Android Enterprise enrollment QR code works, but system apps disappear after policy is appliedSolved

Participant
Discussion
6 months ago Jan 14, 2026

I’m enrolling Android devices in Hexnode using Android Enterprise and wasn’t sure which QR code to scan. The device starts enrolling and shows Samsung Knox activation, but after the policy gets applied, some built-in apps like Camera, Gallery, Calculator, Messages, Phone, and Calendar are missing or blocked. 

The policy also installs/permits work apps like Outlook, OneDrive, Chrome, Adobe apps, and a time-tracking app. Is this expected behavior with Android app policies, or am I using the wrong enrollment QR code? 

Replies (2)

Marked SolutionPending Review
Hexnode Expert
6 months ago Jan 14, 2026
Marked SolutionPending Review

Hi @skylar-a,

For Android Enterprise enrollment, the correct QR code depends on the management mode you want to use:

  • Device Owner: Use this if the device is company-owned and should be fully managed by Hexnode.
  • Profile Owner: Use this if you only want to manage a work profile/container on a personally owned device.

If the device shows enrollment progress and Samsung Knox activation, your QR code is working correctly for a fully managed Samsung device.

The missing system apps are caused by the Android application Allowlist/Blocklist configuration. Unlike iOS, which keeps default apps unless explicitly blocked, Android’s Allowlist behavior is much stricter. When an Allowlist is configured, any app that is not explicitly allowed will be hidden, blocked, or removed from the managed device experience—including system apps like Camera, Gallery, Calculator, Messages, Phone, and Calendar.

To fix this, edit your Android policy and ensure the Allowlist explicitly includes both:

  • Required work apps: Outlook, OneDrive, Chrome, Adobe apps, or internal business apps.
  • Required system apps: Camera, Gallery, Calculator, Calendar, Messages, and Phone.

A practical approach is to create a copy of the Android policy, update the app Allowlist there, and test it on one device first. Once the device syncs and you confirm the system apps remain available, you can apply this updated policy template as the base for all future Android deployments.

Best regards,
Eden Pierce
Hexnode UEM

Marked SolutionPending Review
Participant
6 months ago Jan 15, 2026
Marked SolutionPending Review

That explains it. We had only allowed the work apps, so the phone lost the basic apps after the policy applied. 

Thank you for the help, that sorted it out! 

 

Save