[[["이해하기 쉬움","easyToUnderstand","thumb-up"],["문제가 해결됨","solvedMyProblem","thumb-up"],["기타","otherUp","thumb-up"]],[["이해하기 어려움","hardToUnderstand","thumb-down"],["잘못된 정보 또는 샘플 코드","incorrectInformationOrSampleCode","thumb-down"],["필요한 정보/샘플이 없음","missingTheInformationSamplesINeed","thumb-down"],["번역 문제","translationIssue","thumb-down"],["기타","otherDown","thumb-down"]],["최종 업데이트: 2025-09-04(UTC)"],[[["\u003cp\u003eAccess Context Manager allows you to create access levels based on mobile device characteristics, such as screen lock status, storage encryption, enterprise ownership, admin approval, and OS version.\u003c/p\u003e\n"],["\u003cp\u003eRequests from mobile devices are only granted access if they originate from Safari or Google Chrome and are made by a user account within your organization.\u003c/p\u003e\n"],["\u003cp\u003eChanges made to managed mobile device settings, like enforcing screen lock usage, may take up to 24 hours to propagate, potentially causing delays in the enforcement of mobile device attributes.\u003c/p\u003e\n"],["\u003cp\u003eTo begin using access levels for mobile devices, you must first configure either basic or advanced mobile management in the Google Admin console, and users must sign in to Chrome with their corporate account.\u003c/p\u003e\n"],["\u003cp\u003eIf an access level denies a user request despite correct configuration, you can force a refresh of the server-side device state by removing and re-adding the corporate account on the device.\u003c/p\u003e\n"]]],[],null,["# Use mobile devices with access levels\n\nThis page provides information about using mobile devices with access levels.\n\n- [Overview](#overview)\n\n- [Limitations](#limitations)\n\n- [Getting started](#gettingstarted)\n\n- [Troubleshooting](#troubleshooting)\n\nOverview\n--------\n\nAccess Context Manager supports using [Google basic mobile management](https://support.google.com/a/answer/1734200) and\n[advanced mobile management](https://support.google.com/a/answer/7396025) to create access levels that check for certain\ncharacteristics of mobile devices.\n\nFor iOS and Android devices, requests can be accepted or rejected based on:\n\n- Whether screen lock is enabled.\n\n- Whether storage on the device is encrypted.\n\n | **Note:** For iOS devices, encryption is enabled only if screen lock is also enabled.\n- Whether the device is owned by your enterprise.\n\n- Whether the device has been approved by an administrator.\n\n- The OS version running on the device.\n\nBecause Access Context Manager relies on MDM, the\n[minimum device requirements](https://support.google.com/a/answer/7582673) for basic and advanced management apply.\n\nLimitations\n-----------\n\nThis section describes the limitations of mobile device support in\nAccess Context Manager.\n\n### Request origin\n\nCurrently, access levels checking mobile device attributes will permit access\nonly if:\n\n- The request is made from Safari or Google Chrome.\n\n- The request is made by a user account in your Organization.\n\nIf a request from a mobile device doesn't meet the previous criteria, that\nrequest will be denied, even if the request otherwise meets the requirements of\nthe access level.\n\n### Enforcement delays\n\nWhen you change settings for your managed mobile devices, [it can take time for\nthose changes to propagate](https://support.google.com/a/answer/7514107). For example, if you modify your basic management\nsettings to require use of a screen lock, it can take up to 24 hours to\npropagate that change.\n\nWhile changes to access levels usually come into effect within a few minutes,\nenforcement of mobile device attributes can be delayed while changes to your\nmanaged mobile device settings are propagated.\n\nGetting started\n---------------\n\nTo start using access levels to check mobile device attributes, do the\nfollowing:\n\n1. [Set up basic mobile management](https://support.google.com/a/answer/7400753) or [advanced mobile management](https://support.google.com/a/answer/7396025) for\n your organization.\n\n This step requires access to the [Google Admin console](https://admin.google.com). To limit access\n to the console, [Administrator privilege](https://support.google.com/a/answer/1219251) can be granted specifically for\n [mobile device management](https://support.google.com/a/answer/1219251#mobile).\n2. On your devices,\n [sign in to Chrome using a corporate account](https://support.google.com/chrome/answer/185277?co=GENIE.Platform%3DiOS&hl=en&oco=2).\n\n3. For devices that should be permitted access to protected services, ensure\n requests are coming from Safari or Google Chrome.\n\n4. [Create an access level](/access-context-manager/docs/create-basic-access-level) that includes [device policy attributes](/access-context-manager/docs/access-level-attributes#device-policy-attributes) for\n your organization's mobile devices.\n\nTroubleshooting\n---------------\n\nIf an access level denies a user request but the access level appears to be\nconfigured correctly, the user may need to force the server-side device state\nto refresh.\n\n### Force refresh an Android device\n\nTo force a refresh of the server-side state of an Android device:\n\n1. If you are signed in to `accounts.google.com` on your device's\n browser, sign out of the account.\n\n2. Open your phone's Settings app.\n\n3. Open the Accounts section of the app.\n\n4. Remove the corporate account from the device.\n\n5. Add the corporate account back to the device.\n\nWhen the account is added back to the device, requests for access should be\npermitted as expected.\n\n### Force refresh an iOS device\n\nTo force a refresh of the server-side state of an iOS device:\n\n1. If you are signed in to `accounts.google.com` on your device's\n browser, sign out of the account.\n\n2. Go to a Google app on the device, such as Gmail.\n\n3. Remove the corporate account from the device.\n\n4. Add the corporate account back to the device.\n\nWhen the account is added back to the device, requests for access should be\npermitted as expected."]]