General discussions
Recently active
Hey everyone!Following our recent updates to the Solutions Directory, we want to make sure the browsing experience best supports how you and your team evaluate enterprise hardware.Plus, this is a great opportunity to highlight it as a resource for those of you currently unaware of its existence.Currently, devices default to sorting by release date. We’d love to know whether that serves your workflow best, or if a different view would save you time?Please drop your vote below, and share any thoughts or suggestions in the comments you may have. We’d love to hear about any specific filters or sorting options that would make things easier. ⬇️Cheers,Kirk
Hi all, We have a customer who is trying to enable a preloaded app on our tablet running Android 16 (basic notes taking app). The tablets are enrolled in Intune in COBO or COSU mode. The package name is correct and added in the app enablement list on Intune, but they see the app stuck on “pending install” state, while it works for other apps such as our camera app. We are unsure what’s causing this, does anyone experienced a similar case and has any advice please? Thanks!
We're experiencing an intermittent issue with Managed App Configuration on Android Enterprise devices and are looking to understand whether others have seen similar behaviour.Environment:Android Enterprise Dedicated/Fully Managed devices Honeywell devices (CT32 and EDA series) MDM: Hexnode Application: UKG Pro Mobile App configuration deployed via Managed App Configuration through Android EnterpriseIssue:From time to time, and without any obvious trigger, the UKG application appears to lose its managed configuration (tenant URL and related settings). Users are then unable to access the application as expected.What we've observed:The device remains enrolled and managed. The policy is still present within Hexnode. Other device management functions continue to work normally. Re-syncing the policy from Hexnode immediately restores the configuration and resolves the issue.The behaviour appears random, and we have not yet been able to identify a clear pattern related to device model, Android
We have a google account where it broke our intune connection this week. We tried to unbind then rebind and we cannot because the domain already exists and the primary account was the only admin account. That account was removed as the only admin with out our knowledge. We cannot seem to get any support on this issue and this a last ditch effort for help. Please help us!!
Hi,We run a retail fleet of Android Enterprise dedicated (COSU) devices managed by Intune, with Entra shared device mode and no Managed Home Screen. Devices are Samsung Galaxy XCover6 Pro (SM-G736B), Android 15, build G736BXXSAFYJ3, enrolled via KME, with KSP Premium, KAI and E-FOTA. All our apps are on the KSP battery optimization allowlist.This is the same environment as these two earlier threads, but the symptoms this time are different, so I'm posting it separately:"Disabled apps" (Feb 2025): https://www.androidenterprise.community/android-enterprise-general-discussions-3/disabled-apps-1156 "Intune app disabled" (May 2026): https://www.androidenterprise.community/android-enterprise-general-discussions-3/intune-app-disabled-2570What happened this time (Aug 31, ~12:00 UTC+2, one device so far):Every Intune-managed app was disabled simultaneously: Intune app, Authenticator, Remote Help, Knox Remote Help, Knox Asset Intelligence, our POS app, our own settings app. Icons were greyed out
Since 19 Sep 2026, QR (6-tap) provisioning of Test DPC on a factory-reset device fails. After "Getting ready for work", Play Protect shows "App blocked to protect your device - Test DPC" with only an OK button, so provisioning cannot continue. The same flow worked before that date and nothing changed on our side.Setup: provisioning QR with PROVISIONING_DEVICE_ADMIN_COMPONENT_NAME com.afwsamples.testdpc/com.afwsamples.testdpc.DeviceAdminReceiver, an HTTPS download location for the APK, and the signature checksum.APK: com.afwsamples.testdpc 9.0.12 (versionCode 9012), unmodified, signed by CN=testdpc, O=Google Inc. Signing certificate SHA-256: 8090f6630b4e8962479123249087cb4658feaae36a1b57dbeafd74d109b333dc. File SHA-256: aad38c1f608b1c7289405c4e866977f5d231502643ce2e2401a7c305808f9c00 (on VirusTotal, 1/67, a generic AdLibrary heuristic).I found the approved-DPC allowlist page (https://support.google.com/work/android/answer/16694822) and other threads about custom DPCs being blocked, but
Hello,We have some troubles in Chrome when trying to read pdf file on android. In EDGE it works perfectly. Is there someone who can explain how it works and which app (system or not) is rendering the file ? It seems that sometimes it is the device, sometimes it is the website. The behaviour also doesn’t seem to be the same in Android 16 / 17.In the Android drop last year I find : PDF in Chrome on Android: Revamp workflows with in-browser viewing of linked PDFs, which now open directly within a new Chrome tab. I’d like to attach a little video but unfortunetly it seems we can’t in the forum (or I don’t find the button :)).Steps to reproduce (I’m on a Samsung S25 in Android 17 beta)1 - Drag and drop a pdf file from the “file” app to the “EDGE Browser app”. ==> Sometimes it works, sometimes EDGE is telling it cannot access the file. ==> something not yet “production ready” ?2 - Right click on the pdf file in the “file” app and select “open with”. A window opens to propose some apps,
i got stuck with one situation and need your guidance in solving it. We have our own .apk file for android devices, these are custom in-house developed applications, i want to deploy the application to Android Fully Managed devices (Since the device belongs to company). I did it before with publishing them to google play store as a private app but now the size is the problem as it exceed 200MB, so i cannot use this option. I tried with deploying them as Line of Business application but its been 2 days nothing shows on device and even in intune portal it neither failed or success. Question: How to deploy your custom .apk files to android fully managed devices if the file size se more than 200MB?
We use Google Chrome on Android Enterprise Fully Managed shared devices. Chrome is required for several business use cases including Chrome Custom Tabs (CCT) authentication flows and PWA/web applications.Our environment follows a shared-device model where associates check devices in and out throughout the day. While Chrome is needed for business workflows, users can sometimes reach the full Chrome browser through links opened from applications, authentication flows, PWAs, or other navigation paths.Unless I'm missing something, I have not found a supported Chrome Enterprise app configuration that allows administrators to disable or hide the Chrome address/search bar (omnibox) on Android managed devices. Current options appear to be URL allowlists and blocklists. The challenge with URL-based controls is that they can become difficult to maintain at scale. Business applications often introduce new URLs, redirects, and endpoints over time, which can create ongoing administrative overhead a
Hi i´m looking for an option to disable/clear the Advertising-ID (AD-ID) on a fully managed Device, i found the KBhttps://support.google.com/googleplay/android-developer/answer/6048248?hl=enIs there any option to remove or clear the AD-ID from EMM/MDM side without a User action? and is there any more detail information how AD-ID is working on an managed Device? Appreciate your feedbackBjoern
Hello,We are experiencing an issue with our Android Zero-touch Enrollment account.The TD SYNNEX partner, which was previously associated with our Zero-touch account, is no longer linked. The account now appears to be owned directly by Google, with no partner associated.Could you please help us verify:Why the TD SYNNEX association was removed. The current status of our Zero-touch account. How we can re-associate a partner with the account.Thank you for your support.Kind regards,
Trying to get our Intune tenant connected so that we can start to purchase organizationally owned Android phones and manage them within Intune, similar to what we have done with Apple. When I set up the enrollment to connect to Managed Google Play, I foolishly used my Microsoft account to connect them. I thought better of it and thought I’d try to add a different email to our tenant, and connect using this instead. I’ve tried to add this new email by inviting it through Google Admin. I get prompted to log in using my Microsoft account, when I do this, I get the following: The user I’ve invited, still shows up as “pending” in Google Admin. What else do I need to do so I can use this new account instead of mine?
Hi,does anyone know if there's a possibility to place a feature request to Google regarding Zero-Touch-Portal?I wanted to ask if there's plaanned at any point to provide possibility to implement AD authentication to the portal.
I am trying to make a policy in Omnissa Workspace One for Gboard. I want the keyboard to be a Slovenian QWERTZ keyboard but without changing the android system language. This is because our support needs to remote control the devices and use normal mouse an keyboard then. The employees working with the devices will use gboard and this should be in slovenian.What I need:Gboard working with sl-SL from a managed config without changing system language. My current config:
Is there any way to remotely configure the language settings in gboard and Google voice typing? Multilingual settings are not something I have much experience with and we're looking to better accommodate associates at retail. Thanks!
This blog post says it's now generally available but I'm not seeing it live in my tenant yet: What’s new in Microsoft Intune – MayFor those that don't know, Microsoft has been using Company Portal as their custom DPC but is now transitioning to Google’s Device Policy app to get in line with Google’s mandates. This means (among other things), enrollment will happen at http://aka.ms/enrollymyandroid instead of through the Company Portal app.If they've rolled it out to your tenant, it will look like the first image in this other blog post when you go to Devices > Android > Enrollment > Personally-owned work profile.I am curious if this is live for anyone else. Methinks Microsoft has a weird interpretation of "generally available".
Is it possible to reset the pin of a device that has been rebooted/off and I don't know the pin? I've had devices returned in the past without the pin and it was turned off. My MDMs (yes plural, in the process of switching) can send the commands but the clients do not reply. I've been lucky to have device wipes occur after 15 failed attempts due to policy but was wondering if there was another way.
I’m trying to determine whether the https://developers.google.com/android/management/reference/rest/v1/enterprises.policies#assistcontentpolicyis available for BYOD devices?I’m unable to determine what management types it’s available for, usually most settings state they are only available for Corporate Owned work profile devices or fully managed devices for example. I’m trying to get support from Microsoft (Who are insistent it’s not available for BYOD) to ensure this is available for BYOD devices as we currently have an issue where privileged apps (Assistant apps i.e. Gemini) can grab the screen content from a work profile device.Thanks for your help!
I would like to know the process of getting registered with DLC as we have many customers across for financing android phones and are there any requirements to be met by company to have this?
Hello Android Enterprise Community 😎We are currently evaluating the Samsung Knox Service Plugin (KSP) in an Android Enterprise environment managed through Ivanti EPMM, formerly MobileIron. As part of this evaluation, we would like to hear from organizations that are already using KSP in production. We would be grateful for any real-world examples, lessons learned, best practices, or recommendations you could share. If possible, it would also be helpful to know which EMM solution, Samsung device models, and Android versions you are using. Thank you in advance for your feedback and experience!
Is it good to have a quote and what is the demand threshold of the EMM Quota
Hello everyone, did you encounter any issues with the switch to AMAPI through Intune ? Any devices running through AMAPI is not able to connect to our dedicated SSID through a configuration profile (certificate) We get an error from Intune’s report and nothing is applied on the device ! Sadly it was working before ! Thank you for your help Best Regards
We're experiencing an issue where our custom app's embedded WebView fails to complete authorization callbacks when redirecting to local mobile banking and wallet web services on fully managed devices. The web session drops the authentication token during the handoff.Is there a specific network activity or domain allowlist configuration in Google Play EMM policies required to permit external payment gateway redirects inside managed app containers?
Hi, We recently moved to android enterprise with work profile (using Intune) for all of our android users. And we just found out that with android enterprise with work profile does not support wearOS yet so that our users cannot add their corporate email account (O365) to the outlook app on their samsung watch or pixel watch.we tried to contact microsoft about this and microsoft said that this is not up to Microsoft but it is up to Google Android whether they would like to support wearOS for work profile. Can Google confirm if they would like to provide some support for work profile in the future for wearOS as well? I know that any development of newly feature in android system are fully confidential but it would be good for android end users to know if Google has a plan to support this in the future or not.
Hi everyone, I’m trying to use client certificate authentication (mTLS) with Chrome Custom Tabs on Android. We want to automatically select the client certificate without prompting the user, and also ask for their username and password as part of the login process. This way, we can combine both certificate-based authentication and user credentials for device attestation. On desktop Chrome, this can be done using a policy like AutoselectCertificateForUrls, but it seems this doesn’t work on Android. If this is a known limitation, is there a way to request this feature from the Android or Chrome team?
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.