Android Management API Roundup: Q3 2026
As we close out the third quarter of 2026, here is our latest summary of new Android Management API (AMAPI) features and platform updates. Since our last update, explicit controls for device backup and data restoration have been added as well as stronger enrollment safeguards, and essential maintenance across our SDK and developer guides.
Core Management Updates
Feature 1: Backup Service Control & Restore Anytime
IT admins can now configure the Android Backup Service explicitly through the new backupService policy field. If enabled, configuring backupService allows users to restore their devices on fully managed devices at any time, allowing employees to transfer data from a previous device after initial setup has finished.
Why is this useful?
- Flexible device handoffs: Hardware refreshes and unboxing rarely happen on the same schedule. Backup service helps employees restore their files and apps when convenient.
- Reduced help desk tickets: Eliminates the need to factory reset a newly enrolled device simply because a user skipped the restore prompt during initial unboxing.
- Data leakage prevention: Provides a reliable way to control corporate data syncing to personal cloud storage on company-managed devices.
- Clear administrative intent: Allows organizations to turn off cloud backups entirely across your fully managed devices or explicitly leave the choice to the user, removing the guesswork from backup states.
How can it be applied?
Set the backupService field within your AMAPI policy. This is supported on fully managed devices running Android 8.0 and above. See the Android Management API Documentation for full configuration details.
Feature 2: Enforced Google Authentication During Enrollment
Admins can now require users to sign in with a Google account during enrollment. The new googleAuthenticationOptions setting is available both on enrollment tokens and on your enterprise's sign-in details, and overrides the enterprise-wide Google authentication setting.
Why is this useful?
- Tighter access verification: When set to required, the Google sign-in screen can't be skipped. On an enrollment token you can also name the exact managed Google account that must be used, so a shared or leaked token alone isn't enough to enroll a device.
- Consistent onboarding: Ties enrollment to your organization's managed Google accounts, while letting you apply a different rule to specific tokens or sign-in flows than your enterprise-wide default.
How can it be applied?
Set authenticationRequirement to required (or optional) within googleAuthenticationOptions on an enrollment token or on a sign-in detail. On enrollment tokens you can also set requiredAccountEmail to require a specific account. See the AMAPI Enrollment Documentation for more details.
Feature 3: Nearby App & Notification Streaming Controls
New policy controls nearbyNotificationStreaming and nearbyAppStreaming allow IT administrators to govern whether notifications and apps can be streamed from managed devices to nearby devices. On fully managed devices they apply to the whole device; on devices with a work profile they apply to the work profile.
Why is this useful?
- Data boundary security: Block notification and app streaming entirely, or allow it only to nearby devices signed in with the same managed account (the default).
- Centralized cross-device governance: Gives security teams direct oversight over cross-device streaming capabilities built into the Android platform.
How can it be applied?
Configure both settings under crossDevicePolicies in your policy, choosing disabled, user choice, or user choice limited to the same managed account. Supported on Android 13 and above. See CrossDevicePolicies definitions.
Platform Safeguards & Developer Enhancements
- Smoother reprovisioning on company-owned devices: We fixed an issue where consumer Factory Reset Protection (FRP) could unexpectedly trigger after a factory reset on company-owned devices with no FRP admin emails set in policy, preventing device lockouts during hardware reassignment.
- AMAPI SDK 1.8.4 for custom companion apps: For teams building apps that integrate with Android Device Policy, recent SDK releases fix an issue where Android Device Policy installation could fail during environment preparation, raise the minimum supported Android version to API level 24, and fix a crash affecting SDK v1.8.2 and v1.8.3. We recommend updating to 1.8.4.
- Faster testing with refreshed OAuth Quickstart: the Quickstart guide now explains how to generate your own OAuth client.
- Support baseline aligned to Android 7.0+: Support for Android 6.0 (Marshmallow) is now formally deprecated, matching Google Play services baselines. Devices on Android 6.0 won't receive Android Management API updates, but can still enroll.
Ready to Learn More?
➡️️ Review the Android Management API Release Notes
➡️ Explore the Android Management API Policy Documentation
➡️️ Download the latest Android Management API SDK (v1.8.4)
➡️ For earlier releases, explore Android Management API H1 Update 2026.
Share your thoughts in the comments below: How does the new backupService control fit into your organization’s compliance strategy, and will Restore Anytime help simplify your team's hardware refresh cycles?

