Hexnode Android Enterprise restrictions by tier and API capabilitiesSolved

Participant
Discussion
3 days ago Oct 02, 2026

We’re planning to manage Android Enterprise Device Owner devices through the Hexnode REST API instead of having customers work directly in the portal. The fleet is mostly Motorola, Samsung, and Xiaomi devices.

A few things are unclear before we finalize the integration:

  • Can the API fetch device details like IMEI, ICCID, compliance status, current location, and location history?
  • Are remote actions such as lock, Lost Mode, and wipe available through the API?
  • Can policies be assigned, created, or modified through the API?
  • Can enrollment QR codes and Managed Google Play app approvals be handled through the API?

Replies (3)

Marked SolutionPending Review
Hexnode Expert
3 days ago Oct 02, 2026
Marked SolutionPending Review

Hi @r_foster ,

For Android Enterprise Device Owner deployments, most of the core device management and monitoring workflows you described are available through the Hexnode API.

Supported through the API:

  • Device list and device details, including hardware identifiers such as IMEI and ICCID where reported by the device
  • Compliance status
  • Current and historical location data
  • Remote actions such as lock, wipe, and Lost Mode
  • Assigning existing policies to devices or device groups
  • Creating and modifying policies programmatically

Not currently supported through direct API calls:

  • Creating or provisioning MSP tenant portals. Tenant portals must be created from the MSP console.
  • Generating Android Enterprise enrollment QR codes directly through the API. QR codes must be generated in the portal, or standard self-enrollment URLs can be used where applicable.
  • Approving Managed Google Play apps through the API. App approval requires the embedded Google iframe in the portal.

Regards,
Isabel Lora
Hexnode UEM

Marked SolutionPending Review
Participant
3 days ago Oct 02, 2026
Marked SolutionPending Review

The API capabilities are clear. Also, during testing we used several Android restrictions such as Factory Reset blocking, FRP, app uninstall protection, runtime permissions, Safe Mode blocking, mock location blocking, Force GPS, USB restrictions, and Developer Mode/USB debugging restrictions. The pricing page groups some items under Advanced Restrictions, so I’m trying to understand which ones require Enterprise and which are available on Pro.

Marked SolutionPending Review
Hexnode Expert
3 days ago Oct 02, 2026
Marked SolutionPending Review

These restrictions are available across the Pro and Enterprise tiers, but some of the more advanced device controls require Enterprise. For the restrictions you listed, the tier availability is as follows:

Available on Enterprise:

  • Factory Reset / Advanced Factory Reset
  • Factory Reset Protection, including Google account verification
  • Install apps / Uninstall apps restrictions
  • App Runtime Permissions, including granting runtime permissions to managed apps
  • Trust agents / Smart Lock restrictions
  • Developer Mode / USB debugging restrictions

Available on Pro:

  • Allow MDM administration removal restriction
  • Force GPS to fetch location
  • Mock location restriction
  • Safe Mode restriction
  • Airplane Mode restriction
  • Force Wi-Fi
  • Force Bluetooth
  • Portable Wi-Fi hotspot restriction
  • USB mass storage / USB file transfer restriction
  • Lock screen shortcuts and widgets restrictions

A Device Owner enrollment already prevents the user from removing management in the normal way. However, if you also need to prevent users from manually resetting the device, the Factory Reset restriction must be configured, and that requires Enterprise.

For deployments that specifically require uninstall protection, Factory Reset restrictions, Factory Reset Protection, app runtime permissions, and Developer Mode/USB debugging restrictions, Enterprise is required.

Regards,
Isabel Lora
Hexnode UEM

Save