Play Store app install fails with "Google Play install command failed to update the policy": AFW account
Android
When a Play Store app installation is triggered from Esper Console, the install fails with the error Google Play install command failed to update the policy. The app never installs, and the device Activity Feed shows the command as failed.
Why this happens
Every device enrolled with Managed Google Play requires a managed Google account — called an Android for Work (AFW) account — to be created on the device during provisioning. If that account was not created or was created incorrectly, Esper cannot push Play Store policy updates to the device, and all managed app installs fail. This most often happens when provisioning completes before the AFW account setup has finished, or when a network interruption occurs during that step.
Steps to resolve
- Confirm the device uses Managed Google Play. In the Esper Console, go to Devices & Groups → [Device Name] → Summary. Confirm that Managed Google Play is listed as enabled. If it is not, this article does not apply — contact Esper Support.
- Check whether the AFW account exists on the device. On the physical device, open the Google Play Store app and tap the account icon in the top-right corner. A managed Google account — displayed as an email address ending in a domain associated with your enterprise — should be listed. If a managed account is present, skip to step 4.
- Re-create the AFW account by re-applying the Blueprint. In the Esper Console, go to Devices & Groups → [Device Name] → Blueprints. Verify that the applied blueprint includes Managed Google Play Services set to Always Apply — this setting ensures the AFW account is re-created if it is missing. Select Apply to push the blueprint to the device and wait for convergence to complete. Convergence can take up to 10 minutes depending on network conditions.
- Confirm the AFW account now appears on the device. On the physical device, open the Google Play Store app again and tap the account icon. A managed Google account should now be visible. If it is still missing, the provisioning flow did not complete correctly — see the section below.
- Retry the app installation. In the Esper Console, go to Devices & Groups → [Device Name] → Apps and reissue the install command for the app.
If this doesn't resolve it
If the managed Google account still does not appear after re-applying the Blueprint, the most reliable fix is to re-provision the device using the same Provisioning Template. This ensures the AFW account creation completes as part of a clean enrollment flow.
Before re-provisioning, also check the following:
- Go to Devices & Groups → [Device Name] → Compliance Policy and confirm that Play Store visibility is enabled. A policy that hides the Play Store can interfere with account setup.
- Ensure the device has a stable network connection throughout provisioning. AFW account creation requires uninterrupted access to Google's servers.
If re-provisioning does not resolve the issue, contact Esper Support. Include the device serial number, the exact error message from the Activity Feed, and a description of the provisioning method used.
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments