Category Filter

How to configure Android Enterprise using G Suite

Android Enterprise is a program that creates a work container on your device, thus separating the work app/data from your personal app/data. Hexnode’s integration with G Suite further simplifies the Android Enterprise enrollment process.

You can integrate your organization’s G Suite account, thus facilitating the users/user groups in your G Suite domain to sync with Hexnode MDM.

To enable Android Enterprise enrollment using G Suite, your organization should create a service account with Google, and provide specific API access to apply the configurations to the managed devices.

To enroll your devices in Android Enterprise using G Suite,

  1. Enroll your organization in Android Enterprise using Google domain.
  2. Enroll devices either in Profile Owner or Device Owner mode.
  3. Apply configurations to the managed devices.
Notes:

  • Your Organization should have a G Suite Account.
  • This feature is available in all subscription plans except Express and Pro.

Enroll your organization in Android Enterprise using Google domain

Create Service Account


Your organization requires a service account with Google to configure Android Enterprise using G Suite. Hexnode MDM uses this service account to push the Android Enterprise based configurations to the devices.

  1. Using the G Suite admin credential, login to Google Developers Console.
  2. Click on Create Project.
  3. Create a New Project by providing the following details.
    • Project Name: Provide a suitable project name and a corresponding project ID will be generated.
  4. From the Navigation Menu on the left pane, select APIs and Services > Credentials.
  5. Click on Create Credentials and from the drop-down list that appears select Service account.
  6. Select New service account and provide the following details.
    • Service account name: Provide a suitable name for the service account.
    • Service account ID: An account ID will be automatically generated. If required, you can edit it.
    • Service account description: Provide a suitable description for your service account.
    • Click on Create.
  7. Role: From the drop-down list, select Service Accounts > Service Account Admin, and click Continue.
  8. From Navigation menu > IAM & Admin > Service Accounts. Select your service account and click on Actions > Edit.
  9. Select the checkbox Enable G Suite Domain-wide Delegation.
  10. Click on Add Key > Create new key and choose the key type as JSON and click on Create.
  11. A JSON key will be downloaded. This key is later uploaded on to Hexnode MDM server to configure Android Enterprise.
  12. Click on Save.
  13. Now, click on View Client ID.
  14. Copy the Client ID.
  15. From the Navigation menu select Dashboard and click on Enable APIs and Services.
  16. In the search box that appears, type admin sdk and select the same from the search results.
  17. Click on Enable to enable Admin SDK API.

Manage API Client Access for MDM

This process provides the MDM with a specific API access to apply Android Enterprise configurations to the managed devices. Ensure to Enable API access in the Admin console.

  1. Using your G Suite Admin credentials, log in to Google Admin Console and click on Security.
  2. From API Permissions, click on MANAGE DOMAIN WIDE DELEGATION, and click on +Add new.
  3. Authorize the API clients by providing the following details.
    • Client ID: Paste the Client ID copied from Google Developer Console.
    • OAuth scopes: Copy and paste the link https://www.googleapis.com/auth/admin.directory.user – To sync individual users.
    • https://www.googleapis.com/auth/admin.directory.group – To sync user groups.
    • Click on Authorize.
      Note:

      To sync user groups from your G Suite account to the Hexnode console, you need to provide both the URLs separated by comma.

  4. Navigate to Devices > Mobile & endpoints > Settings > Third-party integrations > Android EMM.
  5. Click on Add EMM providers.
  6. Under Token Generator, click on Generate Token and copy the token.

Integration of G Suite with Hexnode MDM Server

  1. Login to your Hexnode MDM portal.
  2. Navigate to Enroll > Platform – Specific > Android > Android Enterprise.
  3. Select Enrollment type as Google Domain.
  4. Click on Configure G Suite.
    You will have the following options to configure.
    • G Suite Admin Email: Enter the G Suite admin email address of the domain that you want to synchronize with Hexnode.
    • Domain Name: Provide the domain name of the G Suite account where the users you want sync with Hexnode resides.
    • G Suite key: Upload the JSON key previously downloaded.
  5. Click on Save to configure G Suite.
  6. Provide the Token and click on Enroll.
  • Token: Paste the EMM token generated from Google Admin Console.

Integration is automatically completed when the details are provided.

Notes:

  • You can verify whether the integration is completed or not from the Google Admin Console.
  • Go to Devices > Third-party Integrations > Android EMM > Manage EMM providers.
  • If the binding is successful, your EMM provider will be listed there.


Once your organization is configured, you can start Enrolling Devices in Android Enterprise using G Suite.