Getting Started Guide
There are 3 main steps in getting started with CubiLock:
Manage your applications
Create your profile
Enrol your devices
Below is the quick walkthrough of these steps. If you would like to dig deeper, please check out the relevant section of our Help Center.
Step 1: Manage Your Applications
Once you’ve logged in to the console, one of the first steps is to define which applications you want to manage for your organization. In the App Management section you can manage all the applications authorized for installation on your Android Devices. You can manage three different types of applications:
Public Apps: Allows you to publish and manage apps available on the public Google Play Store
Private Apps: Allows you to publish and manage private apps for your enterprise
Web Apps: Allows you to publish and distribute website shortcuts as apps
1.1. Public Applications
From the App Management, go to the PlayStore Apps if you want to add a public application. Select the app you want to approve. For example Slack. Select and click on it to add in your Enterprise Apps.
From your CubiLock console:
Head over to PlayStore Apps page, under Application Management
Search for the Slack application and click on it to open its details
Click on Select to add in your Enterprise Apps
The Slack application now appears in the Enterprise Apps page


For more details on how to add/approve public applications head over to Public Apps section.
1.2. Private Applications
You can also add a private applications from EMM console. From the App Management, head over to PlayStore Apps page and choose Private Apps from the iframe. The Private apps page allows you to publish and manage private apps directly from your EMM console. Specify your app name in the Title field, and upload your APK file. To streamline private app publishing for you, the page:
Silently creates a Play Console account on behalf of the enterprise and grants admin access to IT admins.
Waives the $25 USD Play Console registration fee previously required to publish apps.
Requires only an app’s APK and title.
Publishes apps in as little as 10 minutes (compared to 2 hours in the Play Console).
Note: Apps published from the Private apps page can never be made public.
Upload Private Apps to Your Managed PlayStore:
From your CubiLock dashboard:
Go to the PlayStore Apps page, under Application Management
Select Private Apps from iframe
On the bottom right corner, click on the plus sign
Specify your app name in the Title field, and upload your APK file
Click on the button Create

The first time you publishes an app in the iframe, the iframe silently creates a Play Console account on behalf of the enterprise. If you want to make advanced edits, you're prompted to sign in with a Google Account—this can be any Google Account (e.g. Gmail, Cloud Identity). This Google Account is added as an admin of the enterprise's Play Console account. Afterwards, you can use your Google Account to sign into the Play Console directly, where you can:
Add and manage admin accounts.
Add advanced app details, including a descriptions, screenshots, and more.
Un-publish apps.
For more details on how to add/approve public applications head over to Private Apps section.
1.3. Web Applications
You can also add web applications from EMM console. From the App Management, head over to PlayStore Apps page and choose Private Apps from the iframe. The Web apps page lets you publish website shortcuts as private apps to managed Google Play. Web apps are identifiable by their package name (productId) and typically take 10 minutes to publish. After publishing, they’re automatically approved for your enterprise and can be distributed to users just like any other approved app. Web apps are compatible with other managed Play iframe features: they’re searchable in the Play Search page and can be added to collections.
The web app creation form requires a title, HTTPS or HTTP URL, and icon image (512 x 512 JPG or 32-bit PNG). Additionally, you can choose from the three display options:
Full screen: The app opens in full screen mode, hiding the device's status bar and navigation bar.
Standalone (default): The app shows the device's status bar and navigation bar.
Minimal UI: The app shows the device's status bar and navigation bar, the app's URL, and a refresh option. For HTTP URLs, this is the only available option.
Publish Web Apps From Google PlayStore:
From your CubiLock dashboard:
From the App Management, head over to PlayStore Apps page and choose Web Apps
On the bottom right corner, click on the plus button
Specify your web app Title, URL, Display and Icon
Click on the button Create
Your web app appears in the Enterprise Apps tab

You can see all your managed applications - public, private and web applications in the Enterprise Apps menu.
For more details on how to add/approve public applications head over to Web Apps section.
Step 2: Create a Profile
Profiles (sometimes also called policies) are the central element in Android Enterprise‑based EMM solutions. A profile is a named set of device and app management settings that you apply to a group of devices. Each profile can contain a unique policy configuration and target a specific use case.
A device can only have one profile applied at a time. Devices that do not have a profile applied will be restricted and unable to function until the profile is assigned. Under the Android Management API behavior, if a policy (profile) is not applied within a short period during enrollment, the device enrolment may fail or the device may factory reset.
2.1. Create a Profile
Navigate to the Device Profiles Page
Go to Device Management > Device Profiles in the CubiLock console.
Click Create New Profile (top right of the page).
Enter a Profile Name
In the Profile field, enter a unique name for the profile.
The name should clearly identify the purpose or target use case (e.g., Sales Devices, Kiosk Check‑In, Warehouse Scanners, etc.)
Profile Type
Short Description (UI)
What It Is (Android Enterprise)
Typical Use Cases
Work Profile Mode
I am using my own device and want to keep work and personal data separate.
A work profile creates a separate container for work apps and data on a device; personal apps/data remain private and uncontrolled by IT.
BYOD scenarios; Personal device used for work while keeping personal data private.
Dedicated App Mode
I have a brand new company device that serves a specific purpose and I want the company to manage entirely.
Also called Dedicated Device Mode (or kiosk), devices are fully managed and locked to one app or specific set of apps in a controlled environment.
Kiosks, digital signage, single‑purpose terminals such as check‑in stations.
Fully Managed App Mode
I have a brand new company device which I want the company to manage entirely.
Fully managed (device owner) gives IT full control over device and policies, managing all apps, settings, restrictions, and security features across the whole device.
Company‑owned phones/tablets where full governance is required; enterprise devices not used for personal purposes.

Finish and Create
After choosing the mode, click Create.
The new profile will be added to the list of Device Profiles.
Once created, you can configure policies, assign apps, and set restrictions for that profile.
2.2. Configure Profile
After you create a device profile in CubiLock, you need to configure the policies and settings that control how devices behave once the profile is applied.
When you create a profile it will appear in the Device Profiles list. From here you can update, duplicate, or configure the profile further.
Editing an Existing Profile
To configure a profile you’ve already created:
Go to Device Management > Device Profiles.
Find the profile you want to edit.
Click the three‑dot menu at the right of the profile row.
Select Update Profile.
This will open the Edit Device Profile page, where you can view and adjust all available settings for that profile.

Edit Device Profile Page
On the Edit Device Profile screen you will see multiple tabs including:
Applications – Configure which apps are installed and how they are managed.
Policies – Apply behavior controls and restrictions (Global Restrictions, User Restrictions, Cross Profile Policies).
Kiosk Settings – Configure kiosk mode behavior (if applicable).
Update Settings – Control system update behavior.
Network Settings – Configure Wi‑Fi, VPN, and network policies.
Privacy Settings – Set privacy related controls such as camera and sharing.
Integrations – Configure third party integrations.
Contact Settings – Set options like contact visibility and sharing.

2.3. Push and Configure Applications
The Applications tab of your Device Profile allows you to define exactly how applications are distributed and managed on devices assigned to this profile.
Once on the Edit Device Profile page, switch to the Applications tab to begin adding, updating, and managing apps for that profile.

2.3.1: Application List Overview
In the Applications section you will see a list of all apps configured for this profile. For each app you can control:
Column
Purpose
Application
Name and package identifier of the app.
Install Type
How the app is installed and behaves on the device.
Auto Update Mode
The update priority for the app (e.g., High Priority).
Default Permission
Default runtime permission policy for the app.
Disabled
Whether the app is disabled on the device.
Visible
Whether the app is visible to end users.
Pin To Dock
Whether the app is pinned to the device launcher dock.
Actions
Additional actions available for the app.

2.3.2: Configure Individual App Settings
Install Type
The Install Type dropdown determines how the application is installed on managed devices. The options available in the current UI are:
Unspecified
Force Installed
Pre Installed
Blocked
Available
Required For Setup

Here’s what each means:
Install Type
Meaning / Behavior
Unspecified
No specific install behavior is applied. The app may be controlled by other policies (like PlayStore settings) or not managed at all.
Force Installed
The app is automatically installed and cannot be removed by the user.
Pre Installed
The app is automatically installed but can be removed by the user.
Blocked
The app cannot be installed. If it is already on the device from a prior policy, it will be uninstalled.
Available
The app appears in Managed Google Play on the device, and the user may install/uninstall it at will.
Required For Setup
The app must be installed before device setup can finish. The app is automatically installed and cannot be removed by the user.
2.3.3 Auto Update Mode
For each app, you can select an Auto Update Mode, such as:
High Priority – Updates are pushed quickly and with priority.
Unspecified – Default behavior; no explicit update priority set.
This controls how and when app updates are applied to managed devices.
2.3.4 Default Permissions
From the Default Permission dropdown, you can define a default runtime permission policy for the app (e.g., allow all, deny all, or prompt). This simplifies mass permission handling for managed apps.
2.3.5 Additional App Actions
In the Actions column (three‑dot menu), you’ll find additional controls:
Action
Purpose
App Track
Assign which release track to use (e.g., production, beta).
Permissions
Configure detailed app permission settings.
Set Min Version
Specify the minimum required version of the app.
Delegated Scope
Define delegated scopes if applicable.
Credential Provider
Enable credential provider behavior (for Android 14+ apps).
2.3.6 How to Add / Remove Apps
Add an App: Click + Choose application to pick applications from your Managed Google Play catalog or private apps you’ve uploaded.
Remove an App: Select one or more apps using the checkboxes and click Remove application to remove them from this profile.
2.3.7 Key Points
Only one kiosk install type per profile can be set (if your profile is in kiosk mode).
The policies and install types you configure here apply to all devices that use this profile.
If an app is marked Blocked, it will be removed from devices if already installed under a previous configuration.
Step 3: Enrol the Device
Once you have created and configured a Device Profile, the next step is to enroll Android devices with that profile so they become manageable under CubiLock.
CubiLock supports multiple Android Enterprise enrollment methods that let you provision devices with minimal user interaction. These include:
QR Code Enrollment (recommended)
URL‑based Enrollment (Sign‑in URL)
DPC Identifier Enrollment (afw#setup)
NFC Enrollment (where hardware permits)
Android Zero‑Touch Enrollment for large fleets

Once your enrollment settings (SSID, password, language, system apps, etc.) are configured, CubiLock generates a QR code tied to that Device Profile.
To enroll a device using the QR code:
Reset the device to factory defaults (required for most Android Enterprise provisioning methods).
Turn on the device — at the first Welcome screen:
Tap the screen six times in the same spot to launch the built‑in QR scanner.
(If that doesn’t work on older devices, use the DPC identifier method by entering
afw#setupwhen prompted for an email).
Connect to Wi‑Fi (the device will use the SSID and password encoded in the QR code).
Scan the QR code displayed on the right side of the Device Enrollment page.
The Android Device Policy app is downloaded automatically and begins provisioning.
Follow on‑screen instructions to finalize setup — once complete, CubiLock policies, apps, and restrictions are applied automatically.
💡 Tip: If the QR code expires, click Refresh QR code to generate a new one. New QR codes include your updated Wi‑Fi and localization settings.
Check out our video of a Device Owner enrolment below:
Last updated