Kiosk mode + Managed Google Play: how to connect a device to Managed Google Play to enable browser-only mode
Android
When you want to lock a device to a single browser session, you need both a Managed Google Play binding on your Esper account and a Blueprint configured for kiosk mode before Chrome can be distributed and enforced on the device.
Why this happens
Esper distributes apps to devices through Managed Google Play, which requires a one-time binding between your Esper account and a Google account. Until that binding exists, Chrome cannot be added to a Blueprint, and kiosk mode cannot pin the browser as the sole accessible app.
Before you begin
- At least one device provisioned in your Esper account
- A Google account (Gmail is acceptable for testing; Google Workspace is recommended for production)
- Administrator access to the Esper Console
Steps
- Check your existing Managed Google Play binding status. In the Esper Console, go to Company Settings → Managed Google Play and look at the connection status. If the status shows a connected account, skip to step 3. If it shows "Not connected" or is blank, continue to step 2.
- Bind your Esper account to Managed Google Play. Click Connect Managed Google Play. You will be redirected to Google's Android Enterprise enrollment flow. Sign in with your Google account and complete all steps in the Google wizard before returning to the Esper Console. This is an account-level action — you only need to complete it once, not once per device or per Blueprint.
-
Approve Chrome in your managed app catalog. In the Esper Console, go to Apps & Configuration → Managed Google Play and search for Chrome (package name:
com.android.chrome). Select Approve and accept any permissions. Allow 1–5 minutes for the catalog to sync. Apps that are not explicitly approved here cannot be assigned to a Blueprint. - Add Chrome to your Blueprint. In the Esper Console, go to Blueprints → [Your Blueprint Name] → Apps and add Chrome to the approved app list. Add any other apps the device requires at the same time.
- Enable kiosk mode and set Chrome as the kiosk app. Within the same Blueprint, navigate to the Kiosk section, enable kiosk mode, and select Chrome as the kiosk app. This ensures the device locks to Chrome on startup and prevents users from accessing any other app or the home launcher.
- Configure Chrome's managed settings. Still within the Blueprint, go to Apps & Configuration → Managed Config for Chrome and set the allowed URLs, homepage, or any other browser policy your deployment requires.
- Publish the Blueprint and apply it to your target devices. Save and publish the Blueprint, then go to Devices & Groups → [Target Device] and confirm the Blueprint is applied. Open the Activity Feed on the device record to monitor the sync status.
Verify: On the physical device, Chrome should launch automatically on boot, the display should be locked to your configured URL, and no other apps or the home launcher should be reachable by the end user. The device record in Devices & Groups should show In Sync within 5 minutes of the Blueprint being applied.
Troubleshooting
- The Google wizard fails or does not complete. Confirm that the Google account you are using does not already have an Android Enterprise organization attached to it. If the account belongs to a Google Workspace domain, verify that no conflicting MDM policies are applied at the domain level.
- Chrome does not appear in the app catalog after binding. Return to Apps & Configuration → Managed Google Play and confirm Chrome has been explicitly approved. Unapproved apps are not available for Blueprint assignment, even after a successful binding.
- Kiosk mode is applied but the device does not lock to Chrome. Go to Devices & Groups → [Device Name] → Apps and verify that Chrome is installed and active on the device. Check the Activity Feed for any policy conflicts or errors. Confirm that no other Blueprint or group-level policy is overriding the kiosk setting.
If this doesn't resolve it
Contact Esper Support with the following information:
- Your Esper account name and the device serial number or Esper Device ID
- The name of the Blueprint applied to the device
- A screenshot of the Managed Google Play binding status from Company Settings
- A screenshot or export of the Activity Feed entries for the affected device showing the Blueprint sync attempt
- The Android OS version and Esper Agent version shown in Devices & Groups → [Device Name] → Device Info
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments