# Validate Access Last updated: August 13, 2026 This page explains the Validate Access feature in ManageEngine MDM, which ensures Android Enterprise policies and configurations are pushed only to MDM-enrolled devices. Applicable when Android Enterprise is configured via G Suite, it guides administrators through enabling the feature in the Google Admin Console. Enforcing this policy automatically installs the ManageEngine MDM Self Service app (previously ManageEngine MDM app) on corporate-account devices, prevents corporate data exposure in personal spaces, and restricts Play Store access if app installation is declined. Validate access is a feature to ensure Android Enterprise policies and configurations is pushed only to MDM-enrolled devices. This ensures any device to which the policies and configurations are applied, can be managed at all times. **This is applicable only if Android Enterprise has been configured using [G Suite](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_afw_prerequisites.html#using_g_suite).** To enable Validate Access, the following steps are to be completed (Not applicable if you configured the optional part in Step #21) ## Procedure 1. Login to [Google Admin Console](https://admin.google.com). 2. Navigate to **Device Management** and select **Android settings**. 3. Click on **Work Profile**. 4. Select **Enforced** given under **Work profile setup**. ### Advantages The advantages of enforcing this policy are listed below: - Automatically installs the Self Service app (previously ME MDM app) when the user adds the Corporate Google account in the device through Settings, thus enrolling the device with MDM. - Prevents adding the corporate account in the personal space, ensuring confidential corporate data cannot be accessed and/or shared by the other apps. - The created account cannot be associated with Play Store, if the user denies the automatic installation. ## Frequently Asked Questions 1. **When is the Validate Access feature applicable?** Only when Android Enterprise has been configured using G Suite. It is not applicable if the optional part in the Android Enterprise setup steps was already configured. 2. **What happens if a user denies the automatic Self Service app installation?** The created corporate account cannot be associated with Play Store, restricting further app installations until the Self Service app (previously ME MDM app) is installed. 3. **Where is Validate Access enabled?** In the Google Admin Console, under Device Management > Android settings > Work Profile, by selecting Enforced under Work profile setup.