# How to Blocklist/Allowlist apps on Android devices

Organizations may require to block apps on their devices for various reasons. They may block apps to avoid access to certain apps that may decelerate productivity, prevent malicious apps for data security, and restrict unwanted content on their devices.

With Hexode UEM, the admin can either blocklist or allowlist apps on Android devices. The Blocklist feature blocks the users from accessing any apps added to the list. Whereas, Allowlist restricts the users from using any apps other than the ones allowed.

Applying policy to Blocklist apps
---------------------------------

To block apps on a device using Hexnode’s Blocklist policy,

1. Log in to your Hexnode UEM portal.
2. Tap on **Policies** > **New Policy** > **Android** > **App Management** > **Blocklist/Allowlist**. Click on **Configure**.
**Policy name**– Assign a suitable name for the policy. This is a mandatory field.

**Description**– Provide a brief description of the policy.

5. Choose the **Blocklist** button and click on **+Add** to add either an app or a group of apps to be blocklisted.
6. Once you have selected all the apps, click **Done**.
7. Next, associate the policy with the target devices by clicking on **Policy Targets**.
8. Select the **Devices**/**Device Groups**/**User**/**User Groups**/**Domains** with which the policy is to be attached.
9. Click **Save**.

Applying policy to Allowlist apps
---------------------------------

To block apps using Hexnode’s Allowlist feature,

1. Select **Allowlist** from **Policies** > **New Policy** > **Android** > **App Management** > **Blocklist/Allowlist**  > **Configure**.
2. Enable the option **Blocklist all non-launchable apps** to blocklist the non-launchable applications (for example, Google Play services, Android System WebView, etc.) explicitly.
3. Click on the **+Add** button to add the required apps or app groups to the list. Note that the users cannot access any apps other than the ones mentioned in this list.
4. Click **Done** after selecting the required apps.
5. Next, associate the policy with the target devices by clicking on **Policy Targets**.
6. Select the **Devices**/**Device Groups**/**User**/**User Groups**/**Domains** with which the policy is to be attached.
7. Click **Save**.

[![Only allowlisted apps are present on Android.](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/12/Allowlisted-apps-on-Android-.png)](https://cdn.hexnode.com/mobile-device-management/help/wp-content/uploads/2023/12/Allowlisted-apps-on-Android-.png) Notes:- Supported by [Samsung Knox](https://www.hexnode.com/mobile-device-management/help/hexnode-mdm-for-samsung-knox-devices/) devices and devices enrolled via [Android Enterprise](https://www.hexnode.com/mobile-device-management/help/enroll-organization-in-android-for-work-using-hexnode-mdm/).
- If the device is enrolled in [Android Enterprise in profile owner mode](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-as-profile-owner-using-hexnode-mdm/), only the work apps (the ones with the work badge) can be allowlisted/blocklisted.
- [Kiosk mode](https://www.hexnode.com/mobile-device-management/help/android-kiosk-mode/) is another lockdown mechanism where you can restrict your devices to work in purpose-specific modes. The admin can limit the users to accessing only the required apps.
- If the user associates two policies on the same device in which they blocklist an app in one and allowlist the same app in the other, the app will be blocklisted.
- The following Hexnode apps are automatically allowlisted in the background: 
    - Hexnode Remote Assist
    - Hexnode UEM

 

 Exceptions- For Samsung Knox devices, the user will be able to access an already installed app that is blocklisted/allowlisted. But the user will not be able to install a newly blocklisted app or update an existing one.
- Users are not allowed to install or update a blocklisted app. However, in Samsung Knox, blocklisting an already installed app will not remove an app or hide its icon, and the users are allowed to access the apps.
- Blocklisting/Allowlisting won’t hide apps on other Android devices. Instead, they will be marked as ‘non-compliant’ and the admin is notified via email if notification is enabled from **Admin > Notifications**. However, on a device enrolled in Android Enterprise program, the blocklisted apps get hidden from the device.
 

[![Application compliance status changed to non-compliant.](https:2023/12/Application-Compliance.png)](https:2023/12/Application-Compliance.png)

 Notes:- If the user tries to install a blocklisted app, he receives a notification specifying that the app cannot be installed.
- Blocklisting a system app while the device is in kiosk mode might cause unexpected behaviours.
- Conversely, if the user tries to allowlist a set of apps, all the other apps not included in the list will be treated as blocklisted. A notification specifying the restriction is received if the user tries to update/install a non-allowlisted app.

 

 
In case the user chooses to include an [app group](https://www.hexnode.com/mobile-device-management/help/how-to-configure-app-groups-using-hexnode-mdm/), all the apps included in the group can be either blocklisted or allowlisted.