Managed Google Play Accounts (Android Enterprise Accounts)

License: Silver

Managed Google Play Accounts are required to enable use and configuration of Android Enterprise devices. You no longer have to use Google Apps Directory Sync (GADS) or use Google accounts to register devices.

Important: If you have already set up Android Enterprise, you must first retire those devices to be able to use this feature.

Configuring Android Enterprise using managed Google Play Account

Procedure

  1. Log in to the Ivanti Neurons for MDM portal.

  2. Go to Admin > Google > Android Enterprise.

  3. Under Managed Google Play Account, click Authorize Google to display the Google Play for Work page.

  4. Enter your Google Play Account Email ID.

  5. Click Get Started.

  6. Accept the Android Enterprise agreement.

  7. Click Confirm.

  8. Click Complete Registration.

    The Android Enterprise Configured section displays the following information:

    • Status
    • Admin Email
    • Enterprise Type
    • Google Enterprise ID

When Android Enterprise is set up using managed Google Play Accounts, there is a limitation on the number of devices enrolled per user. To overcome this limitation, while creating a new user, select the Android Enterprise device Account option to enable Android Enterprise work managed device enrollments attached to this account to be automatically assigned a Google Device Account.

Device Accounts are intended for COSU (single-use) deployments (e.g., with Kiosk mode). Users with device accounts may have limited access to Google Play.

Occasionally, a managed Google Play account or its token expires for a variety of reasons like authentication token expiry or the account or enterprise being deleted. In such scenarios, Google Play services will notify the client with a broadcast action that will trigger the client to reprovision the device by removing the existing account and adding an account with a new token obtained from the UEM server.

In case, account re-provisioning fails either because the old account could not be removed or due to many attempts at re-provisioning, user will be notified to start over again by retiring the client or factory resetting the device as the case may be depending on whether device is in work profile mode or in managed device mode, respectively.

Migrate existing Managed Google Play Account to Managed Google Domain Account (BTE)

This feature enables migration of Android Enterprise accounts and devices from Managed Google Play Account to Managed Google Domain Account.

The migration consists of: 

  • Account Upgrade

  • Device Migration

Prerequisites

  • Devices must be enrolled in either Work Managed Device or Work Profile mode; devices enrolled in Work Profile on Company-Owned Device (WPCOD) mode must be running Android 12 or later.

  • Devices are assigned valid corporate or business email IDs.

If the device is assigned to non-corporate email ID, administrator must reassign a valid corporate email ID for the device to be eligible for migration.

Upgrade Android Enterprise Account

Upgrade the Android Enterprise account from Managed Google Play Account to Managed Google Domain Account.

Procedure

  1. Go to Admin -> Google -> Android Enterprise.

  2. Click Upgrade Account.

  3. Sign in using a valid corporate or business email ID.

  4. Complete the upgrade process.

  5. Refresh the page.

Apply Device Migration Configuration

Procedure

  1. Navigate to Configurations.

  2. Select the Android Enterprise: Device Migration from Managed Google Play to Managed Google Account configuration > Edit > Next > All Devices or Custom > Slow Rollout Distribution – By default, the Manual Rollout option is selected > Choose from drop down Custom % of devices in selection summary (slow rollout) or All devices in selection summary.

  3. Click Done.

Complete Device Migration

Procedure

  1. On the device, tap Continue when prompted for "Add your work account".

  2. Verify the corporate email ID.

  3. Enter the password.

  4. Complete two-factor authentication (2FA), if available.

  5. Complete Account Setup process.

Verify Migration

On the Device

  1. Open Google Play Store.

  2. Confirm the account type has changed from Work account to Corporate domain account.

In the Admin Console

  • To view the Android Enterprise: Device Migration from Managed Google Play to Managed Google Account configuration status, navigate to Devices > Devices > Device Details > Configuration > Android Enterprise: Device Migration from Managed Google Play to Managed Google Account ). Ensure the configuration status is in Installed state.

Monitoring Migration Status

Administrators can track migration (Migrated to Managed Google Account) progress using:

  • Device Details – view migration status per device

  • Advanced Search – filter migrated and non-migrated devices

  • Device Groups – grouping migrated and non-migrated devices

These options help identify devices that require further action.

New Enrollment with Managed Google Domain Account (BTE)

Android Enterprise can be configured using Managed Google Domain Account with or without Google Authentication.

Procedure

  1. Log in to the portal.

  2. Go to Admin > Google > Android Enterprise.

  3. Under Managed Google Play Account, click Authorize.

  4. Enter your Corporate or Business Email ID and click Next.

  5. Select Create a new binding with.. in the Select a binding option page.

  6. Click Confirm. The Skip and Enable options will be displayed.

  • Skip- To continue without authentication

  • Enable – To continue with authentication

The Android Enterprise section displays the following information:

  • Status: Displays the connection status.

  • Admin Email: Displays the Corporate or Business email ID.

  • Enterprise Type: Displays the enterprise type.

  • Google Authentication Settings: Displays No/Yes based on authentication requirement.

  • Google Enterprise ID: Displays a unique Google enterprise ID.

  • Enterprise Name: Displays the enterprise name.