Already a NinjaOne customer? Log in to view more guides and the latest updates.

NinjaOne Mobile Device Management (MDM): Android Policy Management

Topic

This article discusses how to configure and manage mobile device management (MDM) policies for Android devices in NinjaOne.

Environment

NinjaOne Mobile Device Management (MDM)

Description

Android policy functionality depends on how you enroll the device in NinjaOne Mobile Device Management (MDM). NinjaOne policies take complete control over work-only device types; if the device is personally owned, some policy settings, such as restrictions, may not apply.

You must activate the Android Mobile Device Management (MDM) application before configuring the Android MDM policy. Refer to Enable the Android MDM application for more information.

If you attempt to apply managed configurations to an additional app after the limit is reached, Android will error on processing the policy. In order to remove the processing error, at least one managed configuration or one app with managed configuration must be removed from the policy.

Select a topic to continue:

Mobile Device Enrollment Types

After you activate MDM and enroll your Apple or Android account, you can add mobile devices and categorize their enrollment type as Personal usage, No personal usage allowed, or Dedicated device.

Enrollment types define how a device is enrolled. Android MDM has three enrollment types:

  • Personal usage (personally-owned): A personally owned device is typically considered a Bring Your Own Device (BYOD) enrollment. NinjaOne has limited access to device information and actions.

    NinjaOne uses the Android Device Policy application, or a link on a device already in active use, to enroll these devices. NinjaOne then enables an organization to manage the applications and data within the work profile alone, with no visibility or management of the personal (or parent) profile.

    You can also use this enrollment type for Company-Owned, Personally Enabled (COPE) devices. Refer to NinjaOne MDM: Adding a Company-Owned, Personally Enabled (COPE) Android device to NinjaOne for more information. For these devices, employers control data and security policies within the work profile. Outside the work profile, the device remains suitable for personal use.

The enrollment type only applies to factory-reset or new devices. Device setup will not work if the device contains existing data.
  • No personal usage allowed (For Work or Company-Owned): These devices are company-owned and enrolled exclusively for business purposes, with no work profile separation.
    • The company has unrestricted control over apps, settings, and configurations, and can perform full device wipes without concern for personal data loss.
    • NinjaOne blocks personal accounts and unauthorized app installations by policy.
    • Users generally cannot modify core device settings.
  • Dedicated device (no specific user): This usage type is similar to No personal usage allowed, but the device is not associated with a single user and does not expect personal usage or corporate identity authentication. For additional details, refer to the Android API's dedicated Device provisioning guide (external link).
NinjaOne MDM does not have access to personal files or photos, whether the device is company-owned or personally owned.

Create a New Policy

  1. In NinjaOne, navigate to AdministrationPolicies, then select MDM Policies from the drop-down menu and click Add MDM policy.
MDMNewPolicy_NavToCreateNew.png
Figure 1: Administration → Policies → Add MDM policy (click to enlarge)
  1. Select a device role, enter the policy details, and activate the Policy enabled toggle. The role you select determines which policies you can set as the parent. Refer to the Inherited Policy Details section of this article for more details. When finished, click Create.
parent policy_mdm.png
Figure 2: The Create a policy window (click to enlarge)

Inherited Policy Details

NinjaOne supports policy inheritance for MDM policies. The role you select determines which policies can serve as the parent policy. You must choose an MDM-specific role to create an MDM-specific parent-child policy relationship.

NinjaOne displays an Inherited tag in the new policy, along with an option to override individual settings. To revert to inherited settings, move your cursor over the policy name and click Inherited policies.

override inheritance.png
Figure 3: Revert an overridden policy value (click to enlarge)
Inherited policies display descriptions beneath their names on the MDM Policies page.
inherited policy description.png
Figure 4: Inherited policy identification (click to enlarge)

Important Considerations

  • Inherited policies cannot remove applications, WiFi configurations, or Android policy enforcements. Instead, you must deactivate these items in the configuration editor.
  • Deactivating changes the status column to Inactive, and the Inherited label changes to Overridden.

Configure the Policy

Follow these steps to configure a new policy, or edit an existing policy's configuration settings.

If you change a policy's configuration, users must restart their devices to populate the changes.
  1. Navigate to AdministrationPoliciesMDM Policies, then select the policy in the list.
MDMNewPolicy_Nav3.png
Figure 5: Administration → Policies → MDM policies (click to enlarge)
  1. Use the configuration links to access settings for the following categories. This article describes the settings for each category in the following tables.
  • Passcode
  • Restrictions
  • Applications
  • Personal usage
  • Network
  • Security
  • Policy enforcement
  • Location tracking
MDMNewPolicy_ConfigOptions.png
Figure 6: Policy configuration options (click to enlarge)

Passcode

Passcode settings let you require and set passcodes to unlock devices and profiles.

Passcode Options Explained

Use the table below to learn about each passcode configuration option.

SettingDescription
Device scope and Profile scopeSet the passcode on the device, the work profile, or both.
EnabledActivate this toggle to require passcode entry.
Require password to unlockChoose whether the device will need a passcode to unlock after every timeout, or every day.
History lengthSpecify the number of previously used passcodes NinjaOne remembers to prevent reuse.
Maximum failed passwords for wipeDefine the number of password attempts before NinjaOne wipes the device. The maximum is 100.
Maximum age (days)Specify the maximum password age (in days) after which NinjaOne requires a newly created password.
Password qualitySelect the criteria for acceptable password strength.

Viewing Passcode Status in the Devices Dashboard

NinjaOne shows passcode setting information in the Devices dashboardDetailsSecurity.

Restrictions

NinjaOne obtains most Android policy restrictions directly from the Android Management API, which provides relevant JSON representation and definitions. In this section, you can activate or deactivate device functionality, security, and connectivity.

Note the following about how restrictions are applied:

  • NinjaOne delivers only values that have been modified from their default settings to a device.
  • If the device was enrolled with a work profile, NinjaOne applies restrictions to that profile only.

Restrictions Options Explained

Use the table below to learn about the configuration options for restrictions.

CategoryDescription
Functionality

Restrict device functions, such as:

  • Calling and messaging capability.
  • Camera and microphone functions.
  • User icon and wallpaper changes.
  • The ability to perform factory resets.
  • Auto-date and timezone activation.
Application

Control application parameters such as:

  • Skipping hints on first use.
  • The ability to install and uninstall apps.
  • Access to widgets in the work profile.
Security & Privacy

Control the ability to perform functions affecting device security or privacy, including:

  • Adding, modifying, or removing accounts.
  • Mounting physical media and USB data transfer.
  • Location mode and location sharing.
  • Private key selection.
  • Keyguard (lock screen) functionality.
  • Screen timeout.
Network & internet

Govern the device's ability to use networks, including:

  • Bluetooth functionality, configuration, and contact sharing.
  • Mobile networks.
  • VPNs.
  • Cell broadcasts.
  • Network setting resets, and network escape hatches.
  • Outgoing NFC beams.
  • Data roaming.
  • WiFi state.
  • Airplane mode state.
  • Cellular 2g state.
  • Minimum WiFi security levels.

Applications

The Applications section has three tabs: Managed Apps, Kiosk Settings, and Advanced.

TabDescription
Managed AppsSelect specific applications to install or block on mobile devices.
Kiosk settingsActivate the native Android Kiosk environment and display all deployed applications added to the assigned policy.
AdvancedAdd advanced configurations that can activate supported applications to perform system actions or access categories, such as setting a default Home or Launcher app.
When enrolling a device, ensure you use the same Android connection as the one used to enroll the device in the Google Play Store. Otherwise, managed configuration and app pushes to the device will fail.

To learn more about adding and modifying these applications, refer to MDM: Android Application Management.

Personal Usage

The configuration options in the Personal usage section let you control policies for the parent device's personal profile.

Personal Usage Options Explained

Use the table below to learn about personal usage configuration options.

CategoryDescription
Cross-profile policies applied on the deviceControl policies that apply to both the personally-owned and company-owned profiles on the device.
Show work contacts in personal profileControl whether work contacts appear in the device's personal dialer and contacts app.
Copy and paste between profilesControl whether users can copy content from one profile and paste it into the other.
Share data between profilesControl whether users can share data from apps in one profile with apps in the other.
Personal applications that can read work notifications

Specify the package names of personal apps that NinjaOne allows to read work profile notifications. By default, no personal apps can read work profile notifications; system apps are exempt from this restriction.

Each entry must be a valid app package name (for example, com.example.app). You can find an app's package name in its Google Play Store URL or in the device's app settings.

Personal usage policies

Set the following personal usage abilities:

  • Camera deactivated
  • Screen capture deactivated
  • The maximum duration the work profile can be off (in days)
  • Account types with management disabled
Private Space policy

Control whether users can create a Private Space on the device. Private Space is available on Android 15 and above. Select from the following options:

  • Unspecified: Defaults to Allowed.
  • Allowed: Users can create a Private Space profile on the device.
  • Disallowed: Users cannot create a Private Space profile. This option is supported only on company-owned devices with a work profile. Selecting this option removes any existing Private Space on the device.
Managed personal applicationsThese options let you restrict the personal Google Play Store to specified applications, or allow full store access.

Network

This section enables you to manage network settings for the device, including setting up proxies and specifying authorized WiFi networks.

Network Settings Explained

Use the table below to learn about network configuration options.

SettingDescription
Manual proxy setupSet up a proxy server for internet access. Activating direct proxy deactivates any established WiFi networks on the device. Refer to the Configure WiFi SSID Settings section of NinjaOne MDM: Android Enrollment Profiles for more information.
WiFi network listTo add a WiFi network, click Add WiFi Network, then enter the configuration name and WiFi name (SSID), and select the appropriate security type.

Security

The Security section enables you to encrypt the device, manage developer settings, define how data is moved for work, and more. The settings in this section are enforced directly through the Android Management API (AMAPI) security policy. For information on how NinjaOne applies policy settings to managed devices, refer to the Policy Enforcement section of this article.

Security settings are split into the following categories:

  • General
  • Private key rules
  • Custom messaging

General Security Settings Explained

Use the table below to learn about general security settings.

SettingDescription
Minimum Android version support (API level)Set the minimum allowed Android API level.
Maximum time to lock (seconds)Select the number of seconds that pass before the device is locked and the user is required to input the password.
User credentials configuration disabledProhibit users from managing how usernames and passwords are saved or used for authentication.
Encryption policyActivate the policy to require a password.
Disabled keyguard customizationsRestricts lock screen items, such as widgets, notifications, camera access, and other tools, when the device is locked.
Battery plugged modeForce a device to keep its screen active under specific conditions (for example, when plugged into AC power, on wireless charging, or connected to a USB connection). To prevent the device from locking while the setting is active, clear Maximum time to lock.
Developer settingsAllow developer options, such as system behaviors, quick settings, and safe boot. For more information about Android developer settings, refer to Configure on-device developer options (external link).
Allowed input methodsConfigure a list of package names for input methods or keyboard apps.
Allowed accessibility servicesDetermine the accessibility services permitted for use on a device, blocking all others. Note that this may detrimentally impact accessibility for device users reliant on specific services.
Memory tagging extensionThis setting controls the Memory Tagging Extension (MTE), a hardware implementation of tagged memory, and is supported on Android 14 and above.
Common Criteria Mode

Control the security standards defined by the Common Criteria for Information Technology Security Evaluation (CC) on the device. This setting is supported on company-owned devices running Android 11 and above. Select from the following options:

  • Unspecified: Defaults to Disabled.
  • Disabled: Common Criteria Mode is not active on the device.
  • Enabled: Common Criteria Mode is active on the device.
Important note: Only activate Common Criteria Mode if your organization requires it. If you deactivate this mode after use, all user-configured WiFi networks may be lost, and enterprise-configured WiFi networks that require user input may need to be reconfigured. Refer to Common Criteria for Information Technology Security Evaluation (external link) for more information.
Send content to assist appsAllow contextual content about the current app or screen state to assist apps such as Gemini, supported on Android 15+. Deactivate this setting to prevent content from being shared.
Factory reset protection allowlisted accountsDefine which Google accounts can unlock a device if factory reset protection is triggered.
Account types with management disabledAdd account type identifiers (for example, com.google) to prevent users from adding or managing accounts of those types on the device. Account type identifiers are registered by app developers and may be found in developer documentation or by inspecting the device directly.

Private Key Rules

Private key rule settings enable you to create and manage private keys for authentication in NinjaOne MDM.

  • To add a key, click Add key and enter the following information:
    • Key name: Give the key a descriptive name.
    • Alias: Enter an alias NinjaOne can use to find the key.
    • URL pattern: Enter any URL hierarchies to which the key will be specific.
    • Package names: Select the package name of the app to which the key will be specific.
  • To edit or delete a key, place your cursor over it and click the actions menu when it appears, then select Edit or Remove.

Custom Messaging Settings Explained

Use the table below to learn about custom messaging settings.

SettingDescription
Custom messaging

Create custom messages to users from Security Administration when they attempt actions on the device. Click Add language to add the message in a NinjaOne-supported language.

  • Short support message: Displays when users attempt an action that is not permitted.
  • Long support message: Appears when the user taps the prompt for more information about the disallowed action.
  • Lock screen message: This option displays a message on the device's lock screen.
System Update Configuration

Specify an update configuration type:

  • Automatic: Download and install available system or Google Play updates as soon as they are available. As part of the update process, a reboot is required and will automatically occur.
  • Windowed: Set a specific time frame (starting after midnight) that adheres to your schedule and time zone. Four hours is usually an ideal amount of time to ensure enough time for installation of the update. This mode is the recommended option to minimize disruption due to update installation and device reboots.
  • Postpone: Do not perform updates at this time.
Freeze Periods

Set an annually repeating time period during which NinjaOne postpones over-the-air (OTA) system updates to freeze the OS version running on a device.

  • You can set multiple freeze periods. Each freeze period must be separated by at least 60 days to prevent inadvertent freezing of the device indefinitely.
  • If the System Update Configuration option is set to Unspecified, you will be unable to add freeze periods.

Policy Enforcement

Policy enforcement allows you to set rules that define behavior when a policy cannot be applied to a device. For example, you can block access to a specific setting on either a work profile or the entire device for a specified number of days. If certain aspects of the policy are not applied successfully, there is an additional option to wipe the device.

Applying Policy Enforcement

Follow these steps to set up a new policy enforcement:

  1. In Policy enforcement, click Add.
  2. The Add new policy enforcement window will open. Fill out the following information:
SettingDescription
Setting NameSelect the feature you want to block. Refer to the Setting names explained table in this article for an explanation of each setting name.
Block ScopeBlock access to apps and data on a company-owned device or in a work profile. This action also triggers a user-facing notification that, if possible, includes information on how to correct the compliance issue.
Block after daysOptionally, set a specific date for the setting to be blocked a specific number of days after the policy changes are saved.
Wipe after daysReset a company-owned device or delete a work profile after a specified number of days.
Preserve FrpPreserve the factory reset protection for personal profiles (optional).

Setting Names Explained

Refer to the table below for an outline of each setting name.

SettingDescription
ApplicationsControl policy settings applied to applications.
Keyguard disabledDeactivate the lock screen on the primary or secondary display.
Permitted accessibility servicesIf the field is not set, any accessibility service can be used. If the field is set, only the accessibility services in this list and the system's built-in accessibility service can be used. In particular, if the field is empty, only the system's built-in accessibility services can be used. You can set this field on fully managed devices and on work profiles. When applied to a work profile, the option affects both the personal profile and the work profile.
Permitted input methodsIf present, only the input methods provided by packages in this list are permitted. If this field is present, but the list is empty, then only system input methods are permitted.
Minimum API levelDefine the minimum allowed Android API level.
Recommended global proxyThis setting controls the network-independent global HTTP proxy. Typically, you should configure proxies per network, using the Network configuration options. However, for unusual configurations like general internal filtering, a global HTTP proxy may be useful. If the proxy is unavailable, the device may lose network access. The global proxy is only a recommendation, and some apps may ignore it.
Location modeSet the degree of location detection activated.
Always on VPN PackageSpecify whether the app is allowed to network when the VPN is not connected and activated. This setting is only supported on devices running Android 10 and above.
Bluetooth config disabledDeactivate Bluetooth connections to and from the mobile device.
Encryption policyDetermine encryption configuration.
Permission grantsExplicitly grant or deny permission for the app.
Password policiesPassword requirement policies. The password Scope field in the policy can be set to different policies for work profiles or fully managed devices.
Advanced security overridesSecurity policies are set to secure values by default. NinjaOne does not recommend overriding any of the default values to maintain a device's security posture.
Personal usage policiesPolicies managing personal usage on a company-owned device.
Cross-profile policiesDetermine whether data from one profile (personal or work) can be shared with apps in the other profile.

After setting the policies, move your cursor over a rule and click the actions icon to edit or delete it. You can also select multiple rules simultaneously using the checkboxes to take bulk action.

The available bulk actions depend on the policy type:

  • Parent policy: Select one rule to access Edit and Delete. Select two or more rules to access Delete only.
  • Child policy: Select one rule to access Edit, Deactivate, and Revert Overrides. Select two or more rules to access Deactivate and Revert Overrides only.

Location Tracking

Refer to NinjaOne Mobile Device Management (MDM): Location Tracking for more information.

Additional Resources

Refer to the NinjaOne MDM: Resource Catalog for more information about managing Android devices.

FAQ

Next Steps