I started my Intune lab with a simple goal: enroll an Android device and learn how Android Enterprise
works with Microsoft Intune.
The first step seemed straightforward. Install Company Portal on the phone, sign in with my Microsoft
365 account, connect Intune to Managed Google Play, and begin exploring device management.
Unfortunately, that's not what happened.
The Android device wouldn't enroll. Company Portal would sign in successfully, but enrollment stopped
with a message informing me that the device didn't meet my organization's enrollment requirements. Since
I was the administrator, support department, and end user all at the same time, that wasn't especially
helpful.
While troubleshooting the enrollment issue, I discovered that Managed Google Play hadn't been
configured. That seemed promising. I navigated to Intune, selected the option to connect Google,
completed the required authentication steps, accepted the permissions, reviewed the Android Enterprise
information, and worked through the setup wizard.
Everything appeared to be working.
Then I reached the end of the process and received a message that simply stated:
"Something went wrong. Your account wasn't created."
That was the beginning of the rabbit hole.
Google accepted the authentication. Google accepted the consent. Microsoft accepted the authentication.
Every visible step appeared successful. Yet the Android Enterprise organization was never
created.
The difficult part wasn't the error itself. The difficult part was the lack of information. Nothing
pointed directly to a root cause. There was no obvious configuration problem to fix and no clear
explanation for why the account creation process was failing.
What followed was a deep dive into Android Enterprise, Managed Google Play requirements, tenant
configuration, account settings, and domain identity. Every lead seemed to generate another theory,
another test, and another round of research.
Eventually the investigation kept circling back to one detail: my lab environment was still operating
entirely on the default onmicrosoft.com tenant domain.
At that point I began asking a new question. Was the problem really Android Enterprise, or was the
problem the identity behind it?
That question led to an entirely different project.
I registered twobirdheads.com and began integrating it into the Microsoft 365 tenant. Domain ownership
verification was completed through Cloudflare, DNS records were reviewed, and I found myself learning
far more about domains, DNS, MX records, verification records, and tenant identity than I ever expected
when I started an Android enrollment project.
Somewhere along the way, the original problem changed. I was no longer trying to enroll a phone. I was
trying to understand the environment itself.
As of this writing, the Android Enterprise configuration issue is resolved. And the rabbit hole produced
valuable results. The lab now has a proper
custom domain, a better understanding of Microsoft 365 identity, and a much clearer picture of how
Android Enterprise, Managed Google Play, and tenant configuration all fit together.
The lesson wasn't how to configure Intune.
The lesson was that sometimes a simple setup wizard can uncover dependencies you didn't even know
existed.
I started out trying to enroll an Android phone.
I ended up learning about domains, DNS, Cloudflare, tenant identity, and the many questions hidden
behind a single error message that said, "Something went wrong." 🐦🐦