We enabled Android Enterprise with Google Domain integration and turned on Third-Party EMM enforcement in Google Workspace. After that, users signing into their corporate Google accounts on personal Android devices started getting forced into Hexnode enrollment before they could access Gmail or Calendar. We need a mixed setup where the same user can have a fully managed corporate Android device enrolled through QR code, Zero-Touch, or afw#setup, but can also use a personal BYOD phone without being forced to enroll just because they sign into Google Workspace apps. Would switching from Google Domain integration to Managed Google Play Accounts be the right approach for this kind of corporate-owned + BYOD environment?
Android Enterprise BYOD users forced to enroll after enabling Third-Party EMMSolved
Replies (3)
Yes. For this scenario, using Android Enterprise with Managed Google Play Accounts is the recommended approach. When Third-Party EMM enforcement is enabled in Google Workspace, Google applies mobile management during the Google account sign-in flow. This means that whenever a user adds their corporate Google account to any Android device, including a personal BYOD device, the sign-in process can require EMM enrollment before allowing account access.
To avoid that behavior, keep Third-Party EMM disabled in Google Workspace and bind Android Enterprise in Hexnode using Managed Google Play Accounts instead of Google Domain integration.
Recommended setup:
- In Google Workspace Admin Console, keep Third-Party Android mobile management disabled.
- In Hexnode, remove the existing Google Domain Android Enterprise binding.
- Re-register Android Enterprise using the Managed Google Play Accounts option.
- Enroll corporate-owned devices through Device Owner methods such as QR code, Android Zero-Touch, Knox Mobile Enrollment, or afw#setup.
- If BYOD management is required later, users can enroll manually into Android Work Profile using the Hexnode app, instead of being forced during Google account sign-in.
This separates corporate device provisioning from Google Workspace account authentication, so personal device sign-ins remain unaffected.
That makes sense. If we still want users from Google Workspace available in Hexnode for assignments and reporting, can we keep directory sync enabled without causing the forced enrollment prompt again?
Yes. Google Workspace directory sync can be used separately from Android Enterprise enrollment enforcement. You can sync the Google Workspace user directory into Hexnode for user mapping, policy targeting, reporting, and assignment workflows. This does not require enabling Third-Party EMM enforcement in Google Workspace. The key point is to keep the directory sync and Android Enterprise device enrollment architecture decoupled. Directory sync imports users; Third-Party EMM enforcement controls what happens during Google account sign-in on Android devices.