Skip to content
Avanet

Deploy and withdraw Android Enterprise apps with Sophos Mobile

This article covers Android Enterprise apps through Managed Google Play in Sophos Mobile. It does not replace Android Enterprise enrollment or the policies for fully managed devices and work profiles. What users see and what changes take effect may vary by policy, management mode and synchronization; test changes on test devices first. Exception: Changing the managed configuration of an already installed app also affects installations outside the test group; see the inventory check below.

Before approving an app: prerequisites and scope

  • Under the profile icon in Sophos Fusion > Licensing, check for an active Sophos Mobile Device Management or full Sophos Mobile license, and verify the administrator’s actual permissions in the tenant to approve, install, configure and withdraw apps. Sophos Mobile Threat Defense alone does not grant access to the MDM functions described here. For the entitlement distinction, see Sophos Mobile licensing; for product access and role review, see Sophos Fusion administrator roles. Still verify permission for the specific Mobile action in the tenant.
  • The organization must be registered with Android Enterprise and its Android Enterprise account connected to Sophos Mobile. Check Sophos Fusion > My Products > Mobile > Setup > Google setup > Android Enterprise to confirm that setup is complete. Do not recreate or change an existing registration just to approve an app.
  • Target devices must be enrolled in the appropriate Android Enterprise management mode: fully managed device or work profile. Check the existing Google Play policy configuration for that specific mode and the administrator’s permission to approve apps. Among other things, the policy controls whether users can see only approved apps or all Google Play apps, and how automatic updates work.
  • Before making changes, decide which devices or device groups should receive the app, who owns the app and its data, what should happen to app data when the app is withdrawn, and whether any task bundle requires the app. Start with a small test group. Approving an app in the catalog is not the same as installing it on every device.

Choose the app type and establish ownership

Public app: Under Apps > Android > Open managed Google Play, open the app you want. Then complete approval using the shared steps below.

Private app: An app developed for internal use within your own organization; it is available only to users in that organization. For the Google-hosted private app described here, permanently determine the Google Play account or organization before the first upload. Sophos warns that once a private app has been added, it cannot later be added to another Google Play account or published publicly—even if it is deleted. Involve the app owner and release managers; check the package identifier, release/signing strategy and account ownership beforehand.

Shared daily limit for private and web apps: Through the embedded publishing route described here, Google allows a total of 15 private apps per day; web apps count toward the same overall limit. Plan private uploads and web app publications together with the release managers. Once the limit is reached, schedule further publications for a later day and check publication status before retrying; repeated Create does not bypass the limit. Waiting intervals for Google’s approval do not reset the daily limit.

For the first upload and subsequent selection:

  1. Under Apps > Android > Open managed Google Play > Private apps > +, fill in the app settings: enter a title, select the AAB or APK file, and click Open to use it. For an AAB, agree to the Play App Signing terms. Decide on signing beforehand: For an app first uploaded as an AAB, Google generates and manages the signing key. If you want to use your own key, plan to upload an APK first.
  2. Choose Create. Google starts automatic approval. On first publication, provide an email address for notifications from Google.
  3. After a few minutes, open the new app’s icon under Private apps. On Edit private app, choose the app through Select, using the shared steps below. If Select is missing, Google’s approval is still in progress: close the window, then reopen it and check again after a few more minutes. This wait is a checking interval, not a guaranteed approval deadline.

Caution: If the Google Play configuration allows access to all Play apps, Sophos says users cannot install private apps themselves; installation through Sophos Mobile remains possible. Do not change this policy merely to troubleshoot installation without checking how it affects visibility of other apps.

Complete approval for public and Google-hosted private apps:

  1. On the open app page, choose Select and confirm approval in Sophos Mobile.
  2. Optionally, use Organize apps to add the approved app to a collection and save changes with Save. A collection makes the app easier to find but does not install it; before saving for the first time, read the note about the old Store layout under Existing configurations.
  3. Close the Managed Google Play window and check in Sophos Mobile that the public or private app appears under Apps - Android Enterprise.
  4. After the device’s next synchronization with Sophos Mobile, check the app in the managed Play Store. This timing applies to both app types. Unless the Play configuration says otherwise, users see only apps added in Sophos Mobile by default. Visibility is not installation and does not override the restriction described above on users installing private apps when access to all Play apps is allowed.

Existing self-hosted private apps: Under Edit approved app > Distribution type, check whether Private (self-hosted) is set. In that case, Managed Google Play manages distribution, but the APK is installed from your own server. The upload procedure above does not apply to self-hosted releases. For distribution or recovery, the release manager must check that the local server can be reached and the appropriate APK package is available.

Web app: Opens a configured website; check the destination URL, access and ownership of the web application. Google Chrome must be installed on target devices and usable in the relevant management scope, including the work profile if one is used. Update Chrome before deployment; older versions may not support all web app features.

Before publishing: Observe the shared daily limit for private and web apps above. Google automatically approves a published web app for distribution through all EMM bindings of the same managed Google domain, not just the Sophos Mobile binding currently in use. Before Create, check with the app owner and responsible administrators which other EMM bindings belong to that domain and whether approval across that entire scope is intended. This automatic distribution approval is not automatic installation on devices; a pilot installation does not restrict the domain-wide approval scope. Subsequent selection and confirmation in Sophos Mobile and targeted installation remain separate steps.

  1. In embedded Managed Google Play, under Web apps > +, set the following:

    • Title: Enter a name users will understand, as it should appear in Managed Google Play, such as Serviceportal.
    • Start URL: Enter the approved HTTPS address of the web application for which the organization is responsible. https://portal.example.com/service/ is a purely fictional example: replace the hostname and path with your own reachable start page. HTTPS protects the connection and enables all display modes below; do not include credentials in the URL.
    • Display mode: Full screen hides the device’s status and navigation bars. Standalone leaves both visible and is the default selection. Minimal UI also shows the URL and a refresh button. For an HTTP URL, only Minimal UI can be selected; do not use HTTP as a workaround for HTTPS problems.
    • Use Upload an icon to select and upload a suitable app icon approved for use. Recheck the title, start URL and display mode before choosing Create.
  2. After a few minutes, open the new app’s icon under Web apps. On Edit web app, choose Select and confirm approval. If Select is missing, Google’s approval is still in progress. Close the window, then reopen it and check again after a few more minutes. This wait is a checking interval, not a guaranteed approval deadline.

  3. Close the Managed Google Play window and check that the web app appears in Sophos Mobile under Apps - Android Enterprise. After the device’s next synchronization with Sophos Mobile, check the app in the managed Play Store. Visibility is not installation.

  4. First install the web app on a pilot device as described under Install on selected devices and verify, then launch it through its icon. Check that the intended HTTPS start page is reachable, sign-in works and the selected display mode takes effect. Also check redirects during sign-in and navigation: the mode applies only to pages belonging to the configured URL; a redirect to another website opens that site in the Chrome browser. If behavior is unexpected, first check Chrome in the correct management scope, the configured start URL and redirect destinations with the web app owner before deploying the app to more devices.

If you want to add the web app to a collection and it is missing under Organize apps, first wait 10–15 minutes for registration at Google. Then enter the full app name in quotation marks in the search bar, even if it contains no spaces. This refreshes the search data. Check again that the app appears before adding it to the collection and saving with Save. Before saving a collection for the first time, read the note about the old Store layout under Existing configurations. This search step concerns visibility under Organize apps, not approval through Select as described above; the 10–15 minutes are not a guaranteed deadline either.

According to Sophos, if a policy allows access to all Play apps, users cannot install web apps themselves either; installation through Sophos Mobile remains possible.

Install on selected devices and verify

  1. Under Apps > Android, choose Install for the approved app. Select individual target devices or device groups through Select device groups; review the selection and its scope again before choosing Finish. Sophos Mobile sends the request to Google; Google-hosted apps are installed through Google Play. For existing self-hosted private apps, the APK must be available from your own server.
  2. On a pilot device, check the installation status under Show device > Installed apps and confirm the app is actually installed on the device. If a request gets stuck, first check availability in the country and for the device type; if the request has already been sent to Google, also check pending downloads in the Play Store. Installation starts only once all tasks above its entry in that list have completed.
  3. Do not confuse updates with installation tasks: Sophos says apps cannot be updated directly from Sophos Mobile; users update them in Google Play. The Play policy has separate options for automatic updates. According to Sophos, Google reinstalls an app installed by Sophos Mobile by default after a user manually uninstalls it; users can remove it permanently only if the appropriate Allow app uninstall setting is enabled in the restrictions policy. Check this separately for the device or work profile.

Configuration and placeholders

Before any change or deactivation: Managed configuration is a shared app setting, not a setting limited to the pilot group selected under Install. After you save, Sophos sends the change or removal through the Google API to all devices where the app is already installed. Installing the app only on pilot devices does not limit this scope. Before saving, inventory all existing installations, previous values and dependencies, and possible effects on credentials and personal data; back up secrets only using approved procedures. If production installations exist, obtain approval for a change across the entire affected installed base first. For a genuinely isolated test, use a separate non-production app/enterprise environment; one pilot device in the same installed base is not enough.

Managed configuration is available only for apps that support it. Only after completing that inventory check, open the approved app under Apps > Android, enable Use managed configuration on Edit approved app, set the fields provided by the app vendor under Edit managed configuration, and save in both windows. Propagation can take several minutes; verify the effects on affected devices, especially accounts, servers and secrets.

Text fields can contain $USERNAME and $EMAILADDRESS: when Sophos Mobile assigns the managed settings to a device, it replaces these with the username and email address, respectively. On devices without an assigned user, both are replaced with empty strings. Under Sophos Fusion > My Products > Mobile > Setup > Google setup > Android Enterprise > Email placeholder, Use the assigned user’s email address controls the value of $EMAILADDRESS: when selected, the email address of the user assigned to the device in Sophos Mobile is used; when not selected, the email address used to enroll the device with Sophos Mobile is used. Choose the intended setting and click Save. Only when this option is selected do already installed apps update the email address after a change of assigned user, according to Sophos, at the device’s next synchronization with Sophos Mobile. Do not use personal-data placeholders until you have checked the target device and intended identity.

Existing configurations: According to Sophos, configurations created before August 13, 2022 remain effective but cannot be converted automatically to the new format. On Edit approved app, the old Managed configuration section is available only if Use managed configuration is already selected and the configuration has not yet been migrated. Expand the section using the plus icon to inspect the existing values. Before editing an existing configuration, or updating an app with changes to its managed configuration, document these values, then re-enter them through Edit managed configuration in the new Managed configuration window. Do not toggle any option or save just to inspect the values; the inventory check and approval described above still apply to any later change.

Earlier Play Store pages and categories are likewise not automatically migrated to collections: the old layout remains active only until collections are used for the first time. Before the first Save of a collection, record the old pages and categories, recreate them as collections, and coordinate the planned switch with a test group; after saving, inspect the managed Store view on a pilot device. Do not assume the old layout will be restored automatically.

Change visibility or withdraw an app

Before a permanent withdrawal: Identify installed devices, pending installation tasks, device and group assignments, and task bundles that could deploy the app again. Coordinate these deployments and outstanding tasks with their owners before uninstalling from selected devices and, if appropriate, removing catalog approval afterwards. An administrator’s uninstall task alone does not prove permanent withdrawal; check in the tenant concerned whether an existing deployment will reinstall the app. After synchronization, check task status and installation state on affected devices again.

  • Change only how apps are displayed: Already approved apps can be arranged in collections; at least one app must be added to the first collection. To remove an app only from a collection, remove it from that collection under Organize apps in embedded Managed Google Play. Then choose Save and check the collection view for a test user. This changes only how the app is displayed in that collection; it does not uninstall the app, remove Sophos catalog approval or withdraw the private publication at Google. Arranging apps in collections does not replace an installation task either.
  • Remove managed configuration: Only after the inventory check and approval described above, disable Use managed configuration on Edit approved app and choose Save. Sophos sends the removal to all devices with the app installed; the effect may be delayed. Check dependent app functions and the effects on affected devices afterwards.
  • Uninstall from selected devices: Before submitting the task, check the Restrictions policy applying to the target fully managed devices or work profiles: if Allow app uninstall is disabled, this blocks not only users from uninstalling apps but also administrators from uninstalling them through Sophos Mobile. Coordinate any necessary policy change with the policy owner for the affected scope only, and verify that the change has reached the target devices; do not assume pending or failed uninstall tasks have automatically completed as a result. Under Apps > Android > Uninstall, select the target devices or groups and then the app, set Now or a scheduled time, and choose Finish only after checking the selection. This also applies to apps users installed themselves from their managed Play Store. Sophos sends uninstall requests to Google; the start and effects on devices may be delayed. Clarify potential data loss and user communication in advance; then check installation state on the target devices.
  • Remove approval from the Sophos catalog: For the app in Apps - Android Enterprise, use the arrow to choose Delete and confirm. This removes Sophos catalog approval, not the private publication at Google. After the next synchronization, users can no longer install it anew, but apps already installed are not uninstalled. According to Sophos, an app used in a task bundle cannot be removed. Check dependencies and the installed base first; if needed, uninstall from selected devices before removing catalog approval. Do not assume that removing a private app makes it transferable to a different Google account.
  • Unpublish or delete a private app at Google: In embedded Managed Google Play, open the app under Private apps and choose Make advanced edits. Sign in to the Play Console with the responsible Google account; Google adds it as an administrator of the organization’s Play Console account. Under Release > Setup > Advanced settings > App Availability, choose Unpublish. New users can no longer find and download the app; existing users can continue using it. You can publish it again later. For permanent deletion, contact Play Console Support. The package name remains reserved: publishing again under the same package name is not possible. This deletion also does not stop existing users from using the app. Both Google actions are separate from Delete in the Sophos catalog and from uninstalling an app on a device.

Recovery after withdrawal: Before removing catalog approval or uninstalling, document the original approval, configuration and affected devices. To make the app available again, first repeat approval and installation on a pilot device; for self-hosted private apps, also check the server and APK. Reapproving or reinstalling neither automatically restores deleted local app data nor undoes a private app’s link to its original Google Play account. Assess recovery of app data separately with the app owner.