Category filter

How to Blacklist / Whitelist Apps in Android Enterprise enabled devices

Organizations may require certain groups of apps to be allowed while preventing access to the rest of the applications. Situations like these necessitate the administrators to allow/block access to a set of applications.

Hexnode, with its immense device management capabilities, allows you to create a blacklist, which is a list of apps to be hidden or rendered unusable, or a whitelist, which is a list of apps to be allowed access on the devices. This allows to prevent the users’ access to inappropriate apps or allows users to access only the required applications.

You can blacklist or whitelist applications on devices enrolled in Android Enterprise; a Google-led initiative for easy management of corporate deployed devices.

Android Enterprise can be configured either in Profile Owner mode or Device Owner Mode.

Blacklisting Apps in Profile Owner mode

Warning

Only the work apps (ones with the work badge) can be blacklisted.

  1. Login to your Hexnode portal.
  2. Go to Policies.
  3. Select an existing policy or create a new policy by clicking on New Policy.
  4. From Android Settings select App Management > Blacklist/Whitelist and click on Configure.
  5. Change the Type to Blacklist.
  6. Click on +Add to add either an app or App group.
  7. Select the apps to be blacklisted and click on Done.
  8. Next, associate the policy to the target devices by clicking on Policy Targets > +Add Device. Choose the device and click Save. The policy will be pushed to the device.



Notes:

  • When blacklisted, the work app gets hidden from the device.
  • Users are not allowed to install or update a blacklisted app. If you try to install/update a blacklisted app, you will receive a notification in the device specifying that the action is restricted.

Whitelisting Apps in Profile Owner mode

Warning

Only the work apps (ones with the work badge) can be whitelisted.

  1. Login to your Hexnode portal.
  2. Go to Policies.
  3. Select an existing policy or create a new policy by clicking on New Policy.
  4. From Android select App Management > Blacklist/Whitelist and click on Configure.
  5. Change the Type to Whitelist.
  6. Enable the option Blacklist all non-launchable apps to blacklist the non-launchable applications (for example, Google Play services, Android System WebView, etc.) explicitly.
  7. Click on +Add to add either an app or App group.
  8. Select the apps to be whitelisted and click on Done.
  9. Now, add the target devices under Policy Targets > +Add Device and save the policy.

List of whitelisted apps on devices enrolled in profile owner mode using Hexnode MDM

Notes:

  • When whitelisted, it shows only the whitelisted work apps in the work profile.
  • Whitelisting a set of apps will automatically recognize the rest of the apps (except a few non-launchable apps such as Google Play Services necessary for proper device functioning) as blacklisted.
  • In the profile owner mode, the work profile will show only the whitelisted work apps and Hexnode for Work app. The user will not be able to install any other app from Play for Work. If you try to install a non-whitelisted app from Play for Work, you will receive a notification in the device specifying that the action is restricted.

Blacklisting Apps in Device Owner Mode

  1. Login to your Hexnode portal.
  2. Go to Policies.
  3. Select an existing policy or create a new policy by clicking on New Policy.
  4. From Android select App Management > Blacklist/Whitelist and click on Configure.
  5. Select the Blacklist button.
  6. Click on +Add to add either an app or App group.
  7. Select the apps to be blacklisted and click on Done.
  8. Apply the policy with the target devices by navigating to Policy Target > +Add Device.


Notes:

  • When blacklisted, the apps get hidden from the device.
  • Users are not allowed to install or update a blacklisted app. If you try to install/update a blacklisted app you will receive a notification specifying that the action is restricted.

Whitelisting Apps in Device Owner mode

  1. Login to your Hexnode portal.
  2. Go to Policies.
  3. Select an existing policy or create a new policy by clicking on New Policy.
  4. From Android select App Management > Blacklist/Whitelist and click on Configure.
  5. Select the Whitelist button.
  6. Enable the option Blacklist all non-launchable apps to blacklist the non-launchable applications (for example, Google Play services, Android System WebView, etc.) explicitly.
  7. Click on +Add to add either an app or App group.
  8. Select the apps to be whitelisted and click on Done.
  9. Now, move to Policy Targets > +Add Device. Choose your device and save the policy.

List of whitelisted apps on devices enrolled in device owner mode using Hexnode MDM

Notes:

  • When whitelisted, it shows only the whitelisted apps and Hexnode for Work app in the entire device.
  • Whitelisting a set of apps will automatically recognize the rest of the apps (except a few non-launchable apps such as Google Play Services necessary for proper device functioning) as blacklisted. In the device owner mode, the device will only show the whitelisted apps and Hexnode for Work app. The user will not be able to install any other app from the Play Store. If you try to install a non-whitelisted app from the Play Store, you will receive a notification in the device specifying that the action is restricted.


Exceptions:

  • It is not possible to add a blacklisted app in kiosk mode.
  • If the apps are whitelisted, then only the whitelisted apps can be added in kiosk mode.

  • Managing 'Android Enterprise' Devices