Security
Allow adding and delete user accounts
Policy determines whether the user can add and delete accounts such as the email account.
Allow take screenshots
Policy defines if user may do screenshots
Allow developer mode
Policy determines whether the user can enable Developer Mode. If the policy is disabled, the Developer Mode return to the default settings.
Allow safe boot of the device
Policy determines whether the user can start safe mode on the device. In safe mode, the device starts up without the third party applications.
Allow factory reset
Policy determines whether the user can restore the device to factory. Restoring device to factory removes the MDM agent and device will be unmanaged.
Use Factory Reset Protection Get Google ID
The policy force the use of Factory Reset Protection. If the device is restored to factory settings, you will be required to enter the Google ID account details listed below.
Allow the user to deactivate the MDM agent
The policy determines whether the user can deactivate the device from the MDM agent.
Allow clearing of application data
Policy allows to clear Proget app data. Clearing the data will disconnect the device from the system.
Allow installation of non Google Play apps
Policy determine whether a user can install non-Google Play apps using the ACTION_INSTALL_PACKAGE mechanism.
Allow adding and deleting Google accounts
Policy determines whether the user can add and delete Google account. If the policy is disabled, the user cannot add new and delete existing Google accounts.
Require device registration in Microsoft Entra ID
The policy enforces user registration in Microsoft Entra ID. If the policy is enabled, the device will be instructed to sign in to a Microsoft account in purpose of its registration.
Automatically set the user login
Setting this field will automatically insert the specified user login when logging into Microsoft account.
Allow using two SIM cards at the same time
Policy determines whether you can use two SIM cards at the same time if the device supports two SIM card slots. If the policy is turned off, the device will be blocked until the second SIM card is removed.
Block the SIM card with the PIN code for slot 1 (Samsung only)
Policy defines whether the device should save a permanent PIN code to unlock the SIM card. Turning on a permanent PIN will block the company’s SIM card usage on another device. Each time a company device is turned on, device will automatically unlocks the SIM card using the permanent PIN code. However, if the SIM card is moved to another device, it will remain locked because the PIN code is not known to the user. The policy applies to slot 1.
PIN code for slot 1
Block the SIM card with the PIN code for slot 2 (Samsung only, if applicable)
Policy defines whether the device should save a permanent PIN code to unlock the SIM card. Turning on a permanent PIN will block the company’s SIM card usage on another device. Each time a company device is turned on, device will automatically unlocks the SIM card using the permanent PIN code. However, if the SIM card is moved to another device, it will remain locked because the PIN code is not known to the user. The policy applies to slot 2 (if applicable).
PIN code for slot 2
Force device periodically connection to the server
Policy determines whether the device have to connect to the MDM server at a specific time interval. Enabling this policy forces the device to contact the server periodically. The date of the last connection will be saved on the server each time.
Maximum time to lock
Policy set the maximum time for user activity until the device will lock. This limits the length that the user can set in device settings.
Time to lock (in minutes)
Action after exceeding the inactivity time
Policy determines whether a defined action should be taken (Clear device data, Clear company data or Block device) after a specified period of inactivity. Action will be taken automatically if the last contact of the device with the server exceeds the defined inactivity time.
Inactivity time (in days)
Action
Message on a blocked device
Enter the message that you want to display on the blocked device
Phone number
Enter the phone number to which the user can make a call when the device is locked
Allow using Smart Lock
The policy defines the possibility of using Smart Lock on device.
Bluetooth
The policy allows you to automatically unlock your phone when it is connected via Bluetooth to a trusted device, such as a watch or an in-car speakerphone.
NFC
The policy allows you to automatically unlock your phone using a trusted NFC tag.
Trusted places
The policy allows you to configure Trusted places. The device will stay automatically unlocked within a radius of up to 80 meters from the Trusted place.
Face
The device will automatically unlock when it recognizes your face. If you set up a trusted face, the device will search for it each time it starts, and it will unlock when it recognizes it.
On-body
The policy allows you to leave the device unlocked when the device is next to the user (e.g. in his hand, pocket or bag). The device will be locked only after the device has been put down (e.g. on a table); the lock will be activated automatically within a minute.
Voice
The policy allows you to unlock the Google Assistant when saying “Ok Google” on the lock screen, after the device recognized the previously recorded voice. You can give Google commands or open websites without the need to manually unlock the device.
Service password
The service password allows to define a password to unlock a blocked device, i.e. lost mode. The password defined in the policy works simultaneously with the password on the device card.
Lock screen notifications
Policy allows you to specify the maximum level of detail of information in notifications on a locked screen (the user can always reduce this level manually).
Store photos from locked device
Policy defines the maximum time for storing photos on the server taken during the lockdown of the device.
Managing operating system updates
The policy allows to specify how system updates are managed on your device.
Mode
From
To