This website uses cookies and other tracking technologies to function, personalize your experience, analyze how users engage with us, and tailor advertising to you. We may share this information with our social media, advertising, and analytics partners. Some of this sharing may be considered a sale or sharing of personal data under certain privacy laws. You can adjust your settings by clicking the manage settings button below. We also recognize GPC signals if you have set them in your browser. Clicking the "x" to close this banner or interacting with our website will accept all cookies and other tracking technologies.
Powered by: cookie notice provider logo

LogMeIn support sites no longer support Microsoft's Internet Explorer (IE) browser. Please use a supported browser to ensure all features perform as they should (Chrome / FireFox / Edge).

The GoTo support site no longer supports Safari 15. Please upgrade your browser to Safari 16 (or newer) or switch to a supported browser such as Google Chrome, Mozilla Firefox, or Microsoft Edge.

Simply secure and manage all devices. Discover LogMeIn Resolve Mobile Device Management.

We are currently experiencing an unplanned outage for this product.
  • Support
  • Products

    Explore support by product

    GoTo Connect

    All-in-one phone, meeting and messaging software

    GoTo Meeting

    Video and audio meeting software

    GoTo Webinar

    All-in-one webinar and virtual events software

    GoTo Room

    Conference room hardware

    GoTo Training

    Online training software

    OpenVoice

    Audio conferencing software

    Grasshopper

    Lightweight virtual phone system

    join.me

    Video conferencing software

    LogMeIn Resolve

    IT management & support

    LogMeIn Resolve MDM

    Mobile device management

    LogMeIn Pro

    Remote device access

    LogMeIn Central

    Remote monitoring & management

    LogMeIn Rescue

    Remote IT support

    GoToMyPC

    Remote desktop access

    GoToAssist

    Remote support software

    Hamachi

    Hosted VPN service

    RemotelyAnywhere

    On-prem remote access solution
  • Community
  • Service Status
  • Try the improved My Cases portal

    Easily manage your ticket, track its status, contact us from an existing case, and more.

    Sign in to try
  • Language selector icon Language selector icon
    • English
    • Français
    • Italiano
    • Deutsch
    • Español
    • Português
    • Nederlands
  • Contact Support
  • Service Status
  • User Avatar User Avatar
    • Support
    • Contact Support
    • Browse Products
    • Service Status
    • Community
    • Sign in
    • User Avatar
    • My Account
    • Personal Info
    • Sign In & Security
    • My Cases
    • Billing Center
    • https://link.goto.com/myaccount-billing
    • My GoTo Connect
    • My Meetings
    • My Webinars
    • My Trainings
    • My Conferences
    • My Resolutions
    • My Mobile Devices
    • My Sessions
    • My Sessions
    • My Incidents
    • Sign out
  • Device Platforms
  • Android
  • Device Data and Configuration
product logo
Back button image Back
Back button image
product logo

Device encryption for Android

This article describes LogMeIn Resolve MDM's device encryption configuration profile for Android.

This configuration is available for customers of all subscription levels. Encryption configuration requires the Miradore client version 2.3.3 or later. Full-disk encryption is not allowed on new devices running Android 10 and higher. For new devices, use  file-based encryption.

Different encryptions

Full-disk encryption uses a single key to protect the whole of a device’s user data partition. It is protected with the user’s device password. This is good for security, but also means that the majority of the core functionality of the phone is not immediately available when rebooting the device.

File-based encryption makes it possible for different files to be encrypted with different keys that can be unlocked independently. It ables a feature called Direct Boot mode, which allows encrypted devices to boot straight to the lock screen. Each user of the device has two storage locations available to applications: Credential Encrypted storage, which is the default storage location which is only available after the user has unlocked the device. Device Encrypted storage is available both during Direct Boot mode and also after the user has unlocked the device.

About the device encryption configuration do

Device encryption configuration for Android sets a requirement to the target device that storage encryption should be enabled.

Worth noting that it may vary between devices what is actually encrypted. It depends on how the manufacturer has decided to support this feature. Here is an excerpt from Android's developer documentation, which makes no guarantees on what is actually encrypted: "This policy controls encryption of the secure (application data) storage area. Data written to other storage areas may or may not be encrypted, and this policy does not require or control the encryption of any other storage areas."

Things to consider before using this configuration

There are multiple issues that should be taken into consideration when enabling this configuration. None of these issues is something we can affect but are features of the Android platform itself, or features of a specific device type.

  • Device encryption cannot be disabled without wiping the whole device
  • The encryption might not be as secure as required if the device is not secured with a password.

An excerpt from the official documentation: "On some devices, it is possible to encrypt storage without requiring the user to create a device PIN or Password. In this case, the storage is encrypted, but the encryption key may not be fully secured. For maximum security, the administrator should also require (and check for) a pattern, PIN, or password."

In LogMeIn Resolve MDM, this can be seen in the device inventory. If the value for encryption status is Encrypted with user key, it means that the user has set up a password that is used in device encryption. If the value is Encrypted with default key, it means that encryption uses a key generated by the device. The default key is always more unsafe, as in theory, an attacker might be able to extract the password from the device, unlike with a key that only the end user knows. If the values is just Enabled, the device has an older Android version that isn't able to report which is the case.

  • Encrypting the device might require the device to be wiped. We are not aware of devices that actually require a wipe, but according to documentation, this is possible.

An excerpt from the official documentation regarding the encryption dialog states: "However, on some devices this activity may never return, as it may trigger a reboot and in some cases a complete data wipe of the device."

Deploying an encryption configuration to a device

Create a new configuration profile and configure it. Start by navigating to Management > Configuration profiles > Device encryption and creating a restrictions configuration for Android. See  Creating a configuration profile for more details.

Currently, there is only one setting, Device encryption enabled, which has to be enabled for the configuration to do anything.

Disabling encryption configurations

Encryption can only be disabled by wiping the whole device.

Related Articles:
  • Android device management
  • Create a configuration profile
  • Configuration profiles
  • Always on VPN for Android
  • Wiping Android devices
  • Samsung Knox Mobile Enrollment
Article last updated: 6 February, 2025

Need help?

Contact icon Contact support
Manage Cases icon Manage cases
Video icon Watch videos
  • Language selector icon Language selector icon
    • English
    • Français
    • Italiano
    • Deutsch
    • Español
    • Português
    • Nederlands
  • About Us
  • Terms of Service
  • Privacy Policy
  • Trademark
  • Do Not Sell or Share My Personal Info
  • Browse Products
  • Cookie Preferences
  • Copyright © 2025 GoTo Group, Inc. All rights reserved

Collaboration Products

GoTo Connect

GoTo Meeting

GoTo Webinar

GoTo Training

join.me

Grasshopper

OpenVoice

Remote Solutions Products

GoTo Resolve

Rescue

GoToAssist

Access Products

Pro

Central

GoToMyPC