About Google Apps Device Policy for Android
This article only applies to G Suite, Education, and Government customers. Learn more about G Suite.
The Google Apps Device Policy app enforces security policies on your Android device to protect it and make it more secure.
Learn how to set up the Google Apps Device Policy app.
- Android 2.2+.
- You've signed in to your G Suite account on your device.
- If you receive the message "Your domain requires mobile device management. Please install the Google Apps Device Policy application to enforce security policies required by the email@example.com account." on your Android device, you need to install the Google Apps Device Policy app.
Some organizations require their users to install the Google Apps Device Policy app on their device. Failure to install the app may block your mail, calendar, and contacts from syncing with your device. Contact your G Suite administrator for more details.
Your administrator can set the following security policies:
- Device password strength.
- Device password length.
- Number of invalid passwords allowed before the device is wiped.
- Number of recently expired passwords that are blocked.
- Number of days before a device password expires.
- Number of idle minutes before a device automatically locks.
- Application auditing.
- Remote account removal from a device.
- Remote wipe a device.
- Device policy app version requirements.
- Number of days device is not synced before wiping.
- Blocking of security-compromised devices.
Your administrator can also configure Wi-Fi networks and manage network access certificates using the app. They might choose to hide a network's details so that only users who have the network name and password can connect to it.
When you open the Google Apps Device Policy app on your device, it opens on the Status screen. To view the Policies or Messages screen, swipe from the left to select the screen that you want to view. You can use the Google Apps Device Policy app to:
- Manage your device: You can access the My Devices page to ring, lock, and locate your device as well as reset your screen-lock PIN. You can also remotely wipe your device if your administrator allows. To determine your device's location, it must be turned on and connected to a network with location services turned on. In addition, Google Apps Device Policy needs permission to access your location. This permission is automatically granted to the Google Apps Device Policy app in the work profile and on company owned devices. Note: Your location information is not shared with your administrator.
- Sync your device: On the Status screen, you can see when your device last successfully synced with the server. To manually sync your device to ensure that you have the most up-to-date policies, touch Sync Now.
- View security policies and network settings: On the Policies screen, you can view the security policies that your administrator sets on your device. If your device doesn’t comply with any of the set policies, you need to take action to resolve them. You can view the list of details about your device that are shared with your administrator, such as Google Apps Device Policy app version, device OS version, device model, your email address, and so on. You can also view the Wi-Fi networks that your administrator configured and server certificates.
- Get multiple-account support: If you set up the Google Apps Device Policy app with multiple G Suite accounts with different policies, the most restrictive policy will be enforced on your device. For example, if one domain requires the device PIN to be 4 characters long and another requires it to be 6 characters long, the device enforces the 6-character length. For more information, G Suite administrators can see Assist users of managed Android devices.
- Create a work profile: If your organization uses Android in the workplace, you can set up a work profile. Android lets you easily switch between work and personal apps on your device. You must have an Android 5.0 Lollipop or later device that supports managed profiles to set up a work profile.