Skip to content

Sandboxed Google Play in Work Profile cannot install apps due to “unknown sources” restriction #5529

Description

@cameronaaron

When enrolling via Intelligent Hub to get enterprise email, GrapheneOS correctly creates an Android work profile and allows installation of the sandboxed Play Store—but that Play Store then cannot install downloaded apps because work profiles globally block “unknown sources,” and because Play Store isnt the default app store on graphine it isn’t exempted which is the mdm and IT teams expectation.

Steps to reproduce
1. On GrapheneOS, install and enroll Intelligent Hub to set up enterprise email.
2. Intelligent Hub creates an Android work profile and prompts for a Play Store.
3. “No Play Store found” error appears; install the GrapheneOS sandboxed Google Play.
4. Sign into Play Store and download required enterprise apps.
5. Downloads complete but installation fails—Play Store lacks INSTALL permission.

Actual behavior
The work profile’s global block on “install from unknown sources” applies even to the sandboxed Play Store, so it cannot install any downloaded APKs.

Expected behavior
While technically things are working correctly Graphine wise it would be nice if there was some kind of a system where the os can whitelist google play in work profiles or the built in graphene app store can proxy downloads from google play to download them somehow allowing enterprise app installs without manual overrides.

Workarounds
None found—IT teams report “we’ve never seen this before” when troubleshooting.

Additional context
This breaks basic enterprise app deployment workflows on GrapheneOS devices; a targeted exemption would restore compatibility with MDM-driven Play Store installs.

Google news is Graphiene itself does not bring the device out of corp compliance at all

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions