General discussions
Recently active
Following Samsung's decision to start sunsetting Samsung Messages (and recommending Google Messages) on newer devices we are now evaluating GM across our estate. Devices are managed by Intune and we can see we can push App Config for RCS Messages and Archiving via the Config designer but after opening up GM I get the "Use Gemini" in my face. Currently we don't use Gemini on our devices - infact we remove it. I have found the option under Settings in GM to Hide the Gemini button but it would be good if we could push that config down with the App......searching round not found anything to date - any thoughts?
Hello everyone,We have the problem that when I want to make the Google Calendar app available on a COPE device, it crashes after the welcome screen with the message "action not allowed".On Work Profile Only/BYOD it works without any problems. Are you aware of this problem?Could this be related to Intune automatically/default blocking the Google accounts in COPE? Thanks,Regards,Daniel
Hi Team, Is there currently an issue uploading a bulk .csv file to ZeroTouch?It's giving me an error. See below. Steps below:I downloaded the sample .csv file then updated it with my data, then uploading it again to the portal as is without changing the name or file extension as seeing above, yet its giving me an error.This was working not long ago, just wondering if there is currently an issue. Thanks
Hello everyone, I am implementing a custom Device Policy Controller (DPC) (device owner mode) and integrating the Android Management API (AMAPI) locally on the device using:EnvironmentClient.prepareEnvironment()AccountSetupClient.startAccountSetup()Both calls happen directly after device enrollment, inside a flow that starts within minutes after provisioning.Most of the time, everything works perfectly.However, randomly, prepareEnvironment() fails immediately after enrollment with: java.lang.SecurityException: Permission denied to call Android Device Policy app. And once this error happens, all subsequent calls to AMAPI continue to fail with the same exception — until the device is rebooted. After reboot, AMAPI works normally again.Sometimes onboarding works the first time, sometimes not, with no changes in our code or provisioning steps.We consistently see repeated Google Play Services / Dynamite module errors whenever the failure occurs:Invalid module.yaml info for apk
OnePlus 15 not listed in the AER(Android Enterprise Recommended) devicesHello Everyone, I've noticed that the OnePlus 15 is not included in the Android Enterprise Recommended (AER) devices list, which can be found here: https://androidenterprisepartners.withgoogle.com/devices/#!?search=Oneplus. While the OnePlus 13 is currently listed, I'm curious to know when the OnePlus 15 might be added. I discovered that the absence of the OnePlus 15 from the AER list is not allowing work profile to be installed on my oneplus 15. Could someone provide insight into whether the OnePlus 15 will be added to the AER list in the near future? Your guidance would be greatly appreciated.
Hi @emrekacmaz057 Thank you for your message and welcome to the customer community! I have translated your message - see your original post below - to make it easier for English speaking community members to respond. Original title: 'İki sAattir su iş profiline giremedim . Biriniz anlatın lütfen' Translation: 'I haven't been able to access this job profile for two hours. Someone please tell me.' Thank you, Emilie
as per : ZTE Portal - no account found | Android Enterprise and ChromeOS Customer Communities - 4093 I'm an admin of a Google workspace instance, let's call it Acme, LLC. This is Google Workspace Business Plus I'm an admin (not owner) of a Android Zero Touch instance, with the ability to make changes to:ConfigsDevicesUsersResellers, etc I've logged into Workspace.google.com for Acme, Inc. Gone to Devices, Mobile & Endpoints, Settings, Enrollment, Manage Zero Touch devices, Link, log in using AZTE user and get the rather lovely: MDM is set to advanced, by the way
Hello everyone, I hope you are doing well. Last year we asked you here in the community about your interest in a possible security certification, we had a great response (and we will be providing an update on this soon).We wanted to expand this further to gauge your interest in providing Android Enterprise training modules. While some of you might be familiar with our Partner Academy resources, this would be specifically looking at training content tailored to your needs as a customer.It would be great to hear you thoughts. Please take a moment to answer the short poll below (or click here to view the form in separate tab). If you have any additional thoughts/details you'd like to share, please add a comment in this thread. Massive thank you for your time and we look forward to hearing what you think. Lizzie Loading…
Hi all, I'm running into a blocking issue provisioning brand-new (and factory-reset) Lenovo Tab M11 - TB311FU devices on Android 15 with Android Management API (fully managed / dedicated, kiosk).On Android 14 everything worked fine with the exact same policy and enrollment flow.The issue only started after updating to Android 15. (this is my test device, i constantly factory reset it) Expected behavior:Standard QR (6-tap) provisioning to proceed past the “Accept Google Services” screen, install Android Device Policy, enroll to my enterprise, and apply the kiosk policy, install app, and done.What happens instead:After Wi-Fi and scanning the AMAPI QR token, Setup Wizard reaches “Accept Google Services”.Tapping Accept shows a spinner, then it returns to the same screen (loop). I simply cannot get past this point.If I reboot at this point, on the very first Welcome screen the device sometimes becomes unresponsive (neither 6-tap nor “Next” reacts) until I factory reset again. 
We're building an Emm solution so while testing I enabled FRP and thought of giving it a shot.So, after factory resetting all i can see is a google window asking me to verify with the account that was previously in the device. What I cannot understand is there was no account signed in except the one google created ( the managed account with the briefcase thingy ).I'd like to understand how can i recover it now? i do have some of the device details on enterprise.devices.get endpoint.Any help would be much appreciated!Rino.
So, we were developing our EMM solution (almost done), and now for deployment purposes, we had to apply for an initial quota via the form.apparently we got a rejection email, stating the use case violates the permissible usages which i've ready and doesnt look like we do.I'd like to reach out to those folks (or if someone can help me connect to them) and try to understand their POV and clarify in case of any mis-phrasing from my side (since english isn't my first language)Regards, Rino James
Hi, I have a situation similar to this older discussion - situation as follows:My EMM is MS Intune.Managed Goole Play Store was set up in April 2024 before the new method of creating Android Enterprise admin accounts on a managed Google domain - using a normal Gmail accountThis Gmail/Google account was forcibly deleted in the last month, presumably for inactivity, as the first linked discussion describes.Only the final termination email was ever sent to the recovery email, no other warnings were received.Recovery was not possible (it just said that no recovery methods were set up, even though there was a recovery email - hence the warnings...!) and now the account shows as nonexistent rather than potentially recoverable, although it's less than the quoted 30 days that recovery is available.I have seen (Community Manager) Lizzie's helpful posts and advice from a couple of years ago, including this article describing the potential for having support migrate the EMM bind from one acc
Friends!Lately Im getting lots of cases regarding apps not starting on our dedicated devices managed in Intune. Edge is the most common problem.If I start Google Play on an effected device I see that the app is disabled. Pressing the Enable button does nothing at all. The version of Edge installed is quite old, which is also strange since it should update automatically.Only way to fix it is to reinstall the app.Any ideas what the root cause can be and how to mitigate it?
Hello,Our users' Samsung smartphones are enrolled in Intune in COPE mode. We have a configuration profile that requires a device unlock code with an expiration time. We haven't configured a code for the work profile, so the One Lock setting is enabled by default.In Android 15, following the expiration of the unlock code, the user is now required to change the unlock code. However, once they do so, when they launch an app in the work profile, the smartphone also asks them to change the work profile code.I don't understand why the smartphone is asking to change the work profile code when the One Lock setting is enabled. Is anyone else having the same problem? Benjamin
Hi, We own and manage an asset management solution used by various clients. Recently (in the last 12 months) we have implemented an MDM/EMM type of solution that uses the Android Management API to enrol/register devices and assist clients with their asset management processes and managing risk through the Android Management API. Now, from an Android Management API perspective, we understand the permissible usage policies and believe we do comply with the requirement. When we originally started the endeavour, the quota on how many device can be registered was a default of 500 devices. We recently noted when some clients try to enrol/register devices, that during the set up process on their devices, that it states that they have reached the usage capacity limits. When we checked the project(s) associated with the clients, most have between 200 - 380 devices enrolled/registered which is below the 500 device qouta. More recently, we noted that the Android Management API
During a recent review, we noticed that some of the Android Enterprise dependencies we use — specifically opencensus-api and opencensus-contrib-http-util — have not been updated for several years. --> Last release: 0.31.1 (April 29, 2022)These libraries are currently required as dependencies for google-http-client.jar, which we use to initialize HTTP clients for API calls.If we exclude the OpenCensus jars, the application fails at runtime with missing class errors. Therefore, these jars are currently mandatory for successful execution.However, from a security perspective, our central security team does not allow bundling outdated or unsupported dependencies.We would appreciate your guidance on the following points:Are there any plans to update or refactor google-http-client.jar to remove or upgrade its dependency on the legacy OpenCensus libraries?Is there an alternative approach or supported path to use OpenTelemetry (or any other supported telemetry library) in place of OpenCensus
Hey everyone, Episode 3 of The Secure Element went live last month! @Bigdogburr (our go-to security expert) sat down with Brian Wood from Google’s Device Security and Privacy team to unpack how devices get approved for use in the US federal government. Spoiler: it’s not simple! From government-approved labs running tests, to annual re-certifications, to the role of NIAP (National Information Assurance Partnership) — there’s a lot going on behind the scenes to make sure devices are truly secure and trustworthy. When you’re looking at new devices, do you pay attention to security certifications or accreditations? If so, what certifications are you most interested in your region? Or do you focus on something else entirely? Let me know your thoughts below — I’d love to hear how you approach this! Chat soon,Emilie
Hello community, I am trying to install a client certificate on fully managed Android devices. The devices have been enrolled via Android Management API. The docs show that there is a OncCertificateProvider policy, but it says it is "not generally available". What does that mean? Will it be available in the future? Where can I apply for using this policy? The specific thing I want to achieve is configuring Cisco AnyConnect/SecureClient with cert authentication. The managed config of the Cisco app allows me to set a "KeyChain Certificate Alias", but I first need to get the cert into the Android KeyChain somehow. I also tried to send the client cert via openNetworkConfiguration, but it does not appear in the key chain (in the settings app) of the device, although the policy is applied without any problems (as reported by Android Management API). I guess those certs here are only used for network config and not stored in the key chain for usage with e.g. VPN apps. Than
Hi there! I am implementing Zero Touch enrollment for our newly purchased Android devices. It is working well and our testing devices end up in "Fully Managed" state after enrollment. I have been wondering if the enrollment could be adjusted so the device ends up in "Work profile on corporate-owned" (WPCO) state instead. I have done a little research and Android spec should allow a device to end up in WPCO state after it is enrolled via Zero Touch. Is this end result achievable with following combination?Device: Samsung with Android 14Enrollment: Zero Touch during device setupEMM: Google WorkspaceGoogle Workspace AFAIK does not have any switch for this in UI.Could the management mode be configured during Zero Touch by using DPC extras set in Zero Touch portal? Developer oriented documentation suggests this is governed by EXTRA_PROVISIONING_MODE.I have tried following Custom Configurations in Google Zero Touch portal so far (all targeting com.google.an
Hello, good afternoon everyone. I'm writing to this forum to ask for help. A few weeks ago, I applied for the EMM and Enterprise Android Partner program. My application was rejected without any explanation in the emails. I'd like to know the requirements to join the program. We are a development company based in Guatemala and the United States (and soon in Mexico and Colombia), as we currently have a client requesting an MDM system for their Android device retail store.This is our first time applying to this program so we can offer our services to this client and any future clients who might be interested. If you could send me the program requirements so I can apply correctly, I would be very grateful. Have a good afternoon. Greetings from Guatemala.
I am experiencing inconsistent behavior with QR code provisioning for Android Enterprise and am seeking guidance from the community.The Issue:QR code provisioning works intermittently, but the failure pattern is inconsistent. A provisioning QR code generated from a specific APK build will work reliably. However, subsequent builds of the exact same source code from the same Android Studio project will sometimes fail. The device displays a generic "Contact your IT admin" error.What I've Verified:The APK is properly signed and the checksum in the QR code is correct.The server delivers the APK with the correct application/vnd.android.package-archive MIME type.The DeviceAdminReceiver is correctly declared in the manifest and the associated XML resource exists.The package name and component name in the QR code are 100% accurate.Comparing a "working" APK and a "failing" APK in APK Analyzer shows no differences in the core components (package name, receivers, reso
Hi We have a custom MDM app which was built to enroll android devices with Device Owner. We have a backend which serves the configuration requires to install/block apps and settings. We are not using Android official management APIs, A few days ago we received a google play protect update on some of our devices and now whenever we try to enroll the devices using QR code enrollment it gets blocked by google play protect. Please help us understand what is required to bypass this so that we can continue to use our custom MDM app. thanks!
Hello Android Enterprise Community,I’m trying to set up my MDM, but I keep encountering the following error:"Someone at testmdm.xyz has already signed up."I have previously attempted to remove the Android Enterprise enrollment from my domain, unlinked the MDM, and followed all standard steps. However, I am unable to re-register the MDM, and my attempts to enroll devices fail.I would greatly appreciate guidance on:How to fully clear any previous Android Enterprise enrollment associated with my domainSteps to re-register an MDM successfullyAny best practices or troubleshooting tips to avoid this issue in the futureThank you in advance for your help. Any advice from experienced admins or Google support is highly welcome.@jasonbaytonBest regards,Khaled
Hello everyone, I’m reaching out from my company as we have encountered an issue with the installation and use of personal digital certificates issued by FNMT (Spain) on Android devices managed through Google Workspace MDM. The certificates install correctly, but apps that should use them (e.g., for Wi-Fi authentication or access to internal services) do not detect or recognize these certificates. We have tested on unmanaged Android devices, and the certificates work fine there, so it seems related to Google Workspace MDM management. We’ve confirmed with the certification authority (FNMT) that their certificates comply with standards. Google mentioned that MDM should not block certificates unless there is a policy configured to do so. However, this problem seems to persist regardless. Additionally, other companies have reported similar issues with personal certificates issued by different certification authorities, which suggests a possible systemic incompatib
Hello, Since android 15, some characters are not taken into account correctly. For example the tilde character is showned on top if you use an external keyboard (Alt Gr + "é") and is showned on the middle of the character if you use the onscreen keyboard. Example in android 16 (but 15 seems to be the same): On external keyboard: "˜"On onscreen keyboard: "~" In our barcodes we sometimes use this character and thus it is an issue after updating to Android 15 the devices in production. does other French people see this or any character change ? (It seems the "¨" also changed)@Lizzie , is there someone in your contacts we can discuss / exchange with on this topic ?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.