> ## Documentation Index
> Fetch the complete documentation index at: https://docs.iru.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Android Setup

> Set up Android Enterprise integration in Iru Endpoint. Connect your managed Google Play account and configure Android device management capabilities.

<Callout icon="android" color="#4f46e5" iconType="regular">This guide applies to Android devices</Callout>

Set up the Android Enterprise integration so you can enroll and manage Android devices with work profiles from one platform. Enable Android in Organization settings and configure Android Enterprise (Google); then configure Blueprints and Library, then set up enrollment. Iru Endpoint uses the Android Management API for company-owned work profile management.

## Prerequisites

Before you begin, ensure you have:

* **Super admin** access to your organization's Google Admin console ([learn more about super admin roles](https://support.google.com/a/answer/2405986?hl=en\&sjid=10473235341862195521-NA))
* **Company-owned devices** in factory reset state for enrollment
* **Android 13 and higher**
* **Third-party Android mobile Management** enabled in Google Workspace (see steps below)

### Enable third-party Android mobile Management in Google Workspace

<Steps>
  <Step title="Sign in to Google Admin console">
    In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com).
  </Step>

  <Step title="Open Third-party integrations">
    Go to **Devices** → **Mobile & endpoints** → **Settings** → **Third-party integrations**.
  </Step>

  <Step title="Select organization unit and Android EMM">
    Select the related organization unit, then select the **Android EMM** block.
  </Step>

  <Step title="Enable and save">
    Check the box for **Enable third-party Android mobile management**, then click **SAVE**.

    <Frame>
      <img src="https://mintcdn.com/iru/5in1I53Emml_ttth/assets/media/images/iru-android-third-party-integrations.png?fit=max&auto=format&n=5in1I53Emml_ttth&q=85&s=19544124777ce8a02a71f69cb5f54302" alt="Third-party integrations in Google Workspace showing Android EMM and Enable third-party Android mobile management" width="2818" height="1500" data-path="assets/media/images/iru-android-third-party-integrations.png" />
    </Frame>
  </Step>
</Steps>

## Enable Android platform

<Note>
  Only users with the **Account Owner** role can enable or disable platforms. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for more details.
</Note>

<Steps>
  <Step title="Navigate to the Account Menu Button">
    In Iru Endpoint, in the sidebar, click the [**Account Menu Button**](/en/iru/platform-overview/account-menu).
  </Step>

  <Step title="Open Organization profile">
    Click **Organization** in the menu.

    <Frame>
      <img src="https://mintcdn.com/iru/8BYPjuKZa-zyEEf_/assets/media/images/iru-nav-org.png?fit=max&auto=format&n=8BYPjuKZa-zyEEf_&q=85&s=f8a368153bc4b87d3a4aa49961d54a20" alt="Screenshot of the account menu with Organization option highlighted" width="562" height="1040" data-path="assets/media/images/iru-nav-org.png" />
    </Frame>
  </Step>

  <Step title="Open the Endpoint tab">
    Select the **Endpoint** tab.
  </Step>

  <Step title="Edit platforms">
    Under **Platforms you use**, click **Edit**.

    <Frame>
      <img src="https://mintcdn.com/iru/eI0Q-5ODciQRYagr/assets/media/images/organization-profile-endpoint-platforms.png?fit=max&auto=format&n=eI0Q-5ODciQRYagr&q=85&s=50cbca12232c4c4c56fb6cd9d1f198dd" alt="Screenshot of the Organization Endpoint tab showing Platforms you use and Edit button" width="1942" height="1046" data-path="assets/media/images/organization-profile-endpoint-platforms.png" />
    </Frame>
  </Step>

  <Step title="Select Android and click Save changes">
    Select **Android** (and optionally Windows if you plan to manage both platforms), then click **Save changes** at the bottom of the page.

    <Frame>
      <img src="https://mintcdn.com/iru/eI0Q-5ODciQRYagr/assets/media/images/organization-profile-endpoint-edit.png?fit=max&auto=format&n=eI0Q-5ODciQRYagr&q=85&s=44025438e49cd6bc5afb6ff4a193446a" alt="Screenshot of the platform selector with platform options and Save changes button" width="1954" height="1282" data-path="assets/media/images/organization-profile-endpoint-edit.png" />
    </Frame>
  </Step>
</Steps>

<Note>
  You can optionally enable the Windows platform at the same time when selecting platforms.
</Note>

## Configure Android Enterprise

If the Configure Android Enterprise window is not open, go to [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**, select **Android** under **Platform integrations**, then click **Configure Android Enterprise**.

<Note>
  Only the **Account Owner** can configure Android Enterprise. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions) for roles and permissions.
</Note>

<Steps>
  <Step title="Enter integration name">
    Enter a name for your Android Enterprise integration.
  </Step>

  <Step title="Sign in with Google">
    Click **Continue with Google** and sign in with your Google Admin account (super admin role required). Select **Next** when prompted (your Iru Endpoint admin email may be pre-filled).
  </Step>

  <Step title="Allow device management">
    Select **Allow** to allow Iru Endpoint to manage your Android devices.
  </Step>

  <Step title="Configure work profile sign-in">
    Choose how users sign in to the work profile: select **Enable** to allow users to sign in with their managed Google account, or select **Skip** to prevent sign-in with a managed Google account in the work profile.
  </Step>

  <Step title="Return to Integrations page">
    You will be redirected back to the **Integrations** → **Android** page.
  </Step>

  <Step title="Verify integration">
    Verify that the Android Enterprise integration is active and configured.

    <Frame>
      <img src="https://mintcdn.com/iru/5in1I53Emml_ttth/assets/media/images/iru-android-integration-complete.png?fit=max&auto=format&n=5in1I53Emml_ttth&q=85&s=41ed4eb38eab6e4849279e24e272d66e" alt="Android Enterprise integration complete in Iru showing active integration" width="1276" height="724" data-path="assets/media/images/iru-android-integration-complete.png" />
    </Frame>

    <Note>
      Keep a note of the **Enterprise ID** shown here; you will use it in the next section when selecting the EMM provider in Google Workspace.
    </Note>
  </Step>
</Steps>

## Set EMM in Google Workspace

After configuring Android Enterprise in Iru, return to Google Workspace and select the EMM that matches the Enterprise ID shown in Iru. This links your Google organization to the Iru Endpoint Android integration.

<Steps>
  <Step title="Sign in to Google Admin console">
    In a web browser, use your organization's super administrator account to sign in to your organization's Google Admin console at [admin.google.com](https://admin.google.com).
  </Step>

  <Step title="Open Third-party integrations">
    Go to **Devices** → **Mobile & endpoints** → **Settings** → **Third-party integrations**.
  </Step>

  <Step title="Select organization unit and Android EMM">
    Select the related organization unit, then select the **Android EMM** block.
  </Step>

  <Step title="Select the EMM that matches Iru">
    Enable third-party Android mobile management if not already enabled, then select the EMM that matches the **Enterprise ID** from your Iru Endpoint Android integration.
  </Step>

  <Step title="Save">
    Click **SAVE**.

    <Frame>
      <img src="https://mintcdn.com/iru/5in1I53Emml_ttth/assets/media/images/iru-android-set-emm.png?fit=max&auto=format&n=5in1I53Emml_ttth&q=85&s=3e90f1f42d7b9801a4828720e8f6e089" alt="Selecting the EMM in Google Workspace that matches the Enterprise ID in Iru" width="2818" height="1466" data-path="assets/media/images/iru-android-set-emm.png" />
    </Frame>
  </Step>
</Steps>

## Disconnecting Android Enterprise

To disconnect Android Enterprise, remove the integration from Iru Endpoint. Iru coordinates the EMM binding cleanup with Google when you delete the integration.

<Steps>
  <Step title="Delete Android device records (if applicable)">
    If you are removing management from enrolled devices, delete each Android device record from Iru Endpoint first. See [Deleting a Device Record and Uninstalling Iru Endpoint](/en/endpoint/devices/device-record-management/deleting-a-device-record-and-uninstalling-iru-endpoint).
  </Step>

  <Step title="Open Integrations">
    In Iru Endpoint, go to [**Account Menu Button**](/en/iru/platform-overview/account-menu) → **Integrations**, then select **Android** under **Platform integrations**.
  </Step>

  <Step title="Remove the Android Enterprise integration">
    Open the action menu (**...**) on the Android Enterprise integration and select **Delete integration**. Confirm the removal when prompted.
  </Step>
</Steps>

<Note>
  Only the **Account Owner** can remove the Android Enterprise integration. See [Team Member Role Permissions](/en/iru/access/team-member-role-permissions).
</Note>

<Warning>
  **Do not disconnect from Google Admin.** Removing Iru as your EMM provider in Google Admin (via **Remove** next to your EMM binding) disconnects the integration outside of Iru Endpoint. After that, you may be unable to delete Android device records or remove the Android Enterprise integration from Iru Endpoint.
</Warning>

In Google Admin, do not click **Remove** next to your Iru EMM provider. The confirmation dialog below removes the binding for your entire organization. Associated Android Enterprise devices may be wiped.

<Frame>
  <img src="https://mintcdn.com/iru/ZWqtbV1RW7aN7V26/assets/media/images/iru-android-emm-remove-binding-google-admin.png?fit=max&auto=format&n=ZWqtbV1RW7aN7V26&q=85&s=ac7810550388edf53dee16c75fa1870b" alt="Remove binding to EMM Provider dialog in Google Admin console — do not use this to disconnect Iru" width="762" height="927" data-path="assets/media/images/iru-android-emm-remove-binding-google-admin.png" />
</Frame>

## Android Management Requirements

Before enrolling Android devices, ensure you have completed the Prerequisites above and have:

* **Android Enterprise** configured in Iru Endpoint (completed in this guide).
* **Blueprint** configured for Android devices.
* **(Recommended)** **Single sign-on (SSO)** configured for secure authentication.

## Android Management Capabilities

Iru Endpoint provides the following Android management features:

* **Work profile management** for company-owned devices.
* **Application deployment** and management.
* **Policy enforcement** and compliance monitoring.
* **Security configuration** and updates.
* **Device inventory** and reporting.

## Considerations

* **Account Owner required**: Only the Account Owner can configure Android Enterprise.
* **Google Admin access**: You need admin access to the Google Admin console.
* **Factory reset required**: Devices must be in factory reset state for enrollment.
* **Work profile only**: Iru Endpoint supports company-owned work profile management.
* **Disconnect through Iru**: Remove the Android Enterprise integration from Iru Endpoint, not from Google Admin. See [Disconnecting Android Enterprise](#disconnecting-android-enterprise).

For detailed information about Android enrollment, see [Configuring Android Enrollment](/en/endpoint/enrollment/android/configuring-android-enrollment) and [User Experience with Android Enrollment](/en/endpoint/enrollment/android/user-experience-with-android-enrollment).

## Next Steps

After configuring Android Enterprise:

<Steps>
  <Step title="Configure Blueprints and Library">
    Create and configure Blueprints so policies and apps are ready before enrollment. See [Configuring Blueprints](/en/endpoint/getting-started/blueprints-and-library/configuring-blueprints) and [Managing Library](/en/endpoint/getting-started/blueprints-and-library/managing-library).
  </Step>

  <Step title="Enable other platforms (optional)">
    To manage Apple or Windows devices as well, see [Apple Setup](/en/endpoint/getting-started/platform-setup/apple-setup) or [Windows Setup](/en/endpoint/getting-started/platform-setup/windows-setup).
  </Step>

  <Step title="Set up enrollment for each platform">
    Once Blueprints are configured, set up enrollment: [Android Enrollment](/en/endpoint/getting-started/enrollment/android-enrollment), [Apple Enrollment](/en/endpoint/getting-started/enrollment/apple-enrollment), or [Windows Enrollment](/en/endpoint/getting-started/enrollment/windows-enrollment).
  </Step>
</Steps>
