Jump to content

Recommended Posts

Posted

I think i'm missing the point with android devices / work profiles / Company owned devices and need a bit of help.

 

We have a few Android Samsung TabA8 devices and i thought i'd look to get them enrolled on to Google Workspace.

 

I'm getting a bit confused on what the set up process is. Documentation says to put the device in Company owned inventory and then set up a work profile for that user but the work profile doesn't go on the device when it's in Company-Owned inventory.

 

Am i reading this wrong?

Posted

If you want to do full on management, you start by enabling Advanced Android device management (in General Device settings) on the OU the target user is in. Then you can set all of the other policies, networks and apps.

 

However, be warned that if you do users will be prompted to set this up on any mobile devices - so including their private device. I've found most users need their hand holding through this process.

 

Once the device has been signed into by a user with Advanced management enabled - you can then mark the device as company owned in devices. Optionally devices can await approval and then they can only use devices you approve.

 

I'd enable on a test OU with a test user and device and test you policies before deploying to real people.

  • Thanks 1
Posted
If you want to do full on management, you start by enabling Advanced Android device management (in General Device settings) on the OU the target user is in. Then you can set all of the other policies, networks and apps.

 

However, be warned that if you do users will be prompted to set this up on any mobile devices - so including their private device. I've found most users need their hand holding through this process.

 

Once the device has been signed into by a user with Advanced management enabled - you can then mark the device as company owned in devices. Optionally devices can await approval and then they can only use devices you approve.

 

I'd enable on a test OU with a test user and device and test you policies before deploying to real people.

 

Thanks for the advice. Just shortly after I posted this, I tested against an OU and a test user whilst deleting the device from Company-Owned Inventory and factory resetting the tablet.

 

The work profile went onto the device via the user account and I can control some of the basic settings.

 

It's a shame that we cannot control the device rather than the user of the device though, or even both.

 

As we sync our AD to Google, a re-think will be required, unless we can use Groups to control users who use managed devices. I guess another way to look at this is to have a specific management account then get the user to add their work account to the device as an additional account.

Posted (edited)

Think i'm going to go with a management account on the device. Turn off pretty much all the services on that account and let the user add their own work account to it as it's going to get too complicated and messy when it comes to other staff and their own devices.

 

Google really don't make it simple! It's either all or nothing with them.

Edited by timbo343
Posted

Now that ive got a management service account on the devices which has only access to ceryain apps, how on earth do i stop the secondary account which is the user account from acccessing the play store so they don't install any other apps.

 

I've disabled google play on the specific OU but that hasn't work.

Posted
Can't remember exactly off the top of my head, but you can make apps from the Play Store available on an allowlist basis.

 

Yeah, i've got that set for the management account on the device but what is interesting is, i've got a test account on my personal phone and work tablet and both are giving different results.

 

The test account on my phone is stating that the play store is not available but if i put the test account on the tablet or the other managed phones which we intend to give out the full play store is available. This also rings true for my work account, my work account on my personal phone doesn't show t the play store content but on the other devices it does.

Posted (edited)

If anyone can help i'd be grateful of it.

 

I've got a Samsung A34 running Android 13 and a Samsung S10 running Android 12.

 

When i add a test account to the S10 i cannot access the play store, happy days because this is how it's set in Google Workspace. However when i add the same account to the phone running Android 13, the Play store shows all the apps just like it's ignoring the Google Workspace policies.

 

Is this a bug against Google?

 

An update to this, i've tested the test account on a A23 running Android 13 and the play store against the test account isn't available, this also rings true against an A53.

 

Now could this be an issue with the A34 phones? Thing is, this also is a problem on a Galaxy Tab A8 too.

Edited by timbo343
Posted (edited)

I think a sanity check is required for these Managed Mobile Devices.

 

Having done some testing, i'd like to know how others have got their devices set.

 

Option 1:

Factory reset the device and set up the account with a specific management account so that staff can still use their work account on their personal devices and not having to tell staff about the "work profile" being added to their personal devices.

Using this option means

+ that we can manage what the work managed device does, for example block Bluetooth connectivity.

+ there is only one "profile" on the phone.

 

However, if we add a second account to the device (the staff's work account),

- we are unable to block the use of Play Store on the staff's account meaning staff members can install all sorts of apps on to the device.

 

This option would be ideal if Google allowed 2 accounts on the managed device not to access Play Store, however this doesn't seem like it's possible.

 

Option 2:

Factory reset the device and skip through the setup of the device. Add the staff work account to the device as a "personal account" and this means that the play store is blocked and no apps are shown.

We would then add the management account to the device which adds a "work" profile so Play Store only shows the management apps, however we are not able to control the device via Google Workspace, yet a "work" play store becomes available to use and download the controlled apps.

 

Option 3:

Rearrange the users who have work android phones so that they are in their own OU (this would mean also changing the OU structure in AD) and apply the "work profile" to these users and tell these staff that they are not to use their personal device. We would not have to install a specific management account on these devices.

 

In Summary...

I don't understand why Google make it so difficult to set this up! What would be really useful is a "device management" policy rather than applying the policies at User Level!!

 

I think which ever way we go with this, staff who have work android phones may end up having to sign an agreement policy stating that accounts are not to be added or removed from the device and must only use the device for work related reasons. This is due to the poor choice of control of the device via Google Workspace.

Edited by timbo343
Posted

Not sure how helpful this will be, but I thought I'd just run down how I've got the Play Store apps managed as an allowlist for OUs in our domain. These are targeting the users' OUs. I've not done anything with managed Android devices: our only Android devices are user-owned.

 

Admin > Devices > Mobile and endpoints > Settings > Universal > General > Mobile Management.

Android is set to Advanced.

 

Admin > Devices > Mobile and endpoints > Settings > Android > Apps and data sharing.

'Available apps' is set to 'Only allowed apps'.

 

Admin > Apps > Web and mobile apps.

Android apps that we want to allow are added here. You can filter that list by platform to show only the Android apps that you've got configured.

 

On the same page as your list of allowed apps, you can select 'Settings > Android app collections' to dress up how the Play Store presents things to end users.

 

When Android sets up a work profile, iirc there are a few key apps that are available by default. From memory, those are the Play Store app itself, Gmail, Google Calendar and maybe one or two other core Google apps.

 

As I say, this may not be answering your problem since we've not been dealing with company-owned Android devices.

  • Thanks 1
Posted
Not sure how helpful this will be, but I thought I'd just run down how I've got the Play Store apps managed as an allowlist for OUs in our domain. These are targeting the users' OUs. I've not done anything with managed Android devices: our only Android devices are user-owned.

 

Admin > Devices > Mobile and endpoints > Settings > Universal > General > Mobile Management.

Android is set to Advanced.

 

Admin > Devices > Mobile and endpoints > Settings > Android > Apps and data sharing.

'Available apps' is set to 'Only allowed apps'.

 

Admin > Apps > Web and mobile apps.

Android apps that we want to allow are added here. You can filter that list by platform to show only the Android apps that you've got configured.

 

On the same page as your list of allowed apps, you can select 'Settings > Android app collections' to dress up how the Play Store presents things to end users.

 

When Android sets up a work profile, iirc there are a few key apps that are available by default. From memory, those are the Play Store app itself, Gmail, Google Calendar and maybe one or two other core Google apps.

 

As I say, this may not be answering your problem since we've not been dealing with company-owned Android devices.

 

Thanks for options to check.

 

Admin > Devices > Mobile and endpoints > Settings > Universal > General > Mobile Management.

Android is set to Advanced.

- This has been set against the androidmanagement account for the device

- Cannot set this against the Staff OU because be doing so staff will receive a Device Policy Message telling people to install the Business policies which will spark a whole load of questions. Yes, staff can ignore the message but it's just another question for them to ask and be weary of.

 

Admin > Devices > Mobile and endpoints > Settings > Android > Apps and data sharing.

'Available apps' is set to 'Only allowed apps'.

- This has been set against the androidmanagement account for the device

- Setting this against staff accounts will cause no end of questions though as the above policy needs to be set to Advanced for staff accounts which means if staff have their work account on their personal device, we would essentially be taking over and managing their personal device.

 

Admin > Apps > Web and mobile apps.

Android apps that we want to allow are added here. You can filter that list by platform to show only the Android apps that you've got configured.

- I managed to work out this is where the "managed apps" are configured :thumb:

 

I think i'm going to stick with a Work profile and a personal profile. The work profile will be the androidmanagement account where the work play store is active and add the staff work account to the device as a personal account, this then disables the play store on this account. The MitM certificate is still pushed out to the device this way.

 

I'm going to have to trust the staff with these devices as we are unable to control via the policies as Google does not allow us to configure the device as required.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...