I know I'm always the negative one but need to add 2 things here:
To. 4. Secure app distribution:
Where is the secure app management (version control) then? An enterprise needs full control of the version(s) they use in the company and not just "no update" or "update to latest". We need that from the MGP or the possibility to grab the apk files from play store so we can do it via the EMM/MDM.
And btw. this also goes for the firmware updates.
To 5. Future-proofing:
Why then limiting admins (on fully managed or COPE devices at least) in their management possibilities with each new version? Admins need full access to files and settings (and the MDM/EMM as well to do it centrally).
Also something i miss, is an implemented way to switch the EMM/MDM without factory resetting the device, so current MDM/EMM triggers the switch so admins are more flexible when choosing/changing EMM/MDM. You can't just wipe and re-enroll thoiusands of devices.