Skip to main content

iOS app: connectivity issue with Google Login

Fix Google Login error on the Spendesk iOS app

If you sign in with Google on the Spendesk iOS app, you may see the error "400: admin_policy_enforced". This happens when your organization's Google Workspace admin hasn't approved the Spendesk app yet. For: Any Spendesk user logging in via Google SSO on iOS. Your Google Workspace admin must complete one setup step.

Before you start

  • You need Google Workspace super-administrator access to complete the fix (usually IT, your CTO, or CEO).

  • You're on the latest version of the Spendesk iOS app.

  • Google Sign-In on iOS uses Google's native SDK, so the fix must be applied on Google's side, not in the Spendesk app.

👥 Only your organization's Google super-administrator can approve the Spendesk app. If you're not an admin, forward this article to them.

Symptoms

  • You try to log in to the Spendesk iOS app with Google and see: "400: admin_policy_enforced".

  • Login works fine on desktop/web but fails on the iOS app.

  • The error appears only for some employees in your organization, or for all iOS users at once.

Causes

  • Your Google Workspace administrator has restricted which mobile apps can connect via OAuth.

  • The Spendesk iOS app hasn't been added as a trusted application in your Google Workspace security settings.

  • This is a Google-side configuration issue, not a Spendesk app error.

Solutions

Ask your Google Workspace super-administrator to complete these steps:

  1. Navigate to Security > API controls > App access control.

  2. Click "Manage third-party app access".

  3. Click the "+" button to add a new app.

  4. Select "iOS" under "App type".

  5. Enter "Spendesk" in the search field and select it.

  6. Confirm the app identifier shows as com.spendesk.spendesk.

  7. Set the access level to "Trusted".

  8. Click "Save".

Then, on your iOS device:

  1. Close the Spendesk app completely.

  2. Reopen the Spendesk app.

  3. Tap "Sign in with Google".

  4. Select your Google account and complete the login.

💡 If your device is managed by an MDM (mobile device management) tool, ask your IT team to allow these URLs: *.spendesk.com, *.googleapis.com, logo.clearbit.com, *.crashlytics.com, sdk.geniusscan.com, *.segment.com, api.segment.io, *.antelop.io, *.antelop.net, and mobile.digitalcard-entrust.com.

Related issue: Android and personal devices

On Android, Google Sign-In is tied to the whole device rather than to the Spendesk app alone. If an employee signs in with a managed Google Workspace account on a personal Android phone, this can trigger MDM enrollment for the entire device, not just Spendesk. This is a structural behavior of Google Sign-In on Android and is separate from the iOS "admin_policy_enforced" error described above.

When to contact support

Contact Spendesk support if:

  • Your Google administrator has completed all the steps above and the error persists.

  • You see a different error message than "400: admin_policy_enforced".

  • The issue affects only one user while colleagues can log in without issue (this may indicate an account-specific problem rather than an organization-wide policy).

Related articles

Did this answer your question?