You will now proceed to configure the Android EMM settings on the Mobile Guardian District Dashboard.
Access Mobile Guardian:
- Go to the Mobile Guardian District dashboard and sign in.
- On the District dashboard, click on the "Settings" menu in the left panel.
- Select "Android Settings" from the dropdown menu.
- Click on the "Google Workspace Account Enrollment" button.
- On the Mobile Guardian dashboard, add your Google domain admin email address used for the Google Admin Console.
- Enter the authentication token generated in the previous step.
Android EMM Settings:
- On the configuration page, you will see the Enterprise ID
- Ensure the Default application runtime permission is set to Auto-grant.
- Ensure the System update policy is set to Automatic.
- Next, Save the Android EMM settings.
ℹ️
Note:
Note the Mobile Guardian Dashboard Enterprise ID and navigate back to the Google Workspace Admin screen. The Enterprise ID on the dashboard should correspond with the ID shown in the EMM Third-party Integrations window.
- If it does not appear, refresh the browser for the page to update.
- Select the correct Enterprise ID from the dropdown and click "Save".
- This will bind Mobile Guardian to your Google Workspace organisational Unit.
Completion
After completing the steps, on the Android EMM Settings page, you will have access to global settings for your Android devices.
Here you can enforce settings to Fully Managed Enrolled devices, such as setting devices into COSU Mode.
- COSU Mode: COSU (Corporate-Owned Single-Use) mode is a kiosk mode for Android devices that locks the device to display only the Mobile Guardian interface.
-
Where: This is where the device will be enrolled.
- Everywhere: Allows devices to enrol across the district and all schools, regardless of whether a school is linked to the district.
- District Only: Restricts enrollment exclusively to the district level.
- District Schools Only: Restricts enrollment strictly to schools that are actively linked to the district.
- Require Secondary Login: Required to be on for students to sign in with their dedicated email and password to move the device to the respective school.
-
Restrict Sign-in to Managed Domain: Restricts the device users to only be able to sign in with your registered domain.
- Only available when Google Workspace Settings/Chromebook Settings are added.
-
Application Sign-in Domain: Restricts which domains students can use when signing into applications (e.g. Google Chrome).
- Examples: gmail.com, outlook.com, or your school's custom domain.