To start managing Android devices, you will need to register Workspace ONE UEM as your Enterprise Mobility Management (EMM) provider with Google. You may complete this registration in the Workspace ONE UEM Console at the Getting Started page or at (All Settings > Devices & Users > Android > Android EMM Registration).
There are two methods of completing Android Enterprise registration. Using a Managed Google Domain is now the recommended method. In this method, Google binds your Android Enterprise devices to your organization's domain. As part of the Android EMM Registration setup wizard, you provide your work email address. If your organization does not yet have a Managed Google Domain, Google creates one and a managed Google account using the email address you provided during setup. You can use this administrator account to log into the Google Admin Console, where you can verify ownership of your domain and manage other Google services. If your organization already has a Managed Google Domain, you will only be prompted to log in using your managed Google account. You may complete Android Enterprise registration in multiple Workspace ONE UEM environments using a single domain.
Completing Android EMM Registration using the Managed Google Play Accounts Enterprise method is now recommended by Google only for edge cases where a Managed Google Domain cannot be used. When using a Managed Google Play Accounts Enterprise, you bind your organization's devices to an Enterprise managed by an @gmail.com account. Organizations that previously completed Android EMM Registration using this method will continue to be able to manage their devices. It is also still possible to clear and re-establish the same Enterprise registration in a Workspace ONE UEM environment.
Important: After completing registration using either method, it is strongly recommended to add additional administrators. This helps with maintaining management of your Android Enterprise registration in the event that the primary account becomes inactive. For Managed Google Domains, add additional administrator accounts in the Google Admin Console. For Managed Google Play Accounts Enterprises, see Assign Roles in Enterprises. Furthermore, do not delete the Organization associated to your Managed Google Play Accounts Enterprise. Deleting this will result in loss of management functionality for your Android devices.
The Google Service Account is a special Google account that is used by Workspace ONE UEM to access Google APIs and must be provided by administrators whenwhen setting up Android using the legacy setup flow for Managed Google Domains. The Google Service Account credentials are otherwise automatically populated after completing the Android EMM Registration setup wizard.
Important: The setup of Android includes the integration of third-party tools that is not managed by Omnissa. The information in this guide for the Google Admin Console and Google Developer Console has been documented with the available version as of March 2024. Integration with a third-party product is not guaranteed and is dependent upon the proper functioning of the third-party solutions.
Register with a Managed Google Domain
To set up Android Enterprise using a new Managed Google Domain, select Register with Google in the Getting Started or Android EMM Registration settings pages. This launches a Google registration wizard and is the recommended method for new organizations. An alternative registration flow is available that allows organizations to manually provide Enterprise tokens, service accounts, and other details. This method is not recommended for organizations configuring Android in a new Workspace ONE UEM environment.
Prerequisites
If the Android EMM Registration page is blocked, make sure you select the Google URLs in your network architecture to communicate with internal and external endpoints.
Using the Google Registration Wizard (recommended)
The Workspace ONE UEM console allows you to complete a simplified setup process to bind the UEM console to Google as your EMM provider.
Procedure
-
Navigate to Getting Started > Workspace ONE > Android EMM Registration.
-
Select Configure and you are redirected to the Android EMM Registration page.
-
Select Register with Google. You will be redirected to a Google setup wizard.
-
Enter your work email address. This account should belong to your organization's domain.
-
Complete email verification.
-
If a Managed Google Domain does not yet exist for your organization, follow the prompts to create a Managed Google Domain and administrator account.
-
Authorize the EMM binding for this organization to Workspace ONE UEM.
You will be redirected to the Android EMM Registration settings page in the Workspace ONE UEM Console. This page will display your organization's name and the email address of the administrator used to register with a Managed Google Domain.
Using the Workspace ONE UEM Registration Wizard (Legacy)
Note: This method is not recommended for new Android Enterprise registrations.
This method for completing Android Enterprise registration using a Managed Google Domain requires the organization to manually create a Managed Google Domain if they do not already have one. You will also complete several manual tasks, such as verifying domain ownership with Google, obtaining an EMM token, and creating an enterprise service account to use this type of setup.
Users enrolling Android devices into Workspace ONE UEM will have to log into their managed Google account as part of enrollment. Users must be provisioned to Workspace ONE UEM. See the Set Up Users section below for more information.
-
Navigate to Getting Started > Workspace ONE > Android EMM Registration.
-
Select Register to be redirected to the Android Setup Wizard to complete three steps:
-
Generate Token: Obtain your enterprise token by registering your enterprise domain with Google.
-
Upload Token: Enter the EMM Token into the Android setup wizard.
-
Setup Users: Configure how users will be created for your entire enterprise.
-
-
Select Go To Google. You are redirected to the G Suite site.
-
Register your enterprise and verify your domain.
Setup Google Service Account
The Google Service Account is a special Google account that is used by applications to access Google APIs. You should create this account after you generate your EMM token so you can upload all information at one time.
-
Navigate to the Google Cloud Platform- Google Developers Console.
-
Sign in with your Google credentials.
The Google Admin credentials do not have to be associated with your business domain. Consider creating a Google account specifically for Android for your organization to use so as not to conflict with any existing Google accounts.
Note: Consider adding additional accounts so that if one account becomes inactive, you will have additional accounts to log in and access your Google Service Account.
-
Use the drop-down menu from the Select a project menu and select New project.
-
Enter a Project Name to create your API project in the New project window. Consider using Android EMM-CompanyName as the naming convention.
-
Agree to the terms and conditions and select Create.
Your project generates and the Google Developer Console redirects you to the API Manager page.
-
Select Enable APIS and Services for Android from the APIs & Services Dashboard.
-
Search and activate the following APIs: Google Play EMM API and Admin SDK.
After creating your project and enabling APIs, create your service account in the Google Developer's Console.
-
Navigate to APIs & Services > Credentials > Create Credentials > Service Account Key > New Service Account.
-
Define the Service Account name for your service account. Consider following the Android naming convention and be sure to note the name you choose as you will need it in further steps. Service Account ID is automatically generated. Click Create and Continue.
-
Use the drop-down menu to select the Role > Project as Owner and select Continue.
-
You can skip step 3 shown to grant other users access to service account. Select Done.
-
Select the service account created. Go to Keys tab and select Add Key > Create New Key. Select P12 and select Create.
The identity certificate gets automatically created and downloaded to your local drive. Be sure to save your identity certificate and password for when you upload the certificate into the Workspace ONE UEM console.
-
Select Manage service accounts from the Service Account page. Under Advanced Settings, there is a link there to Learn More About Domain Wide Delegation Follow steps there to turn on domain-wide delegation.
To delegate domain-wide authority to a service account, a super administrator of the Google Workspace domain must complete the following steps: 1. From your Google Workspace domain's Admin console, go to Main menu menu > Security > Access and data control > API Controls. 2. In the Domain wide delegation pane, select Manage Domain Wide Delegation. 3. Click Add new. 4. In the Client ID field, enter the service account's Client ID. You can find your service account's client ID in the Service accounts page. 5. In the OAuth scopes (comma-delimited) field, enter the list of scopes that your application should be granted access to: https://www.googleapis.com/auth/admin.directory.user 6. Click Authorize.
-
Back in Advanced Settings of your service account created in the Google Admin console, take note/ copy the email and Unique ID in Service account details. You will use these later when doing Android EMM registration.
Set Up Google Admin Console
The Google Admin Console is where administrators manage Google services for users in an organization. Workspace ONE UEM uses the Google Admin Console for integration with Android and Chrome OS.
The Manage API client access page allows you to control custom internal application and third-party application access to supported Google APIs (scopes).
-
Login to the Google Admin Console and navigate to Security > Advanced Settings > Manage API Client Access.
-
Fill in the following details:
Setting Description Client Name Enter the Client ID generated when creating your Google Service Account One or More API Scopes Copy and paste the following Google API scopes for Android: Android: -
Select Authorize.
Generate EMM Token
Your unique EMM token binds your domain for Android management to the Workspace ONE UEM powered by AirWatch. You are directed to the G Suite setup site after selecting Go to Google from the previous task to begin.
The steps in outlined in task are for generating an EMM token for a new domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain.
If you are generating a token for an existing domain, simple navigate to Security > Managed EMM Provider for Androidand select Generate EMM Token and proceed to step 5.
-
Complete the following fields:
-
About You – Enter your admin contact information.
-
About Your Business – Fill out your company information.
-
Your Google Admin Account – Create a Google admin account.
-
Finishing Up – Enter the security verification data.
-
-
Select Accept & create your account after reading and agreeing to terms set by Google.
-
Follow the remaining prompts to Verify domain ownership and Connect with your provider. Once verified, this becomes your managed Google domain.
To verify domain ownership, the following options are available: add a meta tag to your homepage, add a domain host record, or upload HTML file to your domain site. Configure settings for the available options.
-
Select Verify to proceed. If this process is successful, the Connect with your provider section displays your EMM token. This token is valid for 30 days. If you encounter problems during this step, refer to Google support using the number and unique PIN listed.
-
Copy the generated EMM token and select Finish.
Workspace ONE UEM recommends that you create your Google Service Account before you return to the Workspace ONE UEM console to upload the EMM token, so that you can upload all credentials at one time.
Generate EMM Token for Existing Domain
Your unique EMM token binds your domain for Android management to the Workspace ONE UEM powered by AirWatchWorkspace ONE UEM powered by AirWatch. For existing domain, you are directed to the Google Admin Console to generate the EMM token. The steps in outlined in task are for generating an EMM token for an existing domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain. For information on generating an EMM token for a new domain, see . Log into the Google Admin Console using your Google Admin credentials.Navigate to Security > Managed EMM Provider for Android and select Generate EMM Token.Copy and paste the token into the Workspace ONE UEM console.
The steps in outlined in task are for generating an EMM token for an existing domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain.
-
Log into the Google Admin Console using your Google Admin credentials.
-
Navigate to Security > Managed EMM Provider for Androidand select Generate EMM Token.
-
Copy and paste the token into the Workspace ONE UEM console.
Upload EMM Token
Enter the information you obtained from Google during registration. This includes the registered domain, Enterprise Token, and the Google Admin Email Address you created.
You can also get your enterprise token by logging into https://admin.google.com with your Google Admin Email Address under Security→Manage EMM Provider for Android.
-
Navigate to Getting Started > Workspace ONE > Android EMM Registration. If you have closed the window or are not automatically redirected back to Workspace ONE UEM.
-
Select Register to be redirected to the Android Setup Wizard.
-
Select Upload Token from the Android Setup wizard.
This is also referred to as the Enterprise Token.
-
Complete the following fields:
Setting Description Domain Domain claimed for enabling Android associated with your enterprise.Important: If your domain has already been registered with another EMM provider, you will not be allowed to upload a new EMM token. Enterprise EMM Token Token generated in Google Admin Console. Google Admin Email Address This is the admin account used for domain registration, Google Developers Console, and the Google Admin Console. Client ID Client ID generated when creating your Google Service Account. This ID is retrieved from the Google Developer Console Settings. Google Service Account Email Address Email generated from Google Service Account creation. This ID is retrieved from the Google Developer Console Settings. Certificate ID Upload the P12 certificate created when generating Google Service Account. Requires a password. This ID is retrieved from the Google Developer Console Settings. -
Select Next to set users.
Set Up Users
All users in your enterprise using Android need Google accounts created to connect with their devices. This final step in the Android EMM Registration wizard allows you to determine which setup method you prefer for creating users.
You have two options for creating users under Android:
- Allow Workspace ONE UEM to automatically create Google accounts during enrollment.
- Create users manually by logging into the Google Admin Console or using the Google Active Directory Sync Tool (GADS).
The format for the user name is username@(your_enterprise_domain).com.
-
Turn on one of the following options to determine how users are set up:
- Create Google account during enrollment based on enrolled user's email address.
- Use SAML for Authentication - Enable SAML for the enrollment process.
- Use SAML for Google Account Authentication - To use this method, configure single sign-on by navigating to Security > Single sign on in the Google Admin Console. If auto create users is not turned with one of the above methods, the Workspace ONE UEM console directs you to the alternative method of creating Google accounts by the Google Active Directory Sync Tool or the Google Admin Console.
-
Use the Test Connection option which checks for proper communication with Google.
- Play API Access: Validates Google EMM API is turned on and applications can be installed.
- Directory API Access: Validates Admin SDK API is set to enabled and https://www.googleapis.com/auth/admin.directory.user scope is authorized on Google Admin Console.
-
Select Save.
Register with a Managed Google Play Accounts Enterprise
Note: This method is not recommended for new Android Enterprise registrations.
If your organization needs to re-establish the binding between Workspace ONE UEM and a Managed Google Play Accounts Enterprise or if a Managed Google Domain cannot be used, organizations can configure Android to use a Managed Google Play Accounts Enterprise.
Procedure
-
Navigate to Getting Started > Workspace ONE > Android EMM Registration.
-
Select Configure and you are redirected to the Android EMM Registration page.
-
Select Register with Google. You will be redirected to a Google setup wizard.
-
Where prompted to enter your work email address, provide the GMail account that should manage the Managed Google Play Accounts Enterprise. Select Sign up for Android only.
-
Follow the prompts to complete registration. If needed, provide additional information regarding your organization.
- Play API Access: Validates Google EMM API is turned on and applications can be installed.
- Directory API Access: Validates Admin SDK API is set to enabled and https://www.googleapis.com/auth/admin.directory.user scope is authorized on Google Admin Console.
-
Select Save.
Register with a Managed Google Play Accounts Enterprise
Note: This method is not recommended for new Android Enterprise registrations.
If your organization needs to re-establish the binding between Workspace ONE UEM and a Managed Google Play Accounts Enterprise or if a Managed Google Domain cannot be used, organizations can configure Android to use a Managed Google Play Accounts Enterprise.
Procedure
-
Navigate to Getting Started > Workspace ONE > Android EMM Registration.
-
Select Configure and you are redirected to the Android EMM Registration page.
-
Select Register with Google. You will be redirected to a Google setup wizard.
-
Where prompted to enter your work email address, provide the GMail account that should manage the Managed Google Play Accounts Enterprise. Select Sign up for Android only.
-
Follow the prompts to complete registration. If needed, provide additional information regarding your organization.
You will be redirected to the Android EMM Registration settings page in the Workspace ONE UEM Console. Your organization's details and the email address of the administrator used to set up Android Enterprise with the Managed Google Domain will be shown here.
Creating Android Enrollment Users (Legacy Managed Google Domain Registration Only)
It is best to create users for Android automatically during enrollment. The Android setup wizard allows you to specify if you want to automatically create user accounts during enrollment, and if so, to use SAML to authenticate the accounts. If you have not set up SAML previously, the wizard will display a link that directs you to configure your settings.
Creating Users Automatically
-
Select Yes to Create Google accounts during enrollment based on enrolled user's email.
-
Select Yes to Use SAML endpoint to authenticate accounts.
If you have not setup SAML, the wizard will prompt you to configure SAML authentication settings.
-
Select Yes to Use SAML for Google Account Authentication which requires you to configure single sign-on in the Google Admin Console.
-
Select Save to complete Android setup.
Creating Users Manually
You can manually create user accounts for your entire enterprise outside of the Workspace ONE UEM console by either using either the Google Cloud Directory Sync (GCDS) tool or the Google Admin Console. To access the Google Admin Console , you can click the link provided in the setup wizard. You will need to contact Google for further instructions on how to use the console.
The GCDS method requires you to use similar settings as the AirWatch Directory Services. Access the Directory Services settings by navigating to Groups & Settings ► All Settings ► System ► Enterprise Integration ► Directory Services.
You can access the GCDS tool by clicking the link posted in the setup wizard or by downloading the tool directly to your computer from the Google Support page.
The GDCS tool allows you to manually create Google accounts for every employee in your enterprise in one bulk creation. The accounts are created by synchronizing with the information stored from your Workspace ONE Directory Services.
Note: The information discussed here is up to date as of latest version of GCDS v4.4.0 for March 2017.
-
Select the link from the setup wizard or download the GDCS tool directly from Google.
-
Open the tool from your desktop and select User Accounts and Groups to synchronize.
-
Select the Google Domain Configuration tab and enter the following:
-
Enter Primary Domain Name.
-
Select to Replace domain names in LDAP email address (of users and groups) with this domain name. This will ensure that all user email addresses match the domain name.
-
-
Select the Authorize Now button.
-
Follow the steps to continue the authorization process when the Authorize Google Apps Directory Sync dialog displays.
-
Sign-in to your Android admin account.
-
Enter the verification received in email.
-
Select Validate to confirm these settings.
-
-
Select the LDAP Configuration tab to enter the connection settings to sync the AirWatch Directory Services with Google. From here, you can enter the same settings saved in the AirWatch Directory Services to sync with this tool. To access these settings, navigate to Groups & Settings ► All Settings ► System ► Enterprise Integration ► Directory Services.
-
Select Test Connection. If the sync is successful, this will auto create the linked Active Directory accounts and corporate Google accounts in Google.
You will be directed back to the setup wizard to finish setup.
Clearing the Android Enterprise Binding with Workspace ONE UEM
You can unbind your Workspace ONE UEM environment from a Managed Google Domain or Managed Google Play Accounts Enterprise.
Warning: The Android Enterprise binding is required for critical Android device management functionality. The only way to restore this management functionality for devices previously enrolled in the Workspace ONE UEM environment is to restablish the binding to the same Android Enterprise. Google automatically deletes Enterprises that have not been bound to Workspace ONE UEM for 30 days, at which point they are unrecoverable.
-
Navigate to Devices > Device Settings > Devices & Users > Android > Android EMM Registration
-
Select Clear Settings from the Android EMM Registration page.
Was this page helpful?