# How to set up Android device Restrictions?

Setting up device and app restrictions features on the work managed devices reduces distractions and improves its security. Controlling the device settings and restricting access also prevents third-party apps from accessing corporate data and resources.

The availability of the device restrictions might differ based on the UEM plan you’ve subscribed to, the device make, and the operating system of the endpoint. Some of the features listed here are built exclusively for Samsung Knox devices, LG’s GATE (Guarded Access to Enterprise) devices, Kyocera business phones, and Android Enterprise enrolled devices.

Configuring Restrictions for Android devices
--------------------------------------------

To configure Android device restrictions via the Hexnode UEM portal,

1. From your Hexnode portal, head on to the **Policies** tab.
2. Set up a new policy by clicking on the **New Policy** button or continue with an existing one.
3. Navigate to **Android** > **Restrictions** > **Basic/Advanced**. You can set up device restrictions from there.

 Notes:- The Advanced Restrictions in Hexnode UEM lets you have enhanced control over Samsung Knox, LG GATE, Kyocera business phones and Android Enterprise enrolled devices.
- Restrictions set up for devices [enrolled in Profile Owner](https://www.hexnode.com/mobile-device-management/help/how-to-enroll-a-device-in-android-in-the-enterprise-as-profile-owner-using-hexnode-mdm/) mode are only applicable for the apps within the work container.

 

Basic Restrictions
------------------

![Basic restrictions for Android devices on Hexnode UEM](https:2018/08/Basic-restrictions-for-Android-Devices.png "Basic restrictions for android devices")[](https:2018/08/Basic-restrictions-for-Android-Devices.png)

### Allow Basic Device Functionality

Device Functions

 RestrictionsDescriptionSupported DevicesCameraPrevents the users to access the camera app on the device. Camera usage is allowed by default. On Android 10+ devices, the restriction works only on devices enrolled in Android Enterprise program.Knox version 3.0+ (Standard SDK 2.0 and up), LG GATE, Kyocera business phones, Device Owner, Profile Owner, Standard Android devices.USB Mass StorageDisables access to external mass storage devices. Allowed by default.LG GATE, Knox version 3.0+ (Standard SDK 2.5 and up), Kyocera business phones.USB file transferBlocks file transfer via USB entirely. USB file transfer is allowed by default. Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner.Home buttonHome button will not work if this option is unchecked. Home button can be used by default. Knox version 3.0+ (Standard SDK 2.0 and up)Power OffDisabling this option prevents users from turning off the device. By default, it is permitted to turn the device off.  Note:- Unchecking this option will prevent the device from restarting after an OS update.
- Disabling this option will cause the [Restart Device](https://www.hexnode.com/mobile-device-management/help/restart-a-device-using-hexnode-mdm/) action to fail.

 Knox version 3.0+ (Standard SDK 2.7 and up) Safe modeDisabling this option prevents users from booting their devices into safe mode. Provide a suitable password in the ‘Device password’ field. It is required for devices other than Samsung Knox or those enrolled in Android Enterprise as the Device Owner. Users will be prompted to enter this password when they try to enable Safe mode on their devices.  Note: For Standard Android devices below version 7.0, the device password will be cleared on reboot, and the password given in the ‘Device Password’ field will be set as the device password.

Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner, Standard Android Devices running versions below 7.0.Airplane modeDisallow the users to turn airplane mode on. Allowed by default.Knox version 3.0+ (Standard SDK 2.0 and up), Android Enterprise – Device Owner (Android 9.0+).Lock screen shortcutsUncheck this option to prevent users from placing app icons on the device’s lock screen. This option is enabled by default.Knox version 3.0+ (Standard SDK 1.0 and up)Widgets on lock screenPrevents the user from adding widgets to the lock screen. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up) below Android 5.0Screen OrientationUsers can configure screen orientation of their choice on the device if *User can choose* option is selected. You can make your selection from the following options to enforce screen orientation on user’s device: · User can choose · Auto-rotate · Portrait · Left · Right · InvertKnox version 3.0+ (Standard SDK 2.5 and up), LG GATE, Kyocera business phones, Standard Android Devices, Android Enterprise – Device Owner.Screen TimeoutConfigure screen timeout for devices. Choose between – Never, Keep Current Settings, or set a time between 1-5, 10 or 15 minutes.  Note:- Once the restriction is configured, the screen-timeout value cannot be modified from the device end.

 Exception: If both the **Auto-lock after** option under **Device Password** policy and the **Screen timeout** restriction are configured, the setting with a shorter duration will be assigned as the screen timeout value on the device.

Kyocera business phones, Knox version 3.0+ (Standard SDK 2.5 and up), Standard Android Devices, LG GATE, Android Enterprise – Device Owner.

 

 

### Allow Network Settings

Network Restrictions

 RestrictionsDescriptionSupported DevicesWi-FiUncheck to disable Wi-Fi on the devices. **Note:** On standard Android devices, Wi-Fi turns off automatically even if the user tries to turn it on. On Android 10+ devices except Samsung Knox, users will be prompted to turn off Wi-Fi manually. On Samsung Knox devices, Wi-Fi option gets disabled on the device. On Android 10+ devices enrolled in Android Enterprise- Profile Owner mode, the users will be prompted to turn-off Wi-Fi as they open the Hexnode UEM app. LG GATE, Kyocera business phones, Android Enterprise – Device Owner, Android Enterprise – Profile Owner, Standard Android Devices, Knox version 3.0+ (Standard SDK 2.0 and up), Android TV 4.1+.Force Wi-Fi (Works only when the option **Wi-Fi** is enabled)Enabling this option restricts users to turn off the Wi-Fi. **Note:** On Samsung Knox devices, users will not be able to turn off the Wi-Fi. On standard Android devices, even if the users turn off the Wi-Fi, it will be turned back on automatically. On Android 10+ devices, users will be prompted to turn on Wi-Fi manually. On Android 10+ devices enrolled in Android Enterprise-Profile Owner mode, the users will be prompted to turn-off Wi-Fi as they open the Hexnode UEM app. LG GATE, Kyocera business phones, Android Enterprise – Device Owner, Android Enterprise – Profile Owner, Standard Android Devices, Knox version 3.0+ (Standard SDK 2.0 and up), Android TV 4.1+.BluetoothUncheck this option to restrict users to turn on Bluetooth. By default, the users are allowed to use Bluetooth on their devices.Knox version 3.0+ (Standard SDK 2.0 and up), Kyocera business phones, Android Enterprise – Device Owner, Android Enterprise – Profile Owner, Standard Android Devices, LG GATE.Force Bluetooth (Works only when the option **Bluetooth** is enabled)Enabling this option restricts the users to turn off Bluetooth. On Samsung Knox devices, users will not be able to turn off Bluetooth. On standard Android devices, even if the users turn off Bluetooth, it will be turned back on automatically. LG GATE, Knox version 3.0+ (Standard SDK 2.0 and up), Kyocera business phones, Android Enterprise – Device Owner, Android Enterprise – Profile Owner, Standard Android Devices.Mobile dataUncheck this option to prevent the use of mobile data. Mobile data is allowed by default. Kyocera business phones, Knox version 3.0+ (Standard SDK 2.5 and up), LG GATE.TetheringPrevents tethering on devices. Tethering is allowed by default. –USB tethering **(Unable to modify if Tethering is disallowed)**Uncheck this option to prevent users from sharing mobile data with other devices via USB. USB tethering is allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up)Bluetooth tethering **(Unable to modify if Tethering is disallowed)**Disallows the users to share their mobile data with other devices over Bluetooth if this option is selected. Bluetooth tethering is allowed by default. Knox version 3.0+ (Standard SDK 1.0 and up)Portable Wi-Fi hotspot **(Unable to modify if Tethering is disallowed)**Select an option to tether the portable Wi-Fi hotspot: 1. **Users can choose:** Users have the ability to enable or disable the Wi-Fi hotspot directly from the device end.
2. **Always Off:** The Wi-Fi hotspot feature of the device will always remain disabled.
3. **Always On:** The Wi-Fi hotspot feature of the device will always remain enabled.

 Notes: 
Users cannot connect to any Wi-Fi network if the Wi-Fi hotspot is set to ‘Always On’.

The following two options are displayed even when the “Users can choose” option is chosen.

1. **Wi-Fi Hotspot SSID:** The field corresponds to the ‘Wi-Fi Hotspot SSID’ option that allows administrators to set a custom name for the Wi-Fi hotspot, instead of the default SSID of the device. The value entered in this field is reflected as the unique name of the Wi-Fi hotspot on the device.
2. **Set Hotspot Password:** Admins can configure the Wi-Fi hotspot password, and while configuring the password, you must ensure that it consists of a minimum of 8 characters. This password helps establish a connection with the Wi-Fi hotspot.
    If the ‘Set Hotspot Password’ field is left empty, any device can connect to the portable Wi-Fi hotspot. Conversely, if a hotspot password is specified, then the device hotspot will be protected with WPA2-PSK level security.

 Notes:- If only the hotspot password is specified and the SSID field is left blank in the policy, upon policy execution, the device’s Wi-Fi hotspot password will be modified, while the SSID will remain unchanged. Conversely, if the SSID is specified and the password field is left blank, the SSID will be altered while the hotspot password remains the same on the device.
- The ‘Wi-Fi Hotspot SSID’ and ‘Set Hotspot Password’ options are supported on Samsung Knox devices with versions ranging from 2.2 to 3.71, standard Android devices running versions below 8.0, Android Enterprise Device Owner devices running versions below 8.0, and Android Enterprise Profile Owner devices running versions below 8.0.

The Portable Wi-Fi hotspot feature is supported on Knox version 3.0+ (Standard SDK 2.6 and up), Kyocera business smartphones, Android Enterprise – Device Owner, standard Android devices running versions below 8.0 and LG GATE devices.Data roamingUncheck this option to disallow users to turn on Data Roaming and use mobile data outside their home networks. Data roaming may incur additional charges. Data roaming is allowed by default.Knox version 3.0+ (Standard SDK 2.5 and up), Android Enterprise – Device Owner.Connect to 2G NetworkUnchecking this option will prevent the device from scanning for or connecting to 2G networks.Android Enterprise – Device Owner (Android 14.0+) 

 

 

### Allow Location Settings

Location Settings

 RestrictionsDescriptionSupported DevicesMock locationUnchecking this option prevents users from turning on Mock locations which can be enabled from developer options. Enabling Mock location tricks the GPS with a fake location. By default, users are allowed to do so.  Note: For Device owner mode, unchecking this option completely disables the entire developer options on the device.

LG GATE, Knox version 3.0+ (Standard SDK 1.0 and up), Kyocera business phones.GPSUnchecking this option disallows the users from turning GPS on/off. Allowed by default.LG GATE, Knox version 3.0+ (Standard SDK 1.0 and up), Kyocera business phones, Android Enterprise Device Owner.Force GPS to fetch locationForce GPS to be always ON. Users won’t be able to turn it OFF. Location services are forced by default.  Note: This option can only be enabled if the GPS option is checked.

LG GATE, Knox version 3.0+ (Standard SDK 1.0 and up), Kyocera business phones, Android Enterprise Device Owner (Android 9.0 and above).

 

 

### Allow Basic Sync Settings

Sync Settings

 RestrictionsDescriptionSupported DevicesBackup serviceUnchecking this option prevents user’s data from being backed up to or restored from Google drive.Android Enterprise Device Owner (Android 8.0+).

 

 

### Basic Security Options

Security Options

 RestrictionsDescriptionSupported DevicesAllow MDM administration removalUnchecking this option prevents the removal of Hexnode UEM app from devices.
 **Note:** On LG GATE devices running android 7 and above, disabling this option restricts the removal of both Hexnode UEM and LG Service apps. On devices running Android 6 and below, disabling the option restricts only the removal of Hexnode UEM app and not the LG Service app. Knox version 3.0+ (Standard SDK 1.0 and up), LG GATE.

 

 

Advanced Restrictions
---------------------

![Advanced restrictions for Android devices on Hexnode UEM](https:2018/08/Advanced-restrictions-for-Android-devices.png "Advanced restrictions for android devices")[](https:2018/08/Advanced-restrictions-for-Android-devices.png)

### Allow Advanced Device Functionality

Device Functions

 RestrictionsDescriptionSupported DevicesMicrophoneIf this option is unchecked, the microphone will be disabled while using any apps except phone calls. Microphone is allowed by default.Android Enterprise – Device Owner, Knox version 3.0+ (Standard SDK 1.0 and up).Screen captureUnchecking this option prevents users from capturing the screen directly from their device or from Android Studio. Allowed by default.  Note: 
Depending on the device model, Android version or enrollment method used, screen capture restriction works differently across the endpoints. For instance,

- On devices enrolled in Android Enterprise – Profile Owner mode, the screen capture is restricted only within the work apps.
- On Android 12+ devices enrolled in Android Enterprise – Profile Owner mode, a black screen is captured instead of the device screen.

Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Profile Owner, Android Enterprise – Device Owner.ClipboardWhen you copy or cut a text on the system, it’ll go to the clipboard for temporary use. The text is pasted directly from the clipboard. So, disabling this option prevents using clipboard to Cut, Copy and Paste functions. Copying another piece of text will replace the previous one in the clipboard. Clipboard is enabled by default.Knox version 3.0+ (Standard SDK 1.0 and up)Copy contents between normal and work profilesAllow users to copy contents from an app in normal profile to an app in work profile and vice-versa.Android Enterprise – Profile Owner.Share via other appsDisable data sharing between apps using the share option on the device. Enabled by default.Knox version 3.0+ (Standard SDK 2.0 and up) Users can adjust volumePrevents users from adjusting the device volume, if this option is unchecked. Android Enterprise – Device Owner, Android Enterprise – Profile Owner (Android 6+).Make a callUsers are allowed to make calls on their devices by default. Unchecking this option disallows outgoing calls. Android Enterprise – Device Owner.Set default dialer appChoose an application to set as the default dialer app for making calls.  Note: 
If the chosen app is not installed on the device or does not support dialer services, the following message will appear in the *Action History* of the respective configured policy:

‘The default dialer app was not set either because:

- The app was not installed on the device.
- The app does not support dialer services.’

Android Enterprise – Device Owner (Android 14.0+) Receive callsUnchecking the option disables incoming calls on the device, preventing the user from receiving any calls. Knox version 3.0+ (Standard SDK 1.0 and up)USB Host StorageAllow users to connect an external USB device, such as an external hard disk or a flash drive on their devices. If disabled, it blocks all external USB devices (except those specified under the USB Exception list) from connecting to the devices. Enabled by default.Knox version 3.0+ (Standard SDK 2.9 and up) USB Exception listThis setting works only if the option ‘USB Host Storage’ is disabled. You can select the type of USB storage devices that can connect to your Android devices. Any USB device classes not specified here will be blocked. The available USB device classes include: - **Audio**: Speaker, microphone, sound card, MIDI
- **CDC Data**: Devices used together with USB Communication Device Class (CDC)
- **Communication**: Modem, Ethernet adapter, Wi-Fi adapter, RS-232 serial adapter
- **Human Interface Device**: Keyboard, mouse, joystick and other human-interface devices (HIDs)
- **Mass Storage**: USB Flash drive, memory card reader, digital camera, digital audio player, external drive
- **Miscellaneous**: ActiveSync device
- **Still Image**: Webcam, Scanner
- **Vendor Specific**: Devices that need vendor-specific drivers
- **Wireless Controller**: Bluetooth adapter, Microsoft RNDIS

Hexnode UEM app v11.9.5+ and Hexnode for Work app v7.9.5+Allow input methodsEnabling this option allows all input methods, including third-party input apps. If the option is left unchecked, only the system input methods will be accessible. If the option is enabled, and specific package names for third-party input apps are provided, no additional third-party input apps can be enabled on the device end after associating the policy.  Note:- Ensure that the third-party input apps are installed on the device before associating the policy.
- The correct package name must be provided within the restriction. To obtain the correct package name, follow [these steps](#steps-to-fetch-the-package-name-of-an-application) in Hexnode UEM.

Android Enterprise Profile Owner & Device Owner (Android 10+ devices) Exception: If a third-party input method is already enabled on the device via device settings manually, but a different app’s package name is added in the policy, the policy won’t disable the previously enabled input method. In other words, the user will be able to access both input methods.

 

 

 

### Display Settings

Display Settings

 RestrictionsDescriptionSupported DevicesHide System BarsHides the system bars – the status bar, the navigation bar, and the settings toggles. They are shown on devices by default.Knox version 3.0+ (Standard SDK 1.0 and up) Hide Status BarHides the status bar (notification icons, network signal bar, time etc.) at the top of the handset screen. Hiding the status bar will deny access to the notifications bar and the quick settings tray. The status bar is shown by default.Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner.Hide Navigation BarHides the on-screen navigation bar with the back, home and recent apps buttons. Other system bars will not be affected. The navigation bar is shown by default.Knox version 3.0+ (Standard SDK 1.0 and up)Split-screen modeDisabling this option restricts the user from accessing the multi-window or split-screen feature on the device.Knox version 3.0+ (Standard SDK 1.0 and up)Display dialogs/windowsUnchecking this option blocks dialogs/windows for system overlays, alerts, toast messages, incoming/outgoing calls, and application overlays. It also blocks Hexnode’s password prompt, broadcast message alerts and floating kiosk peripheral settings icon.Android Enterprise – Device Owner.Keep Screen On while chargingSelect the type of power source that can cause the device’s screen to stay on while plugged in. The available options include: - **On AC charger**: The screen stays on when the device is plugged in using an AC charger.  Note:
    - This option may not work if the device is plugged in using an unsupported power supply. Make sure to use the supported device chargers for charging devices.
- **On USB charger**: The screen stays on if the device is charging via USB.
- **On wireless charger**: The device screen stays on while it is charging wirelessly.

 Notes: This restriction will not work if:

- The device screen is manually turned off.
- The ‘**Auto-lock after**’ option under *Policies > Android > Password* is enabled.
- The user disables the ‘**Stay Awake**’ option under ‘**Developer options**’. In this case, the policy will have to be pushed again for this feature to work.

Android Enterprise – Device Owner (Android 6.0+).

 

 

### Allow Connectivity Options

Connectivity Options

 RestrictionsDescriptionSupported DevicesNFCIf this option is disabled, NFC, Android Beam and S Beam are turned off, and users cannot perform operations that use Near Field Communication on devices that support it. NFC is enabled by default.Knox version 3.0+ (Standard SDK 2.0 and up)Android BeamDisabling Android Beam will disable S Beam as well. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up) Beam from the deviceUnchecking this option disallows outgoing Android Beam. Allowed by default.Android Enterprise – Device Owner, Android Enterprise -Profile Owner.Wi-Fi DirectUnchecking this option disallows the usage of Wi-Fi Direct. Wi-Fi Direct is enabled by default.Android Enterprise – Device Owner, Android Enterprise – WP-C (Android 13.0+) Ultra-Wideband (UWB)Allow or disallow the usage of Ultra-Wideband Radio by apps on the device. If unchecked, disallows users from turning it back on via Settings.  Note: 
This restriction will work only on devices that support the [Ultra-wideband (UWB](https://developer.android.com/develop/connectivity/uwb#uwb-enabled_mobile_devices)) feature.

Android Enterprise – Device Owner (Android 14.0+)Transfer data via BluetoothUncheck this option prevents the device from transferring data over a Bluetooth connection, turning this option off will also affect Android Beam transfers. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Configure BluetoothDisallows users to configure Bluetooth on their devices if this option is unchecked. Android Enterprise – Device Owner.Configure cell broadcastDisabling this option will prevent users from configuring cell broadcasts. Allowed by default.Android Enterprise – Device Owner.Configure cellular networkIf disabled, restricts users from configuring cellular network settings on their devices. Allowed by default.Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Users can reset network settingsUsers are allowed to reset network settings on their devices by default. Disabling this option disallows users to reset current cellular and Wi-Fi settings, VPN settings, Wi-Fi passwords and so on. Allowed by default
Note: This feature works for Android devices running version 6 and above.Android Enterprise – Device Owner.Configure Wi-FiUnchecking this option prevents users from configuring Wi-Fi on their devices. Allowed by default.Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Configure managed Wi-Fi profileUnchecking this option prevents the user from modifying the managed Wi-Fi configurations pushed from Hexnode.Android Enterprise – Device Owner (Android 6.0+ devices)Configure hotspot and tetheringIf this option is disabled, users can’t configure portable hotspot and tethering on their devices. Allowed by default.  Warning:For Samsung Knox devices below Android 7.0, disabling the options **Configure hotspot and tethering** and **Sync data in background** may cause the device to be stuck in a boot loop.

 Note: 
When disabled, files shared via Quick Share cannot be received by the device. However, files can still be sent from the device via Quick Share.

Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner.

 

 

 Note: Both Android Beam and S Beam identify a device using NFC. Android Beam send files via Bluetooth whereas S Beam will transfer files with Wi-Fi Direct.

 

### Advanced Security options

Security options

**Minimum Wi-Fi security level** – Set a minimum-security level to establish a Wi-fi connection on the device. **Open** is selected as default. The device will not connect to a network which is less secure than the value chosen here.

 Warning: Once the policy gets applied on the device, the current Wi-Fi connection will get disconnected immediately if it has a security level below the minimum level set in the policy.

Security TypeSupported DevicesWEP WPA/WPA2 PSK

EAP- LEAP

EAP-FAST

EAP- PEAP

EAP-TTLS

EAP-TLS

All Samsung Knox versions.FT- PSK EAP-PEAP-FT

EAP-PEAP-CCKM

EAP-TTLS-FT

EAP-TTLS-CCKM

EAP-TLS-FT

EAP-TLS-CCKM

Knox 2.4+EAP-LEAP-FT EAP-LEAP-CCKM

EAP-FAST-FT

EAP-FAST-CCKM

EAP-PWD

EAP-PWD-FT

EAP-PWD-CCKM

EAP-SIM

EAP-SIM-FT

EAP-SIM-CCKM

EAP-AKA

EAP-AKA-FT

EAP-AKA-CCKM

EAP-AKA’

EAP-AKA’-FT

EAP-AKA’-CCKM

Knox 2.5+RestrictionsDescriptionSupported DevicesSetup Private DNSConfigure private DNS to encrypt DNS queries with TLS for improved security. Once configured, the DNS queries will be encrypted when sent to the selected DNS server. This option is unchecked by default. Once checked, you have two options for configuring private DNS: ***Automatic*** and ***Private DNS provider hostname***. The option **Automatic** is chosen by default if **Setup Private DNS** is enabled. It implies that the device will automatically use the private DNS server provided by your network or internet service provider (ISP). If you choose **Private DNS provider hostname**, provide the DNS server’s address as the hostname in the allocated field.Android Enterprise Device Owner (Android 10+ devices)Allow user modification of Private DNS settingsUnchecking this option will prevent the user from modifying the private DNS settings on the device end. This option is checked by default.

 

 

### Allow Advanced Sync Settings

Limiting Data Sync

 RestrictionsDescriptionSupported DevicesSync data in backgroundUnchecking this option prevents the apps from auto-syncing data in the background. By default, users can toggle it on/off.  Note:If this option is disabled, the device will go into Data Saver mode and the end-user will not be able to exit from it. Enable this option to allow the user to make changes to the Data Saver mode.

 Warning:For Samsung Knox devices below Android 7.0, disabling the options **Configure hotspot and tethering** and **Sync data in background** may cause the device to be stuck in a boot loop.

Samsung KnoxSync data with Google accountUncheck this option to disallow the Google apps on the device to sync data with the user’s Google Account. This includes contact, calendar, emails and everything Google except Play Store apps. Allowed by default.Knox version 3.0+ (Standard SDK 2.0 and up)

 

 

### Allow Account Settings

Account Settings

 RestrictionsDescriptionSupported DevicesSMSUncheck to disable incoming and outgoing SMS.Samsung Knox, Android Enterprise – Device Owner.Receive messagesIf disabled, the device can’t retrieve the text messages sent to its user. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up).Send messagesBlocking this feature will restrict the users from sending text messages from their Samsung devices. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up).Set default SMS appChoose an application to set as the default SMS app for sending and receiving messages.  Note: 
If the chosen app is not installed on the device or does not support SMS services, the following message will appear in the *Action History* of the respective configured policy:

‘The default SMS app was not set either because:

- The app was not installed on the device.
- The app does not support SMS services.’

Android Enterprise – Device Owner (Android 10.0+)Modify Accounts/UsersIf disabled, restricts users from adding, removing and switching between the users. For Android Enterprise enabled devices, this option allows the users to add, remove or switch between Google Accounts. Allowed by default.Samsung Knox, Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Add UsersUser will not be allowed to add other users if this option is unchecked. Allowed by default.Knox version 3.0+ (Standard SDK 1.1 and up) Remove UsersUser will not be allowed to delete other users if this option is unchecked. Allowed by default.Knox version 3.0+ (Standard SDK 1.1 and up) Configure user credentialsAllow users to configure user credentials.Android Enterprise – Device Owner, Android Enterprise – Profile Owner.

 

 

### Allow Settings

Restrict Device Settings Modification

 Note: 
Make sure you have the latest versions of the Hexnode UEM app or Hexnode for Work app installed on the devices.

RestrictionsDescriptionSupported DevicesDeveloper modeUnchecking this option will disable developer mode. This will reset any manually-configured developer settings. Allowed by default.Knox version 3.0+ (Standard SDK 2.0 and up)
Android Enterprise Device Owner.USB debugging **(If Developer mode is enabled)**This option enforces the USB debugging state on the managed devices. 1. **Users can choose:** Allows end-users to manually toggle USB debugging on or off within the device’s developer options.
2. **Always Off:** Forcefully disables USB debugging and prevents users from turning it on.
3. **Always On:** Forcefully enables USB debugging across all targeted devices.

Knox version 1.0+ (Standard SDK 1.0 and up)
Android Enterprise Device Owner Modify settingsDisabling this option blocks all future changes to the device settings, until this option is turned back on. By default, Settings can be modified.Knox version 3.0+ (Standard SDK 2.0 and up)Power saving modeIf disallowed the device won’t be able to switch to power saving mode. Allowed by default.Knox version 3.0+ (Standard SDK 2.8 and up) Users can enable location sharingThis option allows users to enable real time location sharing with others. Disabling this option prevents the user from turning on location sharing. Allowed by default.Android Enterprise – Device Owner, Android Enterprise -Profile OwnerFactory ResetUnchecking this option will prevent users from performing a factory reset from the device settings. Allowed by default.  Note:Users would still be able to factory reset the device using hardware keys.

Android Enterprise – Device OwnerAdvanced Factory ResetUnchecking this option will prevent users from performing a factory reset from the device settings, via ADB or even the recovery mode.  Warning:All system recovery options might be affected by disabling this option.

Knox version 3.0+ (Standard SDK 1.0 and up) Read any connected physical external mediaUsers are allowed to connect the devices to external physical media by default. Disabling the option prevents it. Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Disable screen lock if the screen was turned off If this option is enabled, the screen lock option (Settings > Security > Screen Lock) will be disabled on the device. Any unlock pattern, password, PIN on the device will get cleared. Disabled by default.Knox version 3.0+ (Standard SDK 2.0 and up), Android Enterprise – Device Owner Android 7.0Configure VPNAllows users to configure VPN. When disabled, network and data usage restrictions set under **Android > Mobile Data Management** won’t work.Knox version 3.0+ (Standard SDK 1.1 and up), Android Enterprise – Device Owner, Android Enterprise – Profile Owner (Android 6.0)Automatically power off a device when the power cable is detached Enable this option to power off a device whenever the power cable is detached from it. This will not work if ‘Power Off’ under **Policy > Android > Restrictions > Basic** is disabled.  Notes: 
This option works only if:

- A [KPE Premium license key](https://www.hexnode.com/mobile-device-management/help/how-to-add-knox-platform-for-enterprise-kpe-premium-license-key-in-hexnode-mdm/) is attached to the devices. Head on to **General Settings > Knox Platform for Enterprise > Configure** to select the key already added to the portal.
- The **‘Power Off’** option under **Policy > Android > Restrictions** is enabled.

Knox version 3.0+ (Standard SDK 2.8 and up) Automatically power on a device when the power cable is connected Check this option to automatically turn on the device when the power cable is connected.  Notes: 
For this feature to work,

- Attach the [KPE Premium license key](https://www.hexnode.com/mobile-device-management/help/how-to-add-knox-platform-for-enterprise-kpe-premium-license-key-in-hexnode-mdm/) to the devices. Head on to **General Settings > Knox Platform for Enterprise > Configure** to select the key already added to the portal.
- For Android OS 12 and lower, this feature is compatible only with [Qualcomm](https://www.samsung.com/in/smartphones/processor-brand/qualcomm-snapdragon/) and [LSI](https://semiconductor.samsung.com/processor/showcase/smartphone/) chipsets. For Android OS 13 and higher, it functions on all devices regardless of chipset.

Knox version 3.0+ (Standard SDK 2.6 and up)

 

 

### Date and Time Settings

Date and Time restrictions

 RestrictionsDescriptionSupported DevicesSet date and time automatically When enabled, the device automatically updates its date and time with the mobile network time server. This option is enabled by default.Android Enterprise – Device Owner. Set time zone automaticallyEnable this option to automatically set the device time zone based on the mobile network server. This option is enabled by default.Android Enterprise – Device Owner. Set Time ZoneYou can also choose the time zone to be configured on the device by selecting it from the drop-down menu. This option can be configured only when “Set time zone automatically” is disabled.Android Enterprise Device Owner (Android 9+)
Samsung Knox 2.0 – Samsung Knox 3.8. Allow users to modify date and time Users can manually adjust the date and time settings on their devices. Disabling this option will grey out the automatic date and time setting on the device end. This option is enabled by default.  Note: 
On Android 9+ devices, if you unselect this option, users will be unable to modify the date, time, and time zone settings on the device. For devices running Android versions earlier than 9, unselecting this option will prevent users from updating the date and time settings on the device. In this case, the device will automatically update its date and time provided by the mobile network time server. However, the users can still manually change the time zone

Android – Enterprise Device Owner.Time formatThis option allows you to choose between 12-hour or 24-hour time format, or to keep the current settings on the device. The 12-hour format is selected by default.Knox version 3.0+ (Samsung Knox 1.0 – Samsung Knox 3.8).

 

 

### Lock Screen Customizations

Lock screen restrictions

 Notes:- Lock Screen customizations are supported only on devices with a secured lock screen (Devices protected by a PIN, pattern or password lock).
- To customize the lock screen, the device should be updated with the latest version of the Hexnode For Work app.

RestrictionsDescriptionSupported DevicesLock Screen CameraUncheck this option to disable camera and face unlock feature on a secured lock screen.  Notes:- Face unlock configured through trust agents for smart lock may not be disabled even if this option is unchecked.
- Enabling or disabling this feature will have no effect, if **Camera** under **Policies > Android > Restrictions > Basic** is disabled.
- This feature will have no effect on Samsung Knox devices, if **Lock screen shortcuts** under **Policies > Android > Restrictions > Basic** is disabled.

Android Enterprise Device Owner (Android 5.0+).Trust Agents for Smart LockIf disabled, this would prevent trusted agents like device connected via Bluetooth, NFC, etc. from unlocking the device.Android Enterprise Device Owner (Android 5.0+), Android Enterprise Profile Owner (Android 6.0+).Lock Screen NotificationsIf disabled, notifications will not be shown on the secured lock screen.Android Enterprise Device Owner, (Android 5.0+).Unredacted NotificationsIf disabled, only redacted notifications will be shown on the locked screen. Redacted notifications are sensitive notifications with contents hidden on the lock screen. This feature can only be enabled if **Lock Screen Notifications** is enabled.Android Enterprise Profile Owner (Android 6.0+), Android Enterprise Device Owner (Android 5.0+).Fingerprint UnlockIf unchecked, fingerprint unlock will be disabled on a secured lock screen.Android Enterprise – Device Owner (Android 5.0+), Android Enterprise Profile Owner (Android 6.0+).Iris ScannerUncheck to disable iris scanner feature on the secured lock screen.Android Enterprise Device & Profile Owner (Android 9.0+).Face UnlockIf unchecked, users cannot unlock the device via the face unlock feature.  Notes:- Even if this option is disabled, Face unlock configured through trust agents for smart lock may not be disabled.
- If **Camera** under **Policies > Android > Restrictions > Basic** is disabled, enabling or disabling this feature will have no effect.

Android Enterprise Device & Profile Owner (Android 9.0+).

 

 

### Allow App Settings

App-based Restrictions

 RestrictionsDescriptionSupported DevicesInstall appsDisabling this option will block any apps from installing on the device. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Uninstall appsTo disallow a user from uninstalling any apps from the device, disable this option. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Control appsEnabling this option allows users to modify applications in Settings or launchers. If this option is disabled, users can’t uninstall apps, disable apps, clear app data and cache, force stopping apps, clear app defaults and so on.Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Google Play StoreUnchecking this option will hide Google Play Store’s icon from the user’s device. Allowed by default.Knox version 3.0+ (Standard SDK 1.0 and up) Verify apps before install Enabling this option allows Google to verify the app content for any harmful behaviour before installation begins. If disallowed, it prevents Google app verification before installation. Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Install apps from unknown sourcesIf allowed, it enables the users to install apps from Play Store and other sources. Unchecking this option will block app installation from unknown sources and users can’t turn it back on from the device.  Note: 
App installation and updates initiated from the Hexnode portal will remain unaffected.

Knox version 3.0+ (Standard SDK 1.0 and up), Android Enterprise – Profile Owner, Android Enterprise – Device Owner. App Runtime PermissionsSet runtime permissions for apps. You can grant, deny specific permissions or, set default permissions for the app.  Note: 
The app runtime permissions can only be granted on Android 10 or later devices.

Android Enterprise – Device Owner, Android Enterprise -Profile Owner.Parent profile app linkingDisabling this option prevents apps in the parent profile to handle web links from managed profile.
**Note**: This feature works for Android devices running version 6 and above.Android Enterprise – Device Owner, Android Enterprise – Profile Owner.Allow cross-profile app communicationEnable this option to allow data sharing between the personal and work profiles. Check the option and enter the app’s package name(s) that require cross-profile communication privileges. Make sure the app is installed in both profiles. Once the restriction is applied, the user must enable cross-profile data sharing within the app settings on the device manually. If unchecked, the option to enable cross-profile communication within the app settings will be unavailable to the user.  Notes:- This restriction only applies to apps that support cross-profile communication.
- The correct package name must be provided within the restriction. To obtain the correct package name, follow [these steps](#steps-to-fetch-the-package-name-of-an-application) in Hexnode UEM.
- If you need to grant cross-profile communication access to multiple apps, add the package names separated by commas in the provided field.

Android Enterprise Profile Owner (Android 11+ devices)

 

 

 
 Exception: When the Web Content Filtering policy is applied, VPN and tethering/hotspot functionalities on Samsung Knox devices may have conflicts.

 

### Factory Reset Protection (Google Account Verification)

Google [Factory Reset Protection](https://www.hexnode.com/mobile-device-management/help/how-to-securely-bypass-factory-reset-protection-for-android-devices-using-hexnode-mdm/) (FRP) is a security feature enabled by default on devices running Android v5.1+, designed to prevent the use of devices if it gets reset to factory settings without your permission. If you have a Google account set on your device and your device is reset, the device remains unusable until you log in using the Google account previously set on your device.
‘**Default**’ option takes the default device settings for FRP.
‘**Bypass Factory Reset Protection**‘ enforces the Google account verification step. Add Google Workspace email address and/or [Google Plus Profile IDs](https://www.hexnode.com/mobile-device-management/help/how-to-securely-bypass-factory-reset-protection-for-android-devices-using-hexnode-mdm/#how-to-find-your-googleprofile-id) to log in to your devices in situations where you forget/do not know the previously configured Google account credentials. Integrate your [Google Workspace](https://www.hexnode.com/mobile-device-management/help/configure-android-in-the-enterprise-using-gsuite-in-hexnode-mdm/) account with the Hexnode UEM server to add the accounts to the list.
‘**Disable Factory Reset Protection**‘ lets you skip the Google account verification step. When asked to enter the Google account credentials, the user can skip the verification by clicking SKIP.

### Accessibility Settings 

Accessibility restrictions

 RestrictionsDescriptionSupported DevicesAccessibility services Accessibility services are designed to improve the usability of a device for individuals with disabilities or those who may have difficulty interacting with the devices.
Enabling this option will allow all externally installed accessibility services on the device end.  Notes:- Admins can only restrict externally installed accessibility services on the device and cannot restrict built-in services.
- Device end users can still modify accessibility settings if the accessibility shortcut for the app is enabled.
- This restriction might not work as expected on versions below Android 14.

Android Enterprise Device Owner Allow specific accessibility services only Admins can specify which accessibility services are allowed by adding the respective packages using the **Choose Apps** option. Once you add the packages, they will appear in a table below the Accessibility Settings. Android Enterprise Device Owner 

 

 

Steps to fetch the package name of an application
-------------------------------------------------

To configure the following restrictions, ***Allow cross-profile app communication*** and ***Allow input methods***, you must include the correct app package names in the restriction. If these package names are provided incorrectly, the restriction may not function as expected. There are two ways to fetch the app package name within Hexnode UEM. To fetch the correct app package names, follow the steps below in Hexnode UEM.

#### Method 1

1. Navigate to the **Apps** tab.
2. If the application is not yet added to the app inventory, first [add the app to the app inventory](https://www.hexnode.com/mobile-device-management/help/how-to-install-apps-on-android-devices/).
3. If it’s already added, search for the app for which you must specify the package name in the restriction.
4. Ensure that the app’s platform is **Android**, as the same app may be available for multiple platforms.
5. Click on the app to access detailed information about it.
6. In the list of available details, the package name will be listed as the **Identifier**. Use this as the package name within the restriction.

#### Method 2

1. If the application is already installed on the device, navigate to the **Manage** tab > **Devices** > Select the device to view the complete device management details.
2. Within the device details page, navigate to the **Applications** tab.
3. Now, ensure that the Identifier column is available. If the column is not present, you can add it by editing the columns available in the table.
4. Next, search for the application and copy the identifier from the column for use in the policy.

How to Apply the Restrictions to Devices/Groups?
------------------------------------------------

If you haven’t saved the policy yet,

1. Proceed to the **Policy Targets**.
2. Click on **+ Add Devices**, search and select all devices to which the policy is to be applied.
3. Press **OK** button to finish adding devices.

Missed a device? No worries. Click on **+ Add Devices** again and you can add more of them.

To associate the policies with a device group instead, select **Device Groups** from the left pane under **Policy Targets**, and follow the above instructions. You can associate the policy with users, user groups, or domains from the same pane.

If you’ve saved the policy and you’re taken to the page which displays the policy list,

1. Check a policy.
2. From **Manage**, select **Associate Targets**.
3. Add as many devices as you need.