Android Enterprise Customer Community
Recently active
Hi everyone,I'm managing a large number of Android tablets in an educational environment. I'm trying to enroll the devices using Android Enterprise with QR code enrollment, but I'm having trouble getting the QR method to appear. So far, only Zero-Touch shows as an option, but most of our devices were not purchased through Zero-Touch resellers, so we can't use that method.My main question is:Is it strictly necessary to use an external MDM (like Miradore, Intune, etc.) to generate the QR code, or is there a way to create and use it directly from the Google Admin console or natively through Android Enterprise?We want to deploy the tablets efficiently and avoid entering accounts manually. Ideally, each device would automatically enroll with our managed Google Play account by scanning a QR code after a factory reset. This is especially important in a school context, where we have many students and limited time for configuration.We are already registered in Google Workspace, and the tablets
I use a corporate device pixel 7 pro phone. I am using pixel watch 3. THe watch app is installed on personal profile and in notifications, I see option to enable work profile apps which I have done already still I don't see the work apps notifications on my watch. I need to understand how to get this working. People using apple phones are easily using their watch to get such notification but everything with google is so confusing and complex. Let me know any easy way to get this implemented. I am disappointed in google products lately as I see my colleagues do same thing very easily with apple devices.
The Managed Play Store and the Google Play iFrame play a major role in Android Enterprise Management and the Collections are important for managing and displaying apps in the Managed Store.Basically, the collections work well, but I also see room for improvement there. These would not only be useful for admins, but also for users. But first a step back:There are two different layouts: Basic and Custom. A collection (or ‘cluster’) can have up to 100 apps.Basic is a single collectionCustom allows up to 30 collections Easier sorting in the iFrameThe apps are sorted in the iFrame using arrows next to the app icons. Especially with large collections, it becomes a task of patience when an app has to be sorted to the back. A drag & drop feature would make customisation much more convenient. Backup / restore of collectionsA restore function for collections was asked for in another topic. In addition to ‘edit’, ‘delete’ and ‘duplicate’, “export” and ‘import’
Hello,i've recently published a new private app to our Managed play Store through the iFrame in Intune.I can assign the app now, install it and search for it on the Work Profile Play Store on my phone but i can't find the app when i want to add it to a collection. We have a few similar private apps already published and these work fine. It is only the most recent one i can't find in the collections. Is there another Sync i am missing or is it a problem with our Managed Play Store? Thanks for the help. BRSeb
I've got a use case for some multi-user Android tablets and I'm trying to figure out the best solution. I know Android allows you to create secondary users by default but it appears that Microsoft Intune is disabling this setting automatically. Doesn't seem to be a way to allow it given that the only options are block or not configured. I put in a ticket with Microsoft and I'm sure their answer will be to use Microsoft Entra Shared Mode and the Managed Home Screen but that doesn't work very well. Also, it appears multi-user functionality is documented by Google and an EMM can set it up so the user can create secondary users using the standard Android settings or the DPC can create the secondary user. Also looks like there's some work to be done as far as making sure the DPC can still manage the secondary users as well.https://developer.android.com/work/dpc/dedicated-devices/multiple-users So I am curious for those using other EMMs: do you allow secondary users on any of your
I'm looking for a way to block the dinosaur game in chrome on Android. I see the AllowDinosaurEasterEgg managed configuration but that is only for desktop Chrome. Are there any plans to implement this for Android? Is there another way to achieve this? This is a high priority request from our customer to the point where we see the only solution is to switch browsers. Thank You
Hello, We're having trouble assigning the default configuration when resellers add phones to our Zero-Touch account. We've successfully linked Intune to the Zero-Touch account. In Intune, there is a fully managed profile. I used this token to create a profile that works, no problem. However, when resellers add new devices, they don't retrieve our default configuration, which is called PROD_INTUNE_FullyManaged, but retrieve a default profile that we haven't configured. It's quite annoying to have to systematically reassign the correct default profile. Thank you for your help on this issue. *Post updated 27 May, 2025 - translated from French to English
Hi all, I'm just wandering about using paid apps on work devices and wanted to know how others here are working with paid apps. Another brand I shall not name makes it possible to purchase apps via a portal and then deploy those apps to your end users. But Google / Managed Google play does not offer such a solution. It makes it difficult to deploy paid apps. While most apps offer license options outside the playstore, not all of them do. How do people on the community deploy paid apps that need to be purchased through the playstore? As said before, just wandering what solutions people use to better advise our customers in such cases. I don't get this question a lot, but every few weeks it pops up somewhere (mainly because we also provide services on the dark side hardware). I'm aware that this has been mentioned a few years ago on this community, but just seeing if this have evolved. Distributing Paid Apps | Android Enterprise Customer Communi
The ability to apply a managed configuration to Gbaord has disappeared. We think this is due to a recent change to the Gboard app where Google has removed this ability. Environment:MDM = Omnissa Workspace One UEM (we are also hearing reports of this impacting SOTI customers as well)Rugged Zebra Mobile devices, majority running either A11 or A13Leads:Managed App configs are still present on Chrome & ServiceNow Now Agent, hence why we believe this is not an MDM Console issue. We have escalated to Omnissa support anyway, who have in turn escalated to Google.Is anyone else seeing this issue?
All of a sudden I'm having issues installing apps through Managed Play on isolated devices. When navigating to the app directly I can see "This item isn't available in your country." The devices are in the US. Location services confirms this, the external device IP is also US based as well. I have cleared cache and app storage of Google Play and Google Play Services. I have upgraded Google Play Services. The devices are fully managed with manage service accounts. I have reset the account assigned to the device. I have tried to set the Country manually in Google Play setting but am unable to do so. It does not show a current country. I also see an option for "Switch to the United States Play Store" but tapping on it doesn't do anything. Any ideas or suggestions here?
I work for an MSP. We have taken on a new customer that has lost the password for their EMM Bind account (EMM is Intune). Has anyone else been through a recover process for this and have any advice? The have approx 200 devices enrolled, so we can't risk them having to be enrolled.
Hi all, Recently joined the community, first time poster here. TL;DR at the bottom. Hopefully my question has a simple solution but I've looked everywhere (except here of course).I'll try to keep this as simple as possible. Everything is in UAT if that matters. The important bits:Pixel 8aBuild BP1A.250505.005.B1No SIM or eSIMAndroid Enterprise registered to my UAT TenantI'm testing some scenarios for automating device compliance with Omnissa using Workspace ONE Intelligence. To test this successfully I'm going to need to flash back to an older Build and probably more than once for demo purposes. The OEM Unlock toggle is not available however, and I this is preventing me from doing my testing.I've read conflicting posts elsewhere regarding carrier unlock, SIM and/or eSIM etc. ADB is working fine but flashing older images is just not working. Any help from the community on how to get OEM unlock enabled would be greatly appreciated. &nbs
Wondering if anyone has come across a way to restore an "app collection" in the Managed Google Play Store? I would like to be able to take a back up and restore the collection should it be deleted in error. On a shared tenant basis and having only 1 account for the MGPS is something we need to have steps in place for.
Hi all,I’m currently experiencing an issue while setting up Intune MDM on Android devices related to restricting copy and paste to unmanaged apps. Specifically, the issue occurs when users copy text from the Teams app and try to paste within teams app.Here's what happens:After copying text, a message "Your organisation's data cannot be pasted here" immediately appears in the clipboard hud. The copied data seems blocked from being viewed, as the error message appears even before a paste attempt.Despite this, users can manually paste the copied content by long-pressing or selecting "Paste" from the text box. However, when trying to use the "paste from clipboard" feature, the warning message above is pasted instead of the copied content.We’ve set the Intune policy to allow copy/paste within managed apps, but the clipboard interaction seems to be problematic, especially with Gboard. It appears that Gboard, possibly due to Android 13 and 14’s Clipboard Editor, is treated as an unm
Hi, I've got a device owner app I've written, it's working well when I install it via a QR code, but I want the stock Pixel / Moto setup wizard to run during / after the device owner setup wizard.I've done quite a lot of research, this doesn't appear to be easy!Any pointers / leads in the right direction to how I might achieve this would be greatly appreciated. Methods, source code to read, etc.Thanks,Richard
I'm stuck with getting DEVICE_POLICY_MANAGEMENT role for my application. DevicePolicyManager reports that my application is active admin (isAdminActive() returns 'true') and device owner (isDeviceOwnerApp() returns 'true'). But role is not assigned ('dumpsys role' reports no holders for android.app.role.DEVICE_POLICY_MANAGEMENT). Pre-requisites for getting this role seem to be fulfilled (like required-components from roles.xml) Found this article from @jasonbayton saying "Only an OEM can grant this permission to an application". Does this mean there's no way for downloaded application to get DEVICE_POLICY_MANAGEMENT role and device's configuration files to be modified for granting this role (config_devicePolicyManagement)? Thank you!
We have a cloud customer on SoTI mobicontrol who wants to block all outbound traffic in their firewall and only allow what is strictly required. I’ve provided the customer with the official system requirements for SOTI MobiControl and Android Enterprise.However, the customer is only familiar with managing Apple devices and is looking to open the absolute minimum necessary for Android Enterprise to function — particularly avoiding wildcard domains (*) where possible.Can anyone help clarify which Android Enterprise network requirements are actually essential, especially when it comes to Google services, and which ones we can safely leave out? No file sharings, and remote control will be allowed by the customer.
Hi everyone, In our MDM Workspace ONE UEM, we are conducting tests to update Google Play applications on corporate devices under the following scenario: New version of a managed app published in the Production track, deployed in High Priority mode to 100% of devices (no staged rollout).The Android devices have a profile installed with the "Auto update" payload configured to "Always auto update", with an all-day window so the update can occur at any time, ignoring the documented restrictions (https://support.google.com/work/android/answer/9350374?hl=en#zippy=).According to our tests, the device updates itself (without manual intervention) in around 10 hours on average. We expected the update to occur more quickly in this scenario, and we require greater agility for Production deployments. Is it normal to wait around 10 hours for an update in this scenario?Is there anything else we can configure to reduce the waiting time? Thank you very much,Vicente
have a question regarding controlling the managed App version upgrade on device and restricting this via Google managed play https://play.google.com/work. Using managed google play app if I use “Revoke app..” option ( Refer screenshot), App will be unapproved from managed play store and removed from device Managed Private playstore followed by uninstallation from the device whenever there is new permission requested or new release has been pushed by app developer? OR App will be just unapproved from managed play store and will not impact any device already installed the app? 2. App getting Unapproved on managed playstore will see any impact on devices if the app was earlier pushed on Devices as the available app via EMM sol. like Intune. AirWatch ( not required / non-mandatory app) and device have not installed this app and now trying to install the
One of our customers is currently onboarded to Airwatch to manage their devices, but they want to move to our Android Management API (AMA) based device management solution. Is there any support available to silently migrate these devices? Or is the only way to wipe the devices and onboard AMA. I see there is support if we own the custom DPC application. But in this case since its owned by Airwatch its out of our control.
We’re seeing an issue with Google Play’s device integrity checks on meeting strong integrity. Is anyone else seeing this error?
Hello guys. Can i get a ideia about the Motorola G05 compatibility with the Android enterprise service and VMWARE MDM
I have added a private app to our managed play store (MS Intune) and followed the steps documented in Distribute private apps to make this available to a partner organization but unfortunately when they attempt to add the app to their UEM solution (Omnissa Workspace ONE) by play store URL they receive a http 404 response and cannot proceed.We have shared an app with them previously (same app, different productFlavor with app id suffix) and that worked seamlessly so we are bit stumped. Reaching out to our respective vendors has not been fruitful so it's not entirely clear what to do next, would appreciate any advice you have!
Hi,Does Google offer any caching service to help reduce bandwidth usage when deploying apps through an EMM solution?For example, in the case of public iOS applications, Apple provides a Content Caching service that speeds up downloads and reduces bandwidth consumption: https://support.apple.com/en-gb/guide/deployment/depde72e125f/web.Regards.
Hi everyone, I’m trying to use client certificate authentication (mTLS) with Chrome Custom Tabs on Android. We want to automatically select the client certificate without prompting the user, and also ask for their username and password as part of the login process. This way, we can combine both certificate-based authentication and user credentials for device attestation. On desktop Chrome, this can be done using a policy like AutoselectCertificateForUrls, but it seems this doesn’t work on Android. If this is a known limitation, is there a way to request this feature from the Android or Chrome team?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.