# Restrictions Last updated: August 14, 2026 This page provides a comprehensive reference for configuring Android Restrictions profiles in Mobile Device Manager Plus. Administrators can allow or restrict device features across categories including Device Functionality, Security, Sync and Storage, Applications, Browser, Network and Roaming, Device Connectivity, Tethering, Location, Phone, Display, and Miscellaneous settings. The profile description table details feature support across deployment modes — Fully Managed, Work Profile on Personally Owned, Fully Managed with Work Profile, and Legacy — helping admins identify the right restrictions for their Android fleet. **Mobile Device Manager Plus** allows administrators to create an Android Restriction profile to manage various aspects of device functionality effectively. The profile encompasses several key sections, including Device Functionality, Security, Sync and Storage, Applications, Browser Restrictions, Network and Roaming, Device Connectivity, Tethering, Location Settings, Phone, Date/Time Settings, Display Settings, and Miscellaneous. Within each of these sections, administrators can specify features to either allow or restrict during the profile creation process. For detailed information on each section, refer to the Profile Description section below. **Only devices running Android 5.0 or above can be provisioned as [Personally-Owned Work Profile (BYOD, or previously Profile Owner)](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Profile_Owner) or [Fully Managed (COSU and COBO, or previously Device Owner)](https://www.manageengine.com/mobile-device-management/help/android_for_work/mdm_android_for_work_introduction.html#Device_Owner).** **Note:** To view a detailed comparison of various policies supported with respect to specific OS version, click [here](https://www.manageengine.com/mobile-device-management/mdm-android-feature-comparison.html). **Note:** For enhanced security, the admin can configure a kiosk profile to lockdown the device with specific apps and settings or blocklist unwanted apps in the [Inventory](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_kiosk.html). The admin can further ensure corporate security by ensuring only safe apps are installed by users on devices by configuring [application settings](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_android_restrictions.html) for Corporate Owned devices and [Workspace Security](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_workspace_security.html) for BYOD devices. ## Profile Creation To create a Restriction Profile, follow these steps: 1. On the Mobile Device Manager Plus console, navigate to Device Management → Profiles → + Create Profile → Choose Android. ![Create Android Profile](https://www.manageengine.com/mobile-device-management/help/images/ar_1.png) 2. Provide the Profile Name, choose the Profile type, provide a description, and continue. ![Create Android Profile description](https://www.manageengine.com/mobile-device-management/help/images/ar_2.png) 3. Select the Restrictions tab and configure the restrictions as required. Save and publish the restriction. Associate the restriction profile to the desired groups or devices. ![Create Android Profile creation](https://www.manageengine.com/mobile-device-management/help/images/ar_3.png) ## Profile Description > **Note:** > > 1. Since images are from Samsung devices, every OEM does not follow the same text or screens. Images or information texts shown may vary based on OEM. > 2. When a restriction is applied through MDM, the corresponding setting on the user's device is disabled (grayed out) and cannot be modified by the user until the restriction is removed. ### Device Functionality 1. **Camera:** By disabling this, users will not be allowed to use the Camera on their devices. On restricting this, the Camera will remain restricted within the Knox container also. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Legacy ![Camera](https://www.manageengine.com/mobile-device-management/help/images/ar_4.png) 2. **Access Camera from Lock Screen (Supported from Android 5.0):** By disabling this, users are restricted from accessing the Camera from the lock screen of the device. This can be configured only when Camera is allowed on the device. **Note:** For **KNOX-enabled Samsung and legacy devices**, this applies to devices running Android 5.0 or later versions. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Legacy ![Access Camera from Lock Screen](https://www.manageengine.com/mobile-device-management/help/images/ar_5.png) 3. **Access Camera in Personal Space (Supported from Android 5.0):** By disabling this, users are restricted from accessing the Camera from the lock screen of the device. This can be configured only when Camera is allowed on the device. **Note:** For **KNOX-enabled Samsung and legacy devices**, this applies to devices running Android 5.0 or later versions. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Legacy 4. **Video Recording (Supported from Android 5.0):** By disabling this, users will not be able to record videos on their devices. **Note:** Video Recording can be allowed only when Camera is allowed on the device. **Supported Management Type:** Fully Managed, Knox enabled Legacy devices ![Video Recording](https://www.manageengine.com/mobile-device-management/help/images/ar_7.png) 5. **Microphone:** By enabling this, users will be allowed to use the Microphone. If this is disabled, users can use the Microphone only for receiving and making calls. All other voice applications which require Microphone usage will be restricted. **On restricting this on the device, the Microphone will remain restricted within the Knox container also.** **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Knox enabled Legacy devices ![Microphone](https://www.manageengine.com/mobile-device-management/help/images/ar_9.png) 6. **Audio Recording (Supported from Android 5.0):** By disabling this, users will not be able to record audio on their devices. **Note:** 1. Audio recording can be enabled only when the Microphone is enabled on the device. 2. For **Fully Managed (COSU and COBO, or previously Device Owner) mode**, there is no separate restriction available; restrictions apply when the Microphone is restricted. **Supported Management Type:** Fully Managed, Knox enabled Legacy devices ![Audio Recording](https://www.manageengine.com/mobile-device-management/help/images/ar_10.png) 7. **Firmware Recovery (Samsung-only feature):** By disabling this, users cannot perform firmware recovery on the device. **Supported Management Type:** Knox enabled Fully Managed devices, Knox enabled Legacy devices ![Firmware Recovery](https://www.manageengine.com/mobile-device-management/help/images/ar_11.png) 8. **OS Upgrade (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be able to perform OS upgrades on their devices. **Supported Management Type:** Knox enabled Fully Managed devices, Knox enabled Legacy devices ![OS Upgrade](https://www.manageengine.com/mobile-device-management/help/images/ar_12.png) 9. **Screen Capture:** By disabling this, users will not be allowed to capture the screen on the devices. **Note:** Since Samsung API is used to apply the screen capture restriction, API behavior changes from Knox 3.8 and Samsung default apps such as Launcher, SystemUI, Settings, Reminder, Calendar, and Clock may not be disallowed from capturing even if the restriction is applied. **Supported Management Type:** Fully Managed, Work Profile on Company Owned Device, Knox enabled Legacy devices, Personally-Owned Work Profile (BYOD, or previously Profile Owner) devices. ![Screen Capture](https://www.manageengine.com/mobile-device-management/help/images/ar_13.png) 10. **Smart Clip Mode (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be allowed to access smart clip mode on their devices. **Supported Management Type:** Knox enabled Fully Managed devices, Knox enabled Legacy devices ![Smart Clip Mode](https://www.manageengine.com/mobile-device-management/help/images/ar_14.png) 11. **S-Voice (Samsung-only feature, supported from Android 5.0):** By disabling this, users will be unable to use the S-Voice feature on their devices. **Note:** S-Voice can be enabled only when the Microphone is enabled on the device. **Supported Management Type:** Knox enabled Fully Managed devices, Knox enabled Legacy devices 12. **Add Accounts (Supported from Android 5.0):** Enabling this will allow users to add email, Exchange, LDAP, and Google accounts on managed devices. Disabling this prevents users from adding any of these accounts. The account addition is prevented only after the restriction is applied to the devices and accounts already present are not affected. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices, and Knox enabled Legacy devices 13. **Enforce Storage Encryption (Supported from Android 5.0):** All data stored in the internal memory of the device must be encrypted. Ensure devices are charged up to 80% to begin the encryption process. This restriction is applied only if the device is secured through a passcode. If there is no passcode on the device, associate a [Passcode policy](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_android_passcode.html) first and then distribute the restrictions policy. **Note:** For **Personally-Owned Work Profile (BYOD, or previously Profile Owner) and Fully Managed (COSU and COBO, or previously Device Owner) modes**, encryption is enabled by default. **Supported Management Type:** Fully Managed, Personal Device, and Knox enabled Legacy devices 14. **Enforce SD Card Encryption (Samsung-only feature, supported from Android 5.0):** Encryption is forced on the SD Card. This restriction is applied only if the device is secured by a passcode. If there is no passcode on the device, associate a [Passcode policy](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_android_passcode.html) first and then distribute the restrictions policy. **Supported Management Type:** Knox enabled Fully Managed devices, Knox enabled Legacy devices ### Security 1. **Allow Adding or Removing Accounts on the Device:** This restriction applies only to device-wide accounts managed by the Android Account Manager. It does not prevent users from using app-specific accounts or web-based logins from the browser. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices, and Knox enabled Legacy devices ![Allow Adding or Removing Accounts on the Device](https://www.manageengine.com/mobile-device-management/help/images/ar_15.png) 2. **Restore Factory Settings:** By restricting this, admins can prevent users from resetting devices to their factory settings. Admins can also prevent users from removing devices from management by performing a hard reset by restricting this and also [configuring EFRP](https://www.manageengine.com/mobile-device-management/help/profile_management/android/android_enterprise_factory_reset_protection.html) on the devices. **Supported Management Type:** Fully Managed, Knox enabled Legacy devices ![Restore Factory Settings](https://www.manageengine.com/mobile-device-management/help/images/ar_16.png) 3. **Lock Screen Notification Preference:** Configure how notifications appear on the lock screen of the device. Either choose to show all content, hide sensitive content, or completely hide notifications. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. For **KNOX-enabled Samsung**, this applies to devices running Android 5.0 or later versions. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices, and Knox enabled Legacy devices ![Lock Screen Notification Preference](https://www.manageengine.com/mobile-device-management/help/images/ar_17.png) 4. **Installing Non-Market apps:** Allow or restrict installation of apps not listed on the Play Store. Restricting this disables the Install apps from unknown sources setting for app installation. **Note:** For Profile Owner mode, restrictions are applied by default. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices, and Knox enabled Legacy devices 5. **Allow Certificate Installation:** Allow or restrict certificate-based authentication for managed apps. When enabled, the certificate is automatically used for authentication, for example with VPNs, and the user will not be prompted to choose a certificate manually. **Note:** For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices 6. **Allow users to install or modify certificates:** Allow or restrict users from installing or modifying certificates. If disabled, any certificates already added by the user will also be removed. **Note:** For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices ![Allow users to install or modify certificates](https://www.manageengine.com/mobile-device-management/help/images/ar_18.png) 7. **Password Manager Apps:** This setting allows admins to control which password manager applications users are permitted to use on their devices. Select one of the following options to control access: - **Allow Any App:** Allows users to use any password manager apps installed on the device, without restrictions. - **Allow Only System App:** Allows only the device's built-in or system-default password manager. All third-party password manager apps are blocked. - **Allow Only Specific Apps:** Allows only the password manager apps explicitly selected by the admin. Any other password manager apps will be blocked. - **Block Specific Apps:** Blocks only the selected password manager apps while allowing all others. - **Block all Apps:** Blocks all password manager apps installed on the device. ![Password Manager Apps](https://www.manageengine.com/mobile-device-management/help/images/ar-password.png) 8. **Clipboard:** By enabling this, users will be allowed to use Clipboard memory. **Note:** For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Knox enabled Fully Managed, Knox enabled Legacy devices ![Clipboard](https://www.manageengine.com/mobile-device-management/help/images/ar_19.png) 9. **Clipboard Share (Supported from Android 5.0):** By enabling this, users can share Clipboard content between different applications. **Note:** 1. This can be enabled only when the Clipboard feature is enabled on the device. 2. For Profile Owner mode, there is no separate restriction; restrictions apply when Clipboard is restricted. **Supported Management Type:** Knox enabled Fully Managed, Personal, and Knox enabled Legacy devices ![Clipboard Share](https://www.manageengine.com/mobile-device-management/help/images/ar_20.png) 10. **Safe Mode:** Supported by Samsung, Personally-Owned Work Profile (BYOD, or previously Profile Owner), and Fully Managed (COSU and COBO, or previously Device Owner) devices from Android 6.0. By enabling this, users can boot the device in Safe Mode. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Safe Mode](https://www.manageengine.com/mobile-device-management/help/images/ar_21.png) 11. **Developer Mode:** By enabling this, users can use developer options on the device. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Developer Mode](https://www.manageengine.com/mobile-device-management/help/images/ar_22.png) 12. **Share via List (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be allowed to use the share list on their devices. **Supported Management Type:** Knox enabled Fully Managed, Personal, and Knox enabled Legacy devices ![Share via List](https://www.manageengine.com/mobile-device-management/help/images/ar_23.png) 13. **Google Play Protect:** Google Play Protect regularly checks apps and devices for harmful behavior. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Devices, and Legacy ![Google Play Protect](https://www.manageengine.com/mobile-device-management/help/images/ar_24.png) 14. **Auto fill:** By enabling this option, users will be allowed to use Auto-Fill Settings. **Supported Management Type:** Fully Managed, Personal Devices, and Knox enabled Legacy devices ![Auto fill](https://www.manageengine.com/mobile-device-management/help/images/ar_25.png) ### Sync and Storage 1. **Auto-Sync Google Accounts (Samsung-only feature, supported from Android 5.0):** By enabling this option, users will be allowed to sync their Google Accounts on their devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Auto-Sync Google Accounts](https://www.manageengine.com/mobile-device-management/help/images/ar_26.png) 2. **Report Crash to Google (Samsung-only feature, supported from Android 5.0):** By enabling this, crash reports will be sent to Google. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 3. **SD Card:** By enabling this, users will be allowed to use an SD Card on their devices. For non-Samsung devices, this restriction only blocks new SD card mounts; existing mounts are unaffected. For Samsung devices, this restriction applies to both newly inserted and already mounted SD cards. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices 4. **Store data on SD Card (Supported from Android 5.0):** By enabling this, users will be allowed to store data on SD Cards of the devices. **Note:** For Device Owner mode, there is no separate restriction; restrictions apply when the SD Card is restricted. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 5. **Move apps to SD Card (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be able to move applications installed in device memory to the SD card. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 6. **USB:** By enabling this, users will be allowed to use USB on their devices. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices 7. **Connections using USB:** By enabling this, users will be allowed to use USB to establish connections for debugging. **Note:** For Device Owner mode, there is no separate restriction; restrictions apply when USB is restricted. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 8. **Connect a USB storage device:** By enabling this, users will be allowed to connect USB Storage devices. **Note:** For Device Owner mode, there is no separate restriction; restrictions apply when USB is restricted. On Android 15 and above, when this restriction is applied, all USB host functionalities will be restricted on the device. For example, connecting USB peripherals such as keyboards, mice, and USB flash drives will be blocked. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ### Applications 1. **Users can install only approved apps:** This restriction lets the admin grant access to install all applications or restricts installation to apps distributed from the MDM app repository. If configured as Yes, the user can install only admin-approved apps. All apps previously installed by users are disabled, and subsequent installations of unapproved apps are automatically uninstalled. Once this restriction is removed, previously disabled apps are automatically enabled. If No is chosen, a sub-condition is shown where the admin can choose whether the user can access all apps under Managed Google Play or only admin-approved apps. **Note:** Restricting the option Users can install unapproved apps for an Android device also prevents the update and installation of Non-Market apps, even if MDM console profile settings allowed Non-Market apps. Pre-loaded non-system apps are also disabled due to this restriction. For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Users can install only approved apps](https://www.manageengine.com/mobile-device-management/help/images/ar_27.png) 2. **Allow access to all apps under Managed Google Play:** If Managed Google Play is configured in the server, the admin can still restrict access to either all apps under Managed Google Play or only admin-approved apps. 1. If access is given to all apps, admin-distributed apps will be listed under the Work Apps tab in Play Store. 2. Apps available under the Work Apps tab can be arranged according to organizational requirements by customizing the [Play Store](https://support.google.com/googleplay/answer/6185054). **Note:** For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow access to all apps under Managed Google Play](https://www.manageengine.com/mobile-device-management/help/images/ar_28.png) 3. **Allow accessing personal accounts in Play Store:** By enabling this, users can log in to personal accounts in Play Store and switch between accounts as required. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow accessing personal accounts in playstore](https://www.manageengine.com/mobile-device-management/help/images/ar_29.png) 4. **Allow installing non-market apps:** Non-market apps are apps that are not available on the Google Play Store. This setting applies to devices provisioned as Fully Managed, Work Profile-enabled corporate devices, or Profile Owner. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow installing non-market apps](https://www.manageengine.com/mobile-device-management/help/images/ar_30.png) 5. **Allow App Control:** If restricted, the user cannot uninstall apps, disable apps, clear app caches, clear app data, force stop apps, or clear app defaults. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow App Control](https://www.manageengine.com/mobile-device-management/help/images/ar_31.png) 6. **Allow clearing app data and force stopping apps:** If clear app data and force stop is restricted for an app, uninstallation is also restricted. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow clearing app data and force stopping apps](https://www.manageengine.com/mobile-device-management/help/images/ar_32.png) 7. **Allow Uninstalling Apps (Supported from Android 5.0):** By enabling this, users will be allowed to uninstall applications from the device. **Note:** - Despite this setting, apps silently installed on devices cannot be uninstalled by users. - In Fully Managed devices, enabling this setting prevents uninstalling user-installed apps. - For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. - If some apps can still be uninstalled after restricting it, or some apps cannot be uninstalled after allowing it, App Distribution settings configured during app distribution take precedence over this restriction. See the [FAQ](https://manageengine.com/products/mobile-device-management/help/android/faq.html). **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Allow Uninstalling Apps](https://www.manageengine.com/mobile-device-management/help/images/ar_33.png) 8. **Stop system apps (Samsung-only feature, supported from Android 5.0):** By enabling this, users can stop the system apps present on their devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Stop system apps](https://www.manageengine.com/mobile-device-management/help/images/ar_34.png) 9. **Restrict force stop and clear storage settings for the specified app(s):** Blocks users from force-stopping or clearing app storage. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices 10. **Application notification mode (Samsung-only feature, supported from Android 5.0):** By enabling this, the user can choose to allow or restrict app notifications. If restricted, app notifications are disabled. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 11. **Global App Permission policy:** Configuring this lets admins automatically deny or allow permissions for apps present on the device. If Auto-deny is chosen, some apps such as Camera are disabled and the user is not prompted to accept permission. In other apps such as Phone, a display message notifies the user of denied access. Optionally, permission can be left to the user. **Note:** For Work Profile on Company-Owned Devices, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Restrict force stop and clear storage](https://www.manageengine.com/mobile-device-management/help/images/ar_35.png) ### Browser Applicable only for Google Chrome in Legacy. 1. **Android browser:** By enabling this option, users will not be able to use any web browsers on the device. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Android browser](https://www.manageengine.com/mobile-device-management/help/images/ar_36.png) 2. **Fraud warning settings:** By enabling this, users will be allowed to use Fraud Warning Settings on the device. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Fraud warning settings](https://www.manageengine.com/mobile-device-management/help/images/ar_37.png) 3. **Pop-ups:** By enabling this, user pop-ups will be enabled on the device. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![pop-up](https://www.manageengine.com/mobile-device-management/help/images/ar_38.png) 4. **JavaScript:** By enabling this, users will be allowed to use applications running on JavaScript. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![JavaScript](https://www.manageengine.com/mobile-device-management/help/images/ar_39.png) 5. **Auto-fill:** By enabling this, users will be allowed to use Auto-fill settings on the device. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Auto-fill](https://www.manageengine.com/mobile-device-management/help/images/ar_40.png) 6. **Cookies:** By enabling this option, users will be allowed to use Cookies Settings on the device. **Note:** For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Cookies](https://www.manageengine.com/mobile-device-management/help/images/ar_41.png) ### Network and Roaming 1. **Airplane Mode:** Supported for Samsung and devices running Android 9.0 and above. If this is restricted, users will be unable to use airplane mode on their devices. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, Personal Device, and Knox enabled Legacy devices ![Airplane Mode](https://www.manageengine.com/mobile-device-management/help/images/ar_42.png) 2. **Background data (Samsung-only feature):** If Allow is chosen, users can disable background data while background data remains enabled by default. This profile does not get applied automatically and the user has to accept this profile. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Background data](https://www.manageengine.com/mobile-device-management/help/images/ar_43.png) 3. **Data Saver Mode (Samsung-only feature):** Enable this option to reduce data usage by preventing apps from sending or receiving data in the background. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Data saver mode](https://www.manageengine.com/mobile-device-management/help/images/ar_44.png) 4. **Wi-Fi:** If User Controlled is chosen, users can disable or enable Wi-Fi on the device. If Wi-Fi is Always On, users do not have permission to disable it. **Note:** - This is not supported for corporate Samsung devices running Android 10.0 or above enrolled via invites. - If Wi-Fi is Always Off, users do not have permission to enable it. - Managed devices will be out of network connectivity and even the MDM server cannot reach the device until cellular data is enabled. **Supported Management Type:** Fully Managed, Personal Whole Device, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Wi-Fi](https://www.manageengine.com/mobile-device-management/help/images/ar_45.png) 5. **Connecting to Wi-Fi, only if distributed via MDM (Supported from Android 5.0 and above):** Restrict or allow users to connect to Wi-Fi networks only if Wi-Fi configurations have been distributed as a profile via MDM. If no Wi-Fi profile has been configured via MDM, the device can connect to other Wi-Fi networks. If the Wi-Fi SSID changes, modify the profile to include the new SSID and redistribute it to the device. **Note:** Location access must be enabled on the device for this restriction to function as expected. This restriction works only when the Wi-Fi network distributed via MDM can reach the MDM server. If the MDM server is not reachable through that Wi-Fi network, the restriction will not work as expected and devices can lose MDM connectivity. **Supported Management Type:** Fully Managed, Personal Whole Device, Work Profile on a Company owned device, and Knox enabled Legacy devices 6. **Wi-Fi Direct (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be allowed to access Wi-Fi Direct on their devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Wi-Fi Direct](https://www.manageengine.com/mobile-device-management/help/images/ar_46.png) 7. **Allow users to connect to unsecure public Wi-Fi networks:** By restricting this, users will not be able to connect their devices to public or unsecured Wi-Fi network connections that are not protected with a password. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Legacy devices ![Public Wi-Fi](https://www.manageengine.com/mobile-device-management/help/images/ar_47.png) 8. **Allow users to configure VPN (Supported from Android 5.0):** Users are restricted from configuring VPN on devices, apart from VPN configurations distributed through the MDM server. If enabled on Samsung devices running OS 5.0 and above, any VPN configured by the user is deleted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Allow users to configure VPN](https://www.manageengine.com/mobile-device-management/help/images/ar_48.png) 9. **Roaming data (Samsung-only feature):** If allowed, users can choose to allow or disallow roaming data on the device. Otherwise, this setting is disabled and grayed out. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Roaming data](https://www.manageengine.com/mobile-device-management/help/images/ar_49.png) 10. **Sync data while Roaming (Samsung-only feature):** By enabling this, users will be allowed to use the Sync feature while roaming. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 11. **Roaming Push (Samsung-only feature):** By enabling this, data is pushed to devices even while they are roaming. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 12. **Voice Call while Roaming (Samsung-only feature, supported from Android 5.0):** By enabling this, users will be allowed to receive and make voice calls while roaming. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ### Device Connections 1. **NFC:** By enabling this, users can utilize Near Field Communication (NFC). **Note:** For Device Owner, the device displays a policy violation message, prompting the user to enable or disable the NFC setting as specified in the profile. **Supported Management Type:** Fully Managed and Legacy devices ![NFC](https://www.manageengine.com/mobile-device-management/help/images/ar_50.png) 2. **Android Beam (Supported from Android 5.0):** By enabling this, users can utilize Android Beam to transfer data to other supported devices. **Note:** For Profile Owner mode, restrictions are applied by default. For Work Profile on company-owned devices, restrictions are applied only to the Work Profile. **Supported Management Type:** Knox enabled Fully Managed, Personal Device, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Android Beam](https://www.manageengine.com/mobile-device-management/help/images/ar_51.png) 3. **S Beam (Samsung-only feature, supported up to Android 5.0):** By enabling this, users can utilize S Beam to share files with other supported devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 4. **Bluetooth:** By enabling this, users will be allowed to use Bluetooth on their devices. **Supported Management Type:** Fully Managed, Personal Whole Device, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Bluetooth](https://www.manageengine.com/mobile-device-management/help/images/ar_52.png) 5. **Bluetooth Discovery (Samsung-only feature):** By enabling this, users can allow other devices to detect and connect to their devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Bluetooth Discovery](https://www.manageengine.com/mobile-device-management/help/images/ar_53.png) 6. **Bluetooth Pairing (Samsung-only feature):** By enabling this, users will be allowed to pair their devices with other devices to enable data transfer. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Bluetooth Pairing](https://www.manageengine.com/mobile-device-management/help/images/ar_54.png) 7. **Make outgoing calls using Bluetooth (Samsung-only feature):** By enabling this, users will be allowed to place outgoing calls using Bluetooth. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 8. **Connect to Laptop/Desktop via Bluetooth (Samsung-only feature):** By enabling this, users can connect their devices to desktops or laptops using Bluetooth. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Connect to Laptop/Desktop via Bluetooth](https://www.manageengine.com/mobile-device-management/help/images/ar_55.png) 9. **Bluetooth Data transfer (Samsung-only feature):** By enabling this, users will be allowed to transfer data from their devices to other devices using Bluetooth. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Bluetooth Data transfer](https://www.manageengine.com/mobile-device-management/help/images/ar_56.png) 10. **Printing (Supported from Android 9.0):** By enabling this, users will be allowed to use Bluetooth printers through their devices. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Printing](https://www.manageengine.com/mobile-device-management/help/images/ar_57.png) ### Tethering 1. **Tethering:** Disabling this restricts managed devices from tethering with other devices for sharing the cellular network. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices 2. **Bluetooth Tethering:** By enabling this, users will be allowed to share an internet connection via Bluetooth with other devices. **Note:** 1. This can be enabled only when Bluetooth is enabled on a device. 2. For Device Owner, there are no separate restrictions. Tethering is restricted only when Tethering is specifically restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices 3. **Wi-Fi Tethering:** By enabling this, users will be allowed to share an internet connection via Wi-Fi with other devices. **Note:** 1. This can be enabled only when Wi-Fi and Wi-Fi Direct are enabled on the device. 2. For Device Owner, there are no separate restrictions. Tethering is restricted only when Tethering is specifically restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Wi-Fi Tethering](https://www.manageengine.com/mobile-device-management/help/images/ar_58.png) 4. **USB Tethering:** By enabling this, users will be allowed to share an internet connection via USB with other devices. **Note:** 1. This can be enabled only when USB is enabled on the device. 2. For Device Owner, there are no separate restrictions. Tethering is restricted only when Tethering is specifically restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![USB Tethering](https://www.manageengine.com/mobile-device-management/help/images/ar_59.png) ### Location Settings 1. **Location Services (Supported in legacy from OS 5.0):** When set as Always On, Location Services is forcefully enabled. Location Tracking can be highly accurate when Location Services are set to Always On only for devices running OS below 9. Even if users turn it Off, it automatically reverts to On. This is applicable for Always Off as well. When configured as User Controlled, device users can enable or disable it as needed. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Legacy devices ![Location Services](https://www.manageengine.com/mobile-device-management/help/images/ar_60.png) 2. **Mock Location (Samsung-only feature):** Allow or restrict users from falsifying location data. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Mock Location](https://www.manageengine.com/mobile-device-management/help/images/ar_61.png) 3. **Google Maps:** By enabling this, users can utilize Google Maps. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Google Maps](https://www.manageengine.com/mobile-device-management/help/images/ar_62.png) ### Phone 1. **SMS (Supported from Android 5.0 in Samsung devices):** By disabling this, users will not be able to use Short Messaging Service (SMS) on managed devices. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![SMS](https://www.manageengine.com/mobile-device-management/help/images/ar_63.png) 2. **Incoming SMS (Supported up to Android 5.0 in Samsung devices):** By disabling this, users will not be able to receive incoming messages on their devices. **Note:** For Device Owner, there are no separate restrictions. The device is restricted when SMS functionality is restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Incoming SMS](https://www.manageengine.com/mobile-device-management/help/images/ar_64.png) 3. **Outgoing SMS (Supported up to Android 5.0 in Samsung devices):** By disabling this, users will not be able to send outgoing messages from their devices. **Note:** For Device Owner, there are no separate restrictions. The device is restricted when SMS functionality is restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices ![Outgoing SMS](https://www.manageengine.com/mobile-device-management/help/images/ar_65.png) 4. **MMS (Supported from Android 5.0 in Samsung devices):** By disabling this, users will not be able to use Multimedia Messaging Service (MMS) on managed devices. **Note:** For Device Owner, there are no separate restrictions. The device is restricted when SMS functionality is restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices 5. **Incoming MMS (Supported up to Android 5.0 in Samsung devices):** By disabling this, users will not be able to receive incoming MMS on their devices. **Note:** For Device Owner, there are no separate restrictions. The device is restricted when SMS functionality is restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices 6. **Outgoing MMS (Supported up to Android 5.0 in Samsung devices):** By disabling this, users will not be able to send outgoing MMS from their devices. **Note:** For Device Owner, there are no separate restrictions. The device is restricted when SMS functionality is restricted. **Supported Management Type:** Fully Managed and Knox enabled Legacy devices 7. **Call:** If disabled, users cannot make or receive calls. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Call](https://www.manageengine.com/mobile-device-management/help/images/ar_66.png) 8. **Incoming Call (Samsung-only feature):** By disabling this, users will not be able to receive incoming calls on their devices. Even when allowed, incoming calls work only when the Microphone is enabled on the device. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![incomng Call](https://www.manageengine.com/mobile-device-management/help/images/ar_67.png) 9. **Outgoing Call:** By disabling this, users will not be able to place outgoing calls on their devices. Even when allowed, outgoing calls work only when the Microphone is enabled on the device. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Outgoing Call](https://www.manageengine.com/mobile-device-management/help/images/ar_68.png) ### Date/Time Settings 1. **Set device time (Supported from Android 9.0 and above):** You can set the device time either based on the network provider's time or manually. If incorrect time is displayed, try connecting to a different network and check the Wi-Fi router. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Set Device Time](https://www.manageengine.com/mobile-device-management/help/images/ar_69.png) 2. **Timezone (Supported from Android 9.0 and above):** If device time is set manually, choose the desired timezone from the dropdown. **Note:** When you set the timezone, device time is fetched based on the connected network. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Timezone](https://www.manageengine.com/mobile-device-management/help/images/ar_70.png) 3. **Modify date/time settings (Supported from Android 9.0 and above):** Restricting this prevents users from modifying date/time settings such as time format and date format. **Supported Management Type:** Fully Managed, Work Profile on a Company owned device, and Knox enabled Legacy devices ![Modify date/time settings](https://www.manageengine.com/mobile-device-management/help/images/ar_71.png) 4. **Modify date/time (Supported from Android 5.0 in Samsung devices):** Restricting this prevents users from modifying the date/time already set on the device. **Supported Management Type:** Knox enabled Fully Managed devices and Knox enabled Legacy devices ![Modify date/time](https://www.manageengine.com/mobile-device-management/help/images/ar_72.png) ### Display Settings Supported from Android 9.0. 1. **Screen Timeout:** The duration, between 5 and 1800 seconds, of inactivity after which the device goes to sleep. **Note:** Screen Timeout duration cannot be higher than Maximum idle time allowed before auto-lock configured in the Passcode profile. **Supported Management Type:** Fully Managed ![Screen Timeout](https://www.manageengine.com/mobile-device-management/help/images/ar_73.png) 2. **Modify Screen Timeout Settings:** Disabling this ensures the screen timeout configured above or on the device cannot be modified. **Supported Management Type:** Fully Managed ![Modify Screen Timeout Settings](https://www.manageengine.com/mobile-device-management/help/images/ar_74.png) 3. **Brightness:** Provide the level of brightness to be configured on the device. **Supported Management Type:** Fully Managed ![Brightness](https://www.manageengine.com/mobile-device-management/help/images/ar_75.png) 4. **Modify Brightness Settings:** Disabling this ensures the brightness configured above or on the device cannot be modified. **Supported Management Type:** Fully Managed ![Modify Brightness Settings](https://www.manageengine.com/mobile-device-management/help/images/ar_76.png) 5. **Ambient Display:** Enable or disable displaying details such as time and date on the device lock screen while it is asleep. **Supported Management Type:** Fully Managed ![Ambient Display](https://www.manageengine.com/mobile-device-management/help/images/ar_77.png) ### Miscellaneous 1. **Turn the device off, using Power button (Samsung-only feature, supported from Android 5.0):** By disabling this, users will not be able to turn off their devices using the Power Button. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Turn the device off, using Power button](https://www.manageengine.com/mobile-device-management/help/images/ar_78.png) 2. **Background process limit (Samsung-only feature, supported up to Android 5.0):** By enabling this, the background processes running on the device can be enabled or disabled by the user. If disabled, the background process limit is set to maximum. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Background process limit](https://www.manageengine.com/mobile-device-management/help/images/ar_79.png) 3. **Terminating app on exiting (Samsung-only feature, supported from Android 5.0):** This setting, Don't keep activities, is restricted on the device by default. If allowed, users can choose to enable or disable it. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Terminating app on exiting](https://www.manageengine.com/mobile-device-management/help/images/ar_80.png) 4. **Modify default device settings (Samsung-only feature):** Restricts access to the Settings app and Quick Settings panel modifications. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ![Modify default device settings](https://www.manageengine.com/mobile-device-management/help/images/ar_81.png) 5. **Air Command (Samsung-only feature, supported from Android 5.0):** Enabling this allows users to access S Pen-related features such as Notepad, virtual keyboard, Memo, and more. This applies only to Samsung Knox devices. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices 6. **Smart View (Samsung-only feature, supported from Android 5.0):** Enabling this allows users to view multimedia content present on the device on a Samsung smart TV. **Supported Management Type:** Knox enabled Fully Managed and Knox enabled Legacy devices ## Profile Description Table Additional details on each section can be found in the Profile Description table below. **A tick symbol** indicates that a feature is applicable, **a cross symbol** means it is not supported, and **the Knox symbol** denotes applicability only for Knox-enrolled devices. [Export Profile Description in Tab-Separated Values (.tsv) Format](https://workdrive.zohoexternal.com/external/48885d7fdbb2452e3235f258094bd996518709f548b35e9088b079931843d6d4/download?directDownload=true). **Note:** For this restriction to work, the certificate must be pushed by the administrator. - Restricting the option **Users can install unapproved apps** for an Android device also prevents the update and installation of **Non-Market apps**, even if profile settings in the MDM console allowed Non-Market apps. - Pre-loaded non-system apps are also disabled due to this restriction. - For **Work Profile on Company-Owned Devices**, restrictions apply only to the Work Container. ### Details | FEATURE | Fully Managed | WORK PROFILE ON PERSONALLY OWNED | FULLY MANAGED WITH WORK PROFILE | LEGACY | |---|:---:|:---:|:---:|:---:| | **DEVICE FUNCTIONALITY** | | | | | | Camera (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | | Access Camera from Lock Screen (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | | Access Camera in Personal Space (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | | Video Recording (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg)* | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Microphone | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Audio Recording (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg)* | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Firmware Recovery (Samsung-only feature) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | OS Upgrade (Samsung-only feature, supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Screen Capture | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Smart Clip Mode (Samsung-only feature, supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | S-Voice (Samsung-only feature, supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png)* | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png)* | | Add Accounts (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Enforce Storage Encryption (Supported from Android 5.0) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Enforce SD Card Encryption (Samsung-only feature, supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | **SECURITY** | | | | | | Restore Factory Settings | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Lock Screen Notification Preference | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Installing Non-Market apps | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Allow certificate based authentication for managed apps | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | | Allow users to install or modify certificates | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | | Clipboard (Supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Clipboard Share (Supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png)* | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg)* | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png)* | | Safe Mode | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Developer Mode | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Share via list (Samsung-only feature, supported from Android 5.0) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | | Google Play Protect | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | | Auto fill | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Tick Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/tick-icon-2.svg) | ![Cross Icon 2 - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/cross-icon-2.svg) | ![Samsung Knox Logo - ManageEngine MDM](https://www.manageengine.com/mobile-device-management/help/images/samsung-knox-logo.png) | ## Frequently Asked Questions ### How to prevent Gmail app from bypassing MDM content sharing restrictions? For BYOD devices enrolled as **Personally-Owned Work Profile (BYOD, or previously Profile Owner)**, sharing managed data between the Work Profile and unmanaged apps is restricted by default. To tighten this further, configure a [Workspace Security](https://www.manageengine.com/mobile-device-management/help/profile_management/android/mdm_workspace_security.html) profile and restrict sharing between work and personal space, disable clipboard sharing, and restrict app connectivity. On managed Android devices, you can also use **Restrict Specific Accounts** under **Profiles → Android → Restrictions** to block personal Google or Gmail accounts from being added to the device. ### Can the device time be set remotely using MDM? Yes, administrators can remotely configure the device time and timezone using a Restrictions profile in MDM. **Steps:** 1. Navigate to **Profiles → Restrictions → Date/Time Settings**. 2. Under **Set device time**, select **"Select timezone manually"** from the dropdown. 3. Choose the appropriate **Timezone** from the list, for example *UTC+02:00 — CAT*. 4. Set **Modify date/time** to **Restrict** to prevent end users from manually changing the time on the device. 5. Save and distribute the profile to the target devices or groups. Once the profile is applied, the device time automatically reflects the configured timezone. This is especially useful for managing devices deployed across different regions or ensuring consistent time settings for compliance purposes. ### Why does app uninstall behavior differ even after configuring the "Allow Uninstalling Apps" restriction? Some apps can be uninstalled even when uninstalling is restricted, while others cannot be uninstalled even when it is allowed. This is because app distribution settings always take priority over the restriction profile. - When set to **Allow**, users can uninstall apps from the device. - On **Fully Managed Devices**, enabling this prevents users from uninstalling apps they installed themselves. - On **Company-Owned Work Profile Devices**, this restriction applies only to apps inside the Work Profile. - If **Silent Installation** was chosen with **"Restrict users from uninstalling the app"** enabled, the app cannot be uninstalled regardless of the restriction profile. - If **Silent Installation** was chosen without restricting uninstall, users can uninstall the app even if the restriction profile says otherwise.