App access control
Last updated October 8th, 2026
This document is new for the Knox cloud services 26.10 UAT.
To use this feature, you need a Knox Guard Advanced license.
The App access control policy allows you to both block and allow specific apps from your devices. Restrict access to frequently used apps, while also letting device users access essential apps required for day-to-day functions. You can use this feature to encourage payment compliance, or apply measures to help prevent business devices from being misused.
This policy sets the tenant-wide app control configuration settings. To update this policy for a specific device, see Update app access control.
How app access control works
Using app access control, you can configure both an app blocklist and an app allowlist. The blocklist and allowlist function independently of each other:
- If only the blocklist is enabled, device users can access any apps that isn’t specified in the blocklist.
- If only the allowlist is enabled, device users can only access authorized apps you specify. Not applicable to pre-loaded system apps*. To block access to a system app, add it to the blocklist.
- If both the blocklist and allowlist are enabled, device users can only access authorized apps, and also can’t access any blocked apps. This is useful if you want to only allow certain apps, while also blocking access to system apps.
You can allowlist up to 10 apps and blocklist up to 50 apps with this policy.
*Pre-loaded system apps are identified by Android’s ApplicationInfo.FLAG_SYSTEM attribute. Apps without this flag are disabled by the allowlist unless added explicitly. Before applying an allowlist, verify that any app you want to permit either has the FLAG_SYSTEM attribute or is added to the allowlist.
Manage app access control
To configure your tenant-wide app control settings:
-
Navigate to the Policies page.
-
Under SETTINGS, click APP ACCESS CONTROL.
-
To prevent specific apps from running on the device, enable Block apps and enter up to 50 package names.
-
To allow only specific apps to run on the device, enable Allow apps and enter up to ten package names.
For more details on how this feature works, see the How app access control works section.
-
Enable Warning notification to display a message on devices when this policy takes effect. We recommend you use this message to explain the restrictions applied, and if applicable, what actions the device user can take to remove these restrictions.
You can also configure how and when this message displays on devices:
- Persistent notification: The message displays permanently in the notification panel.
- Dismissible notification: Device users can remove the message from the notification panel. You can also choose for the message to Show after device reboot.
-
Click SAVE.
Is this page helpful?
Thank you for your feedback!