Amazon Fire OS enrollment stuck on permissions during Hexnode kiosk setupSolved

Participant
Discussion
5 days ago Sep 23, 2026

I’m testing Amazon Fire tablets in Hexnode and want to lock them down to a corporate email app and one work app using kiosk mode.

The first tablet I tried was an older Fire tablet, and I couldn’t find the Hexnode app in the Amazon Appstore. I then tried a newer Fire tablet and got further with QR enrollment, but setup got stuck around permission prompts like “Draw over apps” and battery optimization.

A few things I’m trying to confirm:

  • Which permissions are required to complete Fire OS enrollment?
  • Can apps be installed silently on Fire tablets?
  • Can Hexnode remove Amazon system ads from Fire OS?
  • How secure is multi-app kiosk mode on Fire tablets?

Replies (4)

Marked SolutionPending Review
Hexnode Expert
5 days ago Sep 23, 2026
Marked SolutionPending Review

Hi @everlycole ,

For Amazon Fire tablets, enrollment can get blocked if the required app permissions are not granted during setup.

For the scenario you described, the working approach is:

1. Use a compatible Fire OS device

  • Older Fire tablets may not show the Hexnode app in the Amazon Appstore due to Fire OS or Appstore compatibility limits.
  • Testing with a newer Fire tablet is recommended if the app is unavailable on the older device.

2. Start enrollment using the Hexnode app or QR code

  • Open the Hexnode app on the Fire tablet.
  • Continue with QR-based enrollment from the Hexnode portal.

3. Grant the required Fire OS permissions when prompted

  • Enable Draw over apps for Hexnode.
  • Allow the required device administration permissions.
  • If Fire OS prompts for battery optimization settings, allow the requested option so the Hexnode app can continue running reliably.

Once these permissions are enabled, enrollment should complete normally.

For kiosk mode, create a Multi-app kiosk policy and add the required apps to it. Then associate the policy with the Fire tablet or a device group. When the device is online, the policy should apply shortly, and the status can be checked from the device action history.

A few Fire OS-specific limitations to keep in mind:

  • Silent app installation is not supported on Fire OS. App installation can be initiated from Hexnode, but the final installation prompt must be completed on the tablet.
  • Amazon system advertisements cannot be fully removed through Hexnode because they are controlled by Fire OS.
  • Users cannot exit kiosk mode freely. To exit, the admin can tap the screen 10 times and enter the kiosk exit password.
Marked SolutionPending Review
Participant
5 days ago Sep 23, 2026
Marked SolutionPending Review

That matches what I saw. The newer Fire tablet enrolled after enabling Draw over apps, but app installation still needed confirmation on the tablet. I was expecting it to install silently, so that explains it.

For multi-app kiosk, do I need to create separate policies for each tablet, or can I use one policy for all Fire tablets?

Marked SolutionPending Review
Participant
5 days ago Sep 23, 2026
Marked SolutionPending Review

We ran into the same Fire OS ad question. Just adding that the lock down works, but the Amazon lock screen or system-level ad behavior is separate from the MDM controls. We ended up planning around that rather than trying to remove it from Hexnode.

Marked SolutionPending Review
Hexnode Expert
5 days ago Sep 23, 2026
Marked SolutionPending Review

Hexnode can manage supported restrictions, kiosk mode, app access, and remote security actions on enrolled Fire OS devices, but Amazon-controlled system advertisements are not removable through Hexnode.

The practical workaround is to validate the Fire OS user experience before scaling the deployment. If the advertisements are not acceptable for the use case, consider using Fire tablets without ads if available in your region, or another Android device model that does not include vendor-controlled ads.

Regards,
Isabel Lora
Hexnode UEM

Save