Dear all,
I have looked at existing discussions about GrapheneOS and work profile and learned that at the end, "some things won't work as expected", either due to sandboxed Google Services framework or the device policy app which is required for advanced MDM.
I'm totally fine with "some things not working out" (like password policies, pushing apps, etc) while using Graphene OS as long as I can use some of those Google apps at all (E.g. read my emails, upload files to Google drive, or having a call through meet etc)
I'm using Pixel 6a with latest Android 15 (patched just a few days ago). I have created a work profile through shelter and other (non Google apps) work flawlessly. I installed sandboxed Google Play Framework trough the "apps" app in the work profile (I tried to clone them from my owner profile, but this didn't work out)
As soon as the Google Play apps are installed in the work profile, I can add my work google account in the work profile. But then, none of the google apps can connect to my work account (I get a "check your network and try again" in e.g. Drive). Also the enrollment process never finishes (independent whether I'm in basic MDM or advanced MDM in Google Workspace). In Google's "manage my account" I see a "Finish signing in to continue". I click "sign in", the "big moving circle" opens, but closes after some seconds and I'm where I was before.
Looking at the logs of (e.g. Google drive), I see a lot of "Auth error getting auth" or "failed to resolve name" (while other apps in the work profile can use the internet).
All Google apps evidently have network permissions and all kinds of other permissions I thought might solve the issue. I also tried giving the sandboxed Play store app and the Play services app all kinds of permissions (including "modify system setting", etc) but nothing resolves this problem. I tried installing microG via F-Droid in the work profile, but this fails as well (also some other apps fail to install in the work profile via F-Droid, while others work).
Is this supposed to work? I already removed and re-created the work profile through shelter once and that didn't change anything. I can access my work account data when I install drive, gmail, etc in my "main" profile.
I know there is the Private space function in Android 15, but I would rather like to try to get the work profile running, as I've configured all other apps there.
thanks,