Android Enterprise Customer Community
Recently active
Regarding the function of configuring the login URL, I have configured the signUrl for the enterprise, and then obtained the signinEnrollmentToken of the enterprise through get, and placed its qrcode into the QR code. When I configure the device, my device redirects to the configured signUrl page, and then after successfully logging in by entering the account and password, I need to call enrollmentTokens.create. However, how can I obtain my enterprise id? Is there any good suggestion
***This survey is now closed*** Hello everyone, As 2025 comes to a close and we look toward a new year, this is often an excellent time for reflection. It has been a busy year, and we've so enjoyed speaking with you and seeing the interact with other community members. The Android Enterprise Customer Success team is dedicated to ensuring that our programs and resources—including the Customer Community, The CAFE, and Advisory Services—are useful, enjoyable, and impactful for you and your teams. As we head into 2026, we’d love to hear directly from you! Would you mind sparing less than 5 minutes (I’ve been assured it won’t take a minute more 😀) to complete our Customer Success Products CSAT survey and share your overall experience please? The survey contains multiple sections for each customer programs. Please only select 'Yes' for the area(s) relevant to you. Your honest feedback is vital and will directly influence the improvemen
Hi all, For Apple (iOS/MacOS ) we use the macos security compliance project tooling (https://github.com/usnistgov/macos_security#readme) for mapping compliance guidelines. A short summary: The macOS Security Compliance Project (mSCP) is an open‑source framework that provides automated, customizable security guidance and baselines for macOS, producing documentation, audit checklists, configuration profiles, and remediation scripts. It supports major security standards, including NIST SP 800‑53, NIST SP 800‑171, DISA STIG, CNSSI 1253, CIS Benchmarks, CIS Critical Security Controls v8, CMMC 2.0 Levels 1–2, and the Netherlands BIO baseline. I haven't found such a project for Android, as anyone aware of such a project that maps security guidelines to available API's for Android Enterprise? Michel
I'm developing a custom MDM solution using Google Android Management API. Successfully created enterprise enterprises/LC02x32bm6 with work email domain, but getting:"Can't set up device. Your organization has reached its usage limits."Key Details:Enterprise created successfully via APIEnrollment token generated successfully0 devices currently enrolledCloud Console shows 0% API quota usageBilling account linked to projectGET /api/enterprise/callback → Returns enterpriseNamePOST /api/enterprise/enrollment-token → Returns enrollment tokenDevice enrollment → ❌ "Usage limits" errorHas anyone encountered this "usage limits" error with 0 devices?Android Management API usage is 0%. Any insights appreciated! Happy to share code snippets or API responses if helpful.
Combining zero-touch with the login URL, I'm not sure how to complete this process for my EMM. Regarding the login URL, I'm not sure how to configure it. I'm not quite clear on how these two should be combined
Hi everyone,I'm a developer who helps enterprises build custom DPC (Device Policy Controller) Reference Documentation apps to manage Android devices based on their unique requirements.Recently, Play Protect has started blocking the installation of custom DPC apps, even when these apps are signed and used internally. The warning claims the app may pose a risk due to access to sensitive data - even though it's strictly for enterprise use. To make things more difficult:Google is no longer accepting registration of custom DPC apps with Android Enterprise, which limits official distribution and management options.Android Management APIs don’t support all use cases, and also have quote limit.I’ve applied twice to join the Android Enterprise portal to build a SaaS-based device management platform, but both requests were rejected without a clear reason. My questions for the community:Is there any official way to get a custom DPC app approved or whitelisted by Play Protect?Are there a
Hello,We use QR code provisioning to install our custom Device Policy Controller (DPC) app from a custom download URL (not Google Play).The exact same APK + QR configuration:Works on:Samsung Galaxy S20 — Android 13 / One UI 5.0Blocked on:Samsung Galaxy S21 — Android 14 / One UI 6.1Play Protect stops installation with the message:"App blocked to protect your device. This app can request access to sensitive data. This can increase the risk of identity theft or financial fraud."Provisioning QR:{"android.app.extra.PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME": "<DeviceAdmin component>","android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_CHECKSUM": "<Package checksum>","android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION": "<S3 bucket url>","android.app.extra.PROVISIONING_LOCALE": "en_US","android.app.extra.PROVISIONING_TIME_ZONE": "Europe/Helsinki","android.app.extra.PROVISIONING_LEAVE_ALL_SYSTEM_APPS_ENABLED": false,"android.app.extra.PROVISIONING_DEVICE_A
We are an organization using a third-party MDM / Device Policy Controller (DPC) solution to manage our Android Enterprise devices. The DPC application is published on Google Play and has been working for managed provisioning.Recently, we started facing issues during Android Enterprise enrollment, and we are seeking guidance on the correct and supported setup.Issues observed1. afw#identifier enrollmentWhen attempting enrollment using afw#<identifier>, the setup fails with errors such as invalid token, wrong setup, or unable to continue enrollment.This previously worked and now fails consistently, even though the DPC remains published on Google Play.2. QR code–based provisioningWhen using QR code provisioning, the device completes initial setup but then Google Play Protect shows “App blocked by Play Protect” for the DPC.The DPC app is Play-approved and not sideloaded by end users.We have already submitted a Play Protect appeal through the official appeal form.3. Distribution method
Hey Android Enterprise community,I'm trying to understand what the "Enable third-party Android mobile management" checkbox in Google Admin does. How does this affect situations where multiple Android Enterprises are bound to multiple EMM solutions? Will both Android Enterprise continue working if they are bound to different EMM solutions, even if only one is selected on the screen above?If I use the Enrollment token link method to provision a device and have no users in my Google Workspace, will switching the EMM provider in the dropdown below the checkbox have any effect? Also, does Authenticate Using Google affect provisioning if there are no users in Google Workspace?Thanks,Marko
Greetings everyone! New day, new challenge.I’ve received a number of Zebra tablets. We already use ZTE, which works fine, but as you know it assigns devices to a single profile based on the serial number.The issue is:These tablets (same model) will be used for many different purposes, and I don’t think it’s efficient to take each device out of the box, read the serial number, and manually assign it to a different ZTE profile. I could easily end up managing 200 different profiles.So my question is:Is there a way to let the device choose which group or category it should belong to during enrollment?For example, during setup the device could ask the user which category it belongs to and based on that selection it would automatically join the correct group and receive the appropriate configuration.Is this possible? Or am I dreaming? 😄Has anyone faced this issue and found a good solution?Thanks in advance!
Hello Android Enterprise Community,I am reaching out to seek assistance regarding a quota increase request for the Android Management API.The Issue: Our project has reached its current AMAPI quota limit, which is now impacting our production environment and device deployment. We submitted the official [Quota Increase Request Form] exactly 7 days ago, but we have not yet received any response or confirmation from the Google support team. Project Details:Project ID: [zztcdc]Impact: We are currently unable to enroll new devices or sync policies for our enterprise clients, causing a significant disruption to our business operations.We understand that these requests take time to review, but given the 7-day silence and the critical nature of our deployment, we would greatly appreciate it if any community manager or Google representative could help check the status of our request or escalate it.Thank you for your time and help! Best regards, [Yichen International Trade & Technol
Hi there,I’m looking for clarification on Microsoft's recent update about upgrading tenants from a Managed Google Play account to a Managed Google Domain account in Intune. Intune Android Enterprise Update We have 130+ Android Enterprise devices enrolled in Intune with an old Gmail account we dont have direct access to. Our Intune connection was originally set up using this account back in 2023.Now we have the option to "Upgrade" our account but we need to understand the risks before we proceed.Microsoft says that we can continue managing devices under the new Entra‑linked Managed Google Domain account without deprecating the old method, and without device impact.Is the migration fully in‑place and non-disruptive?Meaning:No need to retire devicesNo re-enrollmentNo break in Managed Google Play syncNo loss of approved apps or assignments Is this migration guaranteed to perform an in-place transition of the administrative account without:Breaking the existing Android Enterp
We have a great wish to place shortcuts for specific apps on the home screen when the app is installed (or at a later point), but this doesn't seem to be possible.When we discuss this with our MDM provider (SOTI), we are told, it is a Google/Android limitation, and this seems a bit strange to me; is it really not possible to place shortcuts on the home screen to your own liking? I hope this resonates with others - or even better; that I can be corrected, and there is a smart and easy way to achieve this goal. We run all our Android devices as fully managed, if that is relevant.
Hi, I am setting up some new Samsung devices with Intune. I have chosen to go with Company Owned Work Profile (COPE). in the work profile, I see a Work Phone app and a Work Messenger app. How can I transfer the info from their existing phone to here? Smart switch will goto the Personal profile. There is a Samsung and Google Account on the phone. How do I verify that the data like text messages (from the work profile) are being backed up to one of those accounts? I can probably move the contacts to outlook so the work profile is syncing that. Also, on the S24Fe I am testing on, it created Messages in the work profile, but on the S25 it didn'tany way to get that to install? Thanks -Joe
Hey Team, I was trying to add another user as Admin in our Zero Touch Portal. However, post adding the user, my Owner Role was downgraded / changed to Admin. How do I get the Owner Role back to my account. Thanks in advance. (This post was edited to remove personal information, in compliance with our guidelines)
Hi All, I'm trying to get the new Google TV Streamer (4k) to get enrolled in Hexnode as device owner. Now getting the Google tv Streamer into the modus seems to be a problem. You need to fill in an google account but when you do that, the device doesn;t allow you to become device owner because there is already an account on it (even when you delete the account). Tried ADB, the App Store etc. Anyone have suggestions or solutions?Regards, Niels
HeyAs I saw that bunch of question have been left unanswered on the expert forum is no one at Google monitoring the feed? I just wanted to post it here as the conversations seem to get more traction here. Is there official thread where feature request could be sent, I have been supporting mobile device management over way over a decade and in that time I have seen all sorts of things and there would be some features that would help greatly in managing enterprise environments with Android. Couple examples:It would be great if there would be a way to deploy some contact numbers to the devices on device address book, such service desk or onsite support number. This is especially needed for dedicated devices which usually do not have any email accounts associated with them and getting common contacts deployed to all devices is quite labor intensive with the current tools. Another one is the OS update management, which is lacking quite a bit, especially as I need to do a comp
Hi today we raised a case with Microsoft for a specific work profile issue with their current Outlook and MS Teams implementation. I wanted to share this here, maybe there are some other customers/admins facing this issue. Our org started to move from Cisco to MS Teams PSTN calling some month ago and everything was fine, but I assume an update to either Outlook or Teams app was published and the issue started. Scenario: COPE or BYODMS Teams and MS Outlook in work profileMS Teams has a PSTN line configured (either mobile or landline) Open Outlook, search for any contact and try to start a call to a mobile or desk number. The OS does not ask whether you like to use the phone on personal profile (as it did the last couple of years 😅) - it will hand over the call request to MS teams! You cannot decide to make the phone call with your Phone app :-( This breaks almost all use cases for our users. Even worse: A phone number like +49 123 828282 is transfered to M
Hi all, we use a Google account in our Ivanti Neurons mobile device management system as an Android Enterprise account to manage the android apps and devices. Our account gets disabled with the following message: "Apparently, this account has been used in a way that violates Google's policy."We are unaware of any policy violation and don't know why this happened. At the moment everything is still working in the mdm, but Google says the account will be deleted in june 2026. Is there anyone from Google who can help me with that and can tell me why this happened?I fear that we will have to re-enroll all android devices if the account is deleted and we cannot find another solution to reactivate the Google account till then. I would appreciate any help. Thank you.
Hi everyone,I’m building an Android Enterprise device management solution and I want to keep everything fully compliant (Android Enterprise + Google Play policies). Use case: a company provides company-owned devices to customers under a leasing / device financing contract. We need to manage this at scale (10,000+ devices) across multiple customers/tenants. If a customer becomes delinquent, the company needs a temporary restricted mode (e.g., kiosk/limited access) until the account is back in good standing — with clear user notice, grace period, and contractual consent. What we want to control at scale: enrollment, policy assignment, app allow/deny lists, kiosk/lock task mode, updates, compliance reporting, and remote actions aligned with Android Enterprise best practices.Questions:Is this type of “restricted mode for delinquency” considered acceptable in the Android Enterprise ecosystem when devices are Company-Owned (Device Owner) and the policy is transparent/contractual?Fo
Hello,For the past two weeks, we have been experiencing issues during the enrollment of some of our devices. After enrollment, the Play Store is empty and no apps will install. This is a problem that has occurred before, and a fix was provided by Google (link). A case is currently open between our MDM vendor, Ivanti, and Google: link. (issue tracker 399818918)Are other people experiencing this issue? Our vendor has indicated that at least one other customer is currently facing the same problem.Best regards
Hey,Not sure if this is at all correct place to address this, but once again when I started to do the renewal for Android Enterprise Expert certification, I though that I would want to ensure the Android Academy is still the correct place to do these, as the material is seriously outdated, even it still factually largely applies, it still seems frankly dumb to read upon features that came out with Android 5.1 - 8.1, and obtain a certification by that way. Also the session that can be enrolled via the portal, are still titled that what is new on Android in 2025, though the session is for this year. If someone has some knowledge of the above would appreciate any info as had to dig abit via various contacts to get info of this community site.
I am unable to register a new device utilizing the Google Services Framework Android ID. Upon entering the ID and clicking the register button, the page is unresponsive. I have tested this on multiple browsers (Chrome, Brave, Firefox) with extensions disabled, but the issue persists. The page simply does not react.
Is anyone observing AMAPI requests for GetApplication and PatchPolicies failing intermittently ? I am observing intermittent failures with the log - "googleapi: Error 503: The service is currently unavailable., backendError".
Hello,I manage a fleet of more than 1,000 Samsung Android devices using Omnissa Workspace One (AirWatch), devices are enrolled in COPE. We use Gmail, Google Calendar, and the native Samsung Contacts app in the work profile, all synchronized through an Exchange ActiveSync connector. Since Wednesday, November 26th, we have been experiencing synchronization issues: - Contacts and calendar events saved on Exchange disappear after some time.- The Calendar app eventually shows an “Unauthorized Action” error and refuses to open.- Gmail continues to sync emails normally. The issue occurs randomly (sometimes after one hour, sometimes longer). Clearing Gmail’s app data and signing in again temporarily resolves the problem, but the issue always comes back. We've tryied uninstalling and reinstalling the app through our MDM but we can only do it user by user and we're not sure about it fixing the issue. We have no means to "rollback" Gmail's version to an older one through our M
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.