Android Enterprise Customer Community
Recently active
I have enrolled a device and working fine but after some days when we try to access playstore it show offline mode of playstore. I have attached image for more clarification. What is the actual issue behind that.thanks in advance.
Hello Android Enterprise Community,I am the developer of MDM solution. We are facing a critical issue with Google Play Protect (GPP) blocking our Device Policy Controller (DPC) during enrollment.Issue Description:Error message: “This app can request access to sensitive data” when installing the MDM Agent APK via QR Code provisioning on Android 16 (and some earlier versions). We have thoroughly reviewed and ensured compliance with Google’s guidelines: Warning Dev Guidance , Potentially Harmful Applications (PHAs) , Mobile Unwanted Software (MUwS) We have submitted the Play Protect Appeal multiple times (more than 4 appeals over the past 2 months) via Play Protect appeal . However, our DPC is still being blocked.Our Solution Details:Primary deployment mode: Fully Managed Device (Device Owner). Used exclusively internally within our company (On-Premise environment, no public distribution). Heavily focused on Samsung Galaxy devices - we integrate Samsung Knox SDK for additional policies
Hello, all!My team is looking at deploying a custom XML payload that will disable the user’s ability to enable Wi-Fi Sharing on their Mobile Hotspot. The setting is located here (on Android 16): Settings > Connections > Mobile Hotspot and Tethering > Mobile Hotspot > then under network name and Advanced the option to disable Wi-Fi Sharing is there.Our goal is to configure this option OFF via custom XML and not allow the user to configure it on our managed devices.Initial research showed us that the configuration parameter was:<parm name="AllowWiFiSharingViaHotspot" value="false" type="boolean" />However, testing this didn’t yield any results.I can post the full XML profile if needed, but really what I am looking for is something that may guide me to the configuration parameters that are available to MDM’s.
Hey everyone, Security is one of those topics that never stops evolving and is always relevant. We all get regular training at work and we know that scammers and spammers are getting smarter by the day. At the same time, our phones became such a big part of our lives — which makes protecting them (and the data they hold) more important than ever.Here in the Customer Community and at Android Enterprise, you probably already know how much we value security - so much so that we have created our own security podcast (check our latest episode of The Secure Element here)! The theft protection features can bring a real peace of mind (you can read more about those here), especially the Theft Detection Lock which uses Google AI to detect if someone snatches your phone and automatically locks the screen, keeping your data safe. Now, over to you: which Android security feature feels like a real turning point for you and why? What would you like to see in the future? Is there anything you’d like
Hi everyone,We are a new company currently integrating Android Enterprise using the Android Management API, and we are completely blocked at the onboarding stage due to quota restrictions.As per the documentation, we understand that an initial quota of up to 500 devices requires a business justification, and we have already submitted the required request form. However, we have not received any response or acknowledgment so far.At present, our project is effectively limited to 0 devices, which is preventing us from even beginning integration, testing, or validation of our solution. This is a critical blocker for us, as we are unable to move forward without basic provisioning access.We would appreciate urgent clarification on:Expected turnaround time for initial quota requests Whether there is any way to enable minimal access for development/testing while the request is under review The correct escalation path for such casesThis delay is directly impacting our project timelines and deliv
Following up on the latest episode of The Secure Element with Harsh Lal (Senior Software Engineer, Android Authentication @ Google), we’ve been digging into what passkeys actually mean for businesses — and whether they will be replacing passwords in the near future.Passkeys could be seen as the next step of passwords as they can solve several issues that we’ve all experienced with ‘traditional’ passwords like memorising (or reusing) complex credentials, phishing, storage and security issues. Passkeys also allow us to login using biometrics and bring some interesting implications for B2B and enterprise environments: Cross-device access via password managers Compatibility with enterprise systems Support for hardware tokens (e.g. FIDO keys, YubiKeys) The possibility to revoke access instantly as neededThis sounds like a win-win situation, with both better security and better user experience so could passkeys be the end of passwords? With that comes an important question: how will you get
Dear Android Enterprise Support Team, I am experiencing an issue while attempting to enroll my HONOR Magic V5 device into Microsoft Intune for device management. I just bought the device one week ago, but when I try to add a work profile, I receive the following error message:"Can't add work profile. A work profile can't be added to this HONOR Magic V5. If you have questions, contact your IT admin."This issue is preventing me from completing the enrollment process required by my organization. I have already consulted with my company’s global IT support team, and they confirmed that there is no alternative solution on our side. The only way to resolve this issue is for HONOR to make the HONOR Magic V5 compatible with the Microsoft Intune application and Android Enterprise work profile enrollment.Device Details:Model: HONOR Magic V5OS Version: Magic OS 9.0.1Android version: 15Model: MBH-N49Error Screenshot: attached as below Could you please advise if this device supports
I downloaded the work profil but not showing on the screen on HONOR Magic V5 anyone can help
We’re having an issue with Android Enterprise.We have registered Android Enterprise via and MDM Solution.Now when we detached our Android Enterprise on the MDM solution and enrolled on a new MDM Solution, we can no longer claim the domain and we cant even log in to Android Enterprise either.
Hi,We are experiencing an issue. We have delete our organisation from a user account linked to Sophos Central MDM. This organisation is still bound to multiple end user devices which cannot access the Google Play Store and we cannot enroll any new devices. We have the organisation ID and the user account, we are looking for a way to restore the organisation to the account. Do anyone know if it is possible to reverse what we have done and restore an organisation ID to the account?Regards, MattMc
Hello all, We're facing an issue with our Intune/Managed Google Play connector. Google has deleted the account set up specifically to connect to our Managed Google Play instance in Intune. This has been an active link, with the last new device registered about 2 weeks ago and apps on devices being updated since then. We are currently unable to enroll new devices or add new apps. We are also unable to attempt to recover the account and have not been able to find a way to contact Google directly about the account issue. Barring being able to recover the account, are there ways for us to lessen the impact of creating a new account for the linkage? Or are we going to have to have all our Android BYOD users re-enroll their devices?
Hi All, just wondering if Android Auto will work for fully-managed (COBO) Samsung devices enrolled into Intune, or COPE for that matter? Is there anything official from Google on this? Does anyone have any advice on getting it to work or any gotchas along the way?
Working on a large-scale deployment of Android-based devices with key requirements:• Android 14- Google Play Store support- Compatibility with enterprise MDM platforms- Long-term lifecycle support (5 years OS patches and version upgrades) Specifically looking for guidance on the below:Is GMS certification mandatory for devices that include Google Play Store in such deployments? Is Android Enterprise essential for stable MDM integration? For kiosk / signage use cases, is EDLA certification recommended or required? Any known challenges with 5 years OS patches and version upgrades?
One of our customers has replaced 150 devices currently in zero-touch with 150 new devices. The 150 older devices need to be removed. Is there a way to select and remove them all at once from the zero-touch portal?
Hello,I wanted to know if it is possible to access the applications installed via the Play Store through an MDM without going through the MDM.I found this link:https://play.google.com/work/licenses/appsBut it only shows which applications have been approved to be added to the MDM, and not the number of applications installed on the device fleet.Thank you for your help.Best regards,Titouan
Our enterprise account’s primary contact has left the company, and his email is no longer valid. We are unable to update this information ourselves. We need to regain access to our company account to complete Zero Touch Enrollment for a batch of pending mobile devices.Is there a way to change the primary contact to this account? Any guidance or support would be greatly appreciated. Thank you so much!
Hi everyone,I’m encountering a persistent issue where users on MDM-managed devices (specifically Samsung devices using Knox) are unable to complete the Two-Step Verification (2FA) setup in WhatsApp.Whenever they attempt to set a PIN, they receive the following error:"Not possible to perform two-step authentication at the moment. Please try again in a few hours."After analyzing the system logs, I found strong evidence that the management policies are interrupting the authentication activities. Here are the key findings from the logs: Forced Activity Termination: The system triggers a finishIfPossible command on the 2FA activities (TwoFactorAuthActivity and SettingsTwoFactorAuthActivity) immediately after they are collected in a transition. MDM Policy Interference: The logs show ApplicationPolicy (part of the Knox management layer) checking the state of the WhatsApp package precisely during these transitions. Input Channel Disposal: There are multiple W/InputManager-JNI warnings in
Hi all, I’m currently working on a project involving the CIS level 1 and 2 benchmarks (https://www.cisecurity.org/benchmark/google_android ). The goal is to configure this in an EMM (not choosen yet). Most of the rules listed in that PDF can be matched with an API (its hard work, wish Android had done this as they did for STIG 😂), but there is one that I can’t trace back to an API.In the Managed Google Play store there is a setting called Improve harmful app detection which they recommend to set to enabled. But I don’t want a user to be able to toggle this on or off, I need it to be forced on. Does someone now if its even possible to configure the following via an EMM?
IT administrators can set different policy responses based on the device's Security Risk value, including blocking configuration, clearing company data, and allowing continued registration. The EMM service will enforce this policy response based on the results of each integrity check, and the default option does not allow registration to continue. I don't know how to implement the above requirement. My EMM uses AMAPI, and I couldn't find the corresponding fields that can be implemented in the policy
my company is a ZT reseller in France , but does not appear in the French country list . how can i correct this ?
Hi, As an organisation we are pretty new to ZT. We had good success when testing two devices. We enroll them through ZT and manage through Intune. This worked on our test device (Lenovo Tab K11). I set up a Token separate from the default created on the ZT -> Intune Link. We recently bought 120 Lenovo K11 tablets to set up using the same profile, however we used a new reseller. They added these to our portal. I assigned the token this morning. Then, when I connected the devices to the internet. No profile was present, it continued with the non Dedicated device set up. I did see a message about potentially waiting 48 hours for the profile to apply. Is this accurate? I waited at least 4 hours and no success. Do you have any advice or steps to trouble shoot? We have checked the DPC extras Token is correct and used alternate networks to avoid issues with filtering/firewall. We have run SW upgrades on the tablets and Factory reset and re tried. I trie
HelloWe have started using Datalogic Mobile Computers and I recieved a couple of devices that was running Android 13.I then updated them to Android 15 using Datalogics image and Espresso extension. All good, device is happy.We updated the Scan2Deploy agent on the device to latest version.We then did a Factory reset and wanted to enroll the devices into Intune.I created a simple profile in Scan2Deploy with Wi-Fi setup and enrollment. Scanned the QR at the end but then the device runs through few steps and end up on a screen saying “Getting ready for work setup”. Nothing else. Just stuck there.After an hour I reset the device and created a new profile with my phones Hotspot as Wi-Fi to bypass any possible firewall in our company. But the reaction was the same. I could see that the device got 86.77mb of date on the Hot-spot connection and then stuck at “Getting ready..” again. I tried leaving it for the night but it never moved on.The strange thing, is that the exact same enrollment profi
Dear Sir/ Madam,My name is Dominic Ho from “China Mobile Hong Kong Ltd”, we are one of the Samsung Mobile reseller. We have awarded a tender from Hong Kong Police Force recently. and We have deployed the device to HKPF around 1 weeks ago. we then try to perform the “Zero Touch” registration, however, due to the staff has resigned from Our company, We then mistakely input the wrong password many times, and find out the Google Account (**CM - updated to remove personal information) seems now under the “Account Disable” Status.A.) Appreciate to learn how to re-activate the Google Account (**CM - updated to remove personal information) B.) May be we also need to create another “Backup Account” for preventing this situation happened again.
What is a Managed Google Domain? In Android Enterprise land, a Managed Google Domain refers to using a Google-managed organisation (like Cloud Identity or Google Workspace) to create and manage the connection to an EMM (the bind), it sits in contrast with Managed Google Play accounts, which uses a “personal” Gmail account to manage enterprise devices and apps. In practical terms, it means Android management is tied to an organisation’s work domain (e.g. @company.com), managed through the Google Admin console, rather than being tied to a single @gmail.com account. This approach unifies Android management with other Google services (Workspace, Chrome, etc.) under one organisational account, and is not only the default approach for all newly-binding organisations, but recommended by Google as an upgrade for all existing managed Google Play accounts enterprises due to the benefits it provides to IT admins and employees. Historically, organisa
Hi @CoreyC, @Lizzie, @Emilie_B,as you may remember we still wait for a solution to a reported Wifi Settings issue (in 2024).Our EMM has creaed a Google Case Number also long time ago: 403486364It seem not going forward but we really would like to push for this going further (as i tried now for long time via PM’s etc.). Can you tell me something on this? For anyone else if interested, the issue is:We lock the Wi-Fi settings via Soti Mobicontrol Feature Control profile but keep the possibility for the user to turn it on/off:As soon as it takes place, the Wi-Fi settings are locked (as expected) but the status bar also disables the possibility to turn Wi-Fi on/off: Because of this the user isn’t able to turn Wifi on/off anymore even we allowed it through the profile and it was working before and started (if i remember correctly) with Android 14 and stays still with Android 15 and 16.We want the user again to not do changes on Wifi but being able to turn it on/off if needed.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.