General discussions
Recently active
Hi,I am trying to configure Gmail to work with Exchange ActiveSync within a work profile via managed configuration according to the documentation - https://support.google.com/work/android/answer/7065453 The following parameters are specified: "exchange_host", "email_address", "exchange_username", "exchange_authentication_type" (allow_modern_authentication)The "exchange_login_certificate_alias" parameter is not set. I expect that the user will have to select a certificate via the system dialog. But as a result of such a configuration, the certificate selection dialog is not displayed to the user. The mail setup process is interrupted and the error message "Try again later, or contact your IT admin" is displayedHowever, if I specify any random value in the "exchange_login_certificate_alias" parameter, the certificate selection dialog is displayed.I would like to know whether this is expected behavior or a known issue? Versions InfoGmail client - 2025.08.25.800175820.Releas
We manage our mobile device through Intune; we also manage multiple tenants. I didn't know when I did this, but I made the mistake of signing into a new tenant with our Managed Google Play account that we use for our main tenant. Still, unaware of my error, I decided to disconnect the Managed Google Play account from the new tenant and create a new Google Play account for them.The new tenant works fine. I'm able to enroll Android devices and manage apps. However, in our main tenant, under Tenant Administration | Tenant Status for Managed Google Play, it shows a warning: Management Service Error. If I try to go to Android Apps to add an app, I get the following message: "It looks like your tenant has been unbound via the Google Play console. To browse Managed Google Play, your Intune account needs to be connected to your Android Enterprise account." But, in Devices | Android | Android Enrollment | Managed Google Play, it shows the account as Setup (with the green check). I'm also unable
Hello, I was searching for a precise info, but i cant find any official info, and unofficial sources are not precise, to say the least. How many devices can I upload to ZTP from resseller portal using a single .csv file? I have found that limitations are 30, 50, 60 devices per one file, or that the limitation is the size of the file- 50mb. The problem is, probably i will need to add tens of thousands of devices, and maximum 50 devices per one .csv is a big limitation in that case. Or is there any other way to add very large quantities of devices?
Hi Team, Can we add multiple managed accounts in Work Profile ? I was trying to achieve the same but I am getting error saying "A managed account already exists. Only one managed account is allowed for this device. If you have questions, contact your organization’s admin". If it is not possible, do we have any official document for the same. RegardsRahul Kumar
Has anyone able to purchase (paid) apps in the Managed Google Play store? I assume we still have the following limitation in 2025? "Managed Google Play no longer supports the ability to purchase app licenses. Your organization can still manage the app licenses it already owns. However, it won't be possible to purchase any additional licenses." OP: https://support.google.com/googleplay/work/answer/6150398?hl=en The paid app we're trying to purchase:
I want to validate 1.11. Dedicated device provisioning feature but failed. I have shown a zero touch enrollment for dedicated provisioning and provide below video for demonstration purpose.https://drive.google.com/file/d/1X0YD-kgNIODLPjzDHv-eG_U6s0fB2hi0/view?usp=sharing Anyone can please describe what actually I need to do.Thanks in advancee.
Hi everyone, I’m feeling very disappointed and need some help here. We’ve invested significant time and effort into building an EMM solution that aligns fully with Google’s own guidelines: Built according to Android Enterprise requirements Obtained Expert certification for our team Have clients ready to onboard devices immediately Despite doing all of the above, our application keeps getting rejected with the reason: “Doesn’t Meet Program Requirements.” The problem is, there’s no clear reason provided for rejection. Without clarity, there’s no way to improve or move forward. Google has a 500 device limit before allowing scaling, but without program approval, our clients may suffer. We have already done certifications, built the platform, and proven readiness. Our TESTING PLATFORM is live. At this point, I honestly don’t know what else can be done. If there’s no path forward and no constructive guidance, I may be forced to open-source the entire
Thanks to the keen eye of @jasonbayton for spotting this update in the documentation: https://developers.google.com/android/management/manage-custom-apps The lack of this feature has been a key reason I've avoided any AMAPI based EMM (looking at you Intune!) for fully managed device deployments. This is certainly a welcome enhancement to AMAPI and one that I'm honestly surprised Google delivered on. I think I can finally see the writing on the wall that Custom DPC will eventually now die given that AMAPI is finally catching up. I still need file system push and pull for it to truly be a replacement but this is a major step in the right direction. What are the community thoughts on the matter?
Hello everyone,I am exploring how to reduce resource usage on corporate-owned Android devices that are configured with multiple users or profiles.Currently, Android's VPN framework is per-user:Each user (or work profile) maintains its own VPN state.An Always-On VPN can only be configured within the context of the current user or profile.This means that if a device has several users, each user needs to run a separate VPN instance.This design results in unnecessary duplication:Multiple VPN processes or tunnels are active on the same device.System resources (CPU, battery, memory) are consumed redundantly.The VPN app itself must be installed and configured multiple times.My request/idea:Enable a single VPN instance at the device level (not just per-user), so that one VPN tunnel can secure network traffic across all users and profiles. This would:Greatly reduce resource waste.Simplify deployment and management for IT admins.Prevent the need for each user or profile to maintain its own VPN c
taking a page from @jasonbayton's LinkedIn post I wanted to post and discuss the announcement from Google yesterday and their upcoming Android developer verification requirements. This is something that fully managed devices with customer supplied applications will run into, and it will cause issues on devices A while ago Google stated that they wouldn't scan customer-sideloaded applications with GPP if they were fully managed. See here: https://www.androidenterprise.community/discussions/conversations/is-there-any-way-to-disable-google-play-protect-gpp-from-an-emm-or-to-otherwise-/2507 Would this requirement fall under the same umbrella?
My company is trying to provision tablets via headwind MDM.We have no problem on some of our networks, but the location they are being provisioned at at-scale have a strict no-random-mac address rule on their network.Thus far I have been unable to figure out how to create a QR code that will disable random mac address on the SSID of the network the device connects to when enrolling in our MDM.Is there a field I am missing? Surely there must be a way to overcome this.
We have a fleet that is managed with Android Management API that we use for pre prod testing. We started getting `Organization reached its usage limits, your work profile can't be set up` error recently in this enterprise. It had about 800 device when i did the list devices call. I have now removed the older devices and the list device call now returns 84 devices, but I still see the above error when trying to enroll new device. Its been about 2 days since i deleted the devices. Also been about 2 days since i have filled up https://docs.google.com/forms/d/e/1FAIpQLSf4VCzblf27V6jx1_iFt7lD1WjyCDpSDzQcxunTbQdbkEGG4Q/viewform to increase the quota for registered devices. Is there any way to investigate this issue? Can I check the registered devices qouta anywhere in GCP console? Are there any other case where I can see this error? I am seeing this error for both work profile and fully managed device.
Hi just wanted to know if there will be issues with already enrolled devices in Intune if we unlink these accounts.
I have implemented the following feature and I can set application track from my emm console but not understand what to show for validation or how it will further works after set app track info. Thanks in advance.
I wanted to restrict personal emails (with gmail account) from logging into Work GMAIL app for BYOD enrolled devices. I however want workspace accounts to be able to login. When I set modifyAccountsDisabled to true in AMAPI policy, no account can be added (including workspace account). Same problem happens when I specify com.google for accountTypesWithManagementDisabled - no account can log into GMAIL.Is there any solution to this ? Thanks in advance.
Hi, we are currently trialing automatic device enrollment using a Zero Touch Account and baramundi Management Suite as our EMM solution.It all worked well, until I deleted the Android Enterprise account before unlinking it from our Zero Touch account.When I now try to create a new enterprise and link it to our Zero Touch account, it says that it's already linked and I can't proceed to the actual Zero Touch console within the iFrame in the EMM.Sadly I can't change the display language for the iframe. It says "Choose accounts to be linked" and the light grey part next to the checkbox says "already linked". I'm only presented the option to go back and choose another Google account. There doesn't appear to be an option on the web portal version of Zero Touch (https://enterprise.google.com/android/zero-touch/customers/) to unlink the enterprise either. When I try to delete the enterprise it warns me to unlink the Zero Touch account before proceeding and tells me that all ente
We are seeing a spike in HARDWARE_BACKED_EVALUATION_FAILED in https://developers.google.com/android/management/reference/rest/v1/enterprises.devices#securityrisk field in AMA Device response. We are seeing this mostly in the Android 16 customers and for some users it went away without any change on their side. So it does not seem anything wrong with the devices and seems random. Anyone else facing this with AMA or play integrity?
Hi all,Just had a question which might seem quite easy, but couldn't find the answer.I wonder how the number of downloads accompanying an application in the Play store compares to the number of downloads not done manually by a user, but downloads based on apps pushed from an EMM. For several applications, I see relatively low numbers of downloads in the Play store. Based on these low numbers, I can practically guarantee that downloads via Managed Google Play are not included here. In itself plausible, but I have not been able to read anywhere in documentation whether or not this is correct, can anyone confirm this. At the same time if MGP downloads do not count towards the number of downloads listed in the Play Store with the app, are MGP downloads counted separately somewhere? Thank you in advance, Tom
We experiencing issues where we currently are unable to proceed with the enrolment of our Zebra devices to our EMM (WSOne). When we boot the Zebra Handset we get an error Can't finish setup. Zero-touch enrollment isn't avaialble. Check your internet connection and try again. We've tried from different network but getting same error. Their was another post about the same issue affecting Samsung S series devices which apparently samsung has fixed. Not sure how we get that fixed for the Zebra handsets
Hey Everyone, Since a couple of weeks, we are encountering a problem with the re-enrollment of devices that have moved to Android 15. our employees arrive on the next screen :Motorola G54 5G - Zero TouchSamsung Galaxy A35 Android 15 - KMEI reproduced the incident under the following conditions :Step 1 , the device is enrolled on Omnissa WSP1 in COBO with personnal Google AccountStep 2 , for some reasons, the device is erased (example : 10 errors code)Step 3 , the profil in KME or Zero Touch is Microsoft Intune & no more OmnissaStep 4 , It seems that the KME or ZERO Touch verification did not happen at the right time.Step 5 , our employees have to proove the use of the device like a personal device ! We didn't encounter this problem for devices in Android 13 or 14. The devices i used :Motorola g54 5GAndroid 15V1TDS35H.83-20-5-5security patch : 1 july 2025 Samsung A35 - SM-A356BAndroid 15AP3A.240905.015.A2.A356BXXS5BYF3security patch : 1 july 2025
Hey everyone, In ‘5 Overlooked Benefits of Android Enterprise’, we touched on Android zero-touch enrollment, and it’s something many of you are actively using to streamline your device rollouts. For those in IT, Android zero-touch can be a powerful tool - see our handy guide to learn more. It’s about getting devices to your users ready to go, automatically enrolling in your EMM and pulling down all the right policies as soon as they connect. That means less hands-on time for your team and a smoother experience for end-users. We know real-world deployments always have their nuances, but it would be great to hear about your deployment experiences using zero-touch enrollment: Did you overcome any unexpected hurdles? What was the scale of your deployment - a few devices for new joiners, or hundreds for a company-wide refresh? If you could share one key tip or best practice for someone looking to nail their next zero-touch deploymen
Hey everyone, Stop what you’re doing - episode 2 of The Secure Element is out now! Tune in as @Bigdogburr and Theresa Lanowitz, Chief Cybersecurity Evangelist at LevelBlue, dive into achieving cyber resilience in an era of boundaryless computing. Their discussion truly reinforced for me just how vital a holistic approach to securing all end-user computing is - from laptops to mobiles, and everything in between - especially with cyberattacks becoming so sophisticated. The role AI plays in crafting these increasingly targeted attacks was a real eye-opener! This episode got me thinking about the real-world threats we’re all facing. What are the kinds of cyber threats you are most confronted with? Cast your vote in the comment section below: Phishing / Quishing/ Smishing (Email, SMS, or QR code tricks) Deepfakes (Convincing fake video/ voice calls) Malicious apps (Apps designed to steal data/ compromise devices) Network atta
Hi there, hope you're well. Just wondering is it possible to control the Wi-Fi Calling settings within Android via MDM? The closest thing I've seen is to use Knox Asset Intelligence to check Wi-Fi Calling setting status on Samsung devices: https://docs.samsungknox.com/admin/knox-asset-intelligence/dashboard/network-insights/wifi-calling-setting-status/ Thank you for your help & input in advance!
My company is building a startup that utilizes Android boxes, and we want to have a way to provision applications to all of the devices and control their configurations remotely. I had a brief look at "device owner provisioning," and it seems like the right thing. Do we have to use an EMM, or can we use the management API by ourselves? Is there a way to get a technical support on call to discuss the best path for us? Main requirements:- The user does not have to log into the Play Store on the device to receive application updates.- The only application that can be used on the device is the one we provision (Kiosk mode).- Preferably, restrict device settings so only specific settings are visible to the user.- Management of thousands of devices. Constraints:- Devices do not have NFC or a camera.
Hi,I would like to know how to configure the Google Keyboard using Microsoft Intune. Specifically, I need to set up the keyboard with dual language support (Italian and German) on my Android devices managed through Intune.Could anyone help me achieve this goal?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.