Error when blacklisting Google Play store

K
kmart
Vail Resorts

Hey all,

I am using application run control to blacklist applications on my device which is working fine until I blacklist the Google Play Store. This is a work managed device delivering in-house applications so I don't need the Play Store to be active. However when I try to deploy an application to the device with the Play store disabled the package fails to install. Does the play store have to be active or how do you go about removing the play store from the device without interfering with in house managed applications? 

Thanks!

6 years ago
Android
ANSWERS
RC
Raymond Chan Diamond Contributor
6 years ago

Have you deployed any feature-control profile payload to your devices?  If so,  what feature-control options have you checked?

K
kmart
6 years ago

Hey Raymond, 

I haven't used any feature control at this point. all that is checked on feature control is the disable doze mode and disable google account creation. I am on version 14.1.8 and some of the feature control options aren't available so I haven't explored it much at this point until I upgrade. 

R
RTMOD@SOTI
6 years ago

Hello,

If you do not want managed applications on the device and still want your device to be managed device and want to restrict Google play store... then you can choose option from Rule ,"skip google account addition during enrollment on Managed Android devices".

This way your devices will not be able to talk to Google Play Store. Test this on one device. it should server your purpose.

This error seem to be logical if you are using google account to add device on enrollment and then you are black listing Google Play Store. 

Thanks !

K
kmart
6 years ago

I have that option selected on all my Android enrollment rules and I am bypassing any account setup via Zebra StageNow. The play store when blacklisted is still impacting application installations in some way.  

JJ
Jim J Bronze Contributor
6 years ago

I experienced the same thing and had to remove the blacklist of the Play Store. Since there is not a Google account on the device and you have disabled Google account creation, you shouldn't be a way for the end user to download anything from the Play Store.

RC
Raymond Chan Diamond Contributor
6 years ago

Hi kmart,

I've assumed that your device is using Android-Enterprise device agent since you said your device is a work managed device.  I want to clarify if this is the case, or if your device is actually using Android Plus device agent.   What are the active MDM API's reported in the "Device Configuration" tab of your device agent?

K
kmart
6 years ago

Hey Raymond,

I am using an Android Enterprise device agent. I've provided a screenshot of the API's and device agent running which I believe is the latest version. As Jim and I are both bypassing Google accounts I wouldn't think this is an issue but I don't want users to be able to launch the Play Store at all ideally. 

RC
Raymond Chan Diamond Contributor
6 years ago (edited 6 years ago)

As you have skipped google account addition during enrollment and disallowed adding personal Google account on your Managed Android devices, there is no need to blacklist Google Play app to avoid  unexpected app from being installed from Google App stores.  Note that Google Play app does not just include support for Google Play app store, but also Google Play support services that patch Google's Android Enterprise functionalities from time to time.  Hence, it is not advisable to blacklist Google Play app on Android Enterprise devices, at least not for now, not until there is better function partitioning or independent app store access control.

Actually, the same logic also applies to Google Chrome browser on Android Enterprise Work Managed devices, as the Webkit engine associated with Chrome is actually reused by many other bundled or 3rd-party apps for performing some kind of html/CSS rendering in their user interface.  It is thus not advisable (and sometimes even impossible on some AE Work Managed devices) to blacklist Chrome browser.  If there is a need to restrict its usage, many policies can be configured via EMM policies (Browser & Browser Proxy configuration in MobiControl profile)  or customization via AppConfig framework.