# Migrate from Managed Google Play Accounts to Managed Google Domain

> Upgrade an existing Android Enterprise binding from a Managed Google Play Accounts enterprise to a Managed Google Domain in Applivery — without re-enrolling your managed Devices.

Source: https://docs.applivery.com/en/device-management/android/migrate-to-managed-google-domain/  •  Last updated: 2026-07-30

**Key topics:** Android Enterprise identity models, Enterprise upgrade, Managed Google Domain binding, Google Workspace prerequisites, Android Enterprise, Managed Google Play, Managed Google Domain, Google Workspace, Applivery

---

**TL;DR:** If your Android Enterprise is bound as a Managed Google Play Accounts enterprise, you can upgrade it to a Managed Google Domain from Applivery's Android Setup or the Managed Google Play catalog. The upgrade keeps the same Enterprise ID and doesn't re-enroll Devices, but it's one-way.

Android Enterprise supports two identity models for provisioning Devices: **Managed Google Play Accounts Enterprise** and **Managed Google Domain**.

In the first, users are registered through _Managed Google Play Accounts_ — accounts provisioned directly by the EMM provider and not tied to an existing corporate domain. _Managed Google accounts_ aren't supported here, because structurally they aren't part of this model. In the second, your organization operates on a managed Google domain (for example, Google Workspace or Cloud Identity), so users authenticate with their corporate _managed Google accounts_ and that identity is associated directly with the managed Android Devices.

In practice, this determines how much identity control you have. If you need to restrict provisioning to corporate identities from a specific domain, the Managed Google Domain is the model you need. Under a Managed Google Play Accounts enterprise, identity control is limited to the Managed Google Play Accounts scheme, with no way to apply domain-level restrictions. So, whenever you need to limit account sign-up on the Device to only those belonging to your corporate domain, Applivery must have been bound as a **Managed Google Domain**.

:::info
Since 2024, Google provisions a Managed Google Domain by default for all new organizations that register for Android Enterprise, as noted in the [official Android Enterprise documentation](https://support.google.com/work/android/answer/7042221). The Managed Google Play Accounts enterprise model remains as a fallback for specific cases — for example, organizations that can't or don't want to bind a managed Google domain. This migration applies to organizations already running the older model that want to move to the managed domain model.
:::

## Differences and benefits

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><th colspan="1" rowspan="1"><p></p></th><th colspan="1" rowspan="1"><p><strong>Managed Google Play Accounts Enterprise</strong></p></th><th colspan="1" rowspan="1"><p><strong>Managed Google Domain</strong></p></th></tr><tr><td colspan="1" rowspan="1"><p>User account type</p></td><td colspan="1" rowspan="1"><p>Managed Google Play Accounts (limited accounts, created and managed by the EMM)</p></td><td colspan="1" rowspan="1"><p>Managed Google accounts (full accounts, tied to the corporate domain)</p></td></tr><tr><td colspan="1" rowspan="1"><p>Responsible for authentication</p></td><td colspan="1" rowspan="1"><p>The EMM (Applivery)</p></td><td colspan="1" rowspan="1"><p>Google</p></td></tr><tr><td colspan="1" rowspan="1"><p>Tied to a corporate domain</p></td><td colspan="1" rowspan="1"><p>No</p></td><td colspan="1" rowspan="1"><p>Yes</p></td></tr><tr><td colspan="1" rowspan="1"><p>Domain-based sign-up restriction</p></td><td colspan="1" rowspan="1"><p>Not available</p></td><td colspan="1" rowspan="1"><p>Available (<code>Authentication Type: GOOGLE_AUTHENTICATED</code> + managed domain)</p></td></tr><tr><td colspan="1" rowspan="1"><p>Access to other Google services</p></td><td colspan="1" rowspan="1"><p>Managed Google Play only</p></td><td colspan="1" rowspan="1"><p>Full Google suite (Workspace, Cloud Identity, etc.)</p></td></tr><tr><td colspan="1" rowspan="1"><p>Centralized user management</p></td><td colspan="1" rowspan="1"><p>No</p></td><td colspan="1" rowspan="1"><p>Yes (Google Admin Console)</p></td></tr><tr><td colspan="1" rowspan="1"><p>Organization-wide SSO / MFA</p></td><td colspan="1" rowspan="1"><p>No</p></td><td colspan="1" rowspan="1"><p>Yes</p></td></tr><tr><td colspan="1" rowspan="1"><p>Google's recommendation</p></td><td colspan="1" rowspan="1"><p>Fallback only</p></td><td colspan="1" rowspan="1"><p>Recommended and default since 2024</p></td></tr></tbody></table>

Migrating to a Managed Google Domain gives you:

-   **Domain-restricted provisioning** — you can require a corporate account (for example, force authentication with `@yourcompany.com` on the Device's first boot).
    
-   **Corporate-credential administration** — proper identity governance (roles, MFA, SSO) instead of relying on a loose Gmail account.
    
-   **Centralized management** of users, apps, and Devices alongside the rest of your Google products (Workspace, ChromeOS, Chrome browser) from the Google Admin Console.
    
-   **Reduced risk** from depending on a personal Gmail account for the binding — compromise, loss of access if the account owner leaves, and no corporate security controls.
    

## Before you start

Check the following before you begin the migration:

-   Your organization must currently be registered as a **Managed Google Play Accounts enterprise** in Applivery. The upgrade only accepts enterprises with `enterpriseType: MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE`. If the binding is already a managed Google domain, the operation doesn't apply.
    
-   A **managed Google domain** must exist (or be created) for your organization — for example, through Google Workspace or Cloud Identity.
    
-   Your Applivery billing plan must include this feature. The API returns `5050 – Feature not allowed for your billing plan` if it doesn't.
    

### Configure the Google Workspace side

These are the same requirements Applivery asks for when setting up an Android Enterprise directly on a managed domain, and they apply equally before migrating an existing enterprise.

**Verify your domain**

Your corporate domain must be **verified** in Google Workspace. Check and manage it from the [Google Admin Console](https://admin.google.com/), signed in with a **Super Admin** account, under **Domains → Manage domains**. If it isn't verified, Google will show you how (a DNS record or an HTML file upload).

![verify your domain](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/c6b8a356-e987-4cd4-9a13-13e9d36bb8cc.png)

**Enable third-party EMM integration**

For Applivery to manage Devices under the managed domain, enable third-party EMM integration in **Devices → Mobile & endpoints → Settings → Third-party integrations**. Select the relevant Organizational Unit (OU) — you can apply it at the top level or per OU — and turn on **Enable third-party Android mobile management**.

![third-party](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/142c86af-f4be-4cbb-aa91-6a6225231f60.png)

**Confirm admin permissions**

The Google account used in the process must have sufficient permissions — **Super Admin** is recommended. If you use a different account, assign it a role with **Mobile Device Management** privileges from **Admin roles** in the Google Admin Console.

![perms](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/fb96b54f-1e30-40b7-b9f1-66ed4c5e16cc.png)

## Migrate your Enterprise

The upgrade keeps the same enterprise binding (the same Enterprise ID) and doesn't require re-enrolling Devices that are already managed. You can start it from two places in Applivery — both open Google's assistant to bind your account to the managed Google domain.

### Option 1 — From Android Setup

**Open Android Setup**

Once in the [**Applivery Dashboard**](https://dashboard.applivery.io/), go to **Settings**, then **Android**, and open the **Setup** section.

**Start the upgrade**

Click **Start Upgrade**. Google's assistant opens so you can bind the account to your managed Google domain.

![android enterprise binding details](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/89502a08-a003-432c-8f26-43660817b4fd.png)

### Option 2 — From the Managed Google Play catalog

**Open the Google Play catalog inside a policy**

Go to **Policies**, select any Android policy, and open **Apps**. Click **\+ Add App**, then **Google Play**.

**Choose Upgrade for free**

In the Managed Google Play iFrame, click **Upgrade for free** to open Google's binding assistant.

![upgrade for free](https://docs.applivery.com/int/_r2/media/09ac0a4e-3ad8-478f-9f15-3474973eec71/4dcd6e2b-5358-4925-b724-943423e0fc51.png)

### Complete the upgrade in Google

**Sign in with your Super Admin account**

Open the URL from the previous step with the Google Workspace **Super Admin** account for your corporate domain.

**Follow Google's assistant**

Follow the assistant to bind the existing enterprise to the managed domain. Confirm the domain binding and accept the terms Google requests during the process.

**Verify the result**

Back in the Applivery Dashboard, go to **Settings**, then **Android**, open the **Setup** section, and confirm the enterprise now shows as bound to a managed domain.

## Known API errors

<table style="min-width: 75px;"><colgroup><col style="min-width: 25px;"><col style="min-width: 25px;"><col style="min-width: 25px;"></colgroup><tbody><tr><th colspan="1" rowspan="1"><p>Code</p></th><th colspan="1" rowspan="1"><p>Message</p></th><th colspan="1" rowspan="1"><p>Cause</p></th></tr><tr><td colspan="1" rowspan="1"><p><code>5050</code></p></td><td colspan="1" rowspan="1"><p>Feature not allowed for your billing plan</p></td><td colspan="1" rowspan="1"><p>Your billing plan doesn't include this feature</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>6002</code></p></td><td colspan="1" rowspan="1"><p>Body Validation Error</p></td><td colspan="1" rowspan="1"><p>The request body doesn't match the expected schema</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>5147</code></p></td><td colspan="1" rowspan="1"><p>Enterprise upgrade is only available for managed Google Play Accounts enterprises (MANAGED_GOOGLE_PLAY_ACCOUNTS_ENTERPRISE)</p></td><td colspan="1" rowspan="1"><p>The enterprise is already in Managed Google Domain mode</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>5095</code></p></td><td colspan="1" rowspan="1"><p>Error From Emm Android Library</p></td><td colspan="1" rowspan="1"><p>Error returned by the Android EMM library while processing the request</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>4002</code> / <code>4004</code></p></td><td colspan="1" rowspan="1"><p>No auth token / Invalid Token</p></td><td colspan="1" rowspan="1"><p>Authentication failure on the request</p></td></tr><tr><td colspan="1" rowspan="1"><p><code>3001</code></p></td><td colspan="1" rowspan="1"><p>Entity not found</p></td><td colspan="1" rowspan="1"><p>The specified organization doesn't exist</p></td></tr></tbody></table>

If you hit an error code not listed here, contact Applivery support with your organization ID and the exact code.

## Additional considerations

:::warning
This process is **one-way**. Once you migrate to a Managed Google Domain, there is no equivalent downgrade endpoint to return to a Managed Google Play Accounts enterprise.
:::

-   Evaluate the impact on already-enrolled Devices before running the migration in production, and validate it first on a test enterprise or organization if you can.
    
-   After the migration, the **Required Account Email** field in the [Work Account Setup Config](https://docs.applivery.com/en/device-management/android/policies/restrict-enrollment-to-corporate-domain/) policy still accepts only one specific account, not a domain wildcard. Domain-level restriction comes from the nature of the binding (managed Google domain) combined with **Authentication Type: GOOGLE\_AUTHENTICATED**, not from that field.
