Android Enterprise Customer Community
Recently active
SummaryPublishing a private app via the Managed Google Play iframe embedded in Microsoft Intune (Apps → Android → Add → Managed Google Play app → Private apps) consistently fails with a generic "Can't publish app. Try again in a few minutes." UI error. Inspecting the underlying network request shows the backend RPC call returns an INTERNAL error code.EnvironmentIntune tenant: trial (Intune Plan 1) Managed Google Play enterprise: created via Intune's standard "identity" connection flow (no Google Workspace domain) Device tested against: Android, enrolled via Company Portal as Personally Owned Work Profile, showing Compliant in Intune Browser: [fill in your browser + version] Tested across: original Google account binding, and a completely fresh account after a full retire + unbind + reconnect cycle — same result both times Tested across two networks (to rule out local network/firewall interference) — same result on both after resolving an initial ERR_CONNECTION_CLOSED on one networkStep
Hello, We force users to change regularly the device passcode and I’m getting a request from the support because they receive lot of calls from users that don’t understand what happens. USers are telling the device is blocked on a screen with passcode menus and that they can’t escape it. Some are also wiping the device to resolve the issue …Even if they receive the emails telling them they’ll need to change the device passcode, if they don’t change it, when it expires they are getting a notification that displays less than 1 second and then are locked on the screen to set a pincode / passcode. Question 1 : Are we alone to get this user misunderstanding ?Question 2 : Would it be possible to set a custom message that we would push to help users understanding that their code has expired and that they need to change it ? Best regards
Hello,I took over an IT department with numerous company owned phones. The previous IT department did not use an MDM and did not keep track of login information for the phones. They would create a new gmail account for each phone and allow the end user to create their own PIN. I need to access these phones and put them on the MDM. Thank You, Jason
I am the founder and CEO of EMMI Technologies. For more than ten days, we have been unable to access the Google Play Console controlling our Android healthcare applications.Existing case 3-6206000041891 remains unresolved. Google Workspace Support redirects us to Google Play Support, while Google Play Support redirects us back to Workspace. We cannot access either the Workspace Admin Console or the Play Console.We completed Google’s requested ownership verification, including domain verification through DNS. Support then suggested transferring the applications to another developer account but instructed us to perform the transfer ourselves, despite our inability to access the existing account.Our Android customers urgently require support and application updates that we cannot provide. Our iOS customers continue receiving our improvements because our Apple developer access remains operational.Has anyone found a way to reach a senior Google Play account-access specialist who can take ow
Hello,we would like to ask whether other customers using Samsung devices with Android 16 / One UI 8.5 have observed similar behavior. Environment- Samsung Galaxy tablets e.g. X816B- Android 16 / One UI 8.5- Android Enterprise (COPE) & Intune- Screen Pinning / App Pinning used for dedicated business applications After upgrading affected devices to One UI 8.5, notifications and certain system UI elements can appear while an application is pinned. In our environment, this behavior was not observed before the Android 16 / One UI 8.5 update and appears to be related to a change in the interaction between Screen Pinning and notification handling. This issue represents a significant operational risk for our environment. Prior to Android 16 / One UI 8.5, notifications were effectively suppressed while an application was running in Screen Pinning mode. Since the identified Android framework change, certain notifications can appear despite active Screen Pinning, impacting the intended behavi
We are certified Android Enterprise Mobility Management (EMM) provider and an authorized Zero-touch Reseller based in Bangladesh. We specialize in enterprise mobility, with our proprietary MDM platform, MobiManager, actively used by leading organizations for secure device management at scale. In line with the growing demand for secure and inclusive smartphone access, we’ve developed PayProtect—a custom Device Policy Controller (DPC) tailored to support EMI-based smartphone financing. This solution enables real-time compliance, device-level control, and robust protection against default, thereby minimizing risks for telcos, lenders, and retailers. Now we want to integrate Google’s Device Lock Controller (DLC) for built-in solution for better performance. So how can we make partnership Google’s Device Lock Controller (DLC). Thanks in advance.
I have completed all the Android Enterprise courses and obtained the Expert certification. However, the Zero-touch Enrollment Training still does not show as finished. What steps do I need to take to become a Zero-touch Enrollment Reseller?
Hey, I’m trying to better understand this AMAPI release (May 2026), we currently have issues with our corporate owned personally enabled devices where if a users personal gmail account is added to the personal profile of the device if the device is reset via recovery mode the users pin / personal gmail account is required.We started using EFRP admin emails to bypass this so we could get back into our own devices, we’re a large organisation so users generally don’t reset devices before handing them back or hand them back to their manager who is unaware of our process.What I’d like to understand is what the below change did as after testing this it still seems to be the same that when setting the FRP admin emails setting to be not configured a recovery mode wipe still triggers consumer FRP.AMAPI improves Factory Reset Protection (FRP) policy handling on COPE devices by explicitly disabling FRP and clearing account lists when no admin emails are configured, preventing unexpected lockouts
On BYOD devices with an Android Enterprise work profile (personally-owned work profile, managed by Microsoft Intune), the Google Dialer running in the personal profile does not resolve caller names from work profile contacts on the incoming call screen or in the call log. The number is shown instead of the contact name.Framework-level cross-profile lookup is verified to be working: querying PhoneLookup.ENTERPRISE_CONTENT_FILTER_URI directly via adb returns the correct work contact. Cross-profile contact search from the personal profile also works (work contacts appear under the "Work profile contacts" section in the Dialer/Contacts search UI). Only the number-based caller ID resolution path (incoming call UI and call log) fails.EnvironmentDevices reproduced on: Google Pixel 9a, Android 17, build CP2A.260805.005 Xiaomi 14T Pro (Google Dialer as default dialer), Android 16 BP2A.250605.031.A3, HyperOS 3.0.3.0.WNNJPXM Phone by Google version: 234.0.963599666 (latest from Play Store at ti
We’ve got a fleet of corporate owned and Intune enrolled Android devices. For a couple of years, we’ve leaned on “Enable browser access” in authenticator to install a certificate for chrome and WebView browser access to MS resources. That cert passes device information usually without trouble through our CA policy. This week I have had two devices that are unable to recreate the cert. When attempting to rebuild it, an error pops up but is cut off. It says something to the effect, “Certificate installation was unsuccessful becau…”. Not exactly the most helpful for troubleshooting. So I’ve got a few questions. If we have already cleared all creds and user certs out of advanced security options. is there somewhere else that certificate lives? Are there any ways to grab the full error message, or expand the pop up error?Is there a better way to allow webview to pass device information through to entra?At the first webview launch with the new cert, a popup asks if we want to use the new cer
Hi,We want to use GBoard on kiosk devices but we aren't able to remove the suggestion strip using managed configurations.All other settings can be configured fine though.The show suggestion strip configuration is set to disabled.But with versions 15.x and 16.x of GBoard it's still visible on the devices.And when checking the setting locally on the device it's still enabled (Disabling manually works fine)Back in version 14.x this configuration worked fine.Anyone else who has experienced the same thing?We've tested this on devices from Samsung, Bluebird, ELO, and Zebra.Android version doesn't seem to have any impact, just the GBoard version.// Magnus
Hello Android Enterprise team,We are currently developing our own Enterprise Mobility Management (EMM) solution for Android devices.Our company develops and provides Android devices, and we are working on our own EMM platform, including an EMM console/backend and a Device Policy Controller (DPC) application.We are currently integrating the Android Management API (AMAPI) and understand that Android Device Policy is the standard DPC approach for new EMM solutions.However, we also have our own custom DPC application and would like to understand whether there is still a supported path for getting our custom DPC verified/approved by Android Enterprise.Our questions are: Can a new EMM provider currently have its own custom DPC verified and added to the Android Enterprise approved/allowlisted DPCs? If yes, what is the current process for submitting a custom DPC for Android Enterprise verification and approval? Is there a separate registration or approval process for the custom DPC, or is
My Google Pixel is showing “This device is managed” and says Google LLC has configured this device to be fully managed. I am the current owner/user of the device and do not have access to the organization that enrolled it. The device is scheduled to automatically reset. How can I get this device removed from organization/zero-touch enrollment.
Hello,I'm trying to configure a corporate Wi-Fi network with certificate-based authentication.The connection works fine on an Android smartphone enrolled in Intune in COPE mode, but I can't get it to work on a smartphone enrolled in BYOD mode.I have a fleet of Samsung smartphones, both COPE and BYOD.The certificate is installed on the BYOD smartphones via an Intune PKCS profile, and I followed the recommendations (user-type certificate, Subject name = CN={{UserPrincipalName}}, and adding the SAN: User principal name (UPN) = {{UserPrincipalName}}, I published the CA that issued the certificate).The certificate is correctly installed on the BYOD smartphone and visible in the work profile, but the Wi-Fi connection fails.When I check the Wi-Fi configuration on the BYOD smartphone, there's no client certificate, which can explain the connection failure.Has anyone successfully configured a corporate Wi-Fi network with certificate authentication on a smartphone enrolled in BYOD mode on Intune
Hi Google TeamMy name is Fernando from Kueski Pay. We're currently expanding our mobile phone financing business in MexicoIn the past, we used Android DPC for device management. Recently, Springdel approached us with a solution based on the Android Management APIBefore moving forward, we’d like to confirm whether their implementation complies with Google’s policies and licensing requirements for our use case.Thanks in advance for your supportBest regardsFernandoKueski Pay
I keep getting this error while trying to register, I had ae-community@google.com, but I got a reply saying “Thank you for your interest. Unfortunately, we don't provide specific feedback or details regarding application decisions.”. I need guidance as to what the next steps are? Is there any issue with my DUNS number?
Hi everyone,I need assistance regarding access to the Google Zero-Touch Portal for our organization.The Issue: When attempting to sign in at [partner.android.com/zerotouch](https://partner.android.com/zerotouch), I consistently receive the following error message: 403 - The account doesn't have permission to see this pageCurrent Setup & Troubleshooting Completed: Google Account: A standard Google Account has been created and verified using our custom company domain email address. Reseller Assignment: Our reseller (A1) confirmed that our Customer ID has been set up and that our business email address was added as an Administrator in their reseller portal. Isolation Testing: Login attempts were conducted using an Incognito / Private browser window to eliminate multi-account session conflicts or caching issues. Reseller Feedback: The reseller states that all configurations on their end are correct and that they cannot troubleshoot account or permission issues further within the Go
Allow my device to install other apps and allowed to access Bluetooth
Hello everyone,We recently hosted a session on Android Desktop Windowing for our CAFÉ & Insiders members! It was fantastic to hear directly from you about how your organizations are approaching connected display experiences.If you weren't able to attend (or are not currently part of either of these groups), please see the brief overview below. If you're interested in reading the full recap please join Insiders and let us know that you would like to be part of this project (or comment below). Existing Desktop insiders members can view the extended recap here. What We Talked About:During the session, the Desktop Windowing team discussed the evolution of Android's connected display experience following its official General Availability launch in the Q1 2026 Android release. They went over the four product focus areas for their team, some upcoming features and areas of exploration for future versions of desktop mode. What We Heard:We got great feedback during the live Q&A session
Hi,I had requested for increasing device quota of my Android EMM account. I had filled in the google form under developers.google.com/android/management/permissible-usage#quotas_and_restrictions. Was expecting a response in 14 business days, but even after 20 days there is no response. I do I reach out to the right team for help? Soumik
Hi,Is it possible to use a DPC for the following use case:The DaaS provider leases managed devices to the Business Customer (BC) The BC uses devices for their business purposes (for example, gives managed tablets to their field employees) and pays monthly fee for leasing managed devices If a BC stops paying, the DPC installed by the DaaS provider locks devices and requires to payI have reviewed the DPC permissible usage policy and it looks like it restricts Device Financing solutions for B2C/Retail scenarios.Can you please clarify whether Device-As-a-Service (which may include device financing for B2B) is an officially permitted DPC use case?
Hello,I hope you’re doing well.I would like to know how we can obtain Android Zero-touch reseller status.I couldn’t find any companies in my country (Kazakhstan) that are able to register devices in Android Zero-touch.Could you please let me know if it is possible for our company to become an authorized reseller so that we can register devices ourselves?Thank you in advance for your assistance.
Hello Android Enterprise Community Team,We are developing an enterprise Device Policy Controller (DPC) application for managing company-owned devices via Android Enterprise dedicated device management.Issue Summary:- Our DPC app is hosted on our secure HTTPS enterprise server and provisioned via standard 6-tap QR code onboarding on factory-reset devices.- During provisioning, Google Play Protect blocks the application with the message: "App blocked to protect your device".- The DPC app is strictly used for enterprise device management (Device Owner mode, kiosk enforcement, remote lock/unlock, system restrictions) and does NOT harvest sensitive personal user data (contacts, call logs, SMS, and media are completely disabled).Actions Taken:1. We have verified our DPC APK package name, manifest provisioning activities, and public signing certificate SHA-256 checksums match the QR code bundle contract.2. We have submitted the official Google Play Protect Appeal Form (under Android Enterpris
Hi all, hope you’re well. I was wondering are there any ways to add devices to Google ZTE (Zero-Touch Enrollment) if the vendor can't / refused to do it? Q. Why do the vendor refused to do it?A. Some vendors like Officeworks in Australia does not appear in the Google ZTE resellers list. Q. Why don’t you tell the vendor they need to do the right thing / register with Google?A. Good luck with that……(thank you for your feedback, you won’t hear back from us anytime soon……) We also have other none Samsung Android devices purchased from retailers that’s not in the Google ZTE reseller list. With Samsung devices, we use KME (Knox Mobile Enrolment) and it works well. But for non-Samsung devices, we don’t have many options as far as I know. I’m happy to be proven wrong though 😂 Q. Have you tried to ask other vendors (in the reseller list) to add the device to Google ZTE for you?A. Yes I have tried and it does work, but we don’t want to do this as it’s not their responsibility. Q. Maybe you sho
Hi there,I'm a new developer building an EMM solution on the Android Management API, currently in early integration/testing.Environment:- Android Management API enabled, billing active- New service account created with Android Management User role- New Android Enterprise created via signupUrls/enterprises.create (Gmail-based, not Workspace)- Policy created successfully- Enrollment token and QR code generated successfully with no errorsIssue:When scanning the enrollment QR code on a physical test device (Samsung Galaxy A10e, Android 11), provisioning fails immediately with:"Can't set up device. Since your organization reached its usage limits, this device can't be set up."The device never appears in the Android Management API device list — inventory remains empty. I have zero enrolled devices currently, so this appears to be the known default "Safety Quota" of zero applied to new/unverified projects rather than an actual usage limit being hit.I don't see this quota exposed under IAM &am
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.