Android Enterprise Customer Community
Recently active
I wanted to restrict personal emails (with gmail account) from logging into Work GMAIL app for BYOD enrolled devices. I however want workspace accounts to be able to login. When I set modifyAccountsDisabled to true in AMAPI policy, no account can be added (including workspace account). Same problem happens when I specify com.google for accountTypesWithManagementDisabled - no account can log into GMAIL.Is there any solution to this ? Thanks in advance.
Hi, we are currently trialing automatic device enrollment using a Zero Touch Account and baramundi Management Suite as our EMM solution.It all worked well, until I deleted the Android Enterprise account before unlinking it from our Zero Touch account.When I now try to create a new enterprise and link it to our Zero Touch account, it says that it's already linked and I can't proceed to the actual Zero Touch console within the iFrame in the EMM.Sadly I can't change the display language for the iframe. It says "Choose accounts to be linked" and the light grey part next to the checkbox says "already linked". I'm only presented the option to go back and choose another Google account. There doesn't appear to be an option on the web portal version of Zero Touch (https://enterprise.google.com/android/zero-touch/customers/) to unlink the enterprise either. When I try to delete the enterprise it warns me to unlink the Zero Touch account before proceeding and tells me that all ente
We are seeing a spike in HARDWARE_BACKED_EVALUATION_FAILED in https://developers.google.com/android/management/reference/rest/v1/enterprises.devices#securityrisk field in AMA Device response. We are seeing this mostly in the Android 16 customers and for some users it went away without any change on their side. So it does not seem anything wrong with the devices and seems random. Anyone else facing this with AMA or play integrity?
Hi all,Just had a question which might seem quite easy, but couldn't find the answer.I wonder how the number of downloads accompanying an application in the Play store compares to the number of downloads not done manually by a user, but downloads based on apps pushed from an EMM. For several applications, I see relatively low numbers of downloads in the Play store. Based on these low numbers, I can practically guarantee that downloads via Managed Google Play are not included here. In itself plausible, but I have not been able to read anywhere in documentation whether or not this is correct, can anyone confirm this. At the same time if MGP downloads do not count towards the number of downloads listed in the Play Store with the app, are MGP downloads counted separately somewhere? Thank you in advance, Tom
We experiencing issues where we currently are unable to proceed with the enrolment of our Zebra devices to our EMM (WSOne). When we boot the Zebra Handset we get an error Can't finish setup. Zero-touch enrollment isn't avaialble. Check your internet connection and try again. We've tried from different network but getting same error. Their was another post about the same issue affecting Samsung S series devices which apparently samsung has fixed. Not sure how we get that fixed for the Zebra handsets
Hey Everyone, Since a couple of weeks, we are encountering a problem with the re-enrollment of devices that have moved to Android 15. our employees arrive on the next screen :Motorola G54 5G - Zero TouchSamsung Galaxy A35 Android 15 - KMEI reproduced the incident under the following conditions :Step 1 , the device is enrolled on Omnissa WSP1 in COBO with personnal Google AccountStep 2 , for some reasons, the device is erased (example : 10 errors code)Step 3 , the profil in KME or Zero Touch is Microsoft Intune & no more OmnissaStep 4 , It seems that the KME or ZERO Touch verification did not happen at the right time.Step 5 , our employees have to proove the use of the device like a personal device ! We didn't encounter this problem for devices in Android 13 or 14. The devices i used :Motorola g54 5GAndroid 15V1TDS35H.83-20-5-5security patch : 1 july 2025 Samsung A35 - SM-A356BAndroid 15AP3A.240905.015.A2.A356BXXS5BYF3security patch : 1 july 2025
Hey everyone, In ‘5 Overlooked Benefits of Android Enterprise’, we touched on Android zero-touch enrollment, and it’s something many of you are actively using to streamline your device rollouts. For those in IT, Android zero-touch can be a powerful tool - see our handy guide to learn more. It’s about getting devices to your users ready to go, automatically enrolling in your EMM and pulling down all the right policies as soon as they connect. That means less hands-on time for your team and a smoother experience for end-users. We know real-world deployments always have their nuances, but it would be great to hear about your deployment experiences using zero-touch enrollment: Did you overcome any unexpected hurdles? What was the scale of your deployment - a few devices for new joiners, or hundreds for a company-wide refresh? If you could share one key tip or best practice for someone looking to nail their next zero-touch deploymen
Hey everyone, Stop what you’re doing - episode 2 of The Secure Element is out now! Tune in as @Bigdogburr and Theresa Lanowitz, Chief Cybersecurity Evangelist at LevelBlue, dive into achieving cyber resilience in an era of boundaryless computing. Their discussion truly reinforced for me just how vital a holistic approach to securing all end-user computing is - from laptops to mobiles, and everything in between - especially with cyberattacks becoming so sophisticated. The role AI plays in crafting these increasingly targeted attacks was a real eye-opener! This episode got me thinking about the real-world threats we’re all facing. What are the kinds of cyber threats you are most confronted with? Cast your vote in the comment section below: Phishing / Quishing/ Smishing (Email, SMS, or QR code tricks) Deepfakes (Convincing fake video/ voice calls) Malicious apps (Apps designed to steal data/ compromise devices) Network atta
Hi there, hope you're well. Just wondering is it possible to control the Wi-Fi Calling settings within Android via MDM? The closest thing I've seen is to use Knox Asset Intelligence to check Wi-Fi Calling setting status on Samsung devices: https://docs.samsungknox.com/admin/knox-asset-intelligence/dashboard/network-insights/wifi-calling-setting-status/ Thank you for your help & input in advance!
My company is building a startup that utilizes Android boxes, and we want to have a way to provision applications to all of the devices and control their configurations remotely. I had a brief look at "device owner provisioning," and it seems like the right thing. Do we have to use an EMM, or can we use the management API by ourselves? Is there a way to get a technical support on call to discuss the best path for us? Main requirements:- The user does not have to log into the Play Store on the device to receive application updates.- The only application that can be used on the device is the one we provision (Kiosk mode).- Preferably, restrict device settings so only specific settings are visible to the user.- Management of thousands of devices. Constraints:- Devices do not have NFC or a camera.
Hi,I would like to know how to configure the Google Keyboard using Microsoft Intune. Specifically, I need to set up the keyboard with dual language support (Italian and German) on my Android devices managed through Intune.Could anyone help me achieve this goal?
Hello peeps I fancied running automated network connectivity checks in one of my apps. Pulled in the list from the Devices category of network requirements and it looks like one of the OTA cache servers has been down for at least a week. ota-cache2.googlezip.net I raised it quietly but figured it was worth calling out here also.
Hi Team, I'm so sorry to ask this but it is expected that whenever I select the SSID of a Wi-Fi network that contains a SCEP and EAP/TLS configuration, it will show a popup example below? The policy for SCEP and EAP/TLS are already being configured by third-party MDM and we just assume that we don't need to do this manually on each devices.
Hi,We’ve noticed that our Android devices are no longer enrolling automatically, which is resulting in the default profile being applied from the auto-created policy in the Google Zero-Touch customer portal. I’ve reviewed the portal settings, and the correct profile is still assigned by default.This process previously worked as expected.Many thanks,Joe.
We recently signed up as an Android Enterprise Partner through the Android Enterprise Partner Portal. However, we encountered an issue when inputting our DUNS Number—the system returned an error message stating, "Please contact support."This is our second attempt to register; our initial application was declined due to a policy requirement we were unable to fulfill at the time. We would appreciate your guidance or assistance in resolving this issue. If this is not the appropriate channel for support, could you kindly direct us to the correct contact for Android Enterprise Partner assistance ? Thank you for your attention and support.Best regards,
Hi everyone, We are currently managing Samsung enterprise devices via Knox Manage under Android Enterprise DA mode (Device Admin) . Our in-house application previously used the UpdateApplication API to update itself silently without user interaction. This worked well under Android 14. However, after updating to Android 15, this API no longer functions. Based on the Samsung Knox SDK documentation, it appears that UpdateApplication is now restricted to Device Owner (DO) and Profile Owner (PO) apps. We have tried to assign all delegated scopes to our app via Knox Manage policy settings (Android Enterprise → App Restrictions → Delegated Scopes for Apps). Unfortunately, the API call still fails. ✅ What we’re looking for:- Is there any alternative methods that allows silent or managed updates of enterprise apps on Android 15, without being a DO/PO app?- Or is DO/PO elevation now the only viable path?- If so, is there an official onboarding flow or protocol to request
Hi Team, I have created a new configuration item and linked it to Microsoft Intune token.Then I have decided to remove the Intune token configuration before removing the configuration file from Zero touch (which I dont think it should matter). Then I went to remove the configuration item from Zero touch and was getting a strange error message, see below. Now I'm left with a configuration item in Zero touch that I can't remove.Can someone please help or reach out, that would be great. Also, let me know if there is anything else you require from my end.
Hi All, Just wanted to check if someone knows the status of AER certification for the new Oneplus Nord 5 and Nord CE 5. Will the work profile still work without AER certification? Thanks for the help
Hello we are facing a problem some of our Samsung Galaxy XCover 7 devicescan only resolve an internal server with a .local address very slowly.This means that we cannot use the resource, as high latency leads to the connection being terminated.We use our own DNS server which comes with DHCP. If I change the DNS server manually using an app, but to the same DNS server that also comes with DHCP, we can reach the address without any problems and without long latency. (This happens over a VPN tunnel to the dns server)Does anyone have ideas?
Hi,we are in the process to finish our partner registration. But the step on "Enter a D-U-N-S® number for your organization" fails, with an pop-up error of:Something went wrong! If this problem persists, please contact support. DUNS number is correct. Does the portal have an issue? Thanks
Hello,I'm managing Android Enterprise devices via Intune and would like to confirm the behavior of a specific device restriction setting related to NFC.■ Device: AQUOS wish4 (Android), enrolled as a fully managed device■ Policy applied: Device configuration profile with "Beam data using NFC (work-profile level)" set to Block■ Policy configuration path in Intune Admin Center:Microsoft Intune Admin Center > Devices > Manage devices > ConfigurationPlatform: Android EnterpriseProfile type: Template > Device restrictionsConfiguration settings > General- Beam data using NFC (work-profile level): Block○ Background and expectation:My understanding is that this setting is intended to block NFC-based data transfer (i.e., Android Beam) within the work profile.However, I initially assumed it might also block general NFC usage, such as reading contactless transit cards or using mobile wallet services.○ Test scenario and results:A
I'm facing an issue with AMAPI device provisioning.I created a policy, generated a token, built a QR code, and scanned it on a tablet. The device successfully got added under my enterprise (I verified this using the API). However, for the past 2–3 days, while the QR code scanning works, the device gets stuck on the registration screen with a large circular loader for at least 15–20 minutes. After that, I get an option to factory reset the device.Even after the failure message, when I run my script to check for new devices, I can see that the failed device appears under my enterprise. The device's state from the AMAPI response is PROVISIONING.Despite being stuck on the failed screen, I tested sending commands to the device (like reboot and wipe), and surprisingly, they work. This has left me very confused if the device setup failed, how are commands still working?Initially, I thought it might be a device-specific issue, but I tried it on another device (which was never enrolled before),
Hi, We have an issue in our tenant with BYOD device enrollment (Personally owned with Work Profile). We use Intune as EMM. We want to push a WiFi policy to our devices but we do not want to preconfigure auto-connection for our users. Our users must manually connect to the network. The problem is that this setting is not supported for BYOD in Intune, so we have no control over it. In addition, the default behaviour of the devices (tested in Realme, Xiaomi, Nokia, Google, Samsung phones) is that autoconnect is enabled by default. Even if the user disables it, next Intune sync enables it back. Finally, I checked the policy via graph API and I see that: "connectAutomatically": false, "connectWhenNetworkNameIsHidden": false, "wiFiSecurityType": "wpaEnterprise", Is this setting not honored by the OS? Is there anything we can do about it?
Hello,My Zerotouch account is deleted and how we deregistered my already registered device
Hi I am unable to register for the Android Enterprise Partner Portal, It prompts me to enter my corporate email to register but then even with the link used it does not proceed to register.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.