What's new in Google endpoint management

This page is updated as we add features, enhancements, and fixes to Google endpoint management. For Google Credential Provider for Windows (GCPW) updates, go to What's new in GCPW.

Note: Features are typically available to customers within several days of launch, but rollouts can take longer.

July 21, 2020: Manage company-owned iOS devices
You can now manage company-owned iPads and iPhones through Google endpoint management, letting you manage all your organization's devices in one place. You set up company-owned iOS device management as an integration between Google and your existing Apple Business Manager or Apple School Manager account. Learn more
When you enroll devices in supervised mode, you can manage dozens of new device settings in the Admin console. These options include controls on access to apps, networks, data security, and authentication. Learn more
You can see details about the device's enrollment status in the company owned inventory. Learn more
April 20, 2020: New management options for Windows 10 devices

You can now manage Windows 10 device sign in and settings with enhanced desktop security for Windows.

To let users sign in to Windows 10 computers with their work Google Account, you can now enable GCPW. GCPW includes 2-step verification and login challenges. Users can also access G Suite services and other single sign-on (SSO) apps without the need to re-enter their Google credentials. Learn more

For more control over company-owned Windows 10 computers, you can now use Windows device management. You can set users' administrative permission level for Windows. You can also apply Windows security, network, hardware, and software settings. Learn more

March 16, 2020: Data exfiltration protection on iOS
A new iOS setting, Data protection, lets you allow or block the movement of work data between mobile apps. When allowed, users can copy content from a Google app (Gmail, Drive, Docs, Sheets, and Slides) in their work account to a Google app in their personal account or a third-party app. Learn more
March 16, 2020: Distribute certificates to mobile devices

You can now control user access to your organization’s Wi-Fi networks, internal apps, and internal websites on mobile devices by distributing device certificates from your on-premises Certificate Authority (CA). Learn more

March 13, 2020: Endpoint verification no longer requires the native helper app

To make endpoint verification easier to deploy for your organization, users no longer need the native helper app on their Windows®, Mac®, or Linux® computers. They still need the Chrome extension, which you can force install or let users install. Learn more

March 2, 2020: Updates to iOS mobile management settings

To make iOS mobile management easier, we updated the following settings:

  • The Managed Apps settings are now Data sharing.

  • Apple push certificates management is now under iOS settings. The setup process follows a new, simpler flow. Learn more

September 16, 2019: New Android Device Policy app

Android Device Policy is an Android management app that replaces the Google Apps Device Policy app. It still enforces your organization’s policies to protect corporate data, but it also allows Google to automatically add new security features.

New Android Device Policy features

  • Zero-touch enrollment—Deploy company-owned devices in bulk without manually setting up each device. Learn more
  • Advanced password management—Set advanced password requirements. For example, disallow repeating or sequential characters. Learn more
  • Advanced VPN management—Specify an app to be an Always On VPN. Learn more
  • Lock screen feature management—Disable notifications, trust agents, fingerprint unlocks, and keyguard features on fully managed devices. Learn more

Changes to existing features

  • Remote device wipe—The data that’s removed depends on device ownership:
    • If ownership of the device is company-owned, all data is wiped from the device and the device is factory reset.
    • If the device is personally owned and has a work profile, only the work profile is wiped, leaving personal data untouched.
    For more information, see Remove corporate data from a device
  • Auto Wipe setting—Applies when a device falls out of sync and when devices don’t adhere to your organization’s policies, such as a weak device password. For details, see Autowipe.
  • Device policy app icon—Android Device Policy is more tightly integrated into the operating system, so users won’t see a device policy app icon. For details, see About Android Device Policy.
  • Policy conflict prevention—Users can only add one G Suite account to a device. This prevents conflicts that would arise if more than one managed account with different device-management policies were added to a device. 
  • Work profile setup—Personal Android devices that are used in your organization need to set up a work profile. You cannot disable the work profile setup.

Check which management app is on a device

You can see which app is managing a device in the Google Admin console. 

  1. Sign in to your Google Admin console.

    Sign in using your administrator account (does not end in @gmail.com).

  2. From the Admin console Home page, go to Devices.
  3. Click Mobile devices to see your managed mobile devices.
  4. Click the row of the device you want to view details for. 
  5. Click Device security
    The device’s management is listed under User agent. 

Related topics

Google, G Suite, and related marks and logos are trademarks of Google LLC. All other company and product names are trademarks of the companies with which they are associated.

Was this helpful?
How can we improve it?