Preparing for Device Enrolment
Now that Android Enterprise (AfW) is setup you need to create some basic configuration and publish some applications.
Create an Android for Work passcode policy and publish it to the delivery group that will be deployed to your user
To prepare applications first you need log into https://play.google.com/work/ with your Google account in step 1.
Search for the application you wish to make available in the work profile and hit approve.
Now we need to make the application available to the user in XenMobile.
In your XenMobile console navigate to Configure → Apps and add a new Public App Store app.
many thanks for this great documentation I just have an issue while I’m registering my device… I correctly get the “Set up your work profile process” but after that Secure Hub close and I get a message “Your work profile was deleted”. And it doesn’t work… Have you ever experienced this kind of issue ?
are those steps 3 and 4 possible in the on-prem solution or how do you configure it? Is it still possible to use the “Worx Provisioning Tool (Android for Work)” for adding devices?
thank you for your answer!
I use 10.8.x (can not look it up now).
Are there any articles / instructions for all methods?
I got the impression that the are not a lot of articles about that.
Basically I`m looking for a way to deploy different Android devices in an MDM-only scenario.
No possibility to add a Google account
Whitelisting for apps (own app store and no play store on the device)
No AD authentication
Remove / hide unnecessary apps like all google apps or any bloatware
thank you for the answers! This helped a lot! I configured everything and tested it and I`m not amused. The method “afw#xenmobile” works but only with WiFi connection?!
Do you really need WiFi for enrollment? Is there no way around this?
Is it possible to use the “normal” Android policies for Android for work devices? I couldn`t block Chrome with an Android policy.
Do you have experience with the NFC tool of Citrix?
I cant get it to work. WiFi doesnt connect (different networks and always double checked the password).
Citrix is really lacking of usable tools. There are apps of other vendors that are easy to prepare and even create a QR code. I have seen a tool which stats that for Android 6 and newer it`s necessary to use SHA-256 instead of SHA-1.
Do I have to use SHA-256 in the Citrix tool?
Is the URL for the download the “externally hosted url” of the Jason file (like QR Code)?
I am testing with and old Nexus 5 with Android 6. By it`s not possible to hide everything (Chrome and Google Assistant are still there) and you can still login with a google account. Maybe the reason for this is that it is “primarily” a google device.
Zero touch enrolment wont be possible because I have to manage legacy devices (Android 5 – 7). Unfortunately theres no way to add old devices like with Apple DEP.
A second bumper is that COSU wont be possible because Citrix doesnt support this for on-prem XMS right now or maybe never. I think COSU might be the better solution. But I can only go with work manged.
Maybe I cant enrol over mobile data because the device is the problem. I tested it with two different providers. With one SIM-card the connection is very fast (188 Mbps download and 34 Mbps upload). Nevertheless it only worked sometimes with mobile data. Often I get this error message (after downloading Secure Hub). This is very annoying because you have to do a full factory reset every time it doesnt work. If I got another device I`ll test it further.
I think Samsung Knox might be the best solution for supported devices. But you have to connect to WiFi: Android Enterprise | Citrix Endpoint Management
“Only TIMA-enabled Samsung 2.4 devices are supported out of the box by the Samsung KNOX Mobile Enrollment tool. Also, for a device to successfully enroll in the enterprise, the device must connect to WiFi and users must agree to download and install Secure Hub.”
This isn`t true for all devices because Samsung supports OTA enrolment in Knox 2.6: https://docs.samsungknox.com/KME-Getting-Started/Content/about-kme.htm#
Having some errors with the Xenmobile enrollment with AFE and Samsung KME. When continuing the enrollment failing and getting the error " The enrollment couldn’t be Finished" Please try again or contact the administrator.