Feature Control (Android Enterprise Work Profile)

Use this dialog box to configure individual device features.

Device Functionality

Features

Allow Camera When enabled, device user can use the camera.
Note: If disabled, all apps in the Work profile are prevented from launching the camera

Android OS compatibility: 6.0 or later.

Allow Screen Capture When enabled, device users can save images or recordings of the device's display.
Allow Smart Lock When enabled, device users can use Smart Lock on Android which allows devices to unlock without a password when they are within 'safe' places that the device user sets.

If the Allow All Keyguard Features feature control option is enabled, Allow Smart Lock is automatically enabled too.

Android OS compatibility: 6.0 or later.

Allow Printing When enabled, device users can use the device's printing capabilities.

Requires Android 9.0 or later.

Settings

Allow Location Sharing for Work Profile When enabled, Location Sharing is permitted for all Managed Profile apps. Apps running in the Work profile will be unable to use device location information.
Allow Skip App First Use Hints When enabled, when a supported app launches for the first time, it will skip any introductory hints or tutorials.

Security

Security

Allow All Keyguard Features When enabled, device users can use keyguard features on the lockscreen. Keyguard features include fingerprint authentication, viewing of notifications, smart lock access and camera access. Enabling Allow All Keyguard Features will automatically enable the other keyguard feature control options.
Allow Fingerprint Authentication When enabled, device users can use Google's fingerprint authentication framework to secure their devices.

If the Allow All Keyguard Features feature control option is enabled, Allow Fingerprint Authentication will be automatically enabled too.

Android OS compatibility: 6.0 or later.

Allow Account Creation Specify whether device users can add new accounts to the device. Choose an option from the dropdown list
  • All: allows the creation of any type of account, Google accounts included
  • All Accounts except Google Account: allows the creation of non-Google accounts
  • No Accounts: prevents device users from creating any new accounts on the device

This does not remove any existing accounts from the device.

All is selected by default.

Allow Doze Mode When enabled, allows the device to restrict the SOTI MobiControl Android agent for battery optimization.
Note: Disabling this option negates any battery optimizations provided by doze mode and will use additional battery power to stay connected.
Always On VPN Direct all network traffic on the device through a specified VPN.

Enter the package name of the VPN app.

Allow Verify Apps Enforcement When enabled, the device user can change the Scan device for security threats option within the Play Protect settings of the Google Play Store.
Perform SafetyNet Check on Device Check-in When enabled, the SafetyNet check is performed on the device at every device check in, in addition to once daily.

Data Protection

Allow Copy/Paste between Work and Personal When enabled, device users can copy text or images between the Work and Personal profiles.
Allow Sensitive Notifications When enabled, notifications from Android Enterprise Apps display all their details when they appear on secure lock screens.

If the Allow All Keyguard Features feature control option is enabled, Allow Sensitive Notifications will be automatically enabled too.

Android OS compatibility: 6.0 or later.

Allow Uninstallation of Managed Applications When enabled, device users can uninstall any managed applications.
Allow Third Party Input Methods When enabled, device users can enable additional third-party input methods such as keyboards on their devices.
Allow Caller ID Information for Work Profile Contacts When enabled, device user can see Caller ID information for calls from contacts saved within the Work profile.
Allow Installation from Unknown Sources When enabled, device users can install apps that are not from the Google Play store.
Allow Installation from Unknown Sources on Personal When enabled, device users can install apps that are not from the Google Play store on the personal profile of the device.

Supported on Android 10.0 or later.

Allow Sharing from Work Profile to Personal When enabled, device users can use an app's Share function to share between apps on the Work profile to apps on the Personal profile.

Android OS compatibility: 5.1.1 or later.

Allow Outgoing NFC When enabled, devices users can use NFC to send data (only applies to apps in the Work Profile).
Allow Bluetooth Contact Sharing When enabled, device users can use Bluetooth to share contact information.

Android OS compatibility: 6.0 or later.

Allow Backup Service When enabled, device users can turn control whether the backup service (which managers both backup and restore services) is turned on or off.

Policy Messaging

Restriction Policy

Enter the message that should appear to device users when they try to perform an action blocked by feature control.

Note: If you leave this field empty, the following default message will appear to device users: This action is disabled by SOTI MobiControl. Contact your organization's administrator to learn more.

Android OS compatibility: 7.0 or later.

Device Admin Description

Enter the description that should appear if the user presses the more prompt on the restriction policy.

Android OS compatibility: 7.0 or later.

Work Profile Wipe Message

Enter the message that should appear to device users when the Android Work Profile is wiped of its data and removed from the device.

Android OS compatibility: 9.0 or later.