Android disk encryption on Esper-enrolled devices: OS-native, not managed by Esper
Android
Android devices encrypt data at the operating system level before they're enrolled in Esper. Esper doesn't manage or configure disk encryption — this is handled entirely by Android and your device manufacturer. This article explains how encryption works on enrolled devices and where to verify your device's encryption status.
Understanding Android disk encryption
When you enroll an Android device in Esper, the device's storage encryption is already in place. Modern Android devices (Android 10 and newer) ship with file-based encryption enabled by default. This encryption is:
- Applied by the device manufacturer and Android operating system — not by Esper
- Established before MDM enrollment
- Independent of Esper management
- Not configurable through the Esper Console
Esper has no encryption settings, policies, or configuration options because encryption is an OS-native feature outside Esper's scope.
How to check your device's encryption status
To verify that your enrolled device is encrypted, check the device's native security settings:
- On your enrolled device, open Settings
- Navigate to Security (or Security & Privacy, depending on your device manufacturer)
- Look for Encryption & credentials or Encryption status
- The device will display its encryption state — typically "Encrypted" or "File-based encryption enabled"
The device's own security settings are the authoritative source for encryption status, not Esper.
Encryption types on Android devices
Android supports two encryption models:
- Full Disk Encryption (FDE) — Available on Android 5.0 and newer. Encrypts the entire data partition using a single key.
- File-Based Encryption (FBE) — Standard on Android 7.0 and newer. Encrypts individual files with different keys, allowing the device to boot to the lock screen without full decryption. This is the default on most devices shipped with Android 10 or newer.
Google requires encryption to be enabled by default on all compatible hardware running Android 6.0 or newer. Nearly all modern enrolled devices have encryption enabled out of the box.
For compliance documentation
If your organization requires encryption attestation for security or compliance audits, obtain documentation directly from your device manufacturer rather than from Esper. Examples include:
- Google Pixel security whitepaper
- Samsung Knox documentation
- Your device manufacturer's security documentation
You can reference that Android OS and device manufacturers enforce encryption by default on devices running Android 6.0 or newer, prior to Esper enrollment.
Devices without encryption enabled
In rare cases, you may encounter a device where encryption is not enabled:
- Older devices (Android 5.x or below) or custom ROMs may not have encryption enabled
- Industrial or ruggedized devices from some manufacturers may ship with encryption disabled for performance reasons
This is an operating system or device manufacturer issue, not an Esper limitation. Esper cannot remotely enable encryption on a device. Contact your device manufacturer for remediation.
Additional considerations
Samsung Knox devices: Samsung Knox devices include additional encryption layers managed by the Knox platform, which operate independently of both Android's file-based encryption and Esper.
MDM-enforced encryption policies: Esper does not currently support blocking device enrollment based on encryption status. If your compliance framework requires MDM-enforced encryption verification, contact Esper Support to discuss your requirements.
Still need help?
If you have questions about encryption on your enrolled devices or need assistance with compliance documentation, submit a support ticket. Our team can help you understand your device's encryption capabilities and discuss options for your compliance requirements.
Please sign in to leave a comment.
Comments
0 comments