Android policies
Last updated September 25th, 2024
System settings
Setting | Description | Supported system |
---|---|---|
Use Camera |
Allows the device user and apps to operate the camera. Values
|
Android 8 and higher |
Screen capture permission |
Allows the device user and apps to take screenshots. Values
|
Android 8 and higher |
Factory reset |
Allows the device user to factory reset the device. Values
|
Android 8 and higher |
Developer mode |
Allows the device user to toggle developer mode. Values
|
Android 8 and higher |
> Use mock location for testing |
Allows using a mock location for development or test purposes. Applies to Samsung devices only. |
Android 8 and higher Knox 2.0 and higher |
> Set limit for background processes |
Allows limiting background processes on the device. |
|
> Close apps if user signs out of device |
Allows closing all apps when the device user signs out of the device |
|
Safe mode |
Allows use of the Safe Mode on the device. |
Android 8 and higher |
Install system updates |
Determines the schedule for firmware updates on the device. Values
Additionally, you can schedule one or more freeze periods, which are stretches of time where the device won't apply any firmware updates, on top of whichever update setting you select. These periods will recur every year. You can configure as many freeze periods as you need.
Click ADD ANOTHER PERIOD to schedule an additional freeze period. |
Android 8 and higher |
> Set time range |
Specifies start time and end time to install updates. |
|
> Set dates to block updates |
Specifies dates on which to block installation of updates. |
|
Backup data on cloud |
Allows backup of device data. Values
|
Android 8 and higher |
Set date and time |
Allows the device user to adjust the clock and current date. Values
|
Android 8 and higher |
Set user certificates |
Allows the device user to set a certificate. Values
|
Android 8 and higher |
Change language |
Allows the device user to change the language. Values
|
Android 8 and higher |
Change brightness setting |
Allows the device user to change the screen brightness setting. Values
|
Android 8 and higher |
Always on display |
Allows the always on display feature that displays information on the lock screen. Values
|
Android 8 and higher |
Android Easter egg game |
Allows the device user to run the Easter egg game on a device. Values
|
Android 8 and higher |
Wallpaper
Policy | Description | Supported system |
---|---|---|
Change wallpaper |
Allows both the device user and apps to change the wallpaper. Values
|
Android 8 and higher |
Set custom wallpaper |
Applies a custom wallpaper on the device. Values
|
Android 8 and higher |
> Home screen |
Specifies a custom wallpaper to apply to the home screen. Only available if the Set custom wallpaper policy is set for both the home and lock screens. Values
|
Android 8 and higher |
> Lock screen |
Specifies a custom wallpaper to apply to the home screen. Only available if the Set custom wallpaper policy is set for both the home and lock screens. Values
|
Android 8 and higher |
> Wallpaper file |
Specifies a custom wallpaper to apply to the home or lock screen. Only available if the Set custom wallpaper policy is set for home screen or lock screen. Values
|
Android 8 and higher |
Notification
Policy | Description | Supported system |
---|---|---|
Show notifications on device |
Allows display of notification messages on the device. Values
|
Android 8 and higher |
Show error notification after app crash |
Allows the display of notifications related to app crashes. Values
|
Android 9 and higher |
Show notification if event is triggered |
Allows the display of notifications when an event occurs. Values
|
Android 8 and higher |
Show notification if event is disabled |
Allows the display of notifications when an event is disabled. Values
|
Android 8 and higher |
Remove notifications from Quick panel |
Set the removal of notifications from a device's Quick panel. Values
|
Android 8 and higher |
Show message for blocked settings |
Allows display of custom messages on the device. A default message is displayed if you don't set a custom message. Values
|
Android 8 and higher |
Show custom message on lock screen |
Allows the display of notification messages on locked screen of a device. Values
|
Android 8 and higher |
Security settings
Policy | Description | Supported system |
---|---|---|
Take action if OS is compromised | Select a measure to take when a compromised OS is detected. Values
|
Android 8 and higher |
Set encryption for device storage | Specifies the encryption of the device's internal storage or the external SD card. ValuesSelect the storage to encrypt.
|
Android 8 to 10 |
Lock screen
Setting | Description | Supported system |
---|---|---|
Set minimum complexity |
Enforces the minimum complexity for the device's lock. There are three complexity levels, each pre-defined by the Android API. The device user must set a lock that meets or exceeds the minimum level. You can enable this setting and the Set minimum strength at the same time. If you do so, this setting will apply to any assigned devices that are running Android 12 and higher, while Set minimum strength will apply to any devices running Android 8 to 11. Only available if Screen lock policies is turned on. Values
|
Android 12 and higher |
Set minimum strength |
Enforces the minimum strength for the device's lock. Each strength level uses a lock type with minimum strength requirements. For PINs and passwords, you can further define the minimum length and complexity requirements across multiple parameters. The device user must set a lock that meets or exceeds the minimum strength. The password strength increases in the following descending order of the available values, with Weak Biometric being the weakest, and Complex being the strongest. You can enable this setting and the Set minimum complexity at the same time. If you do so, this setting will apply to any assigned devices that are running Android 8 to 11, while Set minimum complexity will apply to any devices running Android 12 and higher. Only available if Screen lock policies is turned on. Values
Depending on the value selected above, you must also set the parameters of the password strength:
|
Android 8 to 11 |
Set days before user must reset password |
Specifies how long the lock will remain active before the device user must change it. Only available if Set minimum complexity is turned on, or Set minimum strength is set to Pattern, Numeric, Numeric Complex, Alphabetic, Alphanumeric, or Complex. ValuesEnter the number of days, between 1 and 365. Default is 30. You can also set:
|
Android 8 and higher |
Limit wrong unlock attempts |
Specifies how many times how many times someone can fail to unlock the device in a row before the device takes action to protect itself. Only available if Set minimum complexity is turned on, or Set minimum strength is set to Pattern, Numeric, Numeric Complex, Alphabetic, Alphanumeric, or Complex. ValuesEnter the number of failed unlock attempts are tolerated, between 1 and 10. Default is 1. You can also set:
|
Android 8 and higher |
Lock devices after a set number of hours |
If the lock complexity is low or its strength is weak, specifies how long after the device is unlocked that it relocks. ValuesEnter the number of hours, between 1 and 72. Default is 1. |
Android 8 and higher |
Screen lock history |
Specifies the minimum number of new locks that must be registered before a user can reuse a previous lock. ValuesEnter the minimum number of locks, between 1 and 10. Default is 1. |
Android 8 and higher |
Screen lock compliance violation |
Specifies what happens if the device user sets a lock that violates the minimum complexity or strength requirements. Values
|
Android 8 and higher |
Block certain actions if screen is locked |
Choose which features to block when the screen is locked. Values
|
Android 8 and higher |
Screen lock time changes by device user |
Specify whether to allow a device user to control the screen lock time setting. Values
|
Android 9 and higher |
Set maximum screen timeout allowed |
Specifies the longest duration that the device user can set for automatic screen timeout and lock. Values
|
Android 8 and higher |
Setting | Description | Supported system |
---|---|---|
Use Wi-Fi |
Controls Wi-Fi availability. Values
|
Android 8 and higher |
Wi-Fi direct |
Controls the use of Wi-Fi Direct connection for Samsung devices. Values
|
Android 8 and higher Knox 1.0 and higher |
Use Bluetooth |
Controls Bluetooth availability. Values
|
Android 8 and higher |
> Desktop connection |
Allows desktop's to connect with the user's device using Bluetooth. Values
|
Android 8 and higher |
> Search mode |
Allows device search mode. Values
|
Android 8 and higher |
Control Bluetooth settings |
Allows device users to control Bluetooth settings on their device. Values
|
Android 8 and higher |
Use VPN |
Allows the use of VPN on a device. Values
|
Android 8 and higher |
Transfer files through USB |
Allows the device user to transfer files between the device and other devices through USB. Charging through the USB connector isn't affected. Values
|
Android 8 and higher |
Transfer data using NFC |
Allows transfer of data using NFC. Values
|
Android 8 and higher |
Use external SD card |
Allows the device user to mount storage media connected through the SD card slot. Values
|
Android 8 and higher |
> Write to external SD card |
Allows writing to an external SD card. Values
|
Android 8 and higher |
Wi-Fi
Sets up a Wi-Fi policy on the device, which are preset Wi-Fi configurations that contain an SSID, password, security type, proxy, and connection behavior of a network or access point.
Each unique SSID requires a separate policy. Click ADD WI-FI POLICY to add configure additional networks or access points. You can add or edit up to 10 policies.
Setting | Description | |
---|---|---|
Policy name |
Determines the name of the policy. ValuesEnter a unique name for the policy. The name must:
|
|
Network name (SSID) |
Determines the name of the policy. ValuesEnter a name. So that Knox Manage can correctly process and store the name, it must:
|
|
Description |
Specifies a description for the policy that is displayed on the Knox Manage console. ValuesEnter a description up to 1,000 characters long. |
|
Security type |
The security protocol of the Wi-Fi network. This value must match the actual security protocol that the network uses. Values
|
|
Password |
The password of the Wi-Fi network. This value must match the actual password that the network uses. Only available if Security type is set to WPA/WPA2-PSK. ValuesEnter the password. So that Knox Manage can correctly process and store the password, it must:
|
|
Proxy configuration |
The Wi-Fi network's proxy. This value must match the actual proxy settings that the network uses. Values
|
|
Additional settings |
Assigns extra settings that control how the device interacts with the Wi-Fi network. Values
|
Setting | Description | Supported system |
---|---|---|
Location settings |
Controls the services that track the device's physical location. Values
|
Android 8 and higher |
Allow collection of location data |
Specifies if collection of data requires user consent. Values
|
Android 8 and higher |
> Set collection time |
Specifies the time period after which location data must be collected. Values
|
Android 8 and higher |
App
Setting | Description | Supported system |
---|---|---|
App installation |
Allows the device user to install apps. Values
|
Android 8 and higher |
App uninstallation |
Allows the device user to uninstall apps. Values
|
Android 8 and higher |
App installation from other sources |
Allows the device user to install Android apps from untrusted sources. This setting doesn't apply to apps on Google Play. Values
|
Android 8 and higher |
Skip app tutorials |
Allows device users to skip the tutorials available for apps. Values
|
Android 8 and higher |
Control apps from settings |
Determines if device users can modify app settings. Values
|
Android 8 and higher |
Delegated scopes for apps |
Specify apps with delegation scope enabled. Click Set App Delegation to select the apps. Values
|
Android 8 and higher |
Runtime permissions for all apps |
Specify whether to allow the setting of app runtime permissions in all areas. The admin can grant or deny app runtime permissions without a user's intervention. Values
For work profile devices running Android 12 and higher, even if the app permissions are set to Grant, functions such as camera, location, microphone, and body sensor are not allowed for privacy. |
Android 8 and higher |
> Exceptions list |
Specifies the apps that do not need runtime permissions. ValuesSpecify the app name.
|
Android 8 and higher |
Hide apps |
Specifies a list of apps to uninstall from the device and prevent the user from installing. If you or the user have already installed an app to the device, once you hide it, it automatically uninstalls. ValuesSelect one or more apps from the app library. |
Android 11 and higher |
Activate certain pre-installed system apps |
Specifies a list of pre-installed system apps to reactivate. Apps specified in the Hide apps list take precedence over this list. ValuesSelect one or more apps from the known list of system apps. |
Android 8 and higher |
Block certain apps from using mobile data |
Specifies a list of apps that must not be uninstalled using mobile data. ValuesSelect one or more apps or system apps from the app library. |
Android 10 and higher |
Kiosk
Configures the device as a kiosk. As of Knox Manage 23.12, you can only configure single-app kiosks, and the app can only be Knox Browser.
Only one kiosk configuration is allowed in a profile.
Setting | Description | Supported system |
---|---|---|
Kiosk package name |
Specifies the single app to offer in the kiosk experience. ValuesEnter the package name. As of Knox Manage 23.12, this value is fixed at com.sds.emm.singleweb — Knox Browser — and can't be changed. |
Android 9 and higher |
Default URL |
Specifies the home page of the Kiosk Browser. ValuesEnter a fully-formed URL. You can insert lookup codes for string substitution. |
Android 9 and higher |
Basic settings |
Controls settings related to core kiosk behavior. Values
|
Android 9 and higher |
Utility settings |
Controls settings related to OS behavior in the kiosk. Values
|
Android 9 and higher |
Advanced settings |
Controls settings related to advanced kiosk behavior. Values
|
Android 9 and higher |
User and account
Setting | Description | Supported system |
---|---|---|
Add or delete account |
Allows device users to add or delete accounts. Values
|
Android 8 and higher |
Account type allowlist and blocklist |
Specifies a list of apps to allow or block on devices. Values
|
Android 8 and higher |
> Account types |
Specifies the account types to allow or block on devices. ValuesEnter account types |
Android 8 and higher |
> Select accounts to allow in Google Play |
Specifies the accounts to allow on devices. Values
|
Android 8 and higher |
>> Accounts |
Specifies the accounts to allow when you select Allow Managed Google Play and selected accounts option in the Select accounts to allow in Google Play setting. ValuesEnter account types |
Android 8 and higher |
User deletion |
Specifies if deletion of users is allowed. Values
|
Android 8 and higher |
On this page
Is this page helpful?