The process involves two key steps: Dashboard Setup and Device Setup. Follow the steps outlined below to complete the enrollment process efficiently.
Dashboard Setup
Follow these steps to configure the Mobile Guardian Dashboard to facilitate the enrollment of EMM QR Scan Devices:
Preparing Your Organisation for EMM:
To set up Android Enterprise using Google Accounts, your organisation must:
-
Have a Managed Google Domain:
- Refer to Get Started with Google Workspace for Education.
- Each domain can only be linked to one EMM console.
- The organisation must follow a verification process to prove domain ownership.
-
Leverage Existing Google Workspace Infrastructure:
- For organisations using Google Workspace, existing domains and identities can be utilised.
- Google Workspace customers already have enterprise IDs, and users are set up with managed Google Accounts.
Let's go through the steps to set up Android EMM for your organisation.
Access Mobile Guardian:
- Go to the Mobile Guardian school dashboard and sign in.
- On the school dashboard, click on the "Settings" menu in the left panel.
- Select "Android Settings" from the dropdown menu.
- Click on the "Google Workspace Account Enrollment" button.
Sign In to Google Admin Console:
In another tab, sign in to the Google Admin console at admin.google.com as a super administrator for your domain.
Configure Third-Party Integrations:
- Click "Devices" > "Mobile & endpoints" > "Settings" > "Third-Party integrations".
- Select the organisational Unit (OU) you wish to use for the EMM enrollments.
- Check the box labelled "Enable third-party Android mobile management".
- Click on "Add EMM provider" / “Manage EMM providers”
Generate or Copy Token:
- Copy the token (a string of characters) or click "Generate Token" to create a new one and then copy it.
Update Mobile Guardian Dashboard:
- On the Mobile Guardian dashboard, add your Google domain admin email address used for the Google Admin Console.
- Enter the authentication token generated in the previous step.
Finalise Settings: (Mandatory)
-
Default application runtime permission:
- Auto Grant
-
System update policy:
- Automatic
-
Require secondary login
- Enable
- Save the Android EMM settings.
Here you can enforce settings on Fully Managed Enrolled devices, such as setting devices into COSU Mode.
-
COSU Mode: COSU (Corporate-Owned Single-Use) mode is a kiosk mode for Android devices that locks the device to display only the Mobile Guardian interface.
- The user will only be able to access third-party applications that are added to the Mobile Guardian Launcher or the My Catalogue section on the device.
-
Require Secondary Login: Required to be on for students to sign in with their dedicated email and password.
- If not enabled, the device will be enrolled, but the student will not be able to sign on to the device.
-
Restrict Sign-in to Managed Domain: Restricts the device users to only be able to sign in with your registered domain.
- Google Workspace Settings need to be set for the domain to be visible
- If it does not appear, refresh the browser for the page to update.
- Select the correct Enterprise ID from the dropdown and click "Save".
- This will bind Mobile Guardian to your Google Workspace organisational Unit.
Completion
After completing the steps, you will be redirected to the Mobile Guardian settings page, showing the details of the enterprise created. On this page, you will have access to global settings for Android devices, such as default application runtime permissions and your system update policy.