General discussions
Recently active
Hi, I have 2 configurations in my zero touch portal and our vendors have been adding devices. For some reason, the configuration I have set as default is not applying and I don't see anywhere else to make changes. Any help would be appreciated. Thanks! JT
Hi!We manage Samsung devices as Android Enterprise Fully Managed via Microsoft Intune. Camera and microphone permissions are granted through App Configuration (Permission state = Grant). At install time everything works fine.After a while — no user action, no reinstall, no policy change — the affected app loses access. Settings shows the permission as Denied and locked by admin. Intune still reports it as Grant. So far we've hit this with 3CX and now Microsoft Teams. Pattern seems to be apps with persistent background camera/mic usage.Workaround that works: re-pushing the App Configuration with any change (a dummy value increment is enough) restores the runtime state. Holds until it breaks again.What I can't figure out: it only happens on some devices, not all. Same model, same firmware, same app versions. No clean correlation with security patch level, One UI version, or enrollment date so far.My questions:Has anyone else seen this on Samsung Fully Managed under Android 16? Any idea w
Hello, I’m totally lost about what I have to do. I was managing apps via Microsoft Intune, and it was working flawlessly - Accepted softwares were available at will, some were forced, and leftover was denied. Now, based on used profile, I got different output, none of them being adequate :Enterprise managed device correctly configurate a “work-xxx...” profile, enforce the few mandatory softwares, but whatever else is accessible (being games, crypto tools, or any other type of random chinese pdf viewer) Work / personal hybrid which complexify even more getting 2 versions of Play Store, one being associated to a “work-xxx...” profile (see first point), the second being associated to a personal account.Is there no possibility anymore to restrict softwares from the Play Store, such as whitelisting software (eg. everything is off by default, and you accept few - and make even fewer mandatory ?)What should I do about my 400+ app whitelist ? Is it useless now ?
Hello,We are partners of your android enterprise portal. As it was complicated to enroll to your program, we have asked to be only We toke the first step only but we need to have access to zero touch resellers. have you any idea how we could have access to the zero touch reseller portal? Many thanks
I wanted to share some feedback regarding the upcoming policy change where Google plans to stop allowing personal, non-corporate Google / Gmail accounts for Android Enterprise and Managed Google Play configurations.While Android Enterprise is built for corporate deployment, there is a dedicated community of individual "prosumer" users who rely on basic MDM features for advanced personal restrictions and digital wellbeing.Specifically, I use Manage Engine MDM on my personal Android phone to enforce strict productivity boundaries. For me and others, Managed Google Play is a way to distribute apps to the device such as app blockers or accountability software applications that prevent access to inappropriate content. Because an app distributed this way cannot be uninstalled from the device itself, it serves as a tamper-proof tool for personal device management that standard consumer Digital Wellbeing apps cannot duplicate. Managed Google Play can also be used to block specific applications
Hello everyone, We’ve had some great responses to surveys over the last couple of months, a big thank you to those of you who took the time to give feedback. Regarding the recent app & OS pinning surveys we will be providing a summary of your responses on those shortly. Next up, we have a bit of a change of gear, towards USSD codes. Our product team is currently reviewing the usage and importance of enterprises configuring call-forwarding on managed devices by issuing USSD (Unstructured Supplementary Service Data) codes in the background. To better understand the impact of potential changes in this area, we’d like to kickstart this off with a brief survey to gauge current usage and specific business requirements. What are USSD codes?USSD codes are often used to trigger specific network-level actions, such as enabling or disabling call-forwarding settings on a device. Some enterprise solutions utilise this functionality to remotely configure these settings for managed devices. Th
Hi everyone, Quick one from me today, but an exciting one! Next Monday, May 12th at 10am PT (1pm ET / 6pm BST), Google is airing The Android Show: I/O Edition.This is a dedicated Android event running just ahead of Google I/O. And if last year is anything to go by, it's going to be worth making time for! At the 2025 edition, the show pulled back the curtain on some genuinely big stuff. Material 3 Expressive, a full visual refresh for the platform, got its first proper reveal there. Gemini Live's live camera and screen sharing made its debut. There were updates across watches, tablets, TVs and cars too. Google I/O followed up with things like: Advanced Protection for high-risk users Private Compute Core for Business keeping sensitive data on-device Digital corporate ID badges via Google Wallet Five years of mandatory security updates baked into Android 16. The I/O season tends to surface the features that matter most to how you actually work, featuring new security updates, manage
Hi everyone,I'm looking for a way to silently install a local APK (not distributed via managed Google Play) on devices managed through Google EMM (Android Enterprise), without any user interaction.On my devices, the Device Owner is Google's own DPC (CloudDPC). I can install apps via AMAPI, but it requires a signature.Is there any way to install apps without the signature requirement — for example, through my own app instead of going through AMAPI / managed Google Play?In other words: with CloudDPC as the Device Owner, can a third-party app perform a silent install on its own, bypassing the AMAPI signature check?Thanks!
Hi!We are currently having big issues with, what seems to be "MARsPolicyManager" on sour Samsung devices.In the dumplogs it says that the Intune app (com.microsoft.intune) is disabled (enabled=4)Pressing "Enable" in Google Play doesnt do anything, and no commands sent from Intune seem to help.The Intune app is in the battery optimization list in KSPThe most critical symptom is that deployed certificates are not updated in the WiFi profile causing the device to loose conection when the current cert expires.com.microsoft.intune is set to enabled=4 by auto_disabler. The state is permanent for the lifetime of the install: MARsPolicyManager: cancelDisablePolicy failed. package: com.microsoft.intuneThe issue is quite like Disabled apps | CommunityAny clues?Br//Niklas
OverviewWe are a Microsoft-certified and Google-certified partner providing enterprise mobility management support. We are reporting a reproducible Android Enterprise enrollment failure on Xiaomi Redmi 12C (HyperOS 1.0.16.0.UCVMIXM) that affects both Zero-touch enrollment and QR code-based fully managed provisioning with Microsoft Intune.This issue was first observed on MIUI 14 and has persisted through the subsequent HyperOS 1 upgrade without any improvement. We are therefore treating this as a device-specific issue on certain Xiaomi models, rather than a problem introduced by HyperOS specifically.We have already reported this issue to both Microsoft and Xiaomi. Despite more than six months having passed, neither party has made meaningful progress toward a resolution. Both Microsoft Intune and the Redmi 12C remain listed in the AER directory as compatible, and enterprise customers continue to purchase and deploy this combination based on that listing. We are therefore bringing this is
I have raised a support case by following feature request “Clarification Regarding Deprecated Feature 4.7 in EMM Technical Requirements 2025DescriptionDear Team,While reviewing the EMM Technical Requirements 2025 document, I noticed that Feature 4.7 is listed as a required item. However, it is also marked as “(DEPRECATED)” beside the feature description.Could you please clarify whether this feature still needs to be implemented for compliance, or if it is no longer mandatory due to its deprecated status?Your guidance on this matter would be highly appreciated.”but partner support team finished my case and said Private Community Question. What is the reason behind?
We use Microsoft Intune to manage devices. For the devices which have upgraded to Android 15, the end users can no longer select Microsoft Authenticator as their default application for auto filling passwords. I cannot find any settings in Intune to allow it. All devices are fully managed corporate owned devices. The devices are all Google Pixel 8 or 8a devices. Is this a bug in 15 or am I missing something?
Hello,We have set up at our MDM solution(Microsoft Intune) a Corporate-owned dedicated profile and configured it to use only specific Mobile APN. We want to allow access from this APN to Google Enterprise Destinations Hosts. I found the below article, Android Enterprise Network Requirements - Android Enterprise Help.However the Network Team which manages this APN, requires IPs instead of host names(FQDN). Then, I read the end of the article which says “If you need to allow traffic based on IP, you should allow your firewall to accept outgoing connections to all addresses contained in the IP blocks listed in Google's ASN of 15169 listed here.”I have 2 questions: Are all these IPs(some not Google as per description) needed; Do the ports remain the same, TCP 443, TCP,UDP 5228-5230 What about time.google.com which requires UDP 123;I understand that these IPs are not static and may be changed. Thank you.
Hey guyswe have around 1500 Samsung devices and manage them with Intune. Previously we didn’t had a license for E-Fota but we bought it and want to configure it for all devices.Also we have Managed Homescreen configured for having the Kiosk Mode. Everything is working when we reset a device and install it new. E-Fota gets installed and registered, but for the already configured devices we are not able to register E-Fota automatically. We already placed E-Fota on the Kiosk Screen, but that doesn’t help. When i click on it the device get’s registered in 10 Seconds without accepting something.Does any of you have a good advice what we could do to have the devices registered automatically? Many thank for your helpBest regards,Marc
Hi, we have a few Zebra devices registered for zero-touch and plan to use zero-touch for all regular mobile devices. the registration and all existing accounts linked to it was created by team members that are unfortunately no longer with us.i do have access to one account with administrator permissions but the account with the "owner" permission was not handed over and credentials are basically lost. which steps are necessary to recover ownership?
Hello,We are a team developing an EMM solution and currently going through the Android Enterprise EMM Partner certification process.We have completed the vast majority of the certification journey: all required certificates, documentation and case studies have been prepared and submitted, training modules are completed, and the relevant scenarios have been successfully validated on our test devices. The process advanced all the way to the final Product Excellence review, where nearly every item was fulfilled and only a single requirement remained. For that last item we received an approval at one point, and roughly an hour later received a rejection on the very same item. Following that, we addressed the rejection with the necessary adjustments and shared the full details through Partner Portal support tickets.For the past ~1.5 months we have been unable to get a response on the support tickets we've opened through the Partner Portal regarding this. The tickets have been moved to "Fini
e operate ~3000 Samsung Galaxy XCover Pro 2 devices (SM-G736B) running Android 16 (BP2A.250605.031.A3, security patch G736BXXSBGZC1) in Fully Managed Device Owner mode via Microsoft Intune. Devices are deployed in retail stores using Microsoft Managed Home Screen with Azure AD Shared Device Mode for store associate sign-in.Sporadically, individual devices have started prompting end users to set a device screen lock credential, even though no Intune compliance policy or DPC-driven password policy requires one. Investigation of dumpstate logs shows that the SetNewPasswordActivity is launched by com.google.android.gms (specifically the auth.managed component, based on activity registration com.google.android.gms.auth.managed.ui.SetNewPasswordActivity): 2026-04-27 18:28:32.812 SetNewPasswordActivity: com.google.android.gms2026-04-27 18:29:09.141 SaveAndFinishWorker: com.android.settings, ComponentInfo{com.android.settings/com.samsung.android.settings.biometrics.BiometricsChooseLockGeneric
when setup the devices offline, they receive notifications with reset after 2Hours, for Samsung devices, Are we able to create DPC templet to let the devices reset after 10 Minutes or to customize this based on the need.
Yes, I am operating as a registered business. I have a valid Udyam registration. Currently, I am managing around 10 Android devices for business operations, and I am planning to scale this further. I am looking for a proper enterprise setup with centralized device management and Zero-Touch enrollment for future devices. Please let me know what details are required from my side for onboarding.
We are using Microsoft Intune as our Android Enterprise EMM.Our Intune tenant is connected to Managed Google Play, but all apps show as “not available in your country/region”, and no Managed Google Play apps can be approved or deployed.This happens even though:Our organisation is based in the United Kingdom Android Enterprise is available in our country The issue persists across browsers, devices, and reconnectionsI could find no way of contacting Google or indeed Microsoft about this. Can anyone help?
Learn more about the changes to the new zero-touch customer portal The new zero-touch customer portal has been designed to make it easier for you to manage your account. Here are some of the key changes: New look and feel: The portal has been redesigned with a modern look and feel, making it easier to navigate and find the information you need. Improved navigation: The navigation menu has been simplified and reorganized, making it easier to find the pages you're looking for. Updated Terms of service: Updated the zero-touch customer terms of service and customers will be prompted to accept the terms of service upon next login to the zero-touch customer portal. The terms of service need to be accepted once by an admin or owner of the customer account. If you own multiple accounts, you might need to accept the terms of service for each one. Note: when attempting to access the zero-touch customer API. Any existing solutions leveraging the zero-touch customer APIs to access an acco
Hello, if I am a manufacturer, how to install Android for devices that I have created?
Busy week for Google with Google Cloud Next in full swing.There's quite a lot already to be excited about and some of it is highly relevant to Android Enterprise. @Rafa has been keeping a live update thread running in the community throughout the week, which is well worth bookmarking if you want to stay on top of everything as it lands.Let’s dive into the main updates so far: 🕶 Android Enterprise management for Android XR devicesYou may well have already seen this one; we covered it in the community back in April, but it's worth a recap given the spotlight Google Cloud Next has put on it. If you want a full breakdown, Lizzie's post has you covered, but the short version is: the same management foundations you already rely on (zero-touch enrollment, Managed Google Play, fully managed deployments) are now integrated for XR. The first device out of the gate is Samsung Galaxy XR, with support from six EMM partners: ArborXR, ManageXR, Microsoft Intune, Omnissa WorkspaceONE, Samsung Knox M
How I can disconnect linking with my it admin because my phone linked when I try connecting with my computer work
Hi everyone,I’m working with managed Android devices in a business environment and have noticed some performance issues during certain workflows.When users perform browser-based tasks that involve file handling (such as uploading or processing documents), the device performance drops noticeably.Some common observations:• Browser becomes slow or temporarily unresponsive• File uploads or processing tasks fail midway• Devices heat up during extended usage• Multitasking between apps affects overall responsivenessIn one case, while testing a browser-based tool for handling documents:PDF Online Editor or Amazon KDP Formatterthe experience was smooth on desktop but less stable on managed Android devices.Environment:• Android Enterprise managed devices• Work profile enabled• Standard browser usage (mostly Chrome-based)• Mixed device configurations (mid-range hardware)What I’ve tried:• Limiting background apps• Testing on different network conditions• Updating system and apps• Comparing managed
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.