Technical · Course T2Lesson 1 of 5
Android Enterprise setup
8 min read- Enable the Android platform and generate the Android Enterprise enrollment URL
- Complete the Google-side binding and verify the Enterprise ID
- Choose the right default policies, including when Non-Play variants apply
Every Android capability in WeGuard — QR enrollment, Zero Touch, managed Google Play, kiosk mode — sits on top of one binding: your customer's tenant linked to Android Enterprise. Set this up once per tenant, correctly, and everything downstream works.
Enable the platform
In the customer's tenant, go to Settings → Platform, select the Android card (the border turns green), and save. This unlocks the Android-specific settings and the Android Enterprise setup card.
You'll need the Billing Admin role — if you can't see the Platform menu at all, that's why.
Bind to Android Enterprise
The binding runs through Google, anchored to a Google Cloud project:
- In Google Cloud Console, create (or pick) a project and note its Project ID.
- Back in WeGuard, enter that Project ID in the Android Enterprise Setup card and click Generate URL.
- Open the generated URL and sign in with the customer's Google Workspace admin account. Accept the terms, link the project, and authorize WeGuard as the MDM.
- You're redirected back to WeGuard when it completes.
The whole flow takes 10–15 minutes when the Google admin is in the room. As a partner, get that admin on the call before you start — the flow dead-ends without them.
Verify the Enterprise ID
Return to Settings → Platform. A successful binding shows an Enterprise ID on the page. This ID is the proof the tenant is bound — and you'll need it again later for Samsung Knox enrollment, so know where it lives (it also appears in Settings → Android with a copy button).
No Enterprise ID = the binding didn't finish. Refresh first; if it's still missing, run the enrollment flow again.
Create the default policies
Under Settings → Device Provisioning, create the policy types the deployment needs. The three Google Play management modes cover most fleets:
| Policy type | Use case |
|---|---|
| Work Profile (BYOD) | Personal devices with an isolated work container |
| Work Managed (Corporate) | Company-owned, fully managed devices |
| Kiosk (Dedicated) | Single-purpose locked-down devices |
Each has a Non-Play variant for devices without Google Play Services — specialized hardware, or regions where Play is unavailable. If your customer runs rugged scanners or ships into a no-Play market, create the Non-Play policies up front.
What you can do next
With the binding verified and policies created, the tenant is ready for actual enrollment — QR codes for small batches, Zero Touch or KME for fleets. That's the rest of this course.