapts to new inputs.

Robustness5/5 · Strong

Quality bar, assumptions and behaviour when inputs are thin.

Observed performance1/5 · Thin

How much real usage the template has behind it.

developers
developers-android
professional-services
android
security
enterprise