<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Google Workspace prvisioning in Endpoint Security</title>
    <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449886#M13516</link>
    <description>&lt;P&gt;Interesting. Do you have any links to more elaborate documentation for the setup?&lt;/P&gt;</description>
    <pubDate>Fri, 25 Apr 2025 00:15:08 GMT</pubDate>
    <dc:creator>marijanlesko</dc:creator>
    <dc:date>2025-04-25T00:15:08Z</dc:date>
    <item>
      <title>Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449882#M13512</link>
      <description>&lt;P&gt;We have around 200+ Apple devices that are reset 2-3 times per year for temporary workers.&lt;/P&gt;&lt;P&gt;I have used a profile to automatically setup Google Workspace mailboxes on iPhones and iPads through SME. &lt;/P&gt;&lt;P&gt;We had 2 mailboxes setup per phone:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Personal, owner's mailbox, with personal email&lt;/LI&gt;&lt;LI&gt;Mailbox (single) containing only external contacts for easier sharing &lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Every device would be provisioned with those 2 mailboxes through MDM. contacts mailbox would have the password pushed using MDM, while personal mailbox would require the owner to provide the password.&lt;/P&gt;&lt;P&gt;We used Exchange Activeync for iOS as instructed by Meraki documentation.&lt;/P&gt;&lt;P&gt;Every Apple device would be provisioned through MDM with owner's email and Google Workspace settings. The owner would only have to enter his email password.&lt;/P&gt;&lt;P&gt;That worked flawlessly for 8+ years until 2 weeks ago when suddenly, both mailboxes would randomly ask device user to enter the password.&lt;/P&gt;&lt;P&gt;The passwords would not be accepted and the request would keep randomly popping up.&lt;/P&gt;&lt;P&gt;I tried to manually provision a single Google WKS email account on a managed device (Apple Mail) and it worked using Google option. &lt;/P&gt;&lt;P&gt;Meraki MDM Exchange Active Sync setting for iOS that worked for many years stopped working for Google workspace. &lt;/P&gt;&lt;P&gt;Our only option is now to provision Google account manually on every device what is time consuming.&lt;/P&gt;&lt;P&gt;Testing, we have discovered that iOS Exchange ActiveSync profile setting now only works for Microsoft 365 and automatically opens Microsoft authentication page. &lt;/P&gt;&lt;P&gt;Setup for Google Workspace using ActiveSync as per Meraki documentation (last version from 2023) does not work anymore.&lt;/P&gt;&lt;P&gt;Is there anybody who had the same issue?&lt;/P&gt;</description>
      <pubDate>Mon, 21 Apr 2025 21:57:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449882#M13512</guid>
      <dc:creator>marijanlesko</dc:creator>
      <dc:date>2025-04-21T21:57:07Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449883#M13513</link>
      <description>&lt;P&gt;We switched away from Exchange accounts several years ago.  Instead we use the Google profile to establish user's email accounts.  They're account is preset on the iPad, but they do have to authenticate with their password to start using it.  Google OAuth is the method of verifications.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 02:23:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449883#M13513</guid>
      <dc:creator>ekramer</dc:creator>
      <dc:date>2025-04-22T02:23:43Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449884#M13514</link>
      <description>&lt;P&gt;I suspect this is the issue being reported by multiple end users at my organization.  &lt;BR /&gt;Can you provide details on the issue for your organization?  &lt;/P&gt;&lt;P&gt;I have had over a dozen users indicate the password incorrect notification, however they are able to use the same password to access their account.   &lt;/P&gt;&lt;P&gt;The truly sad part, is I have been working with a Meraki support rep since April 6th when this was first reported by only 3 or 4 users and they are clueless.   &lt;/P&gt;</description>
      <pubDate>Tue, 22 Apr 2025 16:51:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449884#M13514</guid>
      <dc:creator>Patrick_1</dc:creator>
      <dc:date>2025-04-22T16:51:36Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449885#M13515</link>
      <description>&lt;P&gt;Hm sounds like my issue. &lt;/P&gt;&lt;P&gt;Will have more time tomorrow.&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 00:14:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449885#M13515</guid>
      <dc:creator>marijanlesko</dc:creator>
      <dc:date>2025-04-25T00:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449886#M13516</link>
      <description>&lt;P&gt;Interesting. Do you have any links to more elaborate documentation for the setup?&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 00:15:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449886#M13516</guid>
      <dc:creator>marijanlesko</dc:creator>
      <dc:date>2025-04-25T00:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449887#M13517</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Currently, iOS devices configured to use the Meraki profile that pushes any “Exchange ActiveSync” email configuration are continually prompting users for their passwords&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;This appears to be directly related to this Google blog post &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://workspaceupdates.googleblog.com/2023/09/winding-down-google-sync-and-less-secure-apps-support.html" target="_blank" rel="noopener nofollow noreferrer"&gt;&lt;SPAN&gt;Beginning September 30, 2024: third-party apps that use only a password to access Google Accounts and Google Sync will no longer be supported&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;(search this page for the word “incorrect”)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;At this time, the following workarounds can be used:&lt;BR /&gt;Use the Gmail app (a Meraki profile can be configured for this)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Use Outlook app (a Meraki profile can be configured for this)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Manually configure native iOS app and sign-in using OAUTH&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I have not had any luck configuring a Meraki profile to push a Google Account to an iOS device that successfully syncs email once the user enters their password.   If anyone has a working custom mobileconfig they would be willing to share, I would appreciate it.   &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 25 Apr 2025 14:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449887#M13517</guid>
      <dc:creator>Patrick_1</dc:creator>
      <dc:date>2025-04-25T14:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Google Workspace prvisioning</title>
      <link>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449888#M13518</link>
      <description>&lt;P&gt;Hi &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/23695"&gt;@marijanlesko&lt;/A&gt; &amp;amp; &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/20018"&gt;@Patrick_1&lt;/A&gt;,&lt;/P&gt;&lt;P&gt;Just to add onto &lt;A href="https://community.meraki.com/t5/user/viewprofilepage/user-id/20018"&gt;@Patrick_1&lt;/A&gt;'s comments, we do have a few options for configuration since the recent Google changes in accepted authentication methods:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Configure a 3rd party (non-native iOS Mail App) via a Managed App Config - more on this below:&lt;UL&gt;&lt;LI&gt;&lt;A href="https://documentation.meraki.com/SM/Profiles_and_Settings/Using_the_Managed_App_Settings_Payload" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/SM/Profiles_and_Settings/Using_the_Managed_App_Settings_Payload&lt;/A&gt; &lt;UL&gt;&lt;LI&gt;Gmail&lt;UL&gt;&lt;LI&gt;&lt;A href="https://support.google.com/work/android/answer/7065453?hl=en" target="_blank" rel="noopener nofollow noreferrer"&gt;https://support.google.com/work/android/answer/7065453?hl=en&lt;/A&gt; (Non-Cisco URL)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Microsoft Outlook: &lt;UL&gt;&lt;LI&gt;&lt;A href="https://learn.microsoft.com/en-us/exchange/clients/outlook-for-ios-and-android/account-setup?view=exchserver-2019#key-value-pairs" target="_blank" rel="noopener nofollow noreferrer"&gt;https://learn.microsoft.com/en-us/exchange/clients/outlook-for-ios-and-android/account-setup?view=exchserver-2019#key-value-pairs&lt;/A&gt; (Non-Cisco URL)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Configure and utilize OAuth2 rather than basic authentication - touched on below by Google Support:&lt;UL&gt;&lt;LI&gt;&lt;A href="https://support.google.com/a/answer/9750173?sjid=2283771315733416322-NA" target="_blank" rel="noopener nofollow noreferrer"&gt;https://support.google.com/a/answer/9750173?sjid=2283771315733416322-NA&lt;/A&gt; (Non-Cisco URL)&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;LI&gt;Lastly (and potentially the easiest effort if the default Mail App is desired) - utilize the 'Google Account' Payload. If utilizing 'Owner' e-mail addresses (more on this below) they can be passed through the following process with Apple Configurator:&lt;UL&gt;&lt;LI&gt;&lt;A href="https://documentation.meraki.com/SM/Profiles_and_Settings/Variables_in_Custom_Apple_Profiles_with_Systems_Manager" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/SM/Profiles_and_Settings/Variables_in_Custom_Apple_Profiles_with_Systems_Manager&lt;/A&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;PRE class="lia-code-sample language-markup"&gt;&lt;CODE&gt;&amp;lt;key&amp;gt;AccountName&amp;lt;/key&amp;gt;
&amp;lt;string&amp;gt;$OWNERUSERNAME&amp;lt;/string&amp;gt;
&amp;lt;key&amp;gt;EmailAddress&amp;lt;/key&amp;gt;
&amp;lt;string&amp;gt;$OWNEREMAIL&amp;lt;/string&amp;gt;&lt;/CODE&gt;&lt;/PRE&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://documentation.meraki.com/SM/Other_Topics/Owners" target="_blank" rel="noopener nofollow noreferrer"&gt;https://documentation.meraki.com/SM/Other_Topics/Owners&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;I did confirm internally that our Payload (more on this below) for ActiveSync has not changed as of recent and has been implemented per Apple's Developer Documentation outlined below:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://developer.apple.com/documentation/devicemanagement/exchangeactivesync" target="_blank" rel="noopener nofollow noreferrer"&gt;https://developer.apple.com/documentation/devicemanagement/exchangeactivesync&lt;/A&gt; &lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Tue, 29 Apr 2025 17:51:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/endpoint-security/google-workspace-prvisioning/m-p/5449888#M13518</guid>
      <dc:creator>BrandonD1</dc:creator>
      <dc:date>2025-04-29T17:51:28Z</dc:date>
    </item>
  </channel>
</rss>

