If you hand a staff member a company phone, you are handing over an asset, a data connection and a small amount of risk. Most businesses discover this the first time a work phone comes back with a cracked screen, 14 GB of streaming data used and an app nobody approved. Here is how company-owned Android phones are actually locked down in 2026 — and, just as importantly, what you are not allowed to do.
Everything follows from ownership. If staff use their own phones, you can only manage a separate work profile — you cannot touch the personal side, and you should not try. If the business owns the device and hands it to an employee for work, you can manage the whole thing.
This article is about the second case: company-owned, explicitly enrolled devices.
Locking a phone down properly is not an app you install and hope for. Android has a formal system for it — Android Enterprise, driven through the Android Management API. During setup, Google’s Device Policy controller becomes the owner of the device, which is what makes real restrictions possible.
Once a phone is enrolled as fully managed, you can:
The catch worth knowing up front: some restrictions depend on Android version, manufacturer and carrier. Any serious rollout tests on the exact handset model you intend to buy.
A managed phone cannot be converted from a phone somebody has already been using. It has to be enrolled from a factory-reset state — typically by scanning a QR code on first boot. Plan for this. Buying ten phones and enrolling them in one sitting is straightforward; retrofitting ten phones already in the field is a morning of resets.
This is where a lot of vendors get vague, so let us be direct.
Anyone promising silent, total visibility into a phone is describing either spyware or a product that does not exist.
Managing a company device is lawful. Monitoring an employee without telling them generally is not. Before the first phone is enrolled, put in place a written device policy, tell staff what is monitored and why, keep monitoring to a legitimate operational purpose, and restrict admin access to named people. In South Africa this sits under POPIA; in the EU and UK it is GDPR. The principle is the same everywhere: proportionate, disclosed, and purposeful.
A well-managed fleet is quiet. Staff open the phone and see the four apps they need. When a phone goes missing, an administrator locks it and puts a contact number on the screen. When an app misbehaves on site, someone clears its data remotely instead of driving out. And every one of those actions has a name and a timestamp against it.
That is the model LockFleet is built on — Android Enterprise lockdown, app delivery and remote commands from one console, with an audit trail behind every action and a clearly stated boundary about what it will not do.