Version support
How MDM works
Primo uses Fleet as its MDM agent for Android. The agent is installed via a lightweight package and communicates with Primo to report device state, enforce policies, and run scripts.Initial setup
Android MDM requires connecting a Managed Google Play account to enable app deployment and policy enforcement on enrolled devices.1
Go to MDM > Android
Open the MDM section and select Android.
2
Connect your Managed Google Play account
Follow the prompts to link your organization’s Managed Google Play account. This registers your organization with Android Enterprise and authorizes Primo to manage Android devices on your behalf.
3
Confirm the connection
Once connected, Android MDM is active. Devices can now be enrolled and apps can be deployed from the Play Store.
Enrollment modes
Android supports two enrollment modes. Both are available on every enrollment surface (MDM settings, employee enrollment stepper, and invite emails) — pick the mode that matches how the device is owned and staged.Personal (work profile)
Use this on personal devices an employee already owns. Company apps and data live in a separate work profile; personal apps, photos, and accounts stay private and outside Primo’s visibility. Employees enroll themselves:- Open the enrollment link on the Android device (or scan the QR code shown next to the link).
- Tap Enroll and follow the on-screen steps to create the work profile.
Company-owned (fully managed)
Use this on new or factory-reset company devices. The entire device is managed by Primo — there is no separate personal profile. Fully-managed enrollment is an IT-staging flow, not a self-service one. It requires access to both a second screen and the device during setup:- On a computer or tablet, open the fully-managed enrollment link. Fleet displays a provisioning QR code. Keep the page open.
- Power on the Android device on its welcome screen. If the device has already been set up, factory-reset it first.
- Tap the welcome screen 6 times to open the QR code scanner, then scan the provisioning QR code from step 1.
Fleet generates the provisioning QR code on demand, and it expires roughly one hour after the link is opened. Open the link right before scanning it, not in advance.