HomeSetup guides › Connect Intune to Managed Google Play (Android Enterprise binding)
Setup guide · from scratch

Connect Intune to Managed Google Play (Android Enterprise binding)

One-time, effectively permanent binding that unlocks Android Enterprise. Sign in with an organisational Entra account that has a working mailbox (NOT personal Gmail). Path is Devices > Enrollment > Android > Prerequisites, NOT Connectors and tokens.

one-time human step · Google enterprise registration (launched from Intune)assisted guide — Decolla walks you through this
≈ 15 min
Google — Android · step 1 of 5 · ≈ 15 minNext ›
The Decolla way — the one bit no tool can click for you.

Google enterprise registration (launched from Intune) needs a human to sign in, so this stays manual on purpose. Decolla makes it painless: the wizard shows these exact screens at the moment you need them and flags precisely what to bring back — a token, a file, an ID — so the automated steps either side of it run without a hitch.

⏱ A genuine human step — Decolla cuts the coordination around it, not the sign-in itself.
Before you start
  • An Intune Administrator (or Global Admin) organisational Entra account - never a personal Gmail.
  • Live access to that account's mailbox to catch Google's validation email.
  • Your organisation's legal name and a monitored business contact address for the Android Enterprise agreement.
  • Edge or Chrome with pop-ups allowed for the Microsoft and Google sign-in domains.
0 of 12 done
Step 1. Open Edge or Chrome and put portal.azure.com, play.google.com and enterprise.google.com in the same browser security zone, or the pop-ups get blocked mid-flow.
Screenshot: Browser security-zone / trusted-sites settings (captured during a live customer build — coming to this page)
Why: The registration hands off between Microsoft and Google across pop-up tabs; different security zones let the browser kill that hand-off silently.
Watch for: There is no error - the pop-up simply never opens, leaving you stranded between clicking Launch and Google's sign-in.
Don’t: Do NOT run this in an InPrivate/Incognito window or one with a hard pop-up blocker - the Google tab will not open.
Step 2. Go to https://intune.microsoft.com and sign in with an Intune Administrator organisational account (e.g. [email protected], never a @gmail.com address).
Screenshot: Intune signed in with the org account (captured during a live customer build — coming to this page)
Why: The account you use here becomes the Google enterprise owner - it is baked into the binding, not just this session's login.
Watch for: Avoid a temporary or break-glass account that may later be deleted; losing the owner account can strand the whole enterprise.
Don’t: Do NOT sign in with a personal Gmail - use an organisational Entra account with a working mailbox.
Step 3. Confirm that account has a working mailbox — Google runs an email validation during registration.
Screenshot: Test email received in the account's mailbox (captured during a live customer build — coming to this page)
Why: Google fires a live validation email during registration; an account with no mailbox fails the check and the binding cannot complete.
Watch for: Many admin accounts are unlicensed with no Exchange mailbox - confirm it actually receives mail before you start, not mid-flow.
Don’t: Do NOT assume a valid sign-in means a valid mailbox - the two are unrelated.
Step 4. Click Devices > Enrollment > Android tab. (Do NOT use Tenant administration for this step.)
Screenshot: Devices > Enrollment > Android tab (captured during a live customer build — coming to this page)
Watch for: The path is Devices > Enrollment > Android, NOT Connectors and tokens - a common wrong turn.
Don’t: Do NOT use Tenant administration - the Managed Google Play prerequisite lives under Devices > Enrollment.
Step 5. Under 'Prerequisites' click 'Managed Google Play'.
Screenshot: Prerequisites list with Managed Google Play (captured during a live customer build — coming to this page)
Why: This is the single entry point that launches the Google-side registration - nothing binds until you go through it.
Step 6. Tick 'I agree' (grants Microsoft permission to send user and device info to Google).
Screenshot: 'I agree' consent screen (captured during a live customer build — coming to this page)
Why: This consent authorises Intune to push user and device data to Google; without it the ongoing sync that carries apps and profiles cannot run.
Don’t: Do NOT tick this for an organisation whose data-sharing stance you have not cleared - it authorises continuous data flow to Google.
Step 7. Click 'Launch Google to connect now' — a new Google tab opens.
Screenshot: 'Launch Google to connect now' button (captured during a live customer build — coming to this page)
Watch for: If nothing opens, it is the pop-up/security-zone issue from step 1, not a Google outage - fix the browser rather than retrying blindly.
Step 8. On Google's page confirm the pre-filled Entra account and choose 'Sign in with Microsoft' if offered — do not switch to a personal Google account.
Screenshot: Google sign-in showing the pre-filled Entra account (redact) (captured during a live customer build — coming to this page)
Why: Confirming the pre-filled Entra account ties the enterprise to your tenant rather than to an individual's private Google identity.
Watch for: Google may quietly default to a Gmail you are already signed into - read the address on screen before you continue.
Don’t: Do NOT switch to a personal Google account - the enterprise would then be owned by a private Gmail and near-impossible to hand over.
Step 9. Enter the organisation name (e.g. 'Example Company Ltd') and business contact, then accept the Android Enterprise agreement.
Screenshot: Google org-details / agreement screen (captured during a live customer build — coming to this page)
Why: The organisation name appears on managed devices and in Google's records - enter the real legal entity, not a nickname.
Watch for: The business contact receives Google's Android Enterprise notices - use a monitored shared mailbox, not one person's address.
Don’t: Do NOT use a placeholder name - it is awkward to change afterwards and is visible to end users.
Step 10. Click 'Allow and create account'.
Screenshot: 'Allow and create account' confirmation (captured during a live customer build — coming to this page)
Why: This creates the enterprise and completes the binding - it is the point of no return.
Watch for: The binding is effectively permanent; unbinding later unenrols and wipes every managed Android device, so treat this click as final.
Step 11. Back in Intune confirm a green 'connected' status showing your organisation name; refresh if it still says not-configured.
Screenshot: Intune Managed Google Play 'Connected' status with org name (captured during a live customer build — coming to this page)
Why: A green 'connected' status showing your org name is the proof the two-way binding took - anything else means it did not finish.
Watch for: Intune caches the old 'not configured' state - refresh the blade before concluding it failed.
Don’t: Do NOT re-run the whole flow because it still looks unconfigured - refresh first; re-running risks a duplicate, confused binding.
Step 12. (Recommended) In Google add a second enterprise owner for redundancy.
Screenshot: Google enterprise owners list (captured during a live customer build — coming to this page)
Why: The enterprise is owned by account(s); a lone owner is a single point of failure for a binding you cannot easily rebuild.
Don’t: Do NOT leave a single owner - if that account is deleted, recovery may force a rebind that wipes every device.
On a schedule: Add a second enterprise owner now and review the owners list whenever admin staff change, so one person leaving cannot strand the binding.

Put these on a schedule

StepRecurring action to diarise
Step 12Add a second enterprise owner now and review the owners list whenever admin staff change, so one person leaving cannot strand the binding.

If it goes wrong

The failures people actually hit on this process, each with the diagnosis and fix:

See it on a real device.

Decolla is in private build — early-access members see a build defined, deployed and rolled back first.

Get early access