## TL;DR
The setup pauses until the admin side is ready: the user needs an Intune license, the enrollment must be approved or configured, and managed Google Play must be connected. Fix the admin side, then have the user retry the setup.

## The query
```text
android work profile setup paused: "waiting for your IT admin"
```

## Use this when
- work profile setup shows waiting for your IT admin
- the pause never clears after hours
- one user stuck while others enroll fine

## Not for
- fully managed device enrollment failures
- Company Portal install problems
- work profile creation errors with a specific code

## Steps
1. Confirm the user has an Intune license and is in scope for MDM enrollment. Expected output: license and scope are verified.
2. Check that managed Google Play is connected in the Intune admin center under enrollment. Expected output: the managed Play connection shows healthy.
3. Look for an enrollment approval workflow or enrollment restrictions holding this user. Expected output: any pending approval is found and approved, or restrictions are confirmed clear.
4. Have the user force-stop the setup, then restart work profile creation from the Company Portal. Expected output: setup proceeds past the waiting screen.
5. Confirm the work profile appears and required apps deploy. Expected output: the work profile is active with corporate apps installed.

## Applies to
Microsoft Intune Android Enterprise work profiles, managed Google Play, current Company Portal versions.

## Variant phrasings
### Stuck after a factory reset on a personal device
Old work profile remnants can linger; remove the work account fully before retrying.

### Waiting screen only on Samsung devices
Check Knox enrollment settings; Samsung-specific policies can add an extra gate.

## Why it happens
Android Enterprise enrollment is a handshake between the device, managed Google Play, and Intune. If the admin side is not provisioned, the device waits indefinitely by design.

## Edge cases
- Users with multiple work accounts can confuse the setup; use one account.
- Some carriers delay the initial Play connection; retrying later sometimes clears it.
- Document the enrollment profile type used; personally-owned and corporate-owned flows differ.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_yw2sXMZmA5pauZhKSuMukA
