Skip to main content

Create an Android Work Account Policy

Use this policy to configure work account authentication requirements on managed Android devices. Use this policy to control whether device management proceeds without a Google authenticated account, or whether a specific Google enterprise account email is required during setup. This policy works for devices running Android 6.0 and later.

Prerequisites

Considerations

  • No action is needed on the device to activate this policy after you save and assign it.
  • Set the email address before provisioning. Once a Google authenticated account is added to the device, changing the email has no effect. The address must be an all-lowercase enterprise Google account (no consumer accounts).

Creating the Policy

To create a Work Account policy for Android devices, do the following:

Selecting the Policy Template

  1. Log in to the JumpCloud Admin portal.
Important

If your data is stored outside of the US, check which login URL you should be using depending on your region. If your organization uses LDAP, RADIUS, or requires firewall allow list configuration, the Fully Qualified Domain Names (FQDNs) will also be region specific. See JumpCloud Data Centers for the URLs, FQDNs, and IP addresses.

  1. Go to Device Management > Policy Management. The Policy Management page is displayed.
  2. On the Policy Management page, click +Add New.
  3. Select Device Policy to assign the policy to devices and device groups. On the New Device Policy page:
    • Select the Android tab.
    • Search and select Work Account, then click Configure. The Details tab of the policy is displayed.
    • On the Details tab, configure the required policy configuration settings.
    • (Optional) In the Policy Name field, enter a new name for the policy or keep the default. Policy names must be unique.
    • (Optional) In the Policy Notes field, enter details such as creation date of the policy, and information on testing and deployment of the policy.

Configuring the Policy

Under Settings, use Work Account Authentication to control whether the device must be managed with a Google authenticated enterprise account.

Select one option:

OptionDescription
Authentication Not EnforcedDevice management does not require Google authentication. Google Account Email is not used.
Google AuthenticatedThe device must be managed with a Google authenticated enterprise account. You must enter the required account in Google Account Email.

The default is Authentication Not Enforced.

When Work Account Authentication is Google Authenticated, the Google Account Email field is displayed.

Enter the Google enterprise account email address to require on the device during setup. The address must meet these requirements:

  • Must be an enterprise Google account, not a consumer account.
  • Must be all lowercase.
  • Must be set before the device is provisioned. After a Google authenticated account is added to the device, changing this value has no effect.

You can enter a static email address or use dynamic lookup values to personalize the address. For example, you can use {username} to insert a User attribute at policy apply time.

The Admin Portal validates policy settings before save:

  • Work Account Authentication is required.
  • Google Account Email is required when Work Account Authentication is Google Authenticated.

If you enter an invalid value, an error message is displayed and the policy is not saved until you correct the configuration.

Applying the Policy

  • (Optional) Select the Device Groups tab. Select one or more device groups where you want to apply this policy. For device groups with multiple OS member types, the policy is applied only to the supported OS.
  • Or, select the Devices tab. Select one or more devices where you want to apply this policy.
  • Click save. A success message is displayed indicating the completion of policy creation.

Viewing Policy Status

  1. Select the Status tab.
  2. To see the last Result Log for a device where this policy is applied, click view.
note
  • If any errors occur, they're listed in Exit Status. If you have an Exit Status of 0, no errors occurred when applying or enforcing this policy.
tip

For this policy to take effect, you must specify a device or a device group.

Was this information helpful?