Skip to main content

Glossary

Android Enterprise Recommended

Android Enterprise Recommended is Google's validation program, launched in February 2018, that lists devices and management solutions meeting a published set of enterprise requirements: hardware minimums, timely security updates, zero-touch support and a consistent management experience. For an IT team it's a shortlist that answers the buying question "will this device still be patched in three years and will my MDM manage it properly".

How it works

Google runs two tracks. The device track validates phones, tablets and rugged terminals from manufacturers such as Samsung, Zebra, Honeywell, Google itself and others. The EMM track (enterprise mobility management, Google's word for MDM vendors) validates management consoles against a feature list covering the Android Enterprise modes, app management and security policies.

For devices, the requirements at launch were concrete: at least 2 GB of RAM, Android 7.0 or later, security updates within 90 days of release for a minimum of three years, zero-touch enrollment support, and a consistent behavior for work profile and fully managed modes. Rugged devices got their own rules in 2018 with longer update windows and drop-test expectations. Google has adjusted the thresholds over the years and now publishes the current list on its Android Enterprise site, with each device's committed update period shown.

For management solutions, validation means Google tested the console against its feature set and keeps checking it as Android evolves. Vendors on the list get early access to new APIs and are expected to keep up with each release.

Validation isn't certification of security. It's a statement that the device or console implements Android Enterprise the way Google intends, with an update commitment attached.

Why it matters for a fleet

Buying Android hardware for a fleet is mostly a bet on updates. A cheap tablet that never gets a security patch after month six will fail your compliance policy by year two, and by then you have 300 of them. The Recommended list turns that bet into a written commitment from the manufacturer.

It also cuts the surprises at enrollment. Devices on the list support zero-touch, so they can be shipped sealed to a site and enroll at first boot. Devices off the list sometimes do, sometimes don't, and you find out with the box open.

One caveat: absence from the list isn't disqualification. Some excellent rugged devices skip the program for commercial reasons, and Samsung's Knox line has its own guarantees on top. Use the list as a filter, then check the update policy of whatever you're about to buy.

How Appaloosa handles it

Appaloosa manages Android through Android Enterprise, which is the framework the Recommended program is built around: work profile, fully managed, COPE and dedicated modes, enrollment by zero-touch, QR code, token or Knox Mobile Enrollment, apps from Managed Google Play or private APK uploads, and OEM settings through OEMConfig. Devices on the Recommended list are the ones that enroll and update with the least friction, and compliance rules on patch level catch the ones that fall behind. Everything is detailed on the Android MDM page.

Explore

See the full platform

Enrollment, apps, security, remote support: all in one place.

Explore Appaloosa

See Appaloosa run on your fleet Book a demo

Frequently asked questions

Is Android Enterprise Recommended a security certification?
No. It's a validation that a device or a management console implements Android Enterprise correctly and, for devices, that the manufacturer commits to a security update window. It says nothing about how the device is configured in your fleet; that's still your policy's job.
Should I only buy devices on the Android Enterprise Recommended list?
It's a good default for phones and tablets because the update commitment is public. For rugged devices, also consider models off the list from vendors with their own written update policies, such as Zebra's LifeGuard program. What you want is a dated commitment to security patches, whoever signs it.
Does my MDM need to be Android Enterprise Recommended?
Not strictly. Any MDM using Google's Android Management API can manage Android Enterprise devices. The EMM validation tells you Google tested the console against its feature set, which lowers the risk of a mode or a policy being missing when you need it.