Avoid Microsoft Intune if you use G-Suite and Android

Like me, you might have considered Intune to be your one stop MDM solution if you're an Office/Microsoft 365 user.

On the whole it is pretty good, but it's got one massive failing: It doesn't support Google accounts on Android Work Profiles.

You might think that if you're a Microsoft shop it's not a big deal, but there two major reasons why you might want to use Google alongside Azure Active Directory:

  • SSO. Many companies charge extra for SSO with Azure but include it for free with Google, e.g. Slack and Atlassian.
  • Chrome. Let's face it, everyone uses Chrome rather than Edge so signing in with a Google account to sync your favourites is pretty handy.
Managing this setup in an organisation is pretty easy. Sign up for G-Suite account, sync all your users from Azure AD, configure G-Suite to use AAD for authentication and you're done. Enterprise managed Google accounts for everyone at zero cost if you don't actually need G-Suite.

Given the above setup, it would be quite logical that a user would want to log into their work Google account from their personal Android device in a Work Profile so there's a neat separation between work and play.

Which brings us to Intune, Android Enterprise and G-Suite.

Intune links up with the Google Play Store using a managed account. This needs to be a generic Google account (e.g. mycompany@gmail.com) as Android Enterprise does not support G-Suite accounts for this.

Using this managed account you can decide which apps are available to users in the work profile. So far so good.

Now comes the kicker. Installing a Work Profile on an Android device via Intune deliberately blocks you from adding a Google account and there's no workaround. This is by design...

Why? Well if you could add a Google account, that would give you access to all the apps that the Google account can access, not just the ones that the managed account allows you to have.

With me so far?

The upshot of this is that any Android apps you might wish to use that require a Google account can merrily be installed, but you can't actually use any of them.

Chrome is the obvious example and also the most irritating as there are various references in the Intune documentation on configuring Chrome but they all completely exclude the fact that you can't login to it.

As having a G-Suite creates a work Play store by default (as you'd get if you had a G-Suite created Work Profile on the device), it seems rather odd that neither Android Enterprise nor Intune can play nicely with it rather than having a separate one. I'm not sure who's to blame here, Microsoft or Google

Where does this leave us? I'm going to be attempting to use G-Suite MDM for Android devices and everything else with Intune. No idea if it'll work, but it'll be a royal PITA to manage either way.


Comments

  1. Where can you find the new link for user voice? The provided link os dead :(

    ReplyDelete
    Replies
    1. You can't. They killed off Uservoice and didn't put much in it's place.
      I'll remove the link.

      Delete

Post a Comment

Popular posts from this blog

DFS "Waiting for Initial Replication"

Setting Wallpaper for a Remote Desktop Session