The following profile payloads are available for Android devices managed using Android Management API. The Workspace ONE UEM Console displays the supported management modes and minimum OS versions for each setting.
Network Slicing
You can manage network slicing settings on corporate-owned Android devices. Supported on Android 13 and higher. Consult with your carrier regarding which network slices are available to your devices.
Caution: Misconfiguring network slicing settings can lead to applications losing connectivity to the device’s mobile network.
You can select a Default Network Slice that will be used by all apps in the Work Profile. Managed apps will ignore this setting if you have assigned a specific network in their Application Policy. If you are only configuring network slicing for specific applications, set this to NONE.
You can also configure how applications should behave when they are configured to use a network slice in Workspace ONE UEM.
| Setting | Description |
|---|---|
| Fallback to device network | Set whether applications can fall back to the device’s default mobile network connection when the slice is unavailable. |
| Allow apps to choose another network slice | Set whether applications are allowed to use a different slice than the one configured in Workspace ONE UEM. |
For example, if you set the Default Network Slice to ENTERPRISE, configure the settings as such:
- In the Application Policy for a managed browser application, set the Network Slice to ENTERPRISE3
- For ENTERPRISE:
- Fallback to device network is Allowed
- Allow apps to choose another network slice is Allowed
- For ENTERPRISE3:
- Fallback to device network is Not Allowed
- Allow apps to choose another network slice is Not Allowed
Then:
-
For the managed browser application:
- Android will route network requests from the managed browser application through slice ENTERPRISE3.
- If ENTERPRISE3 is not available, the browser application will not fall back to the default mobile network connection (no network slice, or NONE). The browser will be unable to make network requests until the device is connected to Wi-Fi or ENTERPRISE3 becomes available.
- The browser application is not allowed to use other network slices. For example, if the application developer programs the browser application to use slice ENTERPRISE5 when connecting to certain sites, Android will prevent this.
-
For all other applications in the Work Profile (managed and unmanaged):
- Android will route network requests through ENTERPRISE
- If ENTERPRISE is not available, applications will fall back to the default mobile network connection (no network slice, or NONE). The application’s network requests will not be routed through a specific network slice.
- Applications will be allowed to make network requests through other network slices.
Display Settings
Use this profile to manage the screen timeout and brightness settings on corporate-owned Android devices. Supported on Android 15 and higher.
| Setting | Description |
|---|---|
| Set Screen Timeout | Enable to set a screen timeout value. |
| Screen Timeout in Seconds | The period of inactivity after which the device’s screen should turn off. This value is ignored if it is greater than Restrictions > Set Maximum Screen Timeout. |
| Set Screen Brightness | Enable to manage the screen brightness. Users will be unable to change the device’s screen brightness. |
| Screen Brightness Mode | When set to Automatic, the Preferred Screen Brightness will be taken into account as the screen brightness is adjusted automatically based on ambient light conditions. When set to Fixed, the screen brightness will not change from the Fixed Screen Brightness. |
| Preferred Screen Brightness | Set an average screen brightness for the device. |
| Fixed Screen Brightness | Set a fixed screen brightness for the device. Applicable when Screen Brightness Mode is set to Fixed. |
Advanced Security Overrides
The Advanced Security Overrides payload gives you control over sensitive features in Android. For example, you can use the Advanced Security Overrides payload to restrict users from enabling Developer Settings. Conversely, you can also allow users to disable Play Verify Apps.
| Setting | Description |
|---|---|
| Allow Unknown Apps | Set whether applications can be installed from sources other than Google Play. By default, installation of apps from unknown sources is not allowed in the Work Profile. |
| Allow Disabling Application Verification | Allow users to disable Google Play Verify Apps. |
| Allow Developer Settings | Allow users to enable Developer Settings |
| Allow Personal Apps to Read Work Notifications | Set whether non-system applications in the personal profile are able to read applications in the Work Profile. |
Always on VPN
Use this payload to enable Always-On VPN for a VPN application of your choice. Android will automatically start the VPN service for this application and keep it always running.
| Setting | Description |
|---|---|
| Always On VPN App | The VPN application for which Always-On VPN should be enabled. |
| Allow Connectivity without VPN | If this setting is disabled, the device will lose network connectivity if the VPN is not connected. By default, Intelligent Hub is exempt from this restriction to preserve the ability to mange the device. |
Application Credentials Access
Normally, Android applications cannot silently access user certificates, also known as private keys, that are stored in the Android Keystore. Applications usually must ask the user to choose which user certificate in the Android Keystore they should use. By choosing a user certificate from the list, the user is consenting to the application accessing the user certificate.
Use this payload to allow applications to silently access to user certificates in one of the following ways:
- If no URL pattern is specified, applications can silently get the user certificate using Keychain.getPrivateKey. This is only supported on Android 11 and higher. Note that applications that use this option must know the subject name of the certificate in advance. Workspace ONE UEM sets the subject name of the certificate as the alias, or friendly name, of the certificate when Workspace ONE UEM adds it to the Android Keystore. Normally, administrators pass the certificate alias to applications in advance by sending it as part of the app’s Application Configuration.
- If a URL pattern is provided, when the application calls Keychain.choosePrivateKeyAlias for a URL matching this URL pattern, the application is automatically granted access to the certificate. This is supported on all OS versions.
| Setting | Description |
|---|---|
| URL pattern | Set a URL pattern that will be compared with any Keychain.choosePrivateKeyAlias calls form the application. If not set, the application will be given access to directly retrieve the certificate from the Android Keystore. |
| Allowed Applications | Applications allowed to silently access the certificate. |
| Allowed Credential | The Credentials payload with the certificate that the specified applications should be allowed to silently access. Credentials payloads must be added to the same profile in order to be available in this field. |
Credentials
Certificates can be provisioned to Android devices to satisfy a number of use cases:
- Allow devices to connect to WPA2 Enterprise and WPA3 Enterprise networks.
- Allow applications to perform certificate-based authentication.
- Allow applications to trust 3rd-party and internal Certificate Authorities.
- Secure email communications using S/MIME.
Devices must have a device pin code configured before Workspace ONE UEM can install certificates with a private key.
Custom Message
Use this payload to customize error messages, lockscreen messages, and support information on managed Android devices.
| Setting | Description |
|---|---|
| Set a message for blocked settings | Customize the error message displayed when the user tries to perform an action that has been blocked by the administrator through device management policies. |
| Set a message for users to view in settings | Set the message users view under Settings > Security > Device Administrators for the Android Device Policy application. |
| Set a lockscreen message | Set the message users see displayed over the lockscreen. |
Passcode
Setting a passcode policy requires your end users to enter a passcode, providing a first layer of defense for sensitive data on devices.
The requirements in the Work Profile Passcode policy apply only to work apps, while the requirements in the Device Passcode policy only apply to unlocking the device. The outcome for devices with a Work Profile depends on which policies are enabled:
- Work Passcode Policy only: Users are asked to create a separate passcode just for their work apps that meets policy requirements. However, if the existing device passcode already meets the Work Passcode Policy’s complexity requirements and Allow One Lock is enabled in the Work Passcode Policy, users may not be prompted to set a separate passcode. Instead, their current device passcode is used to unlock personal and work apps.
- Device Passcode Policy only: The device passcode is required to meet policy requirements. If the current device passcode does not meet policy requirements, the user is asked to set a new passcode.
- Applies to Work Passcode Policy and Device Passcode Policy: The outcome is similar to setting a Work Passcode Policy only. However, users are also required to set a device-wide passcode that meets the Device Passcode Policy requirements.
| Setting | Description |
|---|---|
| Passcode Complexity | Ensure the passcode content meets your security requirements by selecting one of the following: Any, Numeric, Alphanumeric, Alphabetic, Complex, Complex numeric or Weak Biometric from the drop-down menu. This is the minimum complexity required for the Work Profile or device passcode. Note: Weak Biometric passcode content allows low-security biometric unlock methods, such as face recognition. |
| Minimum passcode length | Ensure passcodes are appropriately complex by setting a minimum number of characters. |
| Maximum Number of Failed | Attempts Specify the number of attempts allowed before the device is wiped. |
| Passcode History | Set the number of times a passcode must be changed before a previous passcode can be used again. |
| Maximum passcode age(days) | Specify the maximum number of days the passcode can be active. Entering this value as 0 makes the passcode age unlimited |
| Passcode Required Frequency | Set the amount of time after unlocking a device with a non-strong authentication method (such as fingerprint or face recognition) before a passcode is required. This option is also available in Device Passcode Policy. |
| Allow One Lock | Disable to force separate passcodes for the Work Profile and device lockscreen. |
Permissions
Set the default permission behavior for all applications on the device or Work Profile, depending on the device management mode. You can also set exceptions to the default permission behavior for specific permissions. For devices enrolled in Work Profile mode, this payload controls permissions for work apps only.
This payload only applies to runtime permissions, also known as Dangerous permissions. Examples include access to the device camera or location. By default, applications must ask users to grant them runtime permissions. Users can choose to grant or deny these permissions requests. By setting default behavior to Grant or Deny, the administrator avoids user interaction and determines the outcome of permission requests by apps.
Workspace ONE is not able to grant privileged permissions, such as Usage Access or Draw Over Apps, to managed applications. For more information on the types of permissions, please refer the (Android Developer website)[https://developer.android.com/guide/topics/permissions/overview].
For devices on Android 12 and higher that are enrolled in Work Profile mode, Workspace ONE UEM is unable to silently grant runtime permissions that involve sensors, such as the camera, as well as access to the device’s location.
| Setting | Description |
|---|---|
| Default Permission Policy | Set the behavior for any runtime permissions requested by any app. |
| Device Permission Exceptions | Set the behavior for specific runtime permissions requested by any app. |
Restrictions
Apply restrictions related to device functionality, networking, connectivity to other devices, applications, and more. When multiple Restrictions profiles are installed on the device, Workspace ONE UEM chooses the most restrictive value for each setting out of the set of installed profiles.
Tunnel
Use this profile payload to configure the Android Workspace ONE Tunnel application. To enable Always-On VPN for Tunnel, use an Always-On VPN profile payload. In this case, it is recommended to have both the Tunnel and Always-On VPN payloads in the same profile.
Wi-Fi
Configuring a Wi-Fi profile lets devices connect to corporate networks, even if they are hidden, encrypted, or protected.
The Wi-Fi profile can be useful for end users who travel to various office locations that have their own unique wireless networks or for automatically configuring devices to connect to the appropriate wireless network while in an office.
If a user already has previously connected the device to a Wi-Fi network manually, the Wi-Fi configuration cannot be changed by Workspace ONE UEM.
| Setting | Description |
|---|---|
| Service Set Identifier (SSID) | Provide the name of the network to connect. |
| Hidden Network | |
| Set as Active Network | |
| Security Type | |
| Password | The password the device uses to authenticate into the network. If Security Type is set to WEP, only 10-digit and 26-digit passwords are accepted. |
| Single Factor Authentication | Choose an authentication protocol. Available options are EAP-TLS, PEAP, EAP AKA, EAP SIM, or EAP-TTLS. |
| Use Two Factor Authentication | Use Two Factor Authentication- When turned on, the Second Factor Authentication field shows. Only available when Single Factory Authentication is set to PEAP. |
| Second Factor Authentication | Choose an inner authentication method. Available options are MSCHAPv2 and PAP. |
| Anonymous Identity | An anonymous identity that Android uses to establish the WiFi connection. |
| Identity | Identifies the user or device connecting to the network. |
| Identity Certificate | The Credentials payload with the user certificate that the device will use to authenticate into the network. Credentials payloads must be added to the same profile in order to be available in this field. |
| Root Certificate | Choose up to two root certificates for the device to validate the network server’s certificate. Root certificate(s) must be added to the Profile as part of the Credentials payload. At least one of the root certificates should be the certificate authority that issued your current network server’s SSL certificate. If you are migrating your network server’s SSL certificate from one certificate authority to another, add both the current and new certificate authorities as root certificates to maintain trust throughout this process. Note: Leaving the root certificate field blank results in an insecure configuration and is not allowed in newer Android versions. For information on setting multiple root certificates, see this Knowledge Base article on incorrectly installed certificates. |
| Domain | The domain name that the device will use to verify if the network server is trusted. The device will only connect to the network if the Domain matches the network server’s certificate has a dnsName in its SubjectAltName element. Specifically, Android will attempt a suffix match between these values. For example, if Domain is set to “omnissa.com” and the network server certificate’s SubjectAltName contains a dnsName element “test.omnissa.com”, the match will succeed. In the same example, if the dnsName element is “omnissa.test.com”, the match will fail. |
| MAC Address Randomization | Set whether the device will provide a randomized or hardware MAC address when connecting to the network. Android 13 or later. |
| Proxy Type | Turn on to configure the Wi-Fi proxy settings. Note: Wi-Fi Proxy Auto Configuration is not supported using Per-App VPN. |
| Proxy Server | Enter the hostname or IP address for the proxy server. |
| Proxy Server Port | Enter the port for the proxy server. |
| Exclusion List | Enter the hostnames to exclude from the proxy. Hostnames entered here will not be routed through the proxy. Use the * as a wild card for the domain. For example: *.air-watch.com or *air-watch.com. |
| PAC URL | The endpoint from which the device will retrieve the proxy pac configuration file. |
System Updates
Use this profile to manage Android device updates on corporate-owned Android devices enrolled into Workspace ONE UEM.
| Setting | Description |
|---|---|
| Automatic Updates | Install Updates Automatically: Automatically install updates when they become available. Defer Update Notifications: Defer all updates. Send a policy that blocks OS updates for a maximum period of 30 days.Set Update Window: Set a daily time window in which to update the device. |
| Annual System Update Freeze Periods | Device owners can postpone OTA system updates to devices for up to 90 days to freeze the OS version running on these devices over critical periods (such as holidays). The system enforces a mandatory 60-day buffer after any defined freeze period to prevent freezing the device indefinitely. |
| Freeze Period | Use this field to set freeze periods, in month and day, when updates cannot be installed. When the time of the device is within any of the freeze periods, all incoming system updates, including security patches, are blocked and cannot be installed. Each individual freeze period is allowed to be at most 90 days long and adjacent freeze periods need to be at least 60 days a part. |
Considerations for Annual System Update Freeze Periods
Consider how the system applies updates during a freeze period with the following guidelines:
- Devices do not receive any notifications about pending OTA updates.
- Devices do not install any OTA updates to the OS.
- Device users are not able to manually check for OTA updates.
Enterprise Factory Reset Protection
Factory reset protection (FRP) is an Android security feature that prevents access to the device after an unauthorized factory reset. By pushing an Enterprise Factory Reset Protection profile, you can specify what Google accounts can be used to regain access to the device. FRP is triggered when the device is wiped or factory reset unless the device is wiped by the administrator through Workspace ONE UEM.
For example, if the user resets the device from the Android Settings application, they will have to use one of the allowlisted Google accounts to regain access to the device.
| Setting | Description |
|---|---|
| Trusted Google Accounts | Provide a list of Google accounts that can be used to regain access to the device after it is factory reset. |
Personal Usage Restrictions (COPE)
These restrictions apply to the personal side of devices enrolled in Corporate Owned Personally Enabled (COPE) mode.
| Setting | Description |
|---|---|
| Allow screen capture | Allow users to take screenshots of personal applications. |
| Allow Camera Access | Allow users to use the camera from applications in the personal profile. |
| Disallow Account Management by Type | Specify a comma separated list of which kinds of accounts the user is disallowed from managing. Users will be prevented from adding, editing, or removing accounts of these types. Examples of account types: "com.google, com.twitter.android.auth.login” |
| Maximum Days to Allow Disabled Work Profile | Set how many days the Work Profile can remain disabled on a corporate-owned device. The minimum period is 3 days. |
| Restrict Applications in Personal Profile | Restrict what applications users can install in the personal profile of devices managed in Corporate Owned Personally Enabled mode. |
Was this page helpful?