Managing Android devices using Microsoft Intune
Can't add Google Workspace account to Gmail in BYOD work profile — "Action not allowed" despite domain allow-list (Managed Google Play Accounts binding)
Environment:
- Intune (Microsoft 365 Business Premium)
- Android Enterprise – Personally-Owned Work Profile (BYOD), web-based / AMAPI enrollment
- Managed Google Play binding type: Managed Google Play Accounts Enterprise (the "limited / Android only")
- Company email is on Google Workspace (domain: contoso.com is a Workspace domain; MX points to Google)
- Test device: Android (fully enrolled, shows Compliant)
Goal: Allow users to access ONLY their company Google Workspace mailbox (******@contoso.com) via the Gmail app inside the work profile, while blocking personal @gmail.com accounts. We are not using Outlook.
What I configured (Device Restrictions – Personally-Owned Work Profile):
- Add and remove accounts = "Allow all account types"
- Google domain allow-list = contoso.com
- Copy/paste between work & personal = Block
- Screen capture = Block
- (other containment settings enabled)
Problem: When I open the Gmail app in the work profile → Add account → Google → I get "Action not allowed. If you have questions, contact your IT admin." It won't let me type the email address at all.
What I've already tried:
- Confirmed the config profile shows "Succeeded" with a fresh timestamp on the device
- Forced sync 4–5 times from Company Portal (sync succeeds, date updates each time)
- Restarted the device
- Cleared Gmail app data
- Verified domain allow-list is exactly "contoso.com" (no @, no spaces, no blank rows)
- Confirmed "Add and remove accounts" is set to "Allow all account types"
Questions:
- Is adding a Google user account into the work profile actually supported when the enterprise is a "Managed Google Play Accounts Enterprise" binding (vs a managed Google domain)? I've seen references that the work profile runs under a system/dummy Google account and adding another Google account is restricted.
- Does the Google domain allow-list only work with a managed-Google-domain binding, not the Managed Google Play Accounts type?
- If this is a hard limitation, what's the supported way to get Google Workspace mail into a BYOD work profile without verifying our domain in Google / without Outlook?
Any confirmation of whether this is a platform limitation vs a fixable config would be hugely appreciated. Thanks!