Academy
Technical · Course T2

Lesson 1 of 5

Android Enterprise setup

8 min read
In this lesson you'll learn to
  • Enable the Android platform and generate the Android Enterprise enrollment URL
  • Complete the Google-side binding and verify the Enterprise ID
  • Choose the right default policies, including when Non-Play variants apply

Every Android capability in WeGuard — QR enrollment, Zero Touch, managed Google Play, kiosk mode — sits on top of one binding: your customer's tenant linked to Android Enterprise. Set this up once per tenant, correctly, and everything downstream works.

Enable the platform

In the customer's tenant, go to Settings → Platform, select the Android card (the border turns green), and save. This unlocks the Android-specific settings and the Android Enterprise setup card.

You'll need the Billing Admin role — if you can't see the Platform menu at all, that's why.

Bind to Android Enterprise

The binding runs through Google, anchored to a Google Cloud project:

  1. In Google Cloud Console, create (or pick) a project and note its Project ID.
  2. Back in WeGuard, enter that Project ID in the Android Enterprise Setup card and click Generate URL.
  3. Open the generated URL and sign in with the customer's Google Workspace admin account. Accept the terms, link the project, and authorize WeGuard as the MDM.
  4. You're redirected back to WeGuard when it completes.

The whole flow takes 10–15 minutes when the Google admin is in the room. As a partner, get that admin on the call before you start — the flow dead-ends without them.

Verify the Enterprise ID

Return to Settings → Platform. A successful binding shows an Enterprise ID on the page. This ID is the proof the tenant is bound — and you'll need it again later for Samsung Knox enrollment, so know where it lives (it also appears in Settings → Android with a copy button).

No Enterprise ID = the binding didn't finish. Refresh first; if it's still missing, run the enrollment flow again.

Create the default policies

Under Settings → Device Provisioning, create the policy types the deployment needs. The three Google Play management modes cover most fleets:

Policy typeUse case
Work Profile (BYOD)Personal devices with an isolated work container
Work Managed (Corporate)Company-owned, fully managed devices
Kiosk (Dedicated)Single-purpose locked-down devices

Each has a Non-Play variant for devices without Google Play Services — specialized hardware, or regions where Play is unavailable. If your customer runs rugged scanners or ships into a no-Play market, create the Non-Play policies up front.

What you can do next

With the binding verified and policies created, the tenant is ready for actual enrollment — QR codes for small batches, Zero Touch or KME for fleets. That's the rest of this course.

Knowledge check
1. A customer finished the Google enrollment flow, but the Android settings page shows no Enterprise ID. What does that mean?
2. Which policy set exists specifically for devices without Google Play Services?
3. Who can see the Platform menu needed for this setup?