Home › Setup guides › Approve Managed Google Play store apps (in-Intune iframe)
Setup guide · from scratch
Approve Managed Google Play store apps (in-Intune iframe)
Approve Android apps in the embedded Google Play store inside Intune — one action both approves and syncs. Set 'keep approved' for new permissions, and remember approving is not enough: you must also assign to a group.
Intune admin center (Apps > All Apps > Create > Managed Google Play app)
Every step below can be done by hand. Or connect your Microsoft tenant to Decolla once, and Decolla performs this for you over Microsoft Graph in your own tenant — then hands back a verified result you can see and roll back per item. It also puts the fundamentals this step depends on in place — the target group, the licence allocation — so a build is never blocked half-way by a missing dependency.
⏱ By hand: about 15 min of clicking, every build. The Decolla way: part of one tenant connect, then automatic.
Before you start
Managed Google Play already connected to Intune - the enterprise binding must show green before the embedded store will load.
The exact app names or package IDs you intend to approve, so you don't approve a lookalike or clone from the search results.
The target dynamic device group already created, so you can assign each app immediately after approving it.
An Intune admin account with app-management rights.
Screenshot: Select app type with 'Managed Google Play app' highlighted (captured during a live customer build — coming to this page)
Why: 'Managed Google Play app' opens the live embedded store, so one action both approves the real listing and queues it to sync - no manual package upload to keep in step.
Step 3. The Google Play store opens embedded (no separate login); search for the app.
Screenshot: Embedded Managed Google Play iframe search (captured during a live customer build — coming to this page)
Why: The iframe is already signed in as your enterprise from the connector binding, so there is no second login - the bound account does the approving.
Watch for: Search surfaces consumer lookalikes and clones; match the developer and package name, not just the icon, before you approve.
Step 4. Click the app tile, then click 'Approve' / 'Select'.
Screenshot: App tile with Approve button (captured during a live customer build — coming to this page)
Why: Approval is what makes an app available to assign in your tenant - until it is approved it cannot be assigned or installed anywhere.
Step 5. Accept permissions on behalf of all users and choose 'Keep approved when app requests new permissions'.
Screenshot: Permissions prompt with 'Keep approved' toggle (captured during a live customer build — coming to this page)
Why: 'Keep approved' auto-accepts future permission changes; without it the app is suspended tenant-wide the moment its developer adds a permission, and stays off devices until you manually re-approve.
Don’t: Do NOT skip the 'Keep approved' choice - one developer update then silently pulls the app from every device until someone notices.
Step 6. Repeat per app, then click 'Sync' and 'Refresh' on the Intune app pane.
Screenshot: Sync / Refresh action on the app pane (captured during a live customer build — coming to this page)
Why: Approving hands the app to Google; Sync pulls it back into Intune's own app list so it becomes assignable - the two halves of one action.
Watch for: Newly approved apps don't appear instantly - give Sync a few minutes and Refresh the pane rather than assuming it failed and re-approving.
Step 7. Assign each app: open it > Properties > Edit (Assignments), add the target dynamic device group and set the update mode (Default / High Priority / Postponed). Unassigned apps never appear on devices.
Screenshot: Assignments showing the group + update-mode selector (captured during a live customer build — coming to this page)
Why: Assignment is the step that actually deploys; approval only makes an app available to assign. Most 'the app isn't installing' tickets are really an app that was approved but never assigned.
Watch for: The update mode controls rollout speed - 'Postponed' can hold an update back for weeks, fine for stability but wrong for a security patch.
Don’t: Do NOT assume approving was enough - an approved-but-unassigned app sits in your list indefinitely and reaches zero devices.
Step 8. If the store shows 'Custom' mode (after Collections were used), reset via Apps > Managed Google Play > Store layout > Reset to Basic (this deletes all collections).
Screenshot: Store layout showing Basic vs Custom / Reset to Basic (captured during a live customer build — coming to this page)
Why: Basic layout shows every approved app automatically; Custom mode only shows apps you have hand-placed in a collection, which is why a freshly approved app can appear 'missing' on devices.
Watch for: Reset to Basic is destructive - it deletes ALL collections at once, not just the broken one, so record what's there before you reset.