Google Apps gets ability to force encryption, reset PINs on Android devices
Google's move duplicates some of the security capabilities previously available only via Exchange ActiveSync, plus adds a “find my phone” feature — Google is trying to make Android more appealing to businesses …
Context & Ripple Effects
By April 2011 Google is attacking its enterprise credibility gap on two fronts at once: the same day it ships forced encryption and remote PIN resets for Android under Google Apps, it also confirms work on a tablet build of Chrome OS visible in its source tree — evidence of a broader push to make Google's stack acceptable inside corporate fleets, not just consumer ones.
The significance of the security update is who it displaces: until now, remote wipe-grade controls on Android largely flowed through Exchange ActiveSync, meaning companies had to run Exchange infrastructure to manage Google-friendly phones. Duplicating those capabilities inside Google Apps removes the main reason an Android rollout required Microsoft's mail server.
First-order effects
- IT administrators on Google Apps gain native enforcement of device encryption and PIN policies plus a 'find my phone' recovery tool, letting them provision Android handsets without routing management through Exchange ActiveSync.
Second-order effects
- Microsoft loses ActiveSync's role as the default security gateway for Android in Google Apps shops, weakening one of the stickiest reasons enterprises stayed on Exchange when evaluating hosted alternatives.
Third-order effects
- If platform vendors keep absorbing device-management functions natively, enterprise mobility shifts from mail-protocol middleware toward controls owned by the OS maker — raising the question of whether third-party MDM layers remain necessary or become optional add-ons.
The trend: Enterprise mobile-device control is migrating out of mail-server protocols like ActiveSync and into native platform features, as Google positions Google Apps as a self-sufficient Exchange alternative.