Use Workspace ONE UEM to push Android public and internal applications, and web apps to Android devices. This process includes adding and approving applications for integration between Workspace ONE UEM and the Google Play Store. After approval, assign the application to devices using smart groups, a Workspace ONE UEM system that allows you to group devices on criteria you set. The final step is to assign the Terms of Use.

Applications that you push through the integration of Workspace ONE UEM and Android have the same functionality as their counterparts from the Google Play Store.

However, you can use Workspace ONE UEM features to apply policies to the applications. For example, you can add configurations that make using the application more convenient and you can configure settings that make using the application more secure.

  • To add convenience of use, configure the Send Application Configuration option. Application configurations allow you to pre-configure supported key-value pairs and to push them down to devices with the application. Examples of supported values may include user names, passwords, and VPN settings. Support value depends upon the application.

  • To add secure features, use Workspace ONE UEM profiles for Android. Profiles let you set passcodes, apply restrictions, and use certificates for authentication.

The Workspace ONE UEM console allows you to push alpha, beta, or production versions of apps. Using alpha and beta versions of apps allows for testing for compatibility and stability before pushing the production version. You can select specific smart groups for testing and use flexible deployment to determine which users receive which version of the app. If you don't select whether to push the alpha or beta version, the production version is automatically assigned.

For more information on application assignment, see Assign Applications for Android.


VMware productivity apps (Browser, Boxer, Content Locker, etc) are not supported with Android (Legacy) Knox container deployments, such as Dual Persona or Container Only Mode, due to technical limitations with Knox container data separation. The Workspace ONE Intelligent Hub manages the container from the outside, and is not able to communicate with apps on the inside. Since the apps require a direct link to the Workspace ONE Intelligent Hub in order to communicate with the Workspace ONE UEM console, the apps cannot be configured inside the container. In order to use productivity apps with Knox, the device must be enrolled using Android Enterprise on a device running Knox 3.x or higher.