Android Enterprise Customer Community
Recently active
Hey everyone, This month marks three years of the Android Enterprise Customer Community. 🥳🎂🎊 As someone who joined the team fairly recently, I wasn't around for the first two birthdays, but I've read the posts, heard the stories, and spent the last few months getting to know so many of you. One thing has become very clear: this community is something genuinely special, and it's all of you that make it that way. Thank you.The past year has been a big one, with over a million visits to our corner of the internet, and we wanted to take a moment to reflect on some of what we've been up to together. A bigger family Last July, ChromeOS found a new home here alongside Android Enterprise, and in February this year the Chrome Enterprise community also came onboard as we migrated to our on our new community platform. We're settled in now, and it's already opened up some great cross-product conversations. A very special shout out Before anything else, we want to call out some of our top contri
Hello everyone,We are currently facing an issue where Google Play Protect is blocking our Android application during device provisioning.Context: - It is not distributed via Google Play (but is already published); it is hosted externally and installed during provisioning via QR code.- The app is properly signed, and provisioning works at the system level, but Play Protect blocks the app with the message “App blocked to protect your device.”- This started happening recently on new devices / factory reset devices. We have already submitted the official Play Protect appeal form as recommended in the documentation:The form was completed with all required information (APK, package name, signing certificate, use case, etc.).At this point, we are looking for guidance from the community: - How long does it usually take for the Play Protect appeal form to receive a response or decision?- Is there any additional step or channel recommended for Android Enterprise DPC apps in this s
Hi there,is there any way to distribute Paid Apps in Micrsoft Intune through Managed Google Play Store. It really sucks having the “Buy” Button disabled since there is no alternative App to use. I have also not found any workaround. Is there something I’m missing?
This blog post says it's now generally available but I'm not seeing it live in my tenant yet: What’s new in Microsoft Intune – MayFor those that don't know, Microsoft has been using Company Portal as their custom DPC but is now transitioning to Google’s Device Policy app to get in line with Google’s mandates. This means (among other things), enrollment will happen at http://aka.ms/enrollymyandroid instead of through the Company Portal app.If they've rolled it out to your tenant, it will look like the first image in this other blog post when you go to Devices > Android > Enrollment > Personally-owned work profile.I am curious if this is live for anyone else. Methinks Microsoft has a weird interpretation of "generally available".
Hi everyone,We are currently facing many difficulties setting up managed Google accounts using the AMAPI library with our Custom DPC.At the beginning, we were doing everything from a single Activity: calling prepareEnvironment() and then starting the managed Google account setup flow. However, we encountered many reliability issues with this approach.We then changed the implementation to use a chain of Workers: one Worker calls prepareEnvironment(); another Worker starts an Activity responsible for performing the account setup. Each Worker can retry up to 3 times when needed. This improved the success rate, but we still have many failures with different types of errors.The most frequent one is:ApiException: 13Most of the time, this one eventually succeeds after the Worker retries.However, depending on the device, and sometimes randomly on the same device, we also get other errors, such as: AndroidDevicePolicyInstallOrUpdateUnrecoverableException SecurityException — this one happens
Hello,we are currently adding EMM functionality to our system, and I wanted to test it first with our own devices. So I requested the initial quota (<500 devices) via the form, but I omitted the fact that we do plan to offer this feature as a paid service in the future.So the current situation is that our application has been denied, and I wanted to ask what the correct way to reapply would be - since the reply said "this decision is final". We already have most of the code ready for testing, but of course I can’t :(Does anybody know how to proceed further the right way? kind regardsStefan
"I am trying to set up Android Management API (AMAPI) for enterprise device management. My organization uses Google Workspace (G Suite). The managed Google Play signup flow at enterprise.google.com/signup rejects G Suite accounts. How can I create an AMAPI enterprise using my Google Workspace domain without a personal Gmail account?
Hello,I’m looking to gather ideas from the community on the best way to distribute an internally developed .apk file to users in China.Android Enterprise and the Google Play Store are not accessible there, so Managed Google Play is also not an option.We are currently exploring alternatives within Microsoft Intune, but so far users have been manually downloading the .apk from a Box folder and installing it on their devices.Has anyone dealt with a similar scenario or found a more scalable or secure approach?Thanks in advance.
Hey! We recently noticed that a banner is displayed on https://play.google.com/work/apps . According to this, /work will be terminated on April 15. I am aware that the page is generally somewhat outdated and is intended for deprecated EMM APIs. (e.g. https://developers.google.com/android/work/play/emm-api/v1/products/approve ) /work has always been useful for us when it comes to getting a first impression of an app. By replacing /store with /work in the store URL, you could see immediately whether the app was available for Managed Play and offered an AppConfig.https://play.google.com/store/apps/details?id=com.google.android.apps.tachyonhttps://play.google.com/work/apps/details?id=com.google.android.apps.tachyon Will the pages be discontinued without replacement, or is there an alternative? (I mean, yes, you can see everything in the iFrame, but the hurdle for /work was very low and therefore very practical).
About two weeks ago, I replaced my work phone, a Samsung A54, with a Samsung A57. On my previous phone, I had a pair of Garmin Vivomove Trend watches connected, and I was receiving notifications from both my personal profile (such as SMS, WhatsApp, Messenger, etc.) and my work profile (such as Outlook, MS Teams, and similar applications).After switching to the Samsung A57, notifications from the work profile stopped appearing on my watch. I have thoroughly checked all Garmin Connect settings, phone settings, and also reviewed the configuration together with our company's administrators to verify whether the issue could be related to the Company Portal settings or any associated policies.The conclusion is that the new Android version appears to block this functionality, and it simply no longer works. I have also found discussions about this issue on various forums.I would like to know whether there are any plans to re-enable or restore this functionality in the future, as receiving work
Hi Community Team,I am facing an issue where my website (https://cloudstream.pk) is not opening properly on the Google Chrome browser (specifically on mobile devices/Android Enterprise managed devices). The site either fails to load completely, shows a connection error, or displays layout breaking issues, whereas it seems to work differently on some other networks or browsers. Could this be related to Chrome's built-in security settings (like HTTPS/SSL enforcement), Android WebView updates, or regional DNS blocking? Please guide me on how to troubleshoot this so that our users can access the website smoothly on Chrome without any errors. Thank you!
Hello,I'm trying to configure a corporate Wi-Fi network with certificate-based authentication.The connection works fine on an Android smartphone enrolled in Intune in COPE mode, but I can't get it to work on a smartphone enrolled in BYOD mode.I have a fleet of Samsung smartphones, both COPE and BYOD.The certificate is installed on the BYOD smartphones via an Intune PKCS profile, and I followed the recommendations (user-type certificate, Subject name = CN={{UserPrincipalName}}, and adding the SAN: User principal name (UPN) = {{UserPrincipalName}}, I published the CA that issued the certificate).The certificate is correctly installed on the BYOD smartphone and visible in the work profile, but the Wi-Fi connection fails.When I check the Wi-Fi configuration on the BYOD smartphone, there's no client certificate, which can explain the connection failure.Has anyone successfully configured a corporate Wi-Fi network with certificate authentication on a smartphone enrolled in BYOD mode on Intune
According to the documentation of the new portal, admins or owners of the portal have the ability to add devices. However, when as a customer of the portal and owner of it, the devices I try to add are not added. I am always forced to go through the reseller. Would it be possible to delegate the addition of devices to the customer?
Hello everyone, I hope you are doing well. Thank you to all of you have been taking the time to provide feedback via our recent surveys, this is so helpful to our product team. As the survey topics have been on quite an array of areas, I hope you are seeing things come up that resonate with your interests. Today, I’m posting two more community very short surveys. They are unrelated topics, so I’m separating them out to prevent confusion. Below, we have a short survey related to AFW# enrollment: Background to the survey:We are currently seeking to understand the usage and specific business requirements regarding the AFW# enrollment method for Android devices. Your feedback will help us better understand how this method is utilized within enterprise environments. This survey should take less than 3 minutes to complete. What is AFW# enrollment?AFW# is a short identifier (such as afw#EMM) that is entered into the Google account sign-in field during the device setup wizard following a
Hello everyone, As mentioned in my other post on; Enterprise Usage of the AFW# Enrollment Method, here is the second survey we have in the community on App Distribution. Just to recap, as you can probably gather these two surveys are not specifically related to each other. 😀 Background to this survey: We are exploring how organizations would like to distribute private apps to unmanaged devices. We want to understand what drives the demand for this capability. Please take a moment to complete this brief survey. This survey should take around 3 minutes to complete. What is an unmanaged device?Unmanaged devices are devices which are used for work that are not fully controlled by an organization's IT policy. As an example, these devices might be personal devices with some work apps on them, or contractor devices which might be managed by another organization. Click to take the survey: here Have more to share? Please share any use cases or experiences to provide additional context. Thanks
Helloi try to upgrade our intune<>google Android Enterprise Connection from a unmanaged gmail account to an entra account (https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-onboarding-flow-to-managing-android-enterprise-devices-with-microsoft-intune/4206602)Unfortunally i get this error screen at the end of the wizard: Any idea whats going wrong here? Microsoft support cant help, since its a google issue. they told me to ask here for help. can someone assist here?Thanksvt
For the Work profile on company owned device mode, when I used iccid to delete esim, my device refused due to permission issues. Is there any solution
i would like to finish my registration in androidenteprise portal, but if i fill in the duns number, then i will get message, that something went wrong. Please could help me ?
We report the version numbers of certain apps on managed devices. I've noticed an unusual update pattern with some apps for some time now.Although we use a payload for Managed Google Play to automatically update public apps, and the affected devices are actively in use, some apps are still running old versions. Updates for some apps simply aren't being performed. The adoption rate for current versions then continues to decline over time. The cause seems to be an Android feature. Unused apps are disabled after a certain amount of time. For example, on Samsung devices, the affected apps are listed under "Deep sleeping apps" in the device's battery settings. In the app settings and in the Play Store, the apps are shown as disabled. It seems that Deep Sleep is preventing updates in Managed Google Play. The affected apps must be launched or enabled manually. In general, I think it’s fine to save device resources by turning off unused apps. But in an enterprise environment, we do want to mai
Hello,I am integrating Android Management API (AMAPI) for dedicated kiosk devices and I am currently blocked during device enrollment.EnvironmentNew Google Cloud project Android Management API enabled Billing enabled and linked to the project New service account New Android Enterprise created EMM successfully linked in Google Workspace Admin Enrollment tokens successfully created through the API Enterprise accessible through API (HTTP 200)Observed behaviorEnrollment token is generated successfully. QR code provisioning starts correctly. During provisioning, Android displays the following error:Can't set up device. Since your organization reached its usage limits, this device can't be set up.The device never appears in Android Management API. Device inventory always remains empty. No policy is attached to the enrollment token. The issue occurs on multiple devices from different manufacturers.DiagnosticsEnterprise accessible: YES Enrollment token creation: YES Access token generation: YE
Hello everyone,I’m currently trying to onboard a Zebra CC6000 device into our Android Enterprise environment, but I’ve run into an issue.When attempting to add the device using the serial number in the portal, the CC6000 model is not available for selection. Because of this, I’m unable to register or assign the device properly via SN-based enrollment.From what I understand, Zebra devices can typically be enrolled using different methods (e.g., QR code / enrollment token or staging tools like StageNow for dedicated devices), but in this case I’m specifically trying to use serial number-based onboarding.Could you please advise:Is the Zebra CC6000 officially supported for serial number (SN) enrollment? Are there any limitations for kiosk-type / dedicated devices like this model? What would be the recommended onboarding method in this scenario? Would it be correct (or supported) to register the device under a different/similar model in the portal?Any guidance or best practices would be gre
Basic set up: Managed Google Play + Intune Devices all set up as "Corporate-owned, fully managed user devices" Policies are set to allow all apps from store and to allow other accounts to be installed on devices. GSuite individual Google accounts with corporate email addresses signed in to all devices to allow for things like Photos backup. Problem: When migrating a user to a new device, some apps cannot be installed. When a user is signed into Google Play with their Google Account, any app that is already linked to their Google Account from their previous device (for example: WhatsApp, Samsung Notes, Translate), cannot be installed with the error "Your administrator has not given you access to this item". If I sign the user out from their Google account, install the app and then sign them in again, it all works fine, but this should not be necessary. It seems like the problem is stemming from the Play Store not liking the fact that th
As far as we have been able to determine Microsoft is not providing APK files of its applications to customers. We have a need to manage MS Edge on some devices located in China and therefore cannot use the Google Play Store or associated MDM tooling. We want to distribute the APK instead as a side-loaded app. Is there a APK provide (APK Mirror or other) that is considered ‘trustworthy’ and/or are people aware of a way to get a trusted APK of MS Edge for distribution via a MDM?
Before I delve into the adb logs, anyone seeing issues enrolling Samsung devices running Android 14? Since a few weeks now, I and a few other users get the error: “Can’t add work profile”. The only way around it is to reset to factory…I did that yesterday and was able to immediately enroll after and today I unenrolled and re-enrolled and got the same error…
hi allWe already have purchased these handsets from a Phone reseller.NOT a google zero touch / enterprise partner.is there any way we can get them onto GZT?please help
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.