Android Enterprise Customer Community
Recently active
We are using a custom DPC, and a few enterprise customers with critical use case. Because of their strict Change Management (CM) processes, they need at least 60 to 90 days to test and approve any app update.Currently, we suggested to use Managed Google Play and Postpone policies, but there is a problemHere is the exact problem workflow:Day 1: Customer enrolls devices on V1 and applies a 90-day Postpone policy.Next 90 Days: We release V2, V3, and V4 to production to support our other market customers.Around Day 90: The customer’s IT team thoroughly tests and approves V3 from their Management.Issue : The moment the 90-day postponement expires, Managed Google Play automatically pushes the highest available version(V4)The customer wants V3 to be updated in all devices, but Managed Google Play forces them straight to V4.Since our DPC is already live, we can't stop releasing updates for other Customers.How can we solve this issue?
After upgrading my Google Pixel 9 Pro with a personally-owned work profile enrolled in Intune, all the widgets disappeared from my home and lock screens. This is happening to others as well as evidenced by these posts in other communities:Reddit - r/GooglePixel - Widgets gone after android 17 update Reddit - r/GooglePixel - Android 17 causes widgets to disappeare when using Island Google Support - Pixel Phone Help - widgets disappeared from the home screen Google Support - Pixel Phone Help - Widget issues after update to Android 17 Google Issue Tracker #488125748Additionally, I cannot add the widgets back. The widget picker only shows a limited number of widgets and seems to exclude widgets that display personal information. For example, the Google Calendar or Google Tasks widgets. Other widgets that simply function as a shortcut are unaffected.Widgets in the personal profile can be restored by pausing and unpausing the app for the widget you want. However, after rebooting, the widgets
We have two active Zero-touch configurations in our customer account. However, our reseller can’t see any configuration profile while importing devices through the Motorola Zero-touch portal. since reseller can’t see the configuration profile whenever they import device in Zero touch portal devices automatically associate with the default configuration. How can reseller map the devices with appropriate configuration ID when there are multiple configuration profiles configured on google zero touch
Hi there,New to the Android community!I have a problem where my predecessor created an account for the Google Zero Touch portal and used his company phone number for MFA (only method). The phone number is long gone from the company and can’t be used anymore. Is there any chance to recover the account? I know the email and password!If there is not possibility, what steps do I need to do to set up a new one? We have most resellers listed so I believe I I can ask them to change org id. But what about the currently registered devices?
Howdy all,I’m building an internal MDM tool for our small fleet of 22 Samsung tablets.I think I’ve done everything I need to but I can’t enroll a tablet as I don’t have any quota. The API should be enabled on my cloud project and when I look at the quota page, I only see requests-per0minute quotas. What’s the best course of action to increase the quota for a small deployment? I don’t have a DUNS number so the EMM partner form isn’t applicable. Any help is greatly appreciated!Kind regards, - Luke
When the portal asks us to enter the DUNS Number, it gives an error, even though our DUNS Number is valid. Could you help us resolve this issue?
Hello community, I'm writing this post 'cause I'm facing a strange issue with the lock screen setting on our AE devices managed from Intune.The configuration policy was created by my predecessor years ago, and was configured for lock teh screen after one minute. Everything working and all happy.Then I got the request for create an exception group for that, and everything I tried failed.I tried to change the global policy to 5 mins, but it did not worked, and the maximum lock screen time is still one minute.Also remove the setting at all and left it Not Configured didn't had any effect. Then I tried to disable One Lock. With this I was able to change the system lock screen settings but on Settings - Security and Privacy - More Security Settings - Work Profile Security - Use one lock I cannot set anything longer than one minute. Pretty sure this is coming from somewhere in Intune, but also involving Microsoft and sending them the verbose logs wasn't enough.Did any of you ever e
The Scenario: I am currently testing a deployment where I need to manage Android devices as Company-Owned / Device Owner mode. I have already whitelisted and uploaded the device Serial Numbers (S/N) directly into the Google Admin Console inventory. The constraint: I do not want the end-user to input a corporate Google Account during the initial setup wizard, and I am not using a third-party EMM (like MobileIron, Intune, or VMware Workspace ONE). I want to rely strictly on Google Workspace's native Advanced Mobile Management. The Question: How can I seamlessly trigger the Android Device Policy enrollment right out of the box so that the device recognizes its corporate ownership from the S/N inventory without halting at the Google Account sign-in screen?While researching online, I read that it's possible to trigger this native enrollment using a specific Admin QR Code scanned at the initial setup screen (by tapping the screen 6 times). However, information on how to generate or configu
dear community,some days ago i've Retired a Android COPE (Corporate owned work profile enabled) Device from Intune. In Addition, the Device record where also removed from Samsung Knox Mobile Enrollment Service.I've found out, that on the device itself under Device admins the App "Enrollment Service" is in place and cannot be deactivated.Samsung Support told me already, that "Enrollment Service" is not coming from them, this comes from MDM System.Microsoft Support (what a surprise) had absolutely no idea what im talking about.Now, i want to try my luck here in Android Enterprise community.Did someone else had this Situation, especially with Intune?Google Statement about Retire (RELINQUISH_OWNERSHIP)https://developers.google.com/android/management/deprovision-device#relinquish_ownership_commandIn my point of view, the Device should be fully personal after that action.But when a Device Admin App is still in place which cannot be deactivated, this is then weird.For example: If user, who ca
Hello,We implemented an EMM solution using the Android Management API prior to 2024 and were able to successfully test it in our staging environment.As we are now preparing for a production deployment in 2026, we attempted to create a new EMM enrollment token/EMM instance but encountered a "device quota exceeded" message.We are unsure about the current quota policies, and the process for obtaining additional quota or creating a new EMM instance for production use. Could anyone please advise on the next steps or point us to the appropriate documentation or support channel?Any guidance would be greatly appreciated. Thank you in advance.
Hi all,I'm running a self-hosted Fleet MDM instance for personal/homelab use and I'm trying to enroll my own Android phone using a work profile. I've hit the "your organization has reached its usage limits" error during enrollment, despite having zero devices enrolled.Setup details:- Created a brand new Managed Google Play Accounts Enterprise via the "Sign up for Android only" path- Enterprise was created successfully- Enrollment token generated successfully- 0 devices currently enrolled- Enrollment proceeds normally — gets all the way through the work profile setup and hangs on "Updating phone" — then fails with "Your device can't be set up because your organization has exceeded its usage limits" My use case is purely personal — I'm a hobbyist running Fleet MDM at home to manage my own devices, not building a commercial EMM product. Is there any way to get this quota lifted for a single personal device? Is the AE Compliance team the right contact, and if so, how do I reach them?Tha
I am currently using a Microsoft Intune account to connect with the Managed Google Play Admin Console.Due to a company split, I need to change the domain of my Microsoft account (for example, from linon@abc.com to linon@xyz.com) while keeping the same user account.Since the associated Google account will remain unchanged (linon@abc.com), will I still be able to use the updated Microsoft account (linon@xyz.com) to log in to the Managed Google Play Admin Console?
Hello Android Enterprise Community,I am looking for some guidance regarding app publication for our organization. We have developed a custom/line-of-business (LOB) Android app that we need to deploy internally to our managed devices, but I want to make sure we follow the proper procedures.Could anyone share the recommended workflow or best practices for this? Specifically:Is it better to publish the private app directly through our EMM console (using the Managed Google Play iframe) or via the standard Google Play Console? What are the key things to keep in mind regarding Organization IDs to ensure only our targeted devices can see and download the app? How long does the initial publishing/approval process typically take for enterprise private apps?For context, we are currently using [Insert your EMM provider here, e.g., Microsoft Intune, VMware Workspace ONE, Ivanti] to manage our fleet.Any advice, documentation links, or tips from your own deployment experiences would be highly
Hey everyone, This month marks three years of the Android Enterprise Customer Community. 🥳🎂🎊 As someone who joined the team fairly recently, I wasn't around for the first two birthdays, but I've read the posts, heard the stories, and spent the last few months getting to know so many of you. One thing has become very clear: this community is something genuinely special, and it's all of you that make it that way. Thank you.The past year has been a big one, with over a million visits to our corner of the internet, and we wanted to take a moment to reflect on some of what we've been up to together. A bigger family Last July, ChromeOS found a new home here alongside Android Enterprise, and in February this year the Chrome Enterprise community also came onboard as we migrated to our on our new community platform. We're settled in now, and it's already opened up some great cross-product conversations. A very special shout out Before anything else, we want to call out some of our top contri
Hello everyone,We are currently facing an issue where Google Play Protect is blocking our Android application during device provisioning.Context: - It is not distributed via Google Play (but is already published); it is hosted externally and installed during provisioning via QR code.- The app is properly signed, and provisioning works at the system level, but Play Protect blocks the app with the message “App blocked to protect your device.”- This started happening recently on new devices / factory reset devices. We have already submitted the official Play Protect appeal form as recommended in the documentation:The form was completed with all required information (APK, package name, signing certificate, use case, etc.).At this point, we are looking for guidance from the community: - How long does it usually take for the Play Protect appeal form to receive a response or decision?- Is there any additional step or channel recommended for Android Enterprise DPC apps in this s
Hi there,is there any way to distribute Paid Apps in Micrsoft Intune through Managed Google Play Store. It really sucks having the “Buy” Button disabled since there is no alternative App to use. I have also not found any workaround. Is there something I’m missing?
Hi everyone,We are currently facing many difficulties setting up managed Google accounts using the AMAPI library with our Custom DPC.At the beginning, we were doing everything from a single Activity: calling prepareEnvironment() and then starting the managed Google account setup flow. However, we encountered many reliability issues with this approach.We then changed the implementation to use a chain of Workers: one Worker calls prepareEnvironment(); another Worker starts an Activity responsible for performing the account setup. Each Worker can retry up to 3 times when needed. This improved the success rate, but we still have many failures with different types of errors.The most frequent one is:ApiException: 13Most of the time, this one eventually succeeds after the Worker retries.However, depending on the device, and sometimes randomly on the same device, we also get other errors, such as: AndroidDevicePolicyInstallOrUpdateUnrecoverableException SecurityException — this one happens
Hello,we are currently adding EMM functionality to our system, and I wanted to test it first with our own devices. So I requested the initial quota (<500 devices) via the form, but I omitted the fact that we do plan to offer this feature as a paid service in the future.So the current situation is that our application has been denied, and I wanted to ask what the correct way to reapply would be - since the reply said "this decision is final". We already have most of the code ready for testing, but of course I can’t :(Does anybody know how to proceed further the right way? kind regardsStefan
"I am trying to set up Android Management API (AMAPI) for enterprise device management. My organization uses Google Workspace (G Suite). The managed Google Play signup flow at enterprise.google.com/signup rejects G Suite accounts. How can I create an AMAPI enterprise using my Google Workspace domain without a personal Gmail account?
Hello,I’m looking to gather ideas from the community on the best way to distribute an internally developed .apk file to users in China.Android Enterprise and the Google Play Store are not accessible there, so Managed Google Play is also not an option.We are currently exploring alternatives within Microsoft Intune, but so far users have been manually downloading the .apk from a Box folder and installing it on their devices.Has anyone dealt with a similar scenario or found a more scalable or secure approach?Thanks in advance.
Hey! We recently noticed that a banner is displayed on https://play.google.com/work/apps . According to this, /work will be terminated on April 15. I am aware that the page is generally somewhat outdated and is intended for deprecated EMM APIs. (e.g. https://developers.google.com/android/work/play/emm-api/v1/products/approve ) /work has always been useful for us when it comes to getting a first impression of an app. By replacing /store with /work in the store URL, you could see immediately whether the app was available for Managed Play and offered an AppConfig.https://play.google.com/store/apps/details?id=com.google.android.apps.tachyonhttps://play.google.com/work/apps/details?id=com.google.android.apps.tachyon Will the pages be discontinued without replacement, or is there an alternative? (I mean, yes, you can see everything in the iFrame, but the hurdle for /work was very low and therefore very practical).
About two weeks ago, I replaced my work phone, a Samsung A54, with a Samsung A57. On my previous phone, I had a pair of Garmin Vivomove Trend watches connected, and I was receiving notifications from both my personal profile (such as SMS, WhatsApp, Messenger, etc.) and my work profile (such as Outlook, MS Teams, and similar applications).After switching to the Samsung A57, notifications from the work profile stopped appearing on my watch. I have thoroughly checked all Garmin Connect settings, phone settings, and also reviewed the configuration together with our company's administrators to verify whether the issue could be related to the Company Portal settings or any associated policies.The conclusion is that the new Android version appears to block this functionality, and it simply no longer works. I have also found discussions about this issue on various forums.I would like to know whether there are any plans to re-enable or restore this functionality in the future, as receiving work
Hi Community Team,I am facing an issue where my website (https://cloudstream.pk) is not opening properly on the Google Chrome browser (specifically on mobile devices/Android Enterprise managed devices). The site either fails to load completely, shows a connection error, or displays layout breaking issues, whereas it seems to work differently on some other networks or browsers. Could this be related to Chrome's built-in security settings (like HTTPS/SSL enforcement), Android WebView updates, or regional DNS blocking? Please guide me on how to troubleshoot this so that our users can access the website smoothly on Chrome without any errors. Thank you!
According to the documentation of the new portal, admins or owners of the portal have the ability to add devices. However, when as a customer of the portal and owner of it, the devices I try to add are not added. I am always forced to go through the reseller. Would it be possible to delegate the addition of devices to the customer?
Hello everyone, I hope you are doing well. Thank you to all of you have been taking the time to provide feedback via our recent surveys, this is so helpful to our product team. As the survey topics have been on quite an array of areas, I hope you are seeing things come up that resonate with your interests. Today, I’m posting two more community very short surveys. They are unrelated topics, so I’m separating them out to prevent confusion. Below, we have a short survey related to AFW# enrollment: Background to the survey:We are currently seeking to understand the usage and specific business requirements regarding the AFW# enrollment method for Android devices. Your feedback will help us better understand how this method is utilized within enterprise environments. This survey should take less than 3 minutes to complete. What is AFW# enrollment?AFW# is a short identifier (such as afw#EMM) that is entered into the Google account sign-in field during the device setup wizard following a
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.