Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Mobile Device Management (MDM): Android Application Management

Topic

This article describes how to manage applications for Android devices in NinjaOne Mobile Device Management (MDM).

Environment

NinjaOne Mobile Device Management (MDM)

Description

NinjaOne allows you to use a mobile device management (MDM) policy to manage the addition and behavior of Android applications on managed devices.

Upon provisioning company-owned Android Enterprise devices (those configured as "work" in the Add Device flow), NinjaOne deactivates system applications during the provisioning process, rendering the device blank and ready for corporate management.

NinjaOne allows you to activate or block system applications. Refer to the Add an Application section of this article for more information.

Select a topic to continue.

Managing Applications

Navigating to Application Management Options

Follow these steps to navigate to your Android MDM policy's configuration options:

  1. In NinjaOne, navigate to AdministrationPoliciesMDM Policies, then select an Android MDM policy from the list.
Figure 1: Administration → Policies → MDM policies (click to enlarge)
  1. The Android MDM policy's configuration page opens. Click Applications. The menu expands to show three configuration page links:
Figure 2: Applications settings (click to enlarge)

Configuring Application Settings

In the Applications drop-down menu, click Management to access application management configuration options.

Here, you can configure the following settings:

SettingDescription
Default permission policySet a default NinjaOne policy to manage these applications. This option applies globally to all installed applications. More granular, per-app permissions management is available within the app settings.
Play store mode

There are two Play Store modes:

  • Allowlist: Only approved apps will be displayed in the Google Play Store. No other apps will display or be searchable.
  • Blocklist: The Google Play Store displays all apps except those explicitly blocked through the policy.
Untrusted apps policyDefine whether users can sideload applications onto the device via the web, file transfer, or developer options.
Content protection policyActivate content protection, which prohibits users from sharing content from the device through electronic means or output devices.
Native multi-app kiosk launcherActivate or deactivate the Kiosk Settings tab. Refer to the Kiosk Settings section of this article for more information.
Configure always-on VPN packageDefine an app package name that the Android OS will consider the launch virtual private network (VPN) package and ensure it runs as the always-on VPN app.
Block network access if VPN disconnectsBlock network access through WiFi or cellular signal if the VPN is no longer present.
Managed ApplicationsSelect specific applications to be automatically installed or blocked, or made optionally available to users, when the mobile device becomes NinjaOne-managed. Refer to the Managed Applications section of this article for more information.

Working with Managed Applications

The Managed Applications table allows you to select specific applications to be automatically installed or blocked, or made optionally available to users on a NinjaOne-managed Android device. Apps that you add appear in this table.

Managed Applications Table Columns

The Managed Applications table shows data about each app in a series of data columns. You can add or remove columns by clicking the gear icon. You can also rearrange columns by dragging them to new positions in the stack.

App Installation Failure Activity

Three consecutive app installation failures (not specifically on the same app) trigger a failure activity, which NinjaOne reports in the Activity feed on the device's dashboard. This alerting generates automatically and requires no configuration.

Kiosk Settings

The multi-app kiosk launcher dedicates devices to run a specific set of apps so they can function as single-purpose kiosks (such as information terminals, point-of-sale pads, or digital signs). Refer to Android Kiosk Documentation (external link) to learn more about Android kiosk mode.

Activating Kiosk Options

You must activate the native multi-app kiosk launcher before configuring kiosk settings.

On the Android MDM policy's configuration page, click Applications, then select Management from the drop-down menu and activate the Native multi-app kiosk launcher toggle.

Editing Kiosk Settings

On the Android MDM policy's Applications page, click Kiosk settings, then configure the settings to your requirements. This table provides an explanation of each kiosk setting.

SettingDescription
Power buttonAllow or block the long-press button behavior in kiosk mode.
System error warningsActivate or hide system error warnings. Unresponsive apps will automatically close.
System navigationActivate or block navigation buttons such as Home or Overview.
Status barActivate or deactivate system info and notifications in kiosk mode. System navigation settings will affect the ability to activate this setting.
Device settingsAllow or block a user's access to the device's Settings app in kiosk mode.

Advanced Settings

The Advanced tab allows you to configure persistent preferred activities, which are rules that determine which apps the managed devices will employ when users perform specific actions.

Configuring Persistent Preferred Activities

  1. On the Android MDM policy's configuration page, navigate to ApplicationsAdvanced and click Add activity.
  2. In the Add activity window, enter the following information:
OptionDescription
Configuration nameAssign a descriptive name to the configuration.
ActivityEnter the application activity to use for the following actions and categories. Refer to the app developer for supported activities.
Select an actionChoose an action from the drop-down menu. The action options include the intent filter and the app packages.
Select a categoryChoose an action category from the drop-down menu.

Adding an Application

This section explains how to add Google Play Store, system, custom, and private applications.

Special Considerations

Remember these considerations when adding applications.

  • Users without update permissions in the Android MDM policy cannot add, edit, or remove Android applications. Refer to our NinjaOne Mobile Device Management (MDM): Android Policy Management article for more information about assigning user permissions.
  • The Privacy Badger browser extension and similar extensions may block cookies, which could prevent Google Play from displaying in the NinjaOne platform.

Procedure

  1. In NinjaOne, navigate to AdministrationPolicies, then choose an Android MDM policy from the MDM policies list.
Figure 8: Administration → Policies → MDM policies (click to enlarge)
  1. On the policy's configuration page, click ManagementAdd Apps and select whether you want to add an application from the Google Play Store, add a system app, or upload a custom app via APK file.
Figure 9: Management → Add apps (click to enlarge)

Add Apps from the Google Play Store

You can add any apps available on the Google Play Store.

  1. On the Android MDM policy's configuration page, click ManagementAdd Apps and select Play Store from the drop-down menu. The Add New Package menu opens.
  2. Select the Android connection (Enterprise account) from the drop-down menu. If you are creating a new Android connection, refer to MDM: Enable the Android Enterprise Device Management.
  3. Find the application by scrolling or searching, then click the application name.
  4. Click Select to add the application to the device's Android MDM policy. NinjaOne displays the app, along with its details and assignment type, in the Managed Applications table's Installed applications column. The assignment defaults to Preinstalled. Follow the steps in the Configure or Edit Application Restrictions and Settings section below to change default assignment types.

Add System Apps

You may want to install additional apps as system apps on managed Android devices.

  1. On the policy's configuration page, click ManagementAdd Apps and select System app from the drop-down menu.
  2. In the Add system app window, enter the following information:
OptionDescription
Package nameEnter the exact package name that the Android MDM policy will manage. You can find the Android package name in the Google Play Store URL by using the Share function on the app page, via Android debug bridge (ADB) commands, or by using a third-party package name viewer app.
Assignment typeSpecify how NinjaOne should deliver the app to managed devices. Refer to the Application Assignment Types section for a description of each type.
NameEnter an optional display name, which will appear in the Android MDM policy's Applications list.
PublisherEnter an optional publisher name, which will appear in the Android MDM policy's Applications list.

Add Private Apps

NinjaOne deploys private apps only to the devices that share the Android Connection name. We recommend using a separate Android MDM policy to segment connections from other devices that should not have access.

Private App Considerations

  • The Google Play iframe has a size limitation in line with the Google Play Developer Console for Android package kit (APK) files. Avoid uploading files in excess of 100 MB. Larger apps should be uploaded as Android App Bundle (AAB) files in the Developer Console and not through the iframe as an APK.
  • Organizations should leverage external resources and on-demand payloads where possible (for example, any large app or game that alerts you upon launch that it has more to download). These resources provide a better user experience and reduce network failures, as they can be stopped and started as needed.

The Android Connection column in Managed Applications updates when you add a private app.

  1. Click Add Apps and select Play Store.
  2. Select the Android connection (Enterprise account) from the drop-down menu. If you need to create a new Android connection, refer to MDM: Enable the Android Enterprise Device Management.
  3. Move your cursor over the navigation pane and click Private Apps.
  4. Click the + icon and follow the prompts to upload your private apps.

Add Custom App APKs

You can upload custom apps via Android package kit (APK) files directly to an Android MDM policy. To manage custom APK files in a centralized library and apply them across multiple policies without re-uploading, refer to the Managing the APK Library section of this article.

the NinjaOne agent must be version 1.3.5 or later for APK deployment to succeed.
  1. On the Android MDM policy's configuration page, navigate to ManagementManaged Applications.
  2. Click Add apps, then select Upload application from the drop-down menu.
Figure 10: Management → Add apps → Custom app (click to enlarge)
  1. The Upload application window opens. Configure the following settings:
OptionDescription
Android connection

This optional field enables you to specify the Android Enterprise connections that should receive the APK installation.

  • Only the technicians attached to the connection specified will be able to view and manage the app.
  • Leave this field blank to allow APK installation to your full Android MDM ecosystem.
Allow user uninstallDecide if the device end user is able to uninstall the app.
Upload an applicationClick this button, then navigate to the APK file's location to upload it to NinjaOne.
NameEnter an optional display name, which will appear in the Android MDM policy's Applications list.
PublisherEnter an optional publisher name, which will appear in the Android MDM policy's Applications list.
Default permission policy

Select the required behavior when the app requests user permission:

  • Prompt: The device will ask the user if the app should allow or deny the permission.
  • Grant: The device automatically approves the permission request.
  • Deny: The device automatically denies the permission request.
Delegated scope access grants

Android apps can have additional delegation scopes, letting applications install certificates, access managed configurations, block uninstallation, activate system apps, and more. Use the drop-down menu to select from the following:

  • Certificate installation and management
  • Managed configurations management
  • Blocking uninstallation
  • Permission policy and permission grant state
  • Package access state
  • Enabling system apps

View Installed APKs

To view and manage APK files in the centralized APK library, refer to the Managing the APK Library section of this article.

Add Web Apps

Web apps are apps that are maintained online and displayed in a web browser. NinjaOne MDM points to the application website.

  1. On the Android MDM policy's configuration page, click ManagementAdd Apps and select Play Store from the drop-down menu. The Add New Package menu opens.
  2. Select the Android connection (Enterprise account) from the drop-down menu. If you need to create a new Android connection, refer to MDM: Enable the Android Enterprise Device Management.
  3. Move your cursor over the navigation pane and click Web Apps.
  4. Click the + icon and follow the prompts to add your web apps. Refer to Create web apps - Android Enterprise Help and Android Management API: Google for Developers (external links) for more information about this process from Google.

Managing the APK Library

The APK library is a centralized repository for custom APK files. You can upload, edit, and override APKs from the library and apply them across multiple Android MDM policies without re-uploading files at the policy level. Changes you make in the APK library propagate automatically to all associated policies and device-level overrides.

The policy-level Upload application workflow (described in the Add Custom App APKs section above) and the APK library are separate workflows. Use the APK library when you need to manage an APK across multiple policies from a single location.

Navigating to the APK Library

To access the APK library, navigate to AdministrationAppsInstalledNinjaOne MDM Android and click APK library.

Figure 11: Administration → Apps → Installed → APK library (click to enlarge)

The APK library table lists all uploaded APK files. Each row displays the app's name, package name, version, publisher, Android connection, status, and upgrade status. You can add or remove columns by clicking the Actions icon, and rearrange columns by dragging them to new positions.

If NinjaOne cannot retrieve an APK's metadata, the affected fields in the row display as - and an error indicator appears on the row. Hover over the error indicator to view the error details. Reload the table to request the metadata again. [VERIFY WITH PM: confirm error indicator behavior and tooltip text]

APK Scanning Status

NinjaOne scans each APK you upload for security threats. The Status column in the APK library displays the current scan state for each file.

StatusDescription
ScanningNinjaOne is analyzing the APK. You cannot edit or delete the APK while it has this status.
ReadyThe scan completed successfully. The APK is available for deployment.
SuspiciousThe scan identified the APK as potentially suspicious. The APK remains available for deployment. NinjaOne records the scan result in the APK library activity log.
FailedThe scan failed. The APK remains in the library but cannot be deployed to policies.

To filter the APK library table by scan status, click the filter control above the table and select the status values you want to display.

Adding an APK to the Library

Follow these steps to upload a new APK to the APK library.

  1. In the APK library, click Upload.
  2. In the Upload an .apk file window, click Upload file.
  3. Navigate to the file on your system and click Open.
  4. Enter any of the following information that NinjaOne MDM requires.
OptionDescription
Android connectionSelect the Android Enterprise connections that should have access to this APK. Leave this field blank to make the APK available across your full Android MDM ecosystem. Only users attached to the specified connection can view and manage the app. When you update this field later, NinjaOne automatically updates all associated policies and device-level overrides to reflect the change.
Upload an applicationClick this button, then navigate to the APK file's location to upload it to NinjaOne.
NameEnter an optional display name. This name appears in the APK library and in any policy's Applications list where the APK is applied.
PublisherEnter an optional publisher name. This name appears in the APK library and in any policy's Applications list where the APK is applied.
Default permission policy

Select the required behavior when the app requests user permission:

  • Prompt: The device will ask the user if the app should allow or deny the permission.
  • Grant: The device automatically approves the permission request.
  • Deny: The device automatically denies the permission request.
Allow user uninstallDecide if the device end user is able to uninstall the app.
Delegated scope access grants

Android apps can have additional delegation scopes, letting applications install certificates, access managed configurations, block uninstallation, activate system apps, and more. Use the drop-down menu to select from the following:

  • Certificate installation and management
  • Managed configurations management
  • Blocking uninstallation
  • Permission policy and permission grant state
  • Package access state
  • Enabling system apps
  1. Click Save.

After you save, NinjaOne begins scanning the APK. The APK's status changes to Scanning until the scan is complete. NinjaOne records an activity entry when the upload succeeds or fails.

Editing an APK in the Library

You can upload a new version of an existing library APK to replace it. NinjaOne applies the updated file to all associated policies and device-level overrides automatically.

You cannot edit an APK while its status is Scanning. Wait for the scan to complete before editing.
  1. In the APK library, click the Actions menu next to the APK you want to update, then click Edit.
Figure 12: Actions → Edit in the APK library (click to enlarge)
  1. In the edit window, upload the replacement APK file and update any settings you want to change. When finished, click Update.

NinjaOne adds the updated APK information to all associated policies and device-level overrides and records an Activities feed entry for the edit result.

To update an APK's Android connection assignments, edit the APK in the library and change the Android connection field. NinjaOne automatically updates all associated policies and device-level overrides to reflect the change.

Overriding an APK

The override feature replaces one library APK with another version already in the library, across all associated policies and device-level overrides simultaneously. Use this workflow when you want to swap an APK version without uploading a new file.

  1. In the APK library, click the actions menu next to the APK you want to replace, then click Override.
  2. In the override window, select the replacement APK from the library, then click Confirm.
The override window displays only APKs whose package name matches the APK you are replacing.

NinjaOne removes the original APK and updates all associated policies and device-level overrides to use the replacement. NinjaOne records an activity entry that lists the policies and device overrides that were updated.

Filtering the APK Library

You can filter the APK library table by upgrade status, policy, or package name to narrow the list of APKs displayed. Click the filter control above the table and select the filtering category.

You can filter APKs by:

  • Scan Status
  • Upgrade status
  • Policy
  • Package name

APK Library Activity Log

The APK library includes an activity log that records events for each APK. To view the activity log for a specific APK, click the actions menu next to the APK, then click Details. [VERIFY NAVIGATION]

The activity log records the following event types:

  • Upload success and upload failure

.

  • Scan complete, including results where the scan status is Suspicious.
  • Edit success and edit failure.
  • Policy and device override updates that result from an override or Android connection assignment change.
  • APK deletion.

Deleting an APK from the Library

You can delete APKs from the library when they are no longer needed. You can only delete an APK that is not currently assigned to any policy.

Deleting an APK from the library permanently removes the file from storage. You cannot undo this action.
  1. In the APK library, click the Actions menu next to the APK you want to delete, then click Delete.
  2. NinjaOne prompts you to confirm the deletion. Click Yes to complete the action.

NinjaOne removes the APK from the library and records an activity entry logging the filename that was deleted.

If an APK is assigned to one or more policies, the Delete option will not be available. Remove the APK from all policies before deleting it from the library.

Configuring Application Restrictions and Settings

You can edit the applications installed at the policy level to override default settings for each application.

  1. On the Android policy's configuration page, click Applications, then select one or more applications from the Managed Applications list.
  2. The Edit applications policy window opens. In this tab, you can configure the following options:
SettingDescription
Enabled

Control app use on the device.

  • Activate the Enabled toggle to prevent the app from being used on the device.
  • Deactivate the Enabled toggle to allow the app to be used on the device.
Assignment typeSpecify how NinjaOne should deliver the app to managed devices. Refer to the Application Assignment Types section for a description of each type.
Default permission policy

Set the default policy for permissions. You can choose from the following settings:

  • Permission Policy Unspecified
  • Prompt
  • Grant
  • Deny
Connected work and personal app

Allow or disallow work apps and personal apps to share data. You can choose from the following settings:

  • Unspecified
  • Disallowed
  • Allowed
Auto update mode

Control automatic update behavior. You can choose from the following settings:

  • Unspecified
  • Default
  • Postponed
  • High Priority
Allow force stop and clear dataAllow or restrict a user from force-stopping an app and clearing the cache. This option requires Android 11 or later.
Application track for installationSelect available closed-track app versions within Google Play. If an app developer supports application tracks and the app has been shared with the customer's connection ID, NinjaOne will show these versions of the app here. This setting only changes versions on a device when a newer version code is available than what is already installed.
Per app permission overridesSelect a permission from the drop-down menu to allow granular permission control. Each app provides its own declared permissions and will have a different list of available overrides.
Overrides

Each selection made from the Per app permission overrides drop-down menu appears here. These overrides bypass any global permission settings.

  • When you add an override, a new drop-down menu appears. You can allow, deny, or prompt access to the permission.
  • Click the X icon to remove the override.
Delegated scope overrides

Android apps can have additional delegation scopes, letting applications install certificates, access managed configurations, block uninstallation, activate system apps, and more. Use the drop-down menu to select from the following:

  • Certificate installation and management
  • Managed configurations management
  • Blocking uninstallation
  • Permission policy and permission grant state
  • Package access state
  • Enabling system apps

Application Assignment Types

You can configure application assignment types when editing an application that has been added to a policy. Choose from the following assignment types:

Assignment TypeDescription
UnspecifiedUnspecified assignments default to Available. This assignment type is not available for system apps.
PreinstalledNinjaOne automatically installs the app, and the user can remove it.
Force InstalledWhen set, the application ignores any constraints or windows for installation and installs as soon as possible. The user cannot remove the app. Removing the policy also removes the app from the device.
BlockedRestrict the user from using or installing the selected app. If the app is already installed, this setting uninstalls it. If a system app is blocked, NinjaOne deactivates it on the device.
AvailableNinjaOne makes the application available for the user to install from the managed Google Play Store. NinjaOne does not install the app automatically; the user must select it. This assignment type is not available for system apps.
Required for SetupNinjaOne automatically installs the app, and the user cannot remove it. The device cannot complete device setup until the application is installed and configured. This assignment type is not available for system apps.
Single app Kiosk

NinjaOne automatically installs the app in kiosk mode and sets it as preferred and allowlisted for lock task mode.

  • The device cannot complete device setup until the application is installed.
  • After installation, users cannot remove the app.
  • You can select this assignment type for only one application per policy.
  • When this assignment type is present in the policy, the status bar deactivates automatically.

Managed Configurations

In the Managed configurations tab, you can further modify the application, if available.

  1. On the Android MDM policy's configuration page, click Management, then select an app from the Managed Applications list. The Edit applications policy window opens.
  2. Click the Managed configurations tab. If this tab is not present, the app does not support managed configurations. The data provided in this tab depends on the application. For example, Microsoft Teams allows you to configure which user accounts can log in and whether a password is required. In contrast, Google Chrome lets you configure the domain name system (DNS) queries and cache control.
  3. In the Android Connection drop-down menu, select your enterprise account. Refer to our Enable Android Enterprise Device Management article for information about creating a new Android connection.

Supported Variables

NinjaOne supports the following variables for managed app configuration:

VariableDescription
${device.location.name}The device's assigned location name value
${device.location.id}The device's assigned location ID value
${device.organization.name}The device's organization's name value
${device.organization.id}The device's organization's ID value
${device.serialNumber}The device's serial number value
${device.id}The device's GUID value (unique identifier)
${device.owner.email}The device's assigned user email address value
${device.owner.firstName}The device's assigned user's first name value
${device.owner.lastName}The device's assigned user's last name value
${device.owner.displayName}The device's assigned user's display name value

Removing Applications and Application Data

You can use NinjaOne to remotely remove local data for applications installed on an enrolled device, or to delete applications altogether.

NinjaOne cannot uninstall a custom APK app from managed devices if the app is not registered as a custom app in the Android enterprise management policy and the policy's Play Store Mode is set to Blocklist. This is a known issue.

Clear Application Data

You can remotely clear data from selected applications on an individual Android device by following these steps.

Performing these steps removes all data associated with the application stored on the device, including configurations and login information. You cannot undo this action.
  1. On the device's dashboard page, click the Software tab. NinjaOne displays a list of all installed applications.
  2. Select the application packages to remove, then click the Clear App Data button when it appears.
  3. NinjaOne prompts you to confirm the action. Enter your email address to confirm, then click Clear App Data.

Remove Applications

Follow these steps to remove applications from NinjaOne management.

  1. On the Android MDM policy's configuration page, click Applications.
  2. Select one or more applications from the Managed Applications list, then select the checkboxes for the apps you wish to remove and click Remove.

Additional Resources

Refer to the following resources to learn more about working with Android policies:

FAQ

Next Steps