Restrictions
For Android devices with Android Enterprise enrollment, a variety of restrictions are available in Relution. Basically, it is advisable to be clear about exactly which restrictions are combined. This makes it possible to rule out that devices are configured in such a way that they are no longer usable.
In the portal, the configuration is divided into several sections. The following overview follows this structure. If an option only applies to certain enrollment types or Android versions, this is noted for the option.
Account restrictions
- Disable adding new users and profiles
- Disable removal of other users
- Disable adding and removing accounts
- Disable configuration of user credentials
- Enable selection of a private key if no matching rule is defined: The user can select a private key if no rules are defined to automatically select a private key and certificate for authenticating the device to a server. On devices below Android 9, this setting may leave enterprise keys vulnerable.
App restrictions
- Disable app installation
- Disable app uninstallation
- Disable easter egg in settings
Further information: Advanced Security Overrides →
Customization restrictions
- Disable user icon customization
- Disable wallpaper customization
- Enable auto date and time zone (Managed Device only): Defines whether automatic date, time and time zone setting is enabled on a company-owned device. The options are Default, User Choice and Enforced.
Device restrictions
This section contains general device restrictions as well as cross-profile settings for devices with a work profile.
General
- Disable keyguard (Managed Device only)
- Enable Factory Reset Protection (FRP) (Managed Device and Personal profile only) and Google account email for FRP: see Factory Reset Protection →.
- Account types for which management is disabled: Account types that the user cannot manage.
- Permitted input methods and Permitted accessibility services: The options are All allowed, System apps only and System and additional specified apps. With the last option, the additionally permitted apps are stored in a list.
- Enterprise display name visibility: Defines whether the enterprise display name is shown on the device (Unspecified, Visible on the device, Hidden on the device). The display name itself is maintained in the Enterprise Display Name field under
Settings→Device platform specific→Android Enterprise. - Assist content policy (Android 15 and later): Controls whether assist content such as screenshots and app information may be sent to a privileged app such as an assistant app (Unspecified, Allowed, Not allowed).
- Autofill policy: Controls the system autofill service (Android 8 and later) with the options Unspecified, User choice and Disabled. To comprehensively restrict credential management, the Credential provider policy default is configured in addition.
- Credential provider policy default (Android 14 and later): Unspecified, Disallowed or Disallowed except system.
- Printing: Unspecified, Allowed or Not allowed.
Cross profile settings
These settings only apply to the Work profile and Personal profile enrollment types. They are not applied on managed devices without a work profile.
- Work profile widgets default value: Defines whether work profile apps may add widgets to the home screen by default if nothing else is specified for the app (Unspecified, Allowed, Not allowed). Unspecified corresponds to Not allowed.
- Copy and paste: Unspecified, Allowed or Disallow from work to personal profile.
- Data sharing: Unspecified, Allowed, Disallow from work to personal profile or Disallowed.
- Show work contacts in personal profile (Contacts section): Unspecified, Disallowed, Allowed or Allow only system apps to access work contacts in the personal profile. In addition, an app list can be maintained: with Unspecified and Allowed, it contains the apps that are not allowed access; with the other options, it contains the apps that are allowed access.
Multimedia restrictions
- Disable screen capture
- Disable adjusting the master volume
- Disable location sharing
- Disable contact sharing over Bluetooth
- Camera access: Default, User choice, Camera disabled or Camera access enforced. Controls the use of the camera and whether the user can use the camera access toggle (Android 12 and later). On fully managed devices, disabling the camera applies to the entire device; on devices with a work profile, it applies only within the work profile.
- Microphone access: Default, User choice, Microphone disabled or Microphone access enforced. Controls the use of the microphone and whether the user can use the microphone access toggle (Android 12 and later). The setting only takes effect on fully managed devices.
Network restrictions
- Disable configuring Bluetooth
- Disable configuring mobile networks
- Disable reset of network settings
- Disable VPN configuration
- Disable editing of Wi-Fi networks (deprecated, see note below): see Disabling Wi-Fi configuration →.
- Disable Android Beam (NFC) to share data between apps
- Disable Bluetooth
- Enable network escape hatch: If no network connection can be established at boot time, the escape hatch prompts the user to temporarily connect to a network in order to refresh the device policy. After the policy has been applied, the temporary network is removed again.
- Preferential Network Service (Work profile only): Controls whether the preferential network service is enabled in the work profile (Unspecified, Disabled, Enabled). The setting has no effect on fully managed devices.
Storage restrictions
- Disable mounting physical external media
- Disable USB file transfer (deprecated, see note below)
Telephony restrictions
- Disable sending and receiving SMS messages
- Disable outgoing calls
- Disable roaming data services
- Disable configuring tethering and portable hotspots (deprecated, see note below)
- Disable configuring cell broadcast
Possible pitfalls
The following options can result in devices no longer being usable or reachable as intended.
Factory Reset Protection
With the Enable Factory Reset Protection (FRP) option, resetting to factory settings via the Android device settings can be blocked on managed devices. Resetting via the recovery menu is not affected.
The email addresses of device admins are stored in the Google account email for FRP field. These addresses must be Google accounts. If the device has been reset to factory settings, one of these device admins must sign in with their Google account (email and password) to unlock the device. If no addresses are specified, the device does not provide factory reset protection. This setting should therefore be used with caution.
Disabling Wi-Fi configuration
If Disable editing of Wi-Fi networks is active and no Wi-Fi networks are specified, Wi-Fi is disabled on the device. If devices cannot establish a Wi-Fi connection because the configured networks are unreachable or faulty, there is no way to intervene manually. The setting then cannot be undone either, since the devices are offline.
This option should only be used in conjunction with Enable network escape hatch. If no network connection can be established at boot time, it allows a Wi-Fi network to be configured temporarily in order to refresh the device policy.