EN
Español
English
Português
    Policy Configuration

    Device Policy Settings

    1. In the information view of the AEMM Starter Console, you will be able to view the devices found for the defined criteria. Select a device and in the detail view you will be able to view the device’s resume


    2. Select the option View Details to edit or approve the policies associated with the device’s resume.


    3. In the Actions, select the Edit and on the Configuration of the device resume, define a policy (restrictions, password, wifi, web clips, mail, EAS accounts, apps, kiosk) for either Android, Android For Work, or Android Management Api (depending on the configuration).

    Restrictions

    Restrictions on Android

    These are the parameters that are restricted to Android mobile devices, after applying a policy.


    Name Description
    Allow Play Store usage The device may or may not use the Play Store. If you do not allow its use, the necessary applications that are configured will not be installed. (Only applies to Android Knox)
    Allow use of the camera If this option is not selected, the device cannot use the camera or through applications that require it (Only applies to Android version higher than 4.0 or Knox)
    Enable Javascript in Android browser If this policy is enabled, the Android browser does not enable JavaScript. (Only applies to Android Knox).
    Allow pop-ups in the Android browser If this policy is enabled, the device’s browser does not allow pop-up. (Only applies to Android Knox).
    Allow cookies in your Android browser This parameter is activated and the mobile does not enable cookies for the browser. (Only applies to Android Knox).
    Allow backup to cloud services If this parameter is active, the device is active. (Only applies to Android Knox).
    Enable WiFi on an Android device This restriction, if applied to the Android device, does not allow it to connect to the Wi-Fi. (Only applies to Android Knox)
    Encrypt Android device This option is disabled by default; if you apply this option to the device, all data is merged with a password or key. (Only applies to Android Knox)
    Allow voice dialing If this setting is active, voice dialing is not possible through the device. (Only applies to Android Knox)
    Allow voice roaming Allow the device to use voice roaming. (Only applies to Android Knox and LG)
    Allow data roaming If this policy is enabled, the device does not allow the data rooming service. (Only applies to Android Knox).
    Allow USB tethering If this policy is applied, the device does not allow sharing the connection with any other computer (only applies to Android Knox).
    Allow USB Debugging If this option is not selected, it is not possible to perform USB debugging with the mobile device (Only applies to Android Knox).
    Allow USB Media Player (Kies) If this option is not selected, your Android device does not allow syncing with Samsung Kies (only applies to Android Knox).
    Allow SMS If this policy applies, it is not possible to send or receive SMS to your mobile. (Only applies to Android Knox).
    Allow Bluetooth If this setting is active, it does not allow Bluetooth connection on the mobile device. (Only applies to Android Knox)
    Allow GPS manipulation If this parameter is active, you do not have access to the GPS (Only applies to Android Knox).
    Allow video recording Allows the device to turn video recording on or off (Applies to Samsung Knox agent only).
    Allow to enable the microphone Allows you to activate or deactivate the device’s microphone (Only applies to Samsung Knox and LG agents).
    Allow audio recording Allows the device to turn audio recording on or off (Applies to Samsung Knox agent only).
    Allow firmware update Enable or disable firmware update on the device (Only applies to Samsung Knox agent).
    Allow OS Update If this option is inactive, it will not be allowed to download or install operating system updates, both manually and automatically (Only applies to links with Samsung Knox and LG agents).
    Allow Screenshot Allows you to enable or disable screen capture on the device (Only applies to Samsung Knox and LG agents).
    Allow Smart Clip Mode Turn the Smart Clip app on or off. If set to false, the user will not be able to use the smart pen (Applies to Samsung Knox agent only).
    Allow SVoice Enable or disable the launch of the S Voice application (Only applies to Samsung Knox agent).
    Allow account addition Allows you to add accounts on the device (Only applies to Samsung Knox agent).
    Enable Secure Digital (SD) card encryption Allows you to activate or deactivate the encryption of the external card (Only applies to links with Samsung Knox and LG agent).
    Allow factory reset Enable or disable factory reset from the settings option (Only applies to links with Samsung Knox and LG agents).
    Allow installation of apps from unknown sources Enable or disable the installation of applications from unknown sources (Only applies to links with Samsung Knox and LG agents).
    Allow clipboard access Allow or disable clipboard access (Only applies to links with Samsung Knox and LG agents).
    Allow clipboard between applications Allow or not share the clipboard between applications (Only applies to links with Samsung Knox agent).
    Allow Safe Mode Boot Allows the activation or deactivation of the boot in safe mode (Only applies to links with Samsung Knox and LG agent)
    Allow Developer Mode Enable or disable developer mode on the device (Only applies to links with Samsung Knox and LG agents).
    Allows you to view the list of applications to share functionalities Enable or disable the display of the list of applications for the sharing functionality (Only applies to links with Samsung Knox agent).
    Allow Google Backup Turn Google backup on or off (Only applies to links with Samsung Knox and LG agents).
    Allow Google Account auto-sync Turn Google Account sync on or off (Only applies to Samsung Knox agent pairings).
    Allow bug reports to be sent to Google Allow or disable the sending of a bug report to Google (Only applies to links with Samsung Knox and LG agents).
    Allow SD card access Allow or disable access to the Secure Digital (SD) card (Only applies for pairings with Samsung Knox agent) .
    Allow writing to SD card Allows or disables writing to the Secure Digital (SD) card (Only applies to pairings with Samsung Knox agent).
    Allow the option to move files on the SD card Allows you to enable or disable SD card movement options (Only applies to pairings with samsung knox agent)
    Allow an app to install It allows you to determine if an application can be installed on the device (Only applies to links with Samsung Knox and LG agents).
    Allow an app to be uninstalled Allows whether or not you can uninstall the app on the device (Only applies to links with Samsung Knox and LG agents).
    Allow stopped signed system applications Allows you to activate or deactivate signed system applications (Only applies to links with Samsung Knox agent).
    Allow removal of a list of package names from the notification blacklist Allows you to remove a list of packages from the notification blacklist in the status bar. Once the list is deleted, an app with a matching package name can display notifications from the status bar (Only applies to links with Samsung Knox agent).
    Allow the YouTube app to be enabled It allows you to activate or deactivate the YouTube application (Only applies to links with a Samsung Knox agent).
    Enable the native Android browser app Allow to enable or disable the application of the native Android browser (Only applies to links with Samsung Knox and LG agents).
    Enable airplane mode on your device Turn airplane mode on or off on the device (Only applies for pairings with Samsung Knox agent).
    Enable virtual private network (VPN) functionality Enable or disable virtual private network (VPN) functionality (Only applies to links with Samsung Knox agent).
    Allow NFC status to be changed Enable or disable NFC status (Only applies to pairings with Samsung Knox and LG agents).
    Allow device data Turn mobile device data on or off (Only applies to pairings with Samsung Knox and LG agents).


    Restrictions in Android For Work Android for Work

    These are the parameters that are restricted to Android mobile devices linked to Android for Work, after a policy is applied.


    Name Description
    Allow use of the camera If this option is not selected, the device cannot use the camera or through applications that require it (Only applies to Android version higher than 4.0 or Knox)
    Allow web links from the profile Allow apps in the primary profile to manage web links in the managed profile.
    Allow new users and profiles to be added Allow the creation of new users and profiles on the device.
    Allow to adjust the volume Allow the user to adjust the volume of the device
    Allow Modifying Applications Allow the user to modify apps in settings or launchers. (The following actions are not allowed when this restriction is enabled: uninstall apps, disable apps, delete app cache, clear app data, force close apps, remove default app settings.)
    Allow Bluetooth settings Allow the user to modify Bluetooth settings. If this option is restricted, this does not prevent the user from turning Bluetooth on or off.
    Allow you to configure cellular transmission Allow the user to set up cellular transmissions
    Allow User Credential Settings Specifies whether a user has permission to configure mobile networks. The default value is true.
    Allow mobile network setup Specifies whether a user has permission to configure mobile networks. The default value is true.
    Allows you to configure shared connection and access points It allows you to configure tethering and portable access points. The access point mainly offers the possibility of connecting via Wi-Fi, tethering or network connection, and allows us to use other protocols, such as Bluetooth and even USB cable
    Allow virtual private network (VPN) configuration Allows you to configure virtual private network (VPN) functionality
    Allow Wi-Fi access points to be switched Allow the user to change Wi-Fi access points
    Allow you to create windows It allows the creation of the following types of windows: pop-up notifications, dialogs, alerts, errors, overlays, and priority windows.
    Allow copying and pasting into related profiles Allow the user to paste into related profiles what is copied to this profile’s clipboard.
    Allow mobile data usage while roaming Allow the use of mobile data while roaming.
    Enable debugging features Allow the user to enable or access debugging features.
    Allow you to restore factory settings Allow the user to restore factory settings.
    Allows you to have fun with your device Specifies whether the user can’t have fun. In some cases, the device owner can prevent the user from playing video games while using the device. This user restriction only affects the device owner.
    Allow app installation Allow the user to install applications.
    Allow installation of apps from unknown sources Allow the user to install applications from “Unknown Sources”.
    Allow account addition and deletion Allow the user to add or remove accounts
    Allows external hardware to be mounted Allow the user to mount external hardware
    Allow network settings to be adjusted Specifies whether a user has permission to reset network settings from Settings.
    Allow NFC for apps Allow the use of NFC for application data transmission.
    Allow calls (emergency calls are allowed) Allow the user to make outbound calls. (Emergency calls are allowed.)
    Allow you to delete other users Allow the primary user to delete secondary users.
    Allow the device to reboot in Secure Boot mode Allow the user to restart the device in Safe Mode.
    Allow to change the user icon Allows the user to change their icon. The device owner and profile owner can set this restriction. If set by the device owner, only the user in question will be affected.
    Enable location sharing Allow the user to turn on location sharing.
    Allow messages to be sent and received It allows you to send and receive SMS on your mobile device.
    Allow app uninstallation Allow the user to uninstall apps on the device.
    Allows you to adjust the microphone volume Allow the user to adjust the microphone volume.
    Allows file transfer via USB Allow the user to transfer files via USB.
    Runtime Permissions Policy Allow the user to manage the permissions requested by each application. Remember that the permission settings set in the applications tab prevail.
    Allow GPS to be turned off Allow the user to turn the device’s GPS on or off.
    Allow the use of the Play Store The device may or may not use the Play Store. If you do not allow its use, the necessary applications that are configured will not be installed (only applies to Device Owner and Samsung agent).
    Enable JavaScript in your Android browser Allow JavaScript to run in the Android browser (only applies to Device Owner and Samsung agent).
    Allow pop-ups in Android browser Enable pop-ups in the Android browser (only applies to Device Owner and Samsung agent).
    Allow cookies in your Android browser Enable the use of cookies in the Android browser (only applies to Device Owner and Samsung agent).
    Allow backups to cloud services It allows the user to make backups in the cloud of the data stored on the device, such as images, files, videos, among others (only applies to Device Owner and Samsung agent).
    Enable WiFi Allows you to activate or deactivate the WiFi connection on the device (the device must have access to data to avoid being isolated) (only applies to Device Owner and Samsung agent).
    Encrypt Android Device It allows you to encrypt or decrypt the storage device’s system (only applies to Device Owner and Samsung agent).
    Allow voice dialing Allows voice dialing through the KNOX device. On LG devices, when selecting the “No” option, only emergency calls are supported (only applies to Device Owner and Samsung agent).
    Allow voice roaming Allow the device to use the voice roaming service (only applies to Device Owner and Samsung agent).
    Allow USB Media Player (Kies) Allow the device to sync with Samsung Kies (only applies to Device Owner and Samsung agent).
    Disable the Android Settings app If this restriction is applied, it will not be possible to access the native settings app (only applies to Device Owner and Samsung agent).
    Set the AEMM agent as the primary launcher for applications. If this restriction is applied, the AEMM agent is set as the primary application launcher (only applies to Device Owner, profile owner, and Samsung agent).
    Allow OS Update Enable or disable the operating system update (only applies to Device Owner and Samsung agent).
    Enable Backup Service to Be Activated Allows the device or profile owner to turn the backup service on or off. Disabling the backup service will prevent data from being backed up or restored. By default, the backup service is disabled. PO, DO, API 26.
    Allow you to add accounts in the Google Play Store Allows the user to add additional accounts in the Google Play store. PO, DO, For Google Play app versions greater than 80970100.


    Constraints in Android Management Api Android Management API

    These are the parameters that are restricted to Android mobile devices linked to Android for Work, after a policy is applied.


    Name Description
    Allow use of the camera Controls camera usage and whether the user has access to the Camera Access Activation button. The Camera Access Activation button is available on Android 12 and later.
    Allow data sharing with apps from the other profile This setting determines whether data from one profile (personal or professional) can be shared with the apps in the other profile. It specifically controls the exchange of simple data using intents. This includes actions such as opening a web browser, opening a map, sharing content, opening a document, and so on.
    Allow new users and profiles to be added Allow the creation of new users and profiles on the device.
    Allow to adjust the volume Indicates whether the main volume setting is turned on. Also mutes the device.
    Allow Bluetooth settings Allow the user to make changes to Bluetooth settings. If this option is restricted, this does not prevent the user from turning Bluetooth on or off.
    Allow you to configure cellular transmission Allow the user to set up cellular transmissions
    Allow User Credential Settings Specifies whether a user has permission to configure mobile networks. The default value is true.
    Allow mobile network setup Specifies whether a user has permission to configure mobile networks. The default value is true.
    Allows you to configure shared connection and access points It allows you to configure tethering and portable access points. The access point mainly offers the possibility of connecting via Wi-Fi, tethering or network connection, and allows us to use other protocols, such as Bluetooth and even USB cable
    Allow virtual private network (VPN) configuration Allows you to configure virtual private network (VPN) functionality
    Allow Wi-Fi access points to be switched Allow the user to change Wi-Fi access points
    Allow you to create windows It allows the creation of the following types of windows: pop-up notifications, dialogs, alerts, errors, overlays, and priority windows.
    Allow copying and pasting into related profiles Allow the user to paste into related profiles what is copied to this profile’s clipboard.
    Allow mobile data usage while roaming Allow the use of mobile data while roaming.
    Enable developer features and secure boot Controls access to developer settings: developer options and Secure Boot. On devices with a work profile, configuring this policy will not disable Secure Boot.
    Allow you to restore factory settings Allow the user to restore factory settings.
    Allows you to have fun with your device Specifies whether the user can’t have fun. In some cases, the device owner can prevent the user from playing video games while using the device. This user restriction only affects the device owner.
    Allow app installation Allow the user to install applications.
    Allow installation of apps from unknown sources Allow the user to install applications from “Unknown Sources”.
    Allow account addition and deletion Allow the user to add or remove accounts
    Allows external hardware to be mounted Allow the user to mount external hardware
    Allow network configuration reset Specifies whether a user can reset network settings from Settings.
    Allow NFC for apps Allow the use of NFC for application data transmission.
    Allow calls (emergency calls are allowed) Allow the user to make outbound calls. (Emergency calls are allowed.)
    Allow you to delete other users Allow the primary user to delete secondary users.
    Allow to change the user icon Allows the user to change their icon. The device owner and profile owner can set this restriction. If set by the device owner, only the user in question will be affected.
    Enable location sharing Allow the user to turn on location sharing.
    Allow messages to be sent and received It allows you to send and receive SMS on your mobile device.
    Allow app uninstallation Allow the user to uninstall apps on the device.
    Allow the use of the microphone and whether the user has access to the microphone access activation button. Controls microphone usage and whether the user has access to the microphone on/off button. This button is available on Android 12 and later.
    Allows file transfer via USB Allow the user to transfer files via USB.
    Runtime Permissions Policy Allow the user to manage the permissions requested by each application. Remember that the permission settings set in the applications tab prevail.
    Allow GPS to be turned off Allow the user to turn the device’s GPS on or off.


    Restrictions on iOS

    These are the parameters that are restricted to iOS mobile devices, after a policy is applied.


    Details

    Name Description
    Allow App Store (includes installing and updating apps through the App Store) If this setting is applied, your iOS device won’t have access to the App Store.
    Allow Siri while your device is locked This policy does not enable SIRI speech recognition if the device is locked (only applies to iOS devices version higher than 5.1).
    Enable automatic diagnostic reports This active parameter disables the option to send automatic diagnostic reports (Only applies to iOS devices version higher than 6.0)
    Allow Game Center If this option is not selected, the device does not have access to Game Center. (Only applies to iOS devices version higher than 6.0).
    Allow use of the iTunes Store This policy does not allow access to the online store for digital content through the iTunes Store.
    Allow Safari This active parameter does not allow access to the Safari browser.
    Allow backup to cloud services If this setting is applied, the device is not allowed to back up to the Apple Services cloud (Only applies to iOS devices version higher than 5.0)
    Allow Photo Stream This parameter does not allow photo synchronization through PhotoStream (Only applies to iOS devices version higher than 5.0)
    Allow Shared Photo Stream If this policy is applied, the device can’t share the photos that are synced to them. Shared Photo Stream is disabled (Only applies to iOS devices version higher than 6.0)
    Allow cookies in Safari This policy can set Safari Cookies to never, always, or only from visited sites.
    Allow Siri This policy does not enable speech recognition through SIRI.
    Allow use of the camera If this option is not selected, the device cannot use the camera or through applications that require it.
    Allow explicit content This parameter does not allow access to explicit content.
    Allow screenshots When this policy is applied to the device, it is not possible to take screenshots on the mobile device.
    Force iTunes password entry for each transaction If this parameter is active, whenever any transaction is made with iTunes it will ask for the access key (Only applies to iOS devices version higher than 5.0)
    Warn the user about untrusted HTTPS certificates instead of automatically rejecting them If this policy applies to mobile, the user is always warned when the HTTPS certificate is untrusted (Only applies to iOS devices version higher than 5.0)
    Allow document syncing in iCloud This policy does not allow storage in Apple cloud computing (only applies to iOS devices version higher than 5.0).
    Allow BookStore If this policy applies, your device doesn’t have access to the Apple BookStore. (Only applies to iOS devices version higher than 6.0).
    Allow Javascript in Safari This parameter does not allow the use of Javascript in safari.
    Enable predictive keyboards If this option is not selected, the device will not use the predictive keypads option.
    Enable AirDrop If this option is not selected, your device will not use the AirDrop option.
    Allow USB Restricted Mode Allows the device to connect USB accessories while it is locked, in case of inactivity restricts the connection.
    Allow password autofill Allows you to enable/disable the password autofill feature. This restriction also disables automatic strong passwords and strong passwords are no longer suggested to users.
    Allow fingerprint and/or face ID to unlock It allows you to activate/deactivate the device through fingerprint or face ID. If the restriction is inactive, the device cannot be unlocked through the aforementioned mechanisms.
    Allow fingerprint and/or face ID modification It allows the user to modify both the fingerprints and the configured face ID.
    Allow Find My Device Allows you to enable/disable the option to search for the device.


    Password (Device is the Android For Work section) Android for Work

    Android

    These are the parameters that are applied to an Android device to configure on the mobile.


    Name Description
    Password Quality There are 5 types of password settings, these are:
    - Indefinite: It is necessary to enter a password with a minimum of 4 characters.
    - Alphabetical: The password must contain at least 4 alphabetic characters.
    - Alphanumeric: The password must contain at least 4 alphanumeric characters.
    - Complex: The password must contain at least 4 characters of which at least one is a letter, a lowercase letter, a capital letter, a special character and a number.
    - Any: The password can be a pattern, a pin, or a password.
    Minimum Code Length It is the minimum number of characters that the password must have, ranging from 4 to 16.
    Minimum number of letters It is the minimum number of letters that the password must have, ranging from 1 to 16.
    Minimum number of lowercase letters It is the minimum number of lowercase letters that the password must have, ranging from 1 to 16.
    Minimum number of uppercase letters It is the minimum number of capital letters that the password must have, ranging from 1 to 16.
    Minimum number of characters other than letters It is the minimum number of special characters that the password must have, ranging from 1 to 16.
    Minimum number of numbers It is the minimum number of numbers that the password must have, ranging from 1 to 16.
    Minimum number of symbols It is the minimum number of symbols that the password must have, ranging from 1 to 16.


    ios

    These are the parameters that are applied to an iOS device to configure on the mobile


    Name Description
    Allow Simple Value Allows the use of repeating, ascending, and descending character sequences
    Require alphanumeric value Require codes to contain at least one letter.
    Minimum Code Length This is the minimum number of characters that the password must contain, ranging from 1 to 16.
    Minimum number of complex characters It is the minimum number of complex characters that the password must contain, ranging from 1 to 4.
    Maximum code validity period Number of days (1-730) after which the password must be changed.
    Maximum Auto Lock: The device locks after the set time is between 1 to 15 minutes
    Password History Number of unique passwords (1-50) before they can be repeated.
    Maximum grace period for device lock The maximum amount of time the device can remain locked without prompting for the unlock code. The options are: Immediately, 1 minute, 5 minutes, 15 minutes, 1 hour or 4 hours.
    Maximum number of failed attempts Maximum number of attempts allowed to enter the password before all data is erased from the device or locked until it connects to the designated iTunes. It is between 2 and 11.


    Profile

    These are the parameters that are applied to an Android device to configure in the managed profile created in linking Profile Owner (PO).


    Name Description
    Password Quality There are 5 types of password settings, these are:
    - Indefinite: It is necessary to enter a password with a minimum of 4 characters.
    - Alphabetical: The password must contain at least 4 alphabetic characters.
    - Alphanumeric: The password must contain at least 4 alphanumeric characters.
    - Complex: The password must contain at least 4 characters of which at least one is a letter, a lowercase letter, a capital letter, a special character and a number.
    - Any: The password can be a pattern, a pin, or a password.
    Minimum Code Length It is the minimum number of characters that the password must have, ranging from 4 to 16.
    Minimum number of letters It is the minimum number of letters that the password must have, ranging from 1 to 16.
    Minimum number of lowercase letters It is the minimum number of lowercase letters that the password must have, ranging from 1 to 16.
    Minimum number of uppercase letters It is the minimum number of capital letters that the password must have, ranging from 1 to 16.
    Minimum number of characters other than letters It is the minimum number of special characters that the password must have, ranging from 1 to 16.
    Minimum number of numbers It is the minimum number of numbers that the password must have, ranging from 1 to 16.
    Minimum number of symbols It is the minimum number of symbols that the password must have, ranging from 1 to 16.


    Wifi

    The administrator from the policy can configure the WIFI network on mobile devices.

    Android

    The administrator can perform up to three (3) Wi-Fi network configurations on Android devices, under the Add as shown below in the image.

    Name Description
    Service Set Identifier (SSID) This is the name of the wireless network you will connect to
    Security Type Encryption of the wireless network that will be used for the connection. There is WEP, WPA/WPA2, WPA2 Enterprise.
    In the case of WPA2 Enterprise security type, an additional user name must be provided that will be used to authenticate to the radius server associated with the wireless network. The password in this case will be the one associated with the user entered.
    Password This is the password for authentication on the wireless network.


    ios

    Name Description
    Service Set Identifier (SSID) This is the name of the wireless network you will connect to
    Automatic connection: You select whether you want to automatically connect to the target network.
    Hidden network You select whether the destination network is open or not.
    Security Type Encryption of the wireless network that will be used for the connection. There is WEP or WPA/WPA2.
    Password The password for authentication on the wireless network.
    Proxy It is selected whether the setting for the proxy wireless network is none, automatic or manual.
    According to the selection made, different additional fields will be loaded, namely:
    Automatic:
    - ProxyPACFallback allowed: Allows you to connect directly to the destination if the PAC file is not accessible.
    - Proxy server URL: The server from which proxy settings are obtained.
    Manual:
    - Server and Port: The full address and port of the proxy server
    - Authentication: Username used to connect to the proxy
    - Password: Password used to connect to the proxy


    Clips Web

    This policy creates a shortcut on the mobile device, which directs to a URL.

    Android and Android For Work Android for Work


    Name Description
    Label This is the name assigned to the web clip
    URL Address Directing Web Clip
    Icon Image to be displayed in the WebClip. This image must be a maximum size of 200 pixels tall and 200 pixels wide. It is possible to add more than one web clip with the option “Create a new web clip”.


    ios


    Name Description
    Label This is the name assigned to the web clip
    URL Address Directing Web Clip
    Removable Allow deletion of the Web Clip.
    Icon Image to be displayed in the Web Clip. This image must be a maximum size of 200 pixels tall and 200 pixels wide.
    Pre-composed icon The icon will be displayed without any added visual effects.
    Full screen Present the web clip as a full-screen application. It is possible to add more than one web clip with the option “Create a new web clip”.
    URL Address Directing Web Clip


    Mail

    This is the setting for an email account that applies to a mobile device.

    Android

    This setting is only available for Samsung devices with KNOX support.


    Name Description
    Email This is the email to be configured. The administrator has the option to enter it or the mobile user.
    Entry Protocol The name of the protocol for incoming mail from your provider.
    Incoming mail server The address of the incoming mail server.
    Incoming mail server port The port used by the incoming mail server.
    Incoming mail server login Login used on the incoming mail server. The administrator has the possibility to enter the user or ask the user to enter the Username or Email.
    Incoming Mail Server Password Password used on the incoming mail server. This field is only enabled if the information in the previous box is entered.
    Exit Protocol The name of your Provider’s outgoing mail protocol.
    Outgoing Mail Server The address of the outgoing mail server
    Outgoing Mail Server Port The port used by the outgoing mail server
    Outgoing Mail Server Login Login used on the outgoing mail server. The administrator has the possibility of entering the user or asking him to enter his username or email.
    Outgoing Mail Server Password Password used on the outgoing mail server. This field is only enabled if the information in the previous box is entered


    ios


    Name Description
    Account Description Display name of the account.
    Guy Account access protocol. There are two protocols:
    - Pop: It is used in local mail clients to retrieve e-mail messages stored on a remote server.
    - Imap: With this protocol, you can access e-mail from any computer that has an Internet connection.
    User Display Name It is the name of the user. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Email address The account address. The administrator has the possibility of entering the information or requesting the user’s Email.
    Server (Incoming Mail) Server URL or IP.
    Port (Inbound Mail) Port number for connection.
    Username (Incoming Mail) The name used to connect to the incoming mail server. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Authentication Type (Incoming Mail) The authentication method of the incoming mail server.
    Password (Incoming Mail) The password for the incoming mail server.
    Use SSL (inbound mail) Retrieve incoming mail via SSL.
    Server (Outgoing Mail) Server URL or IP.
    Port (Outgoing Mail) Port number for connection
    Username (Outgoing Mail) The name used to connect to the outgoing mail server. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Authentication Type (Outgoing Mail) The outgoing mail server authentication method
    Password (Outgoing Mail) The password for the outgoing mail server.


    EAS (Exchange Active Sync) accounts

    This is the setting for an email account that applies to a mobile device.

    Android

    This setting is only available for Samsung devices with KNOX support


    Name Description
    Email Your personal email. The administrator has the possibility of entering the information or requesting the user’s Email.
    Entry Protocol The name of your provider’s inbound mail protocol
    Incoming mail server The address of the incoming mail server
    Incoming mail server port The port used by the incoming mail server.
    Incoming mail server login Login used on the incoming mail server. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Incoming Mail Server Password Password used on the incoming mail server.
    Exit Protocol The name The address of the outgoing mail server
    Outgoing Mail Server Port The port used by the outgoing mail server.
    Outgoing Mail Server Login Login used on the outgoing mail server. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Outgoing Mail Server Password Password used on the outgoing mail server.


    ios


    Name Description
    Exchange ActiveSync account name: Exchange ActiveSync account name. The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Microsoft Exchange Server Microsoft Exchange Server.
    Allow Moving Messages can be moved between email accounts, and messages can be forwarded or replied to from a different account than the one originally used.
    Use only in Mail Send mail only from the Mail app (avoiding sending mail from third-party apps).
    Use SSL Send all communications via SSL.
    Domain Account domain (if you leave this field empty, the device will prompt the user). The administrator has the possibility of entering the information or requesting the user’s Email.
    User Account user (if you leave this field empty, the device will prompt the user). The administrator has the possibility to enter the information or ask the user for the Username or Email.
    Email address The account address. The administrator has the possibility of entering the information or requesting the user’s Email.
    Password The password for the account.
    Past days of mail included in sync The number of days spent in mail that will be included in the sync. You have the option to select: No limit, one day, three days, one week, two weeks, or one month.


    Applications

    It is a policy that is applied to mobile devices, to audit the applications they have installed. There are three types of lists that classify the state that applications should have.

    Whitelist

    A list of apps that the device associated with this policy will be allowed to install. For KNOX devices, it is possible to uninstall applications that are not listed.


    Blacklist

    A list of apps that you will be prohibited from installing on devices associated with this policy. For Knox Android devices, you can force uninstall these apps.

    Required Applications

    List of applications that must have the device installed associated with this policy. For Knox Android devices, you have the possibility to prevent the uninstallation of these applications.


    Kiosk

    The Kiosk module is intended for the device to present a default interface with the applications and configurations selected here only.

    Android

    Generic Android Kiosk mode is available only for Agent links Samsung Knox and Android higher than 4.0.

    To add applications to kiosk mode, type at least 3 characters into the searchable text box, and then the console will present the matching results in a drop-down list, as shown in the following screenshot.

    Then click on the app to add it to the listing.


    Repeat the process for each application


    To configure additional options, go to the Configuration Options and configure the options that are needed.


    The available configuration options are as follows:

    • Kiosk exit password: By entering a password, the end user of the device will have the ability to exit kiosk mode, after entering that password.
    • Wallpaper: The kiosk mode on the device will display the image that is loaded here. (5 Mb maximum)
    • Personalized message: The kiosk mode interface will display the message that is configured here. (100 characters maximum)

    Android For Work Android for Work

    Kiosk mode for Android for Work is only available for devices linked in AFW DO (Device Owner) mode.

    For Android for Work, only apps that have been approved for AFW in advance can be added.

    To add them to the kiosk, proceed in the same way as in the previous section.

    In the case of configuration options, the following groups are presented in addition to those in the previous section


    In this group you can enable/disable system applications whose packages have been added with the previous in the Android System Applications configuration section. When you tick each box, the selected applications will appear at the kiosk.

    In this group, you can enable/disable configuration screens in kiosk mode for each of the options presented.

    For this group, you can activate/deactivate power switches in kiosk mode to turn each of the options presented on or off.

    A new synchronization option is developed, to favor the user in the execution of commands; Thus, when a command is sent from the console and the user wants to execute the action without waiting for the device to be activated with the push, the user must select the option Synchronize, as shown in the image:

    When the action is performed it displays a successful synchronization message

    ⚐ Note: In the kiosk configuration, the following must be taken into account:

    • Bluetooth functionality for devices smaller than OS version 9 cannot see notifications to grant permission to transmit files via bluetooth.


    Safe browsing (iOS, Android, and Android For Work) Android for Work

    In the Safe Browsing module, you can configure websites to access or restrict access from the Aranda Secure Browser application. This application allows access to internet websites and serves as the device’s web browser.

    ⚐ Note: Currently this functionality is used with the Aranda Secure Browser application, which is not enabled in the store since it will be removed from the suite. You will be able to make the settings in the policy, but not access the app Aranda Secure Browser.


    APN

    IOS, Android For Work, and Android Management Api

    Allows you to configure an Access Point Name (APN) for mobile devices


    Name Description
    APN Name A friendly name to identify the access point configuration.
    Access Point Name The name of the access point provided by the network operator to establish the data connection.
    Mobile Country Code (MCC) A three-digit numerical code that identifies the country of the mobile network operator.
    Mobile Network Code (MNC) A numerical code that identifies the mobile network operator within a country.
    Access Point Type Defines the type of data traffic to be routed through the APN (for example: default, mms, supl, and so on).
    MVNO Type Mobile virtual network operator (MVNO) type. Allows you to specify APN settings for virtual operators.
    Default connection Indicates whether this APN setting will be used as the device’s default data connection.
    Access Point Connection User Username required to authenticate to the operator’s access point.
    Access Point Connection Password Password required to authenticate to the operator’s access point.
    Proxy host address Address of the proxy server through which data traffic will be routed.
    MMS proxy host address Address of the proxy server used to send and receive multimedia messages (MMS).
    MMS host address Address of the Multimedia Messaging Server (MMSC) used to handle MMS messages.
    Authentication Type Authentication method used for connection to the access point. Available types may include: None, PAP, CHAP, or PAP/CHAP.


    Tracking Policy Settings

    In the policy module, after selecting the platform and assigning a name to the policy, the section that allows you to carry out the monitoring parameterization will be displayed.



    Clicking on the “Enable Tracking Policy Editing” option presents the options to select the tracking level to with the values of: low, medium, and high.


    Once the tracking frequency has been selected, the section is available in which the tracking time can be configured. By clicking on the clock icon, the section that allows you to select the hours, minutes and day (a.m./p.m.) in which the tracking will be carried out appears.


    Finally, there is the section that allows you to configure the days, which allows you to individually select the days to apply the configuration or there is also the option that allows you to mark all the days.


    Once the tracking policy has been created and assigned to a device, it can be viewed in the device’s location details


    4. After configuring the policies, select the Save.

    Credential providers

    What applications can a device use to manage and store login credentials? Device policy requires enabling the configuration option Credentials, to allow apps that manage credentials and apply separate settings to them from the rest of the policy, on Android devices linked to your organization.

    This functionality also responds to a requirement from Google for AEMM to remain in the Android Enterprise application directory, which guarantees the organization to maintain the benefits associated with that community.

    Using this setting, the administrator defines a whitelist or blacklist of authorized or restricted packets, and the AEMM agent automatically applies those settings on each device that receives the policy.

    ⚐ Note: The Credentials option is only available when the AEMM console is configured to work with the Google Play EMM API or Android Management Api.

    Prerequisites

    Before configuring this policy, the administrator must verify that:

    • You have access to the AEMM console with permissions to create or edit policies.
    • The console is configured to work with Google Play EMM API or Android Management Api.
    • For the settings to be applied on a device, the device must be paired in DO (Device Owner) or PO (Profile Owner).

    Enable the Credential Provider Policy

    1. Enter the AEMM Startup Console and select the option Policies from the top menu.

    2. Select New to create a new policy, or open an existing policy for editing. In Platform, choose Android.

    3. Inside the section ANDROID FOR WORK or Android Management Api, select the Credentials in the side menu.

    4. Turn the switch on Yes. The system displays the available configuration options.

    5. Select the configuration type: Whitelist or Blacklist. Only one type of list can be used at a time.


    |||


    ⚐ Note: If you select Whitelist, you can also check the box Allow system apps to whitelist.

    6. In the search field, type the name of the credential manager application package and add it to the list.

    7. Click Save.

    Disable the credential provider policy

    1. Enter the policy you want to edit and locate yourself in the ANDROID FOR WORK or ANDROID MANAGEMENT API → Credentials.

    2. Turn off the switch, leaving it at NO. The system hides the configuration options of the section (list type and package list).



    3. Click Save.

    On-device behavior

    What happens on the device when this policy is applied or removed? Enforcing credential provider settings is automatic and does not require any end-user action on the device.

    • When applying the policy: When a paired device in DO (Device Owner) or PO (Profile Owner) receives a policy with the credential providers section enabled and configured, the AEMM agent immediately applies those settings (whitelist, whitelist with system applications, or blacklist) on the credential management applications of the device. If at least one application is configured in Blacklist, it does not allow you to store the credentials in that application, that is, the device blocks it as a credential manager (it does not allow you to store the credentials).
    • When you retire the policy: When the device receives a version of the policy with the credential providers section disabled, the AEMM agent removes the previously applied configuration, leaving no restrictions or authorizations associated with this functionality. If any application was blocked because it was listed in Blacklist, when you retire the policy, it is no longer restricted and you can rehost credentials normally.

    ⚐ Note: The time it takes for the device to receive and apply changes depends on the synchronization of the AEMM agent with the console.