Using Google's Directory APIs, AirWatch manages email access on mobile devices without any password management. Before you configure the deployment type on the AirWatch Console, there are certain options that you must also enable on the Google Admin Console if using the Directory APIs model.

Enable Device Activation

Apart from configuring the deployment type on the AirWatch Console, you need to first enable the Device Activation option on the Google Admin Console. Enabling this option blocks any unmanaged devices from accessing email.


AirWatch recommends you not to enable Device Activation setting until you are ready to go live with the email integration. Enabling this before the integration will block new devices and cause related problems.

To enable Device Activation, do the following:

  1. On the Google Admin Console, navigate to Device management > Mobile > Setup.
  2. On the Setup page, select Device Activation.
  3. Select an organization from the left panel and then select the Require admin approval for device activation check box.
  4. (Optional) Enter an email address to receive notifications when users enroll their devices. You can also enter a group email address that includes all the administrators who can activate the devices. Select Save.

AirWatch checks with Google for a device account during enrollment when the profile is pushed onto the device:

  • If the enrolled device has an account, Google sends a positive response to AirWatch. AirWatch then sends an approve command to Google to allow email access.
  • If your device does not have a Google account setup before enrolling in AirWatch, then Google sends a negative response and AirWatch updates the Email Dashboard as 'Update Failed' for that device. After the device enrolls, the profile is already installed on the device, and any attempt to connect, creates a device record in Google. When the Google scheduler runs at a default interval of five minutes, the device is identified and allowed for email access. The Email Dashboard is then updated with the 'Scheduled Sync Update'.
  • If the device fails to be identified by the scheduler after two days, then the end user must login to SSP and select Sync Email for the device to receive email access.

Configure Deployment on AirWatch Console

After you have enabled the options on the Google Admin Console, configure the DIrect APIs deployment type on the AirWatch Console.

To configure the deployment:

  1. Navigate to Email > Email Settings and select Configure.The Email Config Add wizard displays.
  1. In the Platform wizard form:
    1. Select Direct as the Deployment Model.
    2. Select Google Apps with Direct API as the Email Type.
    1. Select Next.
  2. In the Deployment wizard form:


    Setting Description
    Friendly Name Enter a friendly name for the Gmail deployment.
    Google Apps Settings
    Google Apps Domain Enter the registered Google Apps Domain address.
    Google Apps Sub-Domain Enter the Google Apps sub domain address.
    Google Apps Admin Username Enter the full email address in the Google Apps Admin username field.
    Google Apps Directory APIs Integration
    Service account certificate (*.p12) Upload the Service account certificate. Enter the certificate password when prompted. The certificate password is created while generating the Service Account client ID on the Google console.
    Directory service account email address Enter the Service Account email address.
    Application Name Enter the project name that you created earlier.