Updates to Android MDM documentation from the CS offsite. --------- Co-authored-by: Steven Palmesano <3100993+spalmesano0@users.noreply.github.com>
5.2 KiB
Android MDM setup
Experimental feature. This feature is undergoing rapid improvement, which may result in breaking changes to the API or configuration surface. It is not recommended for use in automated workflows.
This guide provides instructions to turn on Android MDM features by connecting Fleet to Android Enterprise.
Fleet supports Android devices that are Play Protect certified (previously known as GMS).
Turn on
To turn on Android MDM, connect Android Enterprise on Settings > Integrations > Mobile device management (MDM) page.
When you select Connect, Fleet will open the Google signup page. The signup process varies depending on whether your organization uses Google Workspace, Microsoft 365, or another provider. Organizations using Google Workspace and Microsoft don't need to verify domain ownership.
Google Workspace
- If your organization already uses Google Workspace, use your admin account to sign up for Android Enterprise. If you don't know your admin account credentials, ask your Google Workspace admin.
- Follow the steps in Google's signup flow.
- Check your Subscriptions in Google Workspace to validate that the free plan of Android Enterprise has been added.
- After successful signup, a free Android Enterprise subscription is added to your Google Workspace. In Fleet, you can confirm Android MDM is turned on in Settings > Integrations > MDM.
Microsoft 365
- If your organization uses Microsoft 365, you can sign up for Android Enterprise with your Microsoft email. First, select Connect. Then, enter your Microsoft email, click Next, and choose Sign in with Microsoft.
- After signing in with your Microsoft account, follow the steps in Google's signup process.
- After successful signup, a free Android Enterprise subscription is added to your Google Workspace. In Fleet, you can confirm Android MDM is turned on in Settings > Integrations > MDM.
- Go to your Google Admin console.
- Follow these steps to verify your domain name. This way, only you can use your domain to sign up for Google Workspace.
Now you have managed Google domain with an Android Enterprise subscription. Optionally, if you want to add additional subscriptions later (i.e. Google Workspace) you can use this domain. Only the free Android Enterprise subscription is required for Android MDM features.
Other
- If your organization doesn't use Google Workspace or Microsoft 365, in the Google signup page, use a work email to signup for Android Enterprise (don't use personal emails like "@gmail.com").
- After you enter your email, you'll get a verification email. Open the link from the email.
- Enter information about you and your company and select Continue.
- You'll see that your free Android Enterprise subscription will be selected. Select Next.
- Enter a password for your account and select Agree and continue.
- Select Allow and create account on the next screen.
- You'll be asked to log in with your account that you just created and confirm your phone number.
- After successful login and phone verification, you'll be redirected to Fleet. In Fleet, you can confirm Android MDM is turned on in Settings > Integrations > MDM.
- Follow these steps to verify your domain name. This way, only you can use your domain to sign up for Google Workspace.
Now you have managed Google domain with an Android Enterprise subscription. Optionally, if you want to add additional subscriptions later (i.e. Google Workspace) you can use this domain. Only the free Android Enterprise subscription is required for Android MDM features.
Enrollment
Learn how to enroll Android hosts in the enroll hosts guide.
Migration
To migrate hosts from other MDM solution, you must first unenroll hosts from your old solution and share a link with your end users so they can enroll to Fleet. Learn how to find your enrollment link in the enroll hosts guide.
Turn off
- In Fleet, head to Settings > Integrations > MDM.
- In the Mobile Device Management (MDM) section, select Edit next to "Android MDM turned on."
- Select Turn off Android MDM
When you turn off Android MDM in Fleet, your Android Enterprise will be deleted, MDM will be turned off on all hosts, and the work profile will be deleted from all Android hosts.
Deleting Android Enterprise in Google Admin
If you ever delete your Android Enterprise in your Google Admin console, Android MDM will be turned off in Fleet, and the work profile will be deleted from all Android hosts. To re-enroll hosts, refer to the Turn on section.