Chrome app shows "locked down" or "app does not exist" after Blueprint convergence: re-provision device to fix incomplete AFW setup
Android
When a device converts to Blueprint mode and Chrome shows a "locked down" or "app does not exist" error, the device is not launching apps and may display "The device is not managed by Google Play services" when you attempt to install or manage apps from the Esper Console.
Why this happens
During Blueprint convergence, the Android for Work (Android Enterprise) enrollment must complete fully before managed apps can run. If that enrollment handshake is interrupted or incomplete, the device appears managed in the Esper Console but Google Play services cannot enforce app policies, leaving Chrome and other managed apps in a broken state.
Step 1: Retry convergence
- Open the Esper Console and go to Devices & Groups, then select the affected device.
- On the device, open the Esper Agent and run convergence again. Retrying convergence is non-destructive — it re-applies the Blueprint without wiping the device.
- Once convergence completes, open Chrome on the device to check whether it launches without errors.
- From Devices & Groups → [Device Name] → Apps, install a test app to confirm Google Play services is responding correctly.
If Chrome opens and the test app installs successfully, the issue is resolved. If either step fails, continue to Step 2.
Step 2: Reinstall Chrome (if Play services is confirmed working)
If Google Play services is intact but Chrome alone is broken, reinstall it before attempting a full factory reset.
- In the Esper Console, go to Devices & Groups → [Device Name] → Apps.
- Locate Google Chrome in the app list.
- Select Install / Reinstall and confirm the action. This forces the Play services layer to re-deliver a clean copy of the app to the device.
- Once installation completes, open Chrome on the device and verify it launches without errors.
Step 3: Factory reset and re-provision the device
If neither retry convergence nor reinstalling Chrome resolves the issue, the Android Enterprise enrollment is corrupt and the device must be wiped and provisioned from scratch.
- In the Esper Console, go to Devices & Groups and select the affected device.
- Select Actions → Remove Device.
- Check the Factory Reset checkbox, then select Continue. This wipes the device and removes it from the Esper Console simultaneously.
- Once the device restarts to its out-of-box state, re-provision it using your Blueprint. Confirm the Blueprint has Play Store enabled in its configuration before starting — provisioning without this setting enabled will reproduce the same broken state.
- After provisioning completes, verify the following in the Esper Console under Devices & Groups → [Device Name]:
- The device status is healthy and In Sync.
- Chrome appears under Apps and launches on the device without errors.
- A test app installs successfully from the Esper Console.
If this doesn't resolve it
If the device still shows The device is not managed by Google Play services after a clean re-provision, the issue is likely with your Android Enterprise binding rather than the device itself. Before contacting support, collect the following:
- The device serial number and the exact error message displayed on screen.
- Confirmation of which provisioning method was used (QR code, Zero-Touch Enrollment, Knox Mobile Enrollment, or Google Managed Domain).
- A screenshot of the device's status in Devices & Groups and its entry in the Activity Feed.
- Confirmation of whether other devices provisioned using the same Blueprint are affected.
Contact Esper Support with the above information. If the Android Enterprise binding itself is misconfigured, the support team can verify your enterprise account's link to Google Play for Business and guide you through re-binding if necessary.
Improved title: Chrome "locked down" after Blueprint convergence — incomplete Android Enterprise enrollment
Still need help?
If the steps above don't resolve the issue, submit a support ticket with your device model, Android version, Esper Agent version, and a description of what you've already tried — this helps the support team investigate without a follow-up.
Please sign in to leave a comment.
Comments
0 comments