Skip to main content

August 21, 2026

Complete Android Enterprise Registration

To start managing Android devices, you will need to register Workspace ONE UEM as your Enterprise Mobility Management (EMM) provider with Google. This section walks you through:

  • Registering a managed Google Domain
  • Using the Google Registration Wizard
  • Using the Workspace ONE UEM Registration Wizard
  • Register with a Managed Google Play Account Enterprise with managed Google Domain
  • Register with a Gmail Account

Choosing your Android Enterprise Setup Method

There are two methods of completing Android Enterprise registration. Using a Managed Google Domain is now the recommended method. In this method, Google binds your Android Enterprise devices to your organization’s domain. As part of the Android EMM Registration setup wizard, you provide your work email address. If your organization does not yet have a Managed Google Domain, Google creates one and a managed Google account using the email address you provided during setup. You can use this administrator account to log into the Google Admin Console, where you can verify ownership of your domain and manage other Google services. If your organization already has a Managed Google Domain, you will only be prompted to log in using your managed Google account. You may complete Android Enterprise registration in multiple Workspace ONE UEM environments using a single domain.

Completing Android EMM Registration using the Managed Google Play Accounts Enterprise method is now recommended by Google only for edge cases where a Managed Google Domain cannot be used. When using a Managed Google Play Accounts Enterprise, you bind your organization’s devices to an Enterprise managed by an @gmail.com account. Organizations that previously completed Android EMM Registration using this method will continue to be able to manage their devices. It is also still possible to clear and re-establish the same Enterprise registration in a Workspace ONE UEM environment.

Important: After completing registration using either method, it is strongly recommended to add additional administrators. This helps with maintaining management of your Android Enterprise registration in the event that the primary account becomes inactive. For Managed Google Domains, add additional administrator accounts in the Google Admin Console. For Managed Google Play Accounts Enterprises, see Assign Roles in Enterprises. Furthermore, do not delete the Organization associated to your Managed Google Play Accounts Enterprise. Deleting this will result in loss of management functionality for your Android devices.

The Google Service Account is a special Google account that is used by Workspace ONE UEM to access Google APIs and must be provided by administrators when setting up Android using the legacy setup flow for Managed Google Domains. The Google Service Account credentials are otherwise automatically populated after completing the Android EMM Registration setup wizard.

Important: The setup of Android includes the integration of third-party tools that is not managed by Omnissa. The information in this guide for the Google Admin Console and Google Developer Console has been documented with the available version as of March 2024. Integration with a third-party product is not guaranteed and is dependent upon the proper functioning of the third-party solutions.

Register with a Managed Google Domain

There are two ways to set up Android Enterprise using a Managed Google Domain – using the Google registration wizard or the Workspace ONE UEM registration wizard. For most organizations, using the Google registration wizard is recommended.

While the Workspace ONE UEM registration wizard is a manual process, it supports additional functionality that is useful for organizations that use Google identity and productivity services. If organizations use the Workspace ONE UEM registration wizard:

  • All users are required to log in with their managed Google account during enrollment.

  • Workspace ONE UEM can optionally provision users to Google Workspace during enrollment.

Prerequisites

If your Workspace ONE UEM environment is hosted on-premises, ensure that you meet the networking requirements listed in Integrating Workspace ONE UEM with Android.

You will need a domain email address to complete Managed Google Domain registration. Creating a Managed Google Domain ahead of time is not required for organizations using the Google registration wizard.

Using the Google Registration Wizard

The Workspace ONE UEM console allows you to complete a simplified setup process to bind the UEM console to Google as your EMM provider.

Procedure

  1. Navigate to Getting Started > Workspace ONE > Android EMM Registration.

  2. Select Configure and you are redirected to the Android EMM Registration page.

  3. Select Register with Google. If you are already signed in with your Google credentials, you are directed to the Google "Get Started" page.

  4. Enter your work email address and select Next. This account should belong to your organization's domain.

  5. Complete email verification.

  6. If a Managed Google Domain does not yet exist for your organization, follow the prompts to create a Managed Google Domain and administrator account.

  7. Authorize the EMM binding for this organization to Workspace ONE UEM.

You will be redirected to the Android EMM Registration settings page in the Workspace ONE UEM Console. This page will display your organization’s name and the email address of the administrator used to register with a Managed Google Domain.

Using the Workspace ONE UEM Registration Wizard

This method for completing Android Enterprise registration using a Managed Google Domain requires the organization to manually create a Managed Google Domain if they do not already have one. You will also complete several manual tasks, such as verifying domain ownership with Google, obtaining an EMM token, and creating an enterprise service account to use this type of setup.

Users enrolling Android devices into Workspace ONE UEM will have to log into their managed Google account as part of enrollment. Users must be provisioned to Workspace ONE UEM. See the Set Up Users section below for more information.

  1. Navigate to Getting Started > Workspace ONE > Android EMM Registration.

  2. Select Register to be redirected to the Android Setup Wizard to complete three steps:

    1. Generate Token: Obtain your enterprise token by registering your enterprise domain with Google.

    2. Upload Token: Enter the EMM Token into the Android setup wizard.

    3. Setup Users: Configure how users will be created for your entire enterprise.

  3. Select Go To Google. You are redirected to the G Suite site.

  4. Register your enterprise and verify your domain.

Setup Google Service Account

The Google Service Account is a special Google account that is used by applications to access Google APIs. You should create this account after you generate your EMM token so you can upload all information at one time.

  1. Navigate to the Google Cloud Platform- Google Developers Console.
  2. Sign in with your Google credentials.

The Google Admin credentials do not have to be associated with your business domain. Consider creating a Google account specifically for Android for your organization to use so as not to conflict with any existing Google accounts.

Note: Consider adding additional accounts so that if one account becomes inactive, you will have additional accounts to log in and access your Google Service Account.

  1. Use the drop-down menu from the Select a project menu and select New project.
  2. Enter a Project Name to create your API project in the New project window. Consider using Android EMM-Company Name as the naming convention. Agree to the terms and conditions and select Create. Your project generates and the Google Developer Console redirects you to the API Manager page.
  3. Select Enable APIS and Services for Android from the APIs & Services Dashboard.
  4. Search and enable the following APIs: Google Play EMM API and Admin SDK.

After creating your project and enabling APIs, create your service account in the Google Developer’s Console.

  1. Navigate to APIs & Services > Credentials > Create Credentials > Service Account Key > New Service Account.
  2. Define the Service Account name for your service account. The Service account ID is automatically generated after you select Create and Continue.

Consider following the Android naming convention and be sure to note the name you choose as you will need it in further steps.

  1. Use the drop-down menu to select the Role > Project as Owner> Continue and skip step 3 shown to grant other users access to service account. Select Done.

  2. Select the service account created and proceed to Keys tab. Select Add Key > Create New Key> Select P12 and select Create.

The identity certificate is automatically created and downloaded to your local drive. Be sure to save your identity certificate and password for when you upload the certificate into the Workspace ONE UEM console.

  1. Select Manage service accounts from the Service Account page. Under Advanced Settings, there is a link there to Learn More About Domain Wide Delegation Follow steps there to enable domain-wide delegation.

    • To delegate domain-wide authority to a service account, a super administrator of the Google Workspace domain must complete the following steps:
      • From your Google Workspace domain's Admin console, go to Main menu menu > Security > Access and data control > API Controls.
      • In the Domain wide delegation pane, select Manage Domain Wide Delegation.
      • Click Add new.
      • In the Client ID field, enter the service account's Client ID. You can find your service account's client ID in the Service accounts page.
    • In the OAuth scopes (comma-delimited) field, enter the list of scopes that your application should be granted access to Directory User and Android Management listing the following scopes: (https://www.googleapis.com/auth/admin.directory.user) or (https://www.googleapis.com/auth/androidmanagement).
    • Select Authorize.
  2. Back in Advanced Settings of your service account created in the Google Admin console, copy the email and Unique ID in Service account details. You will use these later when doing Android EMM registration.

Set Up Google Admin Console

The Google Admin Console is where administrators manage Google services for users in an organization. Workspace ONE UEM uses the Google Admin Console for integration with Android and Chrome OS.

The Manage API client access page allows you to control custom internal application and third-party application access to supported Google APIs (scopes).

  1. Login to the Google Admin Console and navigate to Security > Advanced Settings > Manage API Client Access.

  2. Fill in the following details:

    SettingDescription
    Client NameEnter the Client ID generated when creating your Google Service Account
    One or More API ScopesCopy and paste the following Google API scopes for Android: https://www.googleapis.com/auth/admin.directory.user
  3. Select Authorize.

Generate EMM Token

Your unique EMM token binds your domain for Android management to the Workspace ONE UEM powered by AirWatch. You are directed to the G Suite setup site after selecting Go to Google from the previous task to begin.

The steps in outlined in task are for generating an EMM token for a new domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain.

If you are generating a token for an existing domain, simple navigate to Security > Managed EMM Provider for Androidand select Generate EMM Token and proceed to step 5.

  1. Complete the following fields:

    1. About You – Enter your admin contact information.

    2. About Your Business – Fill out your company information.

    3. Your Google Admin Account – Create a Google admin account.

    4. Finishing Up – Enter the security verification data.

  2. Select Accept & create your account after reading and agreeing to terms set by Google.

  3. Follow the remaining prompts to Verify domain ownership and Connect with your provider. Once verified, this becomes your managed Google domain.

    To verify domain ownership, the following options are available: add a meta tag to your homepage, add a domain host record, or upload HTML file to your domain site. Configure settings for the available options.

  4. Select Verify to proceed. If this process is successful, the Connect with your provider section displays your EMM token. This token is valid for 30 days. If you encounter problems during this step, refer to Google support using the number and unique PIN listed.

  5. Copy the generated EMM token and select Finish.

Workspace ONE UEM recommends that you create your Google Service Account before you return to the Workspace ONE UEM console to upload the EMM token, so that you can upload all credentials at one time.

Generate EMM Token for Existing Domain

Your unique EMM token binds your domain for Android management to the Workspace ONE UEM powered by Workspace ONE UEM powered by Omnissa. For existing domain, you are directed to the Google Admin Console to generate the EMM token. The steps in outlined in task are for generating an EMM token for an existing domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain. For information on generating an EMM token for a new domain, see . Log into the Google Admin Console using your Google Admin credentials. Navigate to Security > Managed EMM Provider for Android and select Generate EMM Token .Copy and paste the token into the Workspace ONE UEM console.

The steps in outlined in task are for generating an EMM token for an existing domain. The task to generate the EMM token is different depending on if you are registering with a new or existing domain.

  1. Log into the Google Admin Console using your Google Admin credentials.

  2. Navigate to Security > Managed EMM Provider for Android and select Generate EMM Token.

  3. Copy and paste the token into the Workspace ONE UEM console.

Upload EMM Token

Enter the information you obtained from Google during registration. This includes the registered domain, Enterprise Token, and the Google Admin Email Address you created.

You can also get your enterprise token by logging into https://admin.google.com with your Google Admin Email Address under Security→Manage EMM Provider for Android.

  1. Navigate to Getting Started > Workspace ONE > Android EMM Registration. If you have closed the window or are not automatically redirected back to Workspace ONE UEM.

  2. Select Register to be redirected to the Android Setup Wizard.

  3. Select Upload Token from the Android Setup wizard.

    This is also referred to as the Enterprise Token.

  4. Complete the following fields:

    SettingDescription
    DomainDomain claimed for enabling Android associated with your enterprise.Important: If your domain has already been registered with another EMM provider, you will not be allowed to upload a new EMM token.
    Enterprise EMM TokenToken generated in Google Admin Console.
    Google Admin Email AddressThis is the admin account used for domain registration, Google Developers Console, and the Google Admin Console.
    Client IDClient ID generated when creating your Google Service Account. This ID is retrieved from the Google Developer Console Settings.
    Google Service Account Email AddressEmail generated from Google Service Account creation. This ID is retrieved from the Google Developer Console Settings.
    Certificate IDUpload the P12 certificate created when generating Google Service Account. Requires a password. This ID is retrieved from the Google Developer Console Settings.
  5. Select Next to set users.

Set Up Users

All users in your enterprise using Android need Google accounts created to connect with their devices. This final step in the Android EMM Registration wizard allows you to determine which setup method you prefer for creating users.

You have two options for creating users under Android:

  • Allow Workspace ONE UEM to automatically create Google accounts during enrollment.
  • Create users manually by logging into the Google Admin Console or using the Google Active Directory Sync Tool (GADS).

The format for the user name is username@(your_enterprise_domain).com.

  1. Turn on one of the following options to determine how users are set up:

    • Create Google account during enrollment based on enrolled user's email address.
    • Use SAML for Authentication - Enable SAML for the enrollment process.
    • Use SAML for Google Account Authentication - To use this method, configure single sign-on by navigating to Security > Single sign on in the Google Admin Console. If auto create users is not turned with one of the above methods, the Workspace ONE UEM console directs you to the alternative method of creating Google accounts by the Google Active Directory Sync Tool or the Google Admin Console.
  2. Use the Test Connection option which checks for proper communication with Google.

  3. Select Save.

Register with a Managed Google Play Accounts Enterprise

Note: This method is not recommended for new Android Enterprise registrations.

If your organization needs to re-establish the binding between Workspace ONE UEM and a Managed Google Play Accounts Enterprise or if a Managed Google Domain cannot be used, organizations can configure Android to use a Managed Google Play Accounts Enterprise.

Procedure

  1. Navigate to Getting Started > Workspace ONE > Android EMM Registration.

  2. Select Configure and you are redirected to the Android EMM Registration page.

  3. Select Register with Google. You will be redirected to a Google setup wizard.

  4. Where prompted to enter your work email address, provide the GMail account that should manage the Managed Google Play Accounts Enterprise. Select Sign up for Android only.

  5. Follow the prompts to complete registration. If needed, provide additional information regarding your organization.

You will be redirected to the Android EMM Registration settings page in the Workspace ONE UEM Console. Your organization's details and the email address of the administrator used to set up Android Enterprise with the Managed Google Domain will be shown here.

Creating Android Enrollment Users

Note: This section only applies to organizations that set up a Managed Google Domain using the Workspace ONE UEM registration wizard.

Omnissa suggests that you create users for Android automatically during enrollment. The Android setup wizard allows you to specify if you want to automatically create user accounts during enrollment, and if so, to use SAML to authenticate the accounts. If you have not set up SAML previously, the wizard will display a link that directs you to configure your settings.

Creating Users Automatically

  1. Select Yes to Create Google accounts during enrollment based on enrolled user's email.

  2. Select Yes to Use SAML endpoint to authenticate accounts.

    If you have not setup SAML, the wizard will prompt you to configure SAML authentication settings.

  3. Select Yes to Use SAML for Google Account Authentication which requires you to configure single sign-on in the Google Admin Console.

  4. Select Save to complete Android setup.

Creating Users Manually

You can manually create user accounts for your entire enterprise outside of the Workspace ONE UEM console by either using either the Google Cloud Directory Sync (GCDS) tool or the Google Admin Console. To access the Google Admin Console , you can click the link provided in the setup wizard. You will need to contact Google for further instructions on how to use the console.

The GCDS method requires you to use similar settings as the AirWatch Directory Services. Access the Directory Services settings by navigating to Groups & Settings ► All Settings ► System ► Enterprise Integration ► Directory Services.

You can access the GCDS tool by clicking the link posted in the setup wizard or by downloading the tool directly to your computer from the Google Support page.

The GDCS tool allows you to manually create Google accounts for every employee in your enterprise in one bulk creation. The accounts are created by synchronizing with the information stored from your Workspace ONE Directory Services.

Note: The information discussed here is up to date as of latest version of GCDS v4.4.0 for March 2017.

  1. Select the link from the setup wizard or download the GDCS tool directly from Google.

  2. Open the tool from your desktop and select User Accounts and Groups to synchronize.

  3. Select the Google Domain Configuration tab and enter the following:

    1. Enter Primary Domain Name.

    2. Select to Replace domain names in LDAP email address (of users and groups) with this domain name. This will ensure that all user email addresses match the domain name.

  4. Select the Authorize Now button.

  5. Follow the steps to continue the authorization process when the Authorize Google Apps Directory Sync dialog displays.

    1. Sign-in to your Android admin account.

    2. Enter the verification received in email.

    3. Select Validate to confirm these settings.

  6. Select the LDAP Configuration tab to enter the connection settings to sync the AirWatch Directory Services with Google. From here, you can enter the same settings saved in the AirWatch Directory Services to sync with this tool. To access these settings, navigate to Groups & Settings ► All Settings ► System ► Enterprise Integration ► Directory Services.

  7. Select Test Connection. If the sync is successful, this will auto create the linked Active Directory accounts and corporate Google accounts in Google.

    You will be directed back to the setup wizard to finish setup.

Android Management API Setup

If you set up Android Enterprise before Android Management API support was available in your Workspace ONE UEM environment, you will have to take a one-time action to complete Android Management API setup. This is a pre-requisite for managing devices using Android Management API. For more information on Android Management API, see [Integrating Workspace ONE UEM with Android](.

  1. Navigate to Groups & Settings > All Settings > Devices & Users > Android > Android EMM Registration.
  2. Next to Android Management API Registration, select Register.

The Android Management API Registration status will change to Successful, and additional fields will be populated below it.

Clearing the Android Enterprise Binding with Workspace ONE UEM

You can unbind your Workspace ONE UEM environment from a Managed Google Domain or Managed Google Play Accounts Enterprise.

Warning: The Android Enterprise binding is required for critical Android device management functionality. The only way to restore this management functionality for devices previously enrolled in the Workspace ONE UEM environment is to reestablish the binding to the same Android Enterprise. Google automatically deletes Enterprises that have not been bound to Workspace ONE UEM for 30 days, at which point they are unrecoverable.

  1. Navigate to Devices > Device Settings > Devices & Users > Android > Android EMM Registration

  2. Select Clear Settings from the Android EMM Registration page.

Was this page helpful?

Provide feedback for this topic

Was this topic helpful?

Please do not include any personal or confidential information.

Generating link…