General discussions
Recently active
Hey everyone, The wait is over! A warm welcome to our new community home! 🚀 We are pleased to open the doors, and we hope this will make your community experience smoother, clearer, and more connected. A shared space for greater collaboration. One of the most exciting changes is that you are now part of a unified space with the Android Enterprise, ChromeOS, Cameyo and Chrome Enterprise product communities. (Equally, if you are just interested in Android Enterprise, you can feel right at home in the AE areas too). Here are a few things to highlight:Discover shared discussions: Access cross-product insights and expertise all in one place. Dark mode: Take advantage of the new dark mode option for a more comfortable browsing experience. Improved search: the search results page now includes Android Enterprise (as well as Chrome) Help Center articles. Updated Resources area: making it easier to find relevant content and material With any big updates there will be things that need f
Hello,On our Ivanti Neurons MDM, we use this API to retrieve IMEIs:getImei() in TelephonyManager is equivalent to:getImei(getDefaultSim());So when the only sim is inserted in the second slot:getImei() is the same as getImei(1) causing duplication in the report.Ref:https://android.googlesource.com/platform/frameworks/base/+/b6587ea/telephony/java/android/telephony/TelephonyManager.java#843 The API used to retrieve IMEIs seems to target getImei(getDefaultSim()), which causes problems with eSIMs that use IMEI2.It therefore retrieves IMEI2 as the default IMEI, which can cause problems with registration consoles such as ZTE, where only IMEI1 is entered.Is there a way to correct this to avoid IMEI swapping? Regards.
Hi, we are using MS Intune and Google Zero Touch Portal, and a large number of Zebra scanners.We created several profiles in ZTP with DPC extras (JSON) to link the devices to the corresponding Intune enrollment profiles.However, when the scanners are set up and connected to wifi, they will not identify as company devices, but continue setup in "private" mode.I assume there is a problem in our JSON config, but I could not find it. I already checked some other discussions in this forum, but could not yet find a solution. Apologies, if this problem should already be resolved, then I am happy if you point me in the right direction. :) Thanks very much and best regardsTobias
Hi everyone, I’m from ManageEngine MDM, and we’ve observed that Picture-in-Picture (PiP) mode does not work when a device is in Lock Task (Kiosk) mode. In our deployments, the device is configured as Device Owner, and we use DevicePolicyManager#setLockTaskPackages() to enable kiosk mode. However, when an app attempts to enter PiP using enterPictureInPictureMode(), it does not function while Lock Task mode is active. We are receiving multiple customer requests for this capability, particularly for use cases such as:Video conferencing apps running in PiP while a primary kiosk app remains in the foregroundMonitoring/streaming apps that require PiP overlay within a controlled kiosk environmentEnterprise-dedicated devices that require limited multitaskingWe would appreciate clarification on the following:Is PiP intentionally restricted in Lock Task mode by design?Is there any supported approach to enable PiP while maintaining kiosk restrictions?Are there any planned API enhan
I am the IT admin/owner of our Android Zero Touch instance, and I am trying to log into the portal to view and interact with devices associated with our organization. Our zero touch instance is linked with our Intune tenant, and is working correctly. I keep getting the error that my sign in was rejected because it doesn't meet my organization's 2 step verification policy and to contact my IT admin for more information. I am that IT admin, and I can't login. My login information is correct, I have our account ID, and I'm just trying to get in touch with someone to help with the login. I can't even login to support portal to get help, so I had to use my personal Google account to post this.
After correctly completing the configuration of my MDM with the ZTE account, getting this error while registering the device:"Cant finish setup. Zero touch enrollment isn't available. Check your internet connection and try again." Things already cross verified:The internet connection is stable. The EMM setup contains the correct signin url and the zte account contains the correct extra enrollment token in configuration. The device is assigned the correct configuration. The service account allowlisting google form is also approved. The signin url api never got hit during the enrollment of the device and just got this error message.
Hello, I have built a device management system using Android Management API. Devices are enrolled in Device Owner mode. After enrolling Samsung devices (especially newer models like Samsung A07), I noticed that Samsung Smart Switch does not work anymore. On older Samsung devices, Smart Switch works even after enrollment. But on newer Samsung devices, Smart Switch does not work once the device is enrolled as Device Owner. I am not using any third-party MDM solutions only Android Management API. My questions:Is Samsung Smart Switch blocked automatically when a device is enrolled in Device Owner mode?Is this expected behavior on newer Samsung devices?Is there any policy configuration that allows Smart Switch to function while still using Device Owner mode?Is this a Samsung restriction or an Android Enterprise restriction? I would appreciate any clarification on this behavior.Thank you.
We got all our new company Samsung phones added into Samsung Knox. None of the distributors we work with are Android Zero Touch partners; we've asked them to join and they probably won't any time soon. I read that there's been some effort to unify Samsung Knox and Android Zero Touch, although in many cases it still seems like EMMs have better support for Android Zero Touch whereas Samsung would prefer you use their in-house EMM. We would like to try using the Android Zero Touch enrollment as well. Unlike Samsung, it seems like I can't even register my own customer account. So my questions: is there any possible way to get just a Zero Touch customer account set up, with no devices added, when none of the resellers I actually bought a device from are Android partners? Also, is there some way I could get some of our Knox enrolled devices to use Zero Touch?
We are a company specializing in providing financial services to low-income clients in buying all type of phones. Recently came across this app on Google Device Lock Controller and we understood this would help us a lot. I searched for how to apply to be a financial partner to be able to integrate it within our systems but maybe I am missing something. Can anyone suggest how I should conntact google for this service?
Based on the SecurityRisk value of the device, different policy responses are set. What interface should my EMM call, or which field in the policy should I use? Currently, my EMM is using AMAPI. I am confused about how to operate in response to this requirement
Hello,We use WorkspaceONE UEM as our MDM. We sometimes use provisioning profiles to deploy commands to devices run-intents, but I'm not an expert on this subject by any means. I am curious if it is possible to use our MDM to deploy an API command to disable Factory Reset Protection. The command information is here: https://developer.android.com/reference/android/app/admin/FactoryResetProtectionPolicy I realize what a specific question this is. If I can provide more information, please let me know. Thanks in advance!
Dear Team, Greetings,I would like to better understand the management capabilities available for Samsung Android devices, with Intune . Specifically, I am looking for clarity on whether these devices can be fully managed through Intune instead of relying on the Samsung Knox management tool, including support for application deployment, patch distribution, firmware updates, and other administrative functions.Any slides reference would be good for my internal discussion ?.
Good Morning Everyone 🕵️ Deep within the digital infrastructure, a high-stakes mission is being prepped. Five mobility experts have been deployed to solve a massive puzzle: migrating tens of thousands of smartphones to Microsoft Intune. The Goal: Ensure a fluid, secure, and uninterrupted transition for thousands of users. The Battlefront: A complex landscape filled with legacy policies, mixed configurations, and strict deadlines. It’s a race against the clock where one wrong move could start a domino effect. From scripts to security protocols—nothing is left to chance. Failure is not an option. Following Broadcom’s acquisition of VMware in 2023, the Workspace ONE product is now owned by Omnissa. Broadcom’s commercial strategy, which has influenced its spin-off companies, had become highly aggressive toward all customers. Consequently, we have decided to migrate the management of our Android and iOS tertiary fleet to Microsoft Intune.. &
Hello, Recently our COPE profile in ZT is not functioning.The device will go through the enrollment, it gets registered correctly in our tenant (Entra/Intune) and we can get to the home screen just fine. However, after some time the device will receive the following notification:“Your organization has set up this device to be managed by your organization. If this is an error, contact your device’s provider. All data on the device will be deleted. Your device will automatically reset in 2 hour.” The config in ZT and the one in Intune match (token is correct and the DPC extras are fine). This profile was working up until 2 weeks ago.We’re stumped. We recreated a different COPE profiles with the required DPC extras as per Microsoft’s documentation, tried removing compliance policies and device configurations to make it a plain profile. No luck, still receives the reset notification.Phones tested: Samsung A15, Samsung A16 all running the latest Android 16OS with the latest s
Regarding the function of configuring the login URL, I have configured the signUrl for the enterprise, and then obtained the signinEnrollmentToken of the enterprise through get, and placed its qrcode into the QR code. When I configure the device, my device redirects to the configured signUrl page, and then after successfully logging in by entering the account and password, I need to call enrollmentTokens.create. However, how can I obtain my enterprise id? Is there any good suggestion
***This survey is now closed*** Hello everyone, As 2025 comes to a close and we look toward a new year, this is often an excellent time for reflection. It has been a busy year, and we've so enjoyed speaking with you and seeing the interact with other community members. The Android Enterprise Customer Success team is dedicated to ensuring that our programs and resources—including the Customer Community, The CAFE, and Advisory Services—are useful, enjoyable, and impactful for you and your teams. As we head into 2026, we’d love to hear directly from you! Would you mind sparing less than 5 minutes (I’ve been assured it won’t take a minute more 😀) to complete our Customer Success Products CSAT survey and share your overall experience please? The survey contains multiple sections for each customer programs. Please only select 'Yes' for the area(s) relevant to you. Your honest feedback is vital and will directly influence the improvemen
Hi all, For Apple (iOS/MacOS ) we use the macos security compliance project tooling (https://github.com/usnistgov/macos_security#readme) for mapping compliance guidelines. A short summary: The macOS Security Compliance Project (mSCP) is an open‑source framework that provides automated, customizable security guidance and baselines for macOS, producing documentation, audit checklists, configuration profiles, and remediation scripts. It supports major security standards, including NIST SP 800‑53, NIST SP 800‑171, DISA STIG, CNSSI 1253, CIS Benchmarks, CIS Critical Security Controls v8, CMMC 2.0 Levels 1–2, and the Netherlands BIO baseline. I haven't found such a project for Android, as anyone aware of such a project that maps security guidelines to available API's for Android Enterprise? Michel
I'm developing a custom MDM solution using Google Android Management API. Successfully created enterprise enterprises/LC02x32bm6 with work email domain, but getting:"Can't set up device. Your organization has reached its usage limits."Key Details:Enterprise created successfully via APIEnrollment token generated successfully0 devices currently enrolledCloud Console shows 0% API quota usageBilling account linked to projectGET /api/enterprise/callback → Returns enterpriseNamePOST /api/enterprise/enrollment-token → Returns enrollment tokenDevice enrollment → ❌ "Usage limits" errorHas anyone encountered this "usage limits" error with 0 devices?Android Management API usage is 0%. Any insights appreciated! Happy to share code snippets or API responses if helpful.
Combining zero-touch with the login URL, I'm not sure how to complete this process for my EMM. Regarding the login URL, I'm not sure how to configure it. I'm not quite clear on how these two should be combined
Hi everyone,I'm a developer who helps enterprises build custom DPC (Device Policy Controller) Reference Documentation apps to manage Android devices based on their unique requirements.Recently, Play Protect has started blocking the installation of custom DPC apps, even when these apps are signed and used internally. The warning claims the app may pose a risk due to access to sensitive data - even though it's strictly for enterprise use. To make things more difficult:Google is no longer accepting registration of custom DPC apps with Android Enterprise, which limits official distribution and management options.Android Management APIs don’t support all use cases, and also have quote limit.I’ve applied twice to join the Android Enterprise portal to build a SaaS-based device management platform, but both requests were rejected without a clear reason. My questions for the community:Is there any official way to get a custom DPC app approved or whitelisted by Play Protect?Are there a
Hello,We use QR code provisioning to install our custom Device Policy Controller (DPC) app from a custom download URL (not Google Play).The exact same APK + QR configuration:Works on:Samsung Galaxy S20 — Android 13 / One UI 5.0Blocked on:Samsung Galaxy S21 — Android 14 / One UI 6.1Play Protect stops installation with the message:"App blocked to protect your device. This app can request access to sensitive data. This can increase the risk of identity theft or financial fraud."Provisioning QR:{"android.app.extra.PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME": "<DeviceAdmin component>","android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_CHECKSUM": "<Package checksum>","android.app.extra.PROVISIONING_DEVICE_ADMIN_PACKAGE_DOWNLOAD_LOCATION": "<S3 bucket url>","android.app.extra.PROVISIONING_LOCALE": "en_US","android.app.extra.PROVISIONING_TIME_ZONE": "Europe/Helsinki","android.app.extra.PROVISIONING_LEAVE_ALL_SYSTEM_APPS_ENABLED": false,"android.app.extra.PROVISIONING_DEVICE_A
We are an organization using a third-party MDM / Device Policy Controller (DPC) solution to manage our Android Enterprise devices. The DPC application is published on Google Play and has been working for managed provisioning.Recently, we started facing issues during Android Enterprise enrollment, and we are seeking guidance on the correct and supported setup.Issues observed1. afw#identifier enrollmentWhen attempting enrollment using afw#<identifier>, the setup fails with errors such as invalid token, wrong setup, or unable to continue enrollment.This previously worked and now fails consistently, even though the DPC remains published on Google Play.2. QR code–based provisioningWhen using QR code provisioning, the device completes initial setup but then Google Play Protect shows “App blocked by Play Protect” for the DPC.The DPC app is Play-approved and not sideloaded by end users.We have already submitted a Play Protect appeal through the official appeal form.3. Distribution method
Hey Android Enterprise community,I'm trying to understand what the "Enable third-party Android mobile management" checkbox in Google Admin does. How does this affect situations where multiple Android Enterprises are bound to multiple EMM solutions? Will both Android Enterprise continue working if they are bound to different EMM solutions, even if only one is selected on the screen above?If I use the Enrollment token link method to provision a device and have no users in my Google Workspace, will switching the EMM provider in the dropdown below the checkbox have any effect? Also, does Authenticate Using Google affect provisioning if there are no users in Google Workspace?Thanks,Marko
Greetings everyone! New day, new challenge.I’ve received a number of Zebra tablets. We already use ZTE, which works fine, but as you know it assigns devices to a single profile based on the serial number.The issue is:These tablets (same model) will be used for many different purposes, and I don’t think it’s efficient to take each device out of the box, read the serial number, and manually assign it to a different ZTE profile. I could easily end up managing 200 different profiles.So my question is:Is there a way to let the device choose which group or category it should belong to during enrollment?For example, during setup the device could ask the user which category it belongs to and based on that selection it would automatically join the correct group and receive the appropriate configuration.Is this possible? Or am I dreaming? 😄Has anyone faced this issue and found a good solution?Thanks in advance!
Hello Android Enterprise Community,I am reaching out to seek assistance regarding a quota increase request for the Android Management API.The Issue: Our project has reached its current AMAPI quota limit, which is now impacting our production environment and device deployment. We submitted the official [Quota Increase Request Form] exactly 7 days ago, but we have not yet received any response or confirmation from the Google support team. Project Details:Project ID: [zztcdc]Impact: We are currently unable to enroll new devices or sync policies for our enterprise clients, causing a significant disruption to our business operations.We understand that these requests take time to review, but given the 7-day silence and the critical nature of our deployment, we would greatly appreciate it if any community manager or Google representative could help check the status of our request or escalate it.Thank you for your time and help! Best regards, [Yichen International Trade & Technol
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.