Android Enterprise Customer Community
Recently active
Hello everyone, As mentioned in my other post on; Enterprise Usage of the AFW# Enrollment Method, here is the second survey we have in the community on App Distribution. Just to recap, as you can probably gather these two surveys are not specifically related to each other. 😀 Background to this survey: We are exploring how organizations would like to distribute private apps to unmanaged devices. We want to understand what drives the demand for this capability. Please take a moment to complete this brief survey. This survey should take around 3 minutes to complete. What is an unmanaged device?Unmanaged devices are devices which are used for work that are not fully controlled by an organization's IT policy. As an example, these devices might be personal devices with some work apps on them, or contractor devices which might be managed by another organization. Click to take the survey: here Have more to share? Please share any use cases or experiences to provide additional context. Thanks
Helloi try to upgrade our intune<>google Android Enterprise Connection from a unmanaged gmail account to an entra account (https://techcommunity.microsoft.com/blog/intunecustomersuccess/new-onboarding-flow-to-managing-android-enterprise-devices-with-microsoft-intune/4206602)Unfortunally i get this error screen at the end of the wizard: Any idea whats going wrong here? Microsoft support cant help, since its a google issue. they told me to ask here for help. can someone assist here?Thanksvt
For the Work profile on company owned device mode, when I used iccid to delete esim, my device refused due to permission issues. Is there any solution
i would like to finish my registration in androidenteprise portal, but if i fill in the duns number, then i will get message, that something went wrong. Please could help me ?
We report the version numbers of certain apps on managed devices. I've noticed an unusual update pattern with some apps for some time now.Although we use a payload for Managed Google Play to automatically update public apps, and the affected devices are actively in use, some apps are still running old versions. Updates for some apps simply aren't being performed. The adoption rate for current versions then continues to decline over time. The cause seems to be an Android feature. Unused apps are disabled after a certain amount of time. For example, on Samsung devices, the affected apps are listed under "Deep sleeping apps" in the device's battery settings. In the app settings and in the Play Store, the apps are shown as disabled. It seems that Deep Sleep is preventing updates in Managed Google Play. The affected apps must be launched or enabled manually. In general, I think it’s fine to save device resources by turning off unused apps. But in an enterprise environment, we do want to mai
Hello,I am integrating Android Management API (AMAPI) for dedicated kiosk devices and I am currently blocked during device enrollment.EnvironmentNew Google Cloud project Android Management API enabled Billing enabled and linked to the project New service account New Android Enterprise created EMM successfully linked in Google Workspace Admin Enrollment tokens successfully created through the API Enterprise accessible through API (HTTP 200)Observed behaviorEnrollment token is generated successfully. QR code provisioning starts correctly. During provisioning, Android displays the following error:Can't set up device. Since your organization reached its usage limits, this device can't be set up.The device never appears in Android Management API. Device inventory always remains empty. No policy is attached to the enrollment token. The issue occurs on multiple devices from different manufacturers.DiagnosticsEnterprise accessible: YES Enrollment token creation: YES Access token generation: YE
Hello everyone,I’m currently trying to onboard a Zebra CC6000 device into our Android Enterprise environment, but I’ve run into an issue.When attempting to add the device using the serial number in the portal, the CC6000 model is not available for selection. Because of this, I’m unable to register or assign the device properly via SN-based enrollment.From what I understand, Zebra devices can typically be enrolled using different methods (e.g., QR code / enrollment token or staging tools like StageNow for dedicated devices), but in this case I’m specifically trying to use serial number-based onboarding.Could you please advise:Is the Zebra CC6000 officially supported for serial number (SN) enrollment? Are there any limitations for kiosk-type / dedicated devices like this model? What would be the recommended onboarding method in this scenario? Would it be correct (or supported) to register the device under a different/similar model in the portal?Any guidance or best practices would be gre
Basic set up: Managed Google Play + Intune Devices all set up as "Corporate-owned, fully managed user devices" Policies are set to allow all apps from store and to allow other accounts to be installed on devices. GSuite individual Google accounts with corporate email addresses signed in to all devices to allow for things like Photos backup. Problem: When migrating a user to a new device, some apps cannot be installed. When a user is signed into Google Play with their Google Account, any app that is already linked to their Google Account from their previous device (for example: WhatsApp, Samsung Notes, Translate), cannot be installed with the error "Your administrator has not given you access to this item". If I sign the user out from their Google account, install the app and then sign them in again, it all works fine, but this should not be necessary. It seems like the problem is stemming from the Play Store not liking the fact that th
As far as we have been able to determine Microsoft is not providing APK files of its applications to customers. We have a need to manage MS Edge on some devices located in China and therefore cannot use the Google Play Store or associated MDM tooling. We want to distribute the APK instead as a side-loaded app. Is there a APK provide (APK Mirror or other) that is considered ‘trustworthy’ and/or are people aware of a way to get a trusted APK of MS Edge for distribution via a MDM?
Before I delve into the adb logs, anyone seeing issues enrolling Samsung devices running Android 14? Since a few weeks now, I and a few other users get the error: “Can’t add work profile”. The only way around it is to reset to factory…I did that yesterday and was able to immediately enroll after and today I unenrolled and re-enrolled and got the same error…
hi allWe already have purchased these handsets from a Phone reseller.NOT a google zero touch / enterprise partner.is there any way we can get them onto GZT?please help
Hello,We are looking to implement the functionality to provision eSIM profiles on devices with Android 15+. However, we encountered a telecom provider that requires the EID of the devices before providing us with the eSIM activation code.In this initial stage, we are simply trying to obtain the EIDs of all devices so that we can send them to the telecom provider and receive the eSIM activation code in return. To obtain the EID, we are using the following approach: `euiccManager.createForCardId(slot).eid` However, we are encountering this issue as noted here:*Must have carrier privileges on subscription to read EID for cardId=0 [java.lang.SecurityException: Must have carrier privileges on subscription to read EID for cardId=0]* The same issue occurs with `euiccManager.eid`.According to the documentation mentioned above, Android 15 introduced the possibility of managing eSIM profiles without requiring carrier privileges. However, it seems that the same should also app
Hey everyone,Thank you to everyone who participated in Part 1 of our version control series (if you are only just spotting this, the first survey is still open - take a look here). We’ve already seen some fantastic engagement and insightful comments regarding OS and App version pinning. It appears that having more control over updates—to allow for testing or to ensure stability for business apps—is a point of interest for many of you. As promised, we are now moving on to Part 2, where we shift our focus from "pinning" to rollbacks. While pinning potentially helps provide time for testing and spot issues before they happen, we want to understand your requirements for those moments when an update has already gone out and you need to revert to a previous, stable state. This second part is another quick-fire, anonymous survey that should take less than 3 minutes to complete. Your feedback here is purely exploratory but is extremely helpful for our product team. Similar to our previous su
I know that some new Google Play Console accounts are able to publish apps without completing the testing requirement. However, I don't know exactly how they are doing it. I would like to understand the process and the conditions under which a new Play Console account can publish an app directly to production without going through the testing phase. in individual account
I am using Android Management API to build my own device management system. I am not an Android partner, but I integrated Android Management API into my platform.I successfully enrolled a device, and on the device side it shows as enrolled correctly. Also, in the enrollment history/logs, I can see that the device enrollment was successful.However, the problem is that the device does not appear in the active devices list/system dashboard after enrollment.So currently: The device shows as enrolled on the physical device Enrollment history/logs show successful enrollment But the device is missing from the active/managed devices list Could you please help me understand why this happens and how to resolve it?
Hi @Lizzie,We have Microsoft Intune connected to Managed Google Play since 24/06/2020 using a Gmail account. We have 468 Android devices enrolled and cannot disconnect.When we try to use the Upgrade option in Intune to migrate to a corporate domain account (*hidden), Google returns the error: "Someone at xxx.com.br has already signed up."We cannot identify who originally registered the domain on Android Enterprise side. We need Google support to either:Release/migrate the domain binding so we can reconnect properly through IntuneMicrosoft support confirmed this must be resolved on Google's side. Can you help escalate this? *Email domain hidden in line with Community Guidelines
I am very concerned about the Enhanced GPP features coming soon that are currently being piloted in other regions. https://security.googleblog.com/2023/10/enhanced-google-play-protect-real-time.html This is not a welcome feature whatsoever for the fully managed space where we have business apps written internally that are being installed on business devices, owned by that business. In no way do we want Google sitting in between deciding whether a very legitimate app written internally for an organization should be installed on devices that are purchased and owned by the same organization on fully managed devices. I would like a way to disable GPP completely, or at a minimum whitelist applications from scanning as we don't want Google interfering in the business operations. GPP is a helpful consumer protection features but fully managed devices should have the ability to be opted in or out of the program. Otherwise GPP can incorrectly flag a mission critical app and
Hi everyone I am struggling to create an AE policy for COPE devices (in our case Samsung) to allow developers to sideload apps into the work profile for testing and debugging purposes. We are using Intune and the only policy (beside enable Development mode) which should affect this behavior is enabled: Is there anyone else who tried this already? In our scenario the app is installed via adb install into the personal and work profile. After a few seconds DPC is removing the app from the work profile… 03-17 09:56:09.195 1010307 4220 32308 I clouddpc: [PackageChangeHandlerImpl.kt:handlePackageInstalled:349] CloudDPC didn't request play to install the package com.company.staff.android.debug, and it wasn't sideloaded by CloudDPC.03-17 09:56:09.195 1010307 4220 32308 I clouddpc: [PackageChangeHandlerImpl.kt:resetReapplySchedule:457] About to schedule policy re-apply for : [blockApplicationsEnabled, playStoreMode, crossProfilePolicies, applications]03-17 09:56:09.196 10316 6724 6724 I BudsCon
We’re currently using a mix of Android 13 and 14 devices (specifically Zebra mobile computers). With some recent update, across all applications users see popups to perform autofill on form inputs. We’re currently using SOTI’s Mobicontrol EMM along with SOTI’s Surf browser. So this isn’t limited to Chrome.This also occurs on the Search Apps input field.Is there any way to completely disable this? It’s causing significant impact.
Looking for input from other AMAPI customers / EMM operators.We run a small managed Android fleet using Android Management API +Android Device Policy. The workflow is dedicated-device, kiosk-modeas default state, with periodic supervisor-driven transitions in andout of kiosk for short operational windows.Our pain point is latency on routine kiosk transitions. When we PATCH adevice's policyName from a non_kiosk variant to a kiosk variant, timefrom API call to device-side behaviour change varies enormously: - Best case: ~30 seconds (Cloud DPC awake) - Typical: 3 to 8 minutes - Worst seen: >4 hours (Cloud DPC asleep on idle devices, especially on certain Vivo Funtouch builds)Verified via device.lastStatusReportTime. Cloud DPC on idle devicessimply doesn't check in often. Our own WebSocket channel delivers in<300 ms RTT, so the latency is in the Cloud DPC poll cadence, not inour code or network.What we've already done: - Play Integrity attestation - Stable app
Hi Community,we're running shared Android devices (1,000+) with Microsoft Managed Home Screen (MHS) enrolled via Intune in Dedicated Device mode.The Problem: Users couldn't open PDFs from within apps – the "Open with…" picker dialog never appeared, so files simply didn't open.Microsoft's suggested fix: Add the system app with package ID android to the allowed apps list in MHS and include it in the Device Restrictions policy. After deploying this app, the "Open with…" dialog started appearing correctly and PDF opening works as expected.Before we roll this out to 1,000+ devices, we have two questions:1. What exactly does enabling the android system app unlock? The package android is essentially the Android framework / core OS package. We're not sure what capabilities or UI surfaces get exposed by whitelisting it in MHS beyond the intent picker. Does it give users access to any system settings, dialogs, or functionality they shouldn't have on a kiosk/dedicated device?2. Is there a safer o
I recently updated Android Studio to the latest version, and since the update I am unable to install any plugins from the Marketplace or from disk. Every attempt results in an error saying the plugin cannot be installed or downloaded.Here is what I have already checked: My internet connection is working normally Firewall settings are fully open for Android Studio Proxy settings are configured correctly and match Android’s recommended configuration I also tested the same process on my MacBook, and I get the exact same error I tried restarting Android Studio, invalidating caches, and reinstalling plugins manually — nothing works The issue started only after updating Android Studio It seems like Android Studio is unable to reach the plugin repository even though the network is fine.Question: What could be causing Android Studio (on both Windows and macOS) to fail when installing plugins after an update, and what steps can I take to fix this?
We are observing an issue with Android Management API Lost Mode state synchronization.Issue Summary: When Lost Mode is exited manually by the user on the device (by entering the correct device password/PIN), the device successfully exits Lost Mode locally. However, the Android Management API device resource continues to report the device state as LOST.Environment:Android Management API Android Device Policy Lost Mode initiated using START_LOST_MODE command Device owner / fully managed deviceSteps to Reproduce:Issue START_LOST_MODE command using Android Management API. Device successfully enters Lost Mode. Verify device resource state changes to: "state": "LOST" On the device, manually unlock Lost Mode using the correct device password/PIN. Device exits Lost Mode successfully on the device UI. Fetch device resource again using: enterprises.devices.getObserved Behavior:Device UI exits Lost Mode successfully. However, API response still returns: "appliedState": "LOST" Issuing STOP_LOST_MO
Android Enterprise managed Play application deployment issue observed recently:In multiple deployments, managed applications are correctly approved, assigned, and synced to devices, but installation intermittently fails on select devices with errors related to missing or invalid install IDs (“No install ID found”).Behavior observed: Same application installs successfully on some devices within the same policy/group Affected devices remain stuck in pending/not installed state Policies, compliance, and Play configuration appear correct Issue appears intermittent and difficult to reproduce consistently Troubleshooting already performed: Clearing Google Play Store and Google Play Services data Republishing applications Re-adding apps from Managed Google Play Refreshing/re-syncing devices Reprovisioning affected devices Android bug reports have now been collected from impacted devices for deeper analysis.Interesting edge case because the deployment request successfully reaches
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.