I have been playing with the iPad MDM in the admin console. One issue that I have come across that could be a non negotiable is as follows
We force install Google Device Policy and log in with the desired user to create the managed iPad.
We then push out the Google Drive App
Drive is logged in with the correct user. BUT I can go to the avatar, select "Manage accounts on this device" and then remove that account, Now the device does not have the Policy app logged in and device is no longer "managed"
Anyone else seen this and found a solution?