These restrictions are available across the Pro and Enterprise tiers, but some of the more advanced device controls require Enterprise. For the restrictions you listed, the tier availability is as follows:
Available on Enterprise:
- Factory Reset / Advanced Factory Reset
- Factory Reset Protection, including Google account verification
- Install apps / Uninstall apps restrictions
- App Runtime Permissions, including granting runtime permissions to managed apps
- Trust agents / Smart Lock restrictions
- Developer Mode / USB debugging restrictions
Available on Pro:
- Allow MDM administration removal restriction
- Force GPS to fetch location
- Mock location restriction
- Safe Mode restriction
- Airplane Mode restriction
- Force Wi-Fi
- Force Bluetooth
- Portable Wi-Fi hotspot restriction
- USB mass storage / USB file transfer restriction
- Lock screen shortcuts and widgets restrictions
A Device Owner enrollment already prevents the user from removing management in the normal way. However, if you also need to prevent users from manually resetting the device, the Factory Reset restriction must be configured, and that requires Enterprise.
For deployments that specifically require uninstall protection, Factory Reset restrictions, Factory Reset Protection, app runtime permissions, and Developer Mode/USB debugging restrictions, Enterprise is required.
Regards,
Isabel Lora
Hexnode UEM