General discussions
Recently active
Hello Android Enterprise Community 😎We are currently evaluating the Samsung Knox Service Plugin (KSP) in an Android Enterprise environment managed through Ivanti EPMM, formerly MobileIron. As part of this evaluation, we would like to hear from organizations that are already using KSP in production. We would be grateful for any real-world examples, lessons learned, best practices, or recommendations you could share. If possible, it would also be helpful to know which EMM solution, Samsung device models, and Android versions you are using. Thank you in advance for your feedback and experience!
I would like to know the process of getting registered with DLC as we have many customers across for financing android phones and are there any requirements to be met by company to have this?
Hello everyone, We’ve had some great responses to surveys over the last couple of months, a big thank you to those of you who took the time to give feedback. Regarding the recent app & OS pinning surveys we will be providing a summary of your responses on those shortly. Next up, we have a bit of a change of gear, towards USSD codes. Our product team is currently reviewing the usage and importance of enterprises configuring call-forwarding on managed devices by issuing USSD (Unstructured Supplementary Service Data) codes in the background. To better understand the impact of potential changes in this area, we’d like to kickstart this off with a brief survey to gauge current usage and specific business requirements. What are USSD codes?USSD codes are often used to trigger specific network-level actions, such as enabling or disabling call-forwarding settings on a device. Some enterprise solutions utilise this functionality to remotely configure these settings for managed devices. Th
I’m trying to determine whether the https://developers.google.com/android/management/reference/rest/v1/enterprises.policies#assistcontentpolicyis available for BYOD devices?I’m unable to determine what management types it’s available for, usually most settings state they are only available for Corporate Owned work profile devices or fully managed devices for example. I’m trying to get support from Microsoft (Who are insistent it’s not available for BYOD) to ensure this is available for BYOD devices as we currently have an issue where privileged apps (Assistant apps i.e. Gemini) can grab the screen content from a work profile device.Thanks for your help!
This blog post says it's now generally available but I'm not seeing it live in my tenant yet: What’s new in Microsoft Intune – MayFor those that don't know, Microsoft has been using Company Portal as their custom DPC but is now transitioning to Google’s Device Policy app to get in line with Google’s mandates. This means (among other things), enrollment will happen at http://aka.ms/enrollymyandroid instead of through the Company Portal app.If they've rolled it out to your tenant, it will look like the first image in this other blog post when you go to Devices > Android > Enrollment > Personally-owned work profile.I am curious if this is live for anyone else. Methinks Microsoft has a weird interpretation of "generally available".
Is it good to have a quote and what is the demand threshold of the EMM Quota
Hello everyone, did you encounter any issues with the switch to AMAPI through Intune ? Any devices running through AMAPI is not able to connect to our dedicated SSID through a configuration profile (certificate) We get an error from Intune’s report and nothing is applied on the device ! Sadly it was working before ! Thank you for your help Best Regards
We're experiencing an issue where our custom app's embedded WebView fails to complete authorization callbacks when redirecting to local mobile banking and wallet web services on fully managed devices. The web session drops the authentication token during the handoff.Is there a specific network activity or domain allowlist configuration in Google Play EMM policies required to permit external payment gateway redirects inside managed app containers?
Hi, We recently moved to android enterprise with work profile (using Intune) for all of our android users. And we just found out that with android enterprise with work profile does not support wearOS yet so that our users cannot add their corporate email account (O365) to the outlook app on their samsung watch or pixel watch.we tried to contact microsoft about this and microsoft said that this is not up to Microsoft but it is up to Google Android whether they would like to support wearOS for work profile. Can Google confirm if they would like to provide some support for work profile in the future for wearOS as well? I know that any development of newly feature in android system are fully confidential but it would be good for android end users to know if Google has a plan to support this in the future or not.
Hi everyone, I’m trying to use client certificate authentication (mTLS) with Chrome Custom Tabs on Android. We want to automatically select the client certificate without prompting the user, and also ask for their username and password as part of the login process. This way, we can combine both certificate-based authentication and user credentials for device attestation. On desktop Chrome, this can be done using a policy like AutoselectCertificateForUrls, but it seems this doesn’t work on Android. If this is a known limitation, is there a way to request this feature from the Android or Chrome team?
Hi,We run a retail fleet of Android Enterprise dedicated (COSU) devices managed by Intune, with Entra shared device mode and no Managed Home Screen. Devices are Samsung Galaxy XCover6 Pro (SM-G736B), Android 15, build G736BXXSAFYJ3, enrolled via KME, with KSP Premium, KAI and E-FOTA. All our apps are on the KSP battery optimization allowlist.This is the same environment as these two earlier threads, but the symptoms this time are different, so I'm posting it separately:"Disabled apps" (Feb 2025): https://www.androidenterprise.community/android-enterprise-general-discussions-3/disabled-apps-1156 "Intune app disabled" (May 2026): https://www.androidenterprise.community/android-enterprise-general-discussions-3/intune-app-disabled-2570What happened this time (Aug 31, ~12:00 UTC+2, one device so far):Every Intune-managed app was disabled simultaneously: Intune app, Authenticator, Remote Help, Knox Remote Help, Knox Asset Intelligence, our POS app, our own settings app. Icons were greyed out
SummaryPublishing a private app via the Managed Google Play iframe embedded in Microsoft Intune (Apps → Android → Add → Managed Google Play app → Private apps) consistently fails with a generic "Can't publish app. Try again in a few minutes." UI error. Inspecting the underlying network request shows the backend RPC call returns an INTERNAL error code.EnvironmentIntune tenant: trial (Intune Plan 1) Managed Google Play enterprise: created via Intune's standard "identity" connection flow (no Google Workspace domain) Device tested against: Android, enrolled via Company Portal as Personally Owned Work Profile, showing Compliant in Intune Browser: [fill in your browser + version] Tested across: original Google account binding, and a completely fresh account after a full retire + unbind + reconnect cycle — same result both times Tested across two networks (to rule out local network/firewall interference) — same result on both after resolving an initial ERR_CONNECTION_CLOSED on one networkStep
We use Google Chrome on Android Enterprise Fully Managed shared devices. Chrome is required for several business use cases including Chrome Custom Tabs (CCT) authentication flows and PWA/web applications.Our environment follows a shared-device model where associates check devices in and out throughout the day. While Chrome is needed for business workflows, users can sometimes reach the full Chrome browser through links opened from applications, authentication flows, PWAs, or other navigation paths.Unless I'm missing something, I have not found a supported Chrome Enterprise app configuration that allows administrators to disable or hide the Chrome address/search bar (omnibox) on Android managed devices. Current options appear to be URL allowlists and blocklists. The challenge with URL-based controls is that they can become difficult to maintain at scale. Business applications often introduce new URLs, redirects, and endpoints over time, which can create ongoing administrative overhead a
Hello, We force users to change regularly the device passcode and I’m getting a request from the support because they receive lot of calls from users that don’t understand what happens. USers are telling the device is blocked on a screen with passcode menus and that they can’t escape it. Some are also wiping the device to resolve the issue …Even if they receive the emails telling them they’ll need to change the device passcode, if they don’t change it, when it expires they are getting a notification that displays less than 1 second and then are locked on the screen to set a pincode / passcode. Question 1 : Are we alone to get this user misunderstanding ?Question 2 : Would it be possible to set a custom message that we would push to help users understanding that their code has expired and that they need to change it ? Best regards
Hello,I took over an IT department with numerous company owned phones. The previous IT department did not use an MDM and did not keep track of login information for the phones. They would create a new gmail account for each phone and allow the end user to create their own PIN. I need to access these phones and put them on the MDM. Thank You, Jason
I am the founder and CEO of EMMI Technologies. For more than ten days, we have been unable to access the Google Play Console controlling our Android healthcare applications.Existing case 3-6206000041891 remains unresolved. Google Workspace Support redirects us to Google Play Support, while Google Play Support redirects us back to Workspace. We cannot access either the Workspace Admin Console or the Play Console.We completed Google’s requested ownership verification, including domain verification through DNS. Support then suggested transferring the applications to another developer account but instructed us to perform the transfer ourselves, despite our inability to access the existing account.Our Android customers urgently require support and application updates that we cannot provide. Our iOS customers continue receiving our improvements because our Apple developer access remains operational.Has anyone found a way to reach a senior Google Play account-access specialist who can take ow
Hello,we would like to ask whether other customers using Samsung devices with Android 16 / One UI 8.5 have observed similar behavior. Environment- Samsung Galaxy tablets e.g. X816B- Android 16 / One UI 8.5- Android Enterprise (COPE) & Intune- Screen Pinning / App Pinning used for dedicated business applications After upgrading affected devices to One UI 8.5, notifications and certain system UI elements can appear while an application is pinned. In our environment, this behavior was not observed before the Android 16 / One UI 8.5 update and appears to be related to a change in the interaction between Screen Pinning and notification handling. This issue represents a significant operational risk for our environment. Prior to Android 16 / One UI 8.5, notifications were effectively suppressed while an application was running in Screen Pinning mode. Since the identified Android framework change, certain notifications can appear despite active Screen Pinning, impacting the intended behavi
We are certified Android Enterprise Mobility Management (EMM) provider and an authorized Zero-touch Reseller based in Bangladesh. We specialize in enterprise mobility, with our proprietary MDM platform, MobiManager, actively used by leading organizations for secure device management at scale. In line with the growing demand for secure and inclusive smartphone access, we’ve developed PayProtect—a custom Device Policy Controller (DPC) tailored to support EMI-based smartphone financing. This solution enables real-time compliance, device-level control, and robust protection against default, thereby minimizing risks for telcos, lenders, and retailers. Now we want to integrate Google’s Device Lock Controller (DLC) for built-in solution for better performance. So how can we make partnership Google’s Device Lock Controller (DLC). Thanks in advance.
I have completed all the Android Enterprise courses and obtained the Expert certification. However, the Zero-touch Enrollment Training still does not show as finished. What steps do I need to take to become a Zero-touch Enrollment Reseller?
Hey, I’m trying to better understand this AMAPI release (May 2026), we currently have issues with our corporate owned personally enabled devices where if a users personal gmail account is added to the personal profile of the device if the device is reset via recovery mode the users pin / personal gmail account is required.We started using EFRP admin emails to bypass this so we could get back into our own devices, we’re a large organisation so users generally don’t reset devices before handing them back or hand them back to their manager who is unaware of our process.What I’d like to understand is what the below change did as after testing this it still seems to be the same that when setting the FRP admin emails setting to be not configured a recovery mode wipe still triggers consumer FRP.AMAPI improves Factory Reset Protection (FRP) policy handling on COPE devices by explicitly disabling FRP and clearing account lists when no admin emails are configured, preventing unexpected lockouts
On BYOD devices with an Android Enterprise work profile (personally-owned work profile, managed by Microsoft Intune), the Google Dialer running in the personal profile does not resolve caller names from work profile contacts on the incoming call screen or in the call log. The number is shown instead of the contact name.Framework-level cross-profile lookup is verified to be working: querying PhoneLookup.ENTERPRISE_CONTENT_FILTER_URI directly via adb returns the correct work contact. Cross-profile contact search from the personal profile also works (work contacts appear under the "Work profile contacts" section in the Dialer/Contacts search UI). Only the number-based caller ID resolution path (incoming call UI and call log) fails.EnvironmentDevices reproduced on: Google Pixel 9a, Android 17, build CP2A.260805.005 Xiaomi 14T Pro (Google Dialer as default dialer), Android 16 BP2A.250605.031.A3, HyperOS 3.0.3.0.WNNJPXM Phone by Google version: 234.0.963599666 (latest from Play Store at ti
We’ve got a fleet of corporate owned and Intune enrolled Android devices. For a couple of years, we’ve leaned on “Enable browser access” in authenticator to install a certificate for chrome and WebView browser access to MS resources. That cert passes device information usually without trouble through our CA policy. This week I have had two devices that are unable to recreate the cert. When attempting to rebuild it, an error pops up but is cut off. It says something to the effect, “Certificate installation was unsuccessful becau…”. Not exactly the most helpful for troubleshooting. So I’ve got a few questions. If we have already cleared all creds and user certs out of advanced security options. is there somewhere else that certificate lives? Are there any ways to grab the full error message, or expand the pop up error?Is there a better way to allow webview to pass device information through to entra?At the first webview launch with the new cert, a popup asks if we want to use the new cer
Hi,We want to use GBoard on kiosk devices but we aren't able to remove the suggestion strip using managed configurations.All other settings can be configured fine though.The show suggestion strip configuration is set to disabled.But with versions 15.x and 16.x of GBoard it's still visible on the devices.And when checking the setting locally on the device it's still enabled (Disabling manually works fine)Back in version 14.x this configuration worked fine.Anyone else who has experienced the same thing?We've tested this on devices from Samsung, Bluebird, ELO, and Zebra.Android version doesn't seem to have any impact, just the GBoard version.// Magnus
Hello Android Enterprise team,We are currently developing our own Enterprise Mobility Management (EMM) solution for Android devices.Our company develops and provides Android devices, and we are working on our own EMM platform, including an EMM console/backend and a Device Policy Controller (DPC) application.We are currently integrating the Android Management API (AMAPI) and understand that Android Device Policy is the standard DPC approach for new EMM solutions.However, we also have our own custom DPC application and would like to understand whether there is still a supported path for getting our custom DPC verified/approved by Android Enterprise.Our questions are: Can a new EMM provider currently have its own custom DPC verified and added to the Android Enterprise approved/allowlisted DPCs? If yes, what is the current process for submitting a custom DPC for Android Enterprise verification and approval? Is there a separate registration or approval process for the custom DPC, or is
My Google Pixel is showing “This device is managed” and says Google LLC has configured this device to be fully managed. I am the current owner/user of the device and do not have access to the organization that enrolled it. The device is scheduled to automatically reset. How can I get this device removed from organization/zero-touch enrollment.
Already have an account? Login
No account yet? Create an account
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.