# Protected: Allow Hexnode UEM app permissions for enrolling Android devices

Hexnode UEM app permissions must be enabled to ensure the endpoint management features and configuration policies function correctly on enrolled Android devices.

Why are Hexnode UEM App Permissions Required?
---------------------------------------------

When enrolling an Android device, users must explicitly grant specific Hexnode UEM app permissions. These permissions are essential for various features and functionalities to be configured successfully on the device from the Hexnode UEM console. Failure to grant these permissions will result in the corresponding features not functioning as intended.

 Prerequisites:- Ensure the device is running a supported Android OS version.
- The appropriate Hexnode app must be installed: **Hexnode UEM – Legacy** (for standard enrollment) or **Hexnode For Work** (for Android Enterprise enrollment).

 

 Notes: 
The specific set of permissions requested, and their required configuration may vary depending on whether the device is enrolled using **Hexnode UEM – Legacy** or **Hexnode For Work**.

 

Hexnode UEM App Permissions and Associated Features
---------------------------------------------------

 Permission name  Description  Key features enabled by this permission **Device Administration**A mandatory permission essential for UEM enrollment and for all actions and policies to take effect on the device. Core enrollment and policy enforcement.**Draw Over Apps**Grants the app permission to display its interface over other active applications.- Saving logs using the [DOWNLOAD APP LOGS](https://www.hexnode.com/mobile-device-management/help/how-to-acquire-hexnode-app-logs-for-android-devices/#download-app-logs-to-the-device) option
- Retrieving logs using the [Hexnode App Logs](https://www.hexnode.com/mobile-device-management/help/how-to-acquire-hexnode-app-logs-for-android-devices/#request-hexnode-app-logs-from-the-portal) action
- [Kiosk Screensaver](https://www.hexnode.com/mobile-device-management/help/how-to-enable-screensaver-for-android-devices-locked-in-kiosk-mode/)
- Specifying the [kiosk exit password](https://www.hexnode.com/mobile-device-management/help/how-to-exit-android-kiosk-mode-in-hexnode-mdm/#method-4-manually-exit-kiosk-mode-from-the-device)
- Accessing [Peripheral Settings](https://www.hexnode.com/mobile-device-management/help/how-to-enable-peripheral-settings-for-android-devices-locked-in-kiosk-mode/) (in Kiosk Mode)
- [Broadcast Message](https://www.hexnode.com/mobile-device-management/help/broadcast-messages-to-a-device-enrolled-in-hexnode-mdm/)
- Showing system Alerts 
    - Password required
    - Kiosk activation failed
    - Disable battery optimization
    - Allow Nearby devices permission
    - Set Hexnode as default launcher
    - Location missing (for Bluetooth in kiosk)
    - Install again (if app installation gets failed in kiosk)
    - All Files Access permission alert (for opening files in kiosk)
    - Change Wi-Fi

**Usage Access** Allows the Hexnode UEM app to access usage statistics for system features and applications, enabling remote activity monitoring.- [Basic restriction](https://hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#basic-restrictions): Force Wi-Fi
- [Network Data Usage Management](https://www.hexnode.com/mobile-device-management/help/managing-android-devices/network-data-usage-management-android/)
- [Remote App Launch](https://www.hexnode.com/mobile-device-management/help/how-to-remotely-launch-app-on-your-android-devices/)

**Write Systems Settings** Allows the Hexnode UEM app to modify core Android system settings such as screen brightness, orientation, timeout, and airplane mode. - [Basic restriction](https://www.hexnode.com/mobile-device-management/help/set-up-android-mdm-restrictions-using-hexnode-mdm/#basic-restrictions): Screen Orientation, Screen timeout
- [Peripheral Settings](https://www.hexnode.com/mobile-device-management/help/how-to-enable-peripheral-settings-for-android-devices-locked-in-kiosk-mode/): Brightness, Airplane mode
- [Advanced Website Kiosk Settings](https://www.hexnode.com/mobile-device-management/help/how-to-configure-advanced-web-kiosk-settings-with-hexnode-mdm/): Screen Orientation

**Notification Access** Enables the Hexnode UEM app to access and manage device notifications. - Blocking notifications in kiosk mode
- Connecting to saved Wi-Fi networks in kiosk mode

**Allow App Installation** Permits the Hexnode UEM app to install applications on the device (for Hexnode UEM – Legacy app only). - Installing apps via [Required Apps](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/#method-1-add-as-required-apps) policy
- Installing apps via [Install Application](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/#install-apps-via-remote-actions) remote action

**Manage All Files**Allows the Hexnode UEM app to read, write, and manage files across the device’s entire storage. - Installing apps via [Required Apps](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/#method-1-add-as-required-apps) policy or [Install Application](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/#install-apps-via-remote-actions) remote action.
- Exporting logs using [DOWNLOAD APP LOGS](https://www.hexnode.com/mobile-device-management/help/how-to-acquire-hexnode-app-logs-for-android-devices/#download-app-logs-to-the-device)
- [Required Apps](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/#method-1-add-as-required-apps)
- [Import contacts to device](https://www.hexnode.com/mobile-device-management/help/how-to-import-contacts-to-devices-using-hexnode-mdm/#importing-contacts-to-android-devices-using-hexnode-uem)
- [Changing Ringtone](https://www.hexnode.com/mobile-device-management/help/how-to-set-ringtone-on-android-devices-using-hexnode-mdm/)
- [Wallpaper](https://www.hexnode.com/mobile-device-management/help/how-to-set-wallpaper-on-android-devices-with-mdm/)
- [Kiosk Screensaver](https://www.hexnode.com/mobile-device-management/help/how-to-enable-screensaver-for-android-devices-locked-in-kiosk-mode/)
- [Boot/Shutdown Animation](https://www.hexnode.com/mobile-device-management/help/how-to-add-custom-boot-and-shutdown-animations-for-samsung-knox-devices-using-hexnode-mdm/)
- [File management](https://www.hexnode.com/mobile-device-management/help/how-to-transfer-files-to-devices-using-hexnode-mdm/)
- [File Explorer](https://www.hexnode.com/mobile-device-management/help/how-to-move-copy-or-delete-files-and-folders-on-android-devices-using-file-explorer-in-hexnode-mdm/)
- OS update
- Syncing the data usage details of each app in the [Data Management](https://www.hexnode.com/mobile-device-management/help/how-to-manage-mobile-data-usage-with-hexnode-mdm/#data-usage-summary) sub-tab on the Device Summary page
- [Automatically Update Hexnode UEM Android App](https://www.hexnode.com/mobile-device-management/help/mdm-settings/#hexnode-app-updates)
- Setting files as [Digital signage](https://www.hexnode.com/mobile-device-management/help/how-to-lockdown-your-devices-onto-digital-signage-kiosk-using-hexnode/) display (in Kiosk Mode)

**App Logs** Grants access to various device logs for diagnostic and compliance purposes. Uploading Hexnode App logs to Hexnode UEM via [SEND APP LOGS](https://www.hexnode.com/mobile-device-management/help/how-to-acquire-hexnode-app-logs-for-android-devices/#sending-logs-from-the-device) option or [Hexnode App Logs](https://www.hexnode.com/mobile-device-management/help/how-to-acquire-hexnode-app-logs-for-android-devices/#request-hexnode-app-logs-from-the-portal) remote action. **Alarms and Reminders** Allows Hexnode UEM to trigger scheduled actions immediately, even if the device is inactive. Inactivity based automation triggers **Password Token** Allow the app to remotely set and clear the device password using a password token (for Hexnode For Work app only). Remote actions: - [Clear Password](https://www.hexnode.com/mobile-device-management/help/remove-password-from-a-device-using-hexnode-mdm/)
- [Set Password](https://www.hexnode.com/mobile-device-management/help/how-to-configure-a-device-password-on-android-devices-remotely/)

**Activate VPN** Allow the app to activate a VPN for secure network connections. [Network Data Usage Management ](https://www.hexnode.com/mobile-device-management/help/managing-android-devices/network-data-usage-management-android/)**Hexnode Assist/Remote View** Choose whether to automatically install the Hexnode Assist or Remote View app for remote screen viewing and controlling. [Remote View & Control](https://www.hexnode.com/mobile-device-management/help/remotely-control-android-devices-from-pc-using-hexnode-mdm/) of device screen for troubleshooting.Granting Permissions Post-Enrollment
------------------------------------

You can grant missing Hexnode UEM permissions after the initial enrollment process if the device is configured as a [Device Owner](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-in-android-in-the-enterprise-as-device-owner-using-hexnode-mdm/) or [Work Profile on Company-Owned Device (WP-C)](http://Work%20Profile%20on%20Company-Owned%20Device%20(WP-C).).

### Steps to Modify App Permissions

For devices enrolled as Device Owner or Work Profile on Company-Owned Device (WP-C), follow these steps to manage Hexnode UEM app permissions directly on the device:

1. Open the **Hexnode UEM app** on the device.
2. Go to **Navigation > Settings**.
3. Tap the **three-dot icon** in the top-right corner.
4. Select **Permissions**.
5. Enable necessary permissions as required.