Manage Android Enterprise users
A user must have a managed Google account to enroll an Android Enterprise device. Depending on your Android Enterprise configuration, these accounts are managed differently.
The following management types exist:
-
Sophos Mobile manages user accounts for you in these cases:
- You registered your organization with Android Enterprise in Managed Google Play Account mode and haven't upgraded to managed Google domain mode.
- You registered your organization with Android Enterprise in managed Google domain mode after April 9, 2024, and haven't turned on Use managed Google domain device enrollment.
-
You manage user accounts in your Google Workspace or Cloud Identity account if you turned on Use managed Google domain device enrollment. See Google Workspace or Cloud Identity users.
- You manage user accounts in Sophos Fusion if you registered your organization with Android Enterprise in managed Google domain mode before April 9, 2024, and haven't turned on Use managed Google domain device enrollment. See Sophos Fusion users.
Google Workspace or Cloud Identity users
This section applies if you turned on Use managed Google domain device enrollment. This setting isn't available if you registered your organization with Android Enterprise in Managed Google Play Account mode and haven't upgraded to managed Google domain mode.
With managed Google domain device enrollment, you must add users to your organization's Google Workspace or Cloud Identity account before they enroll devices.
You can add users in one of the following ways:
- Add managed Google accounts to your Google Workspace or Cloud Identity account. For Google Workspace, see Options for adding users. For Cloud Identity, see Create Cloud Identity user accounts.
- Configure an external identity provider (IdP) in your Google Workspace or Cloud Identity account. See Use an external IdP.
For more information about Google identity management, see Overview of Google identity management and Best practices for planning accounts and organizations.
Upgrade user management to managed Google domain
If you registered your organization with Android Enterprise in managed Google domain mode before April 9, 2024, and later turn on managed Google domain device enrollment, make sure to keep existing usernames when adding users to your managed Google domain. If you use a different username, Sophos Mobile can't find the user.
For example, if a user's email address in Sophos Fusion is johndoe@your_company.com and your managed Google domain is your_managed_Google_domain, the account name in your managed Google domain must be johndoe@your_managed_Google_domain.
Sophos Fusion users
This section applies if you registered your organization with Android Enterprise in managed Google domain mode before April 9, 2024, and haven't turned on Use managed Google domain device enrollment.
With the managed Google domain registration mode, Sophos Mobile creates a managed Google account when a user enrolls a device in Sophos Fusion Self Service Portal.
Account names are formed like an email address, for example user@your_managed_Google_domain. Sophos Mobile checks if a managed account for the user already exists on the Google server. For this, the username from the user's email address in Sophos Fusion is combined with your managed Google domain. If an account with that name doesn't exist, Sophos Mobile creates it.
Example
If the user's email address in Sophos Fusion is user@your_company.com and your managed Google domain is your_managed_Google_domain, Sophos Mobile checks the Google server for an account user@your_managed_Google_domain.
Other than creating a managed Google account for the user during enrollment, Sophos Mobile doesn't manage the account lifecycle. If you delete the user account in Sophos Mobile, the Google managed user account remains.
You can manage the accounts for your managed Google domain from the Google Admin console.
If required, you can create accounts from your LDAP directory using Google Cloud Directory Sync (GCDS). See About Google Cloud Directory Sync.