# CubiLock Guide

Welcome to the CubiLock user guide! Get familiar with the features and how they work

## What is CubiLock?

CubiLock is an Enterprise Mobility Management solution that mitigates IT challenges in driving enterprise mobility for your business with easy device deployment, security & app distribution. CubiLock helps streamline everything you need for painless management of your devices.

## Features

1. **Enforce Passcode Policy** Enforce strong password policies to protect critical company data stored on mobile devices.
2. **Factory Reset Protection** Allow/block the specific Google Accounts that can be used to sign-in to the device if they are factory reset.
3. **Detect Compliance Violations** Empower the IT admin to detect any compliance violations and take appropriate actions accordingly.
4. **Kiosk Mode** IT admin can lock a device into Kiosk mode and prevent access to system settings or any other apps.
5. **Control Screen Capture** Restrict your employees from taking Screenshots of Work Apps on their Personal Devices.
6. **Remote Wipe/Factory Reset** Allow the IT admin to remote wipe/factory reset device to prevent data loss or theft.
7. **Administrator Activity Logs** Get insights into the activities performed by admin on the CubiLock dashboard.
8. **Configure Wifi Settings** Push WiFi settings, blocking device connection to unidentified networks.
9. **SafetyNet Attestation** Perform Android device integrity, security, and compatibility check and assign policies accordingly.
10. **QR Code/URL based enrolment** Create QR codes and URLs for specific device policies and send them to users over email. End-users can scan the QR code using the device camera or access the URL to enrol the devices.
11. **Application Management** Select apps available on the Google Play Store. Push on Android devices. Configure, update or uninstall remotely.

## Support

If you need any help with the installation and set-up, reach out to support via email <support@cubilock.com> or call directly at [+45 3615 3600](tel:+45%203615%203600)


# Getting Started Guide

There are 3 main steps in getting started with CubiLock:&#x20;

1. Manage your applications
2. Create your profile
3. Enrol your devices

Below is the quick walkthrough of these steps. If you would like to dig deeper, please check out the relevant section of our Help Center.

## Step 1: Manage Your Applications

Once you’ve logged in to the console, one of the first steps is to define which applications you want to manage for your organization. In the **App Management** section you can manage all the applications authorized for installation on your Android Devices. You can manage three different types of applications:

* **Public Apps:** Allows you to publish and manage apps available on the public Google Play Store
* **Private Apps:** Allows you to publish and manage private apps for your enterprise
* **Web Apps:** Allows you to publish and distribute website shortcuts as apps

### 1.1. Public Applications

From the **App Management**, go to the **PlayStore Apps** if you want to add a public application. Select the app you want to approve. For example Slack. Select and click on it to add in your **Enterprise Apps**.

From your CubiLock console:

1. Head over to **PlayStore Apps** page, under **Application Management**
2. Search for the **Slack** application and click on it to open its details
3. Click on **Select** to add in your **Enterprise Apps**
4. The Slack application now appears in the **Enterprise Apps** page

![Search for the Slack application and click on it to open its details](/files/oT8Tm5zciQpHuf4GyMpl)

![](/files/yiZQEttHgdOXnwIH8tsl)

{% hint style="info" %}
For more details on how to add/approve public applications head over to [**Public Apps**](https://docs.cubilock.com/application-management/public-apps) section.&#x20;
{% endhint %}

### 1.2. Private Applications

You can also add a private applications from EMM console. From the **App Management**, head over to **PlayStore Apps** page and choose **Private Apps** from the iframe. The Private apps page allows you to publish and manage private apps directly from your EMM console. Specify your app name in the **Title** field, and upload your APK file. To streamline private app publishing for you, the page:

* Silently creates a Play Console account on behalf of the enterprise and grants admin access to IT admins.
* Waives the $25 USD Play Console registration fee previously required to publish apps.
* Requires only an app’s APK and title.
* Publishes apps in as little as 10 minutes (compared to 2 hours in the Play Console).

{% hint style="info" %}
**Note:** Apps published from the Private apps page can never be made public.
{% endhint %}

### Upload Private Apps to Your Managed PlayStore:

From your CubiLock dashboard:

1. Go to the **PlayStore Apps** page, under **Application Management**
2. Select **Private Apps** from iframe
3. On the bottom right corner, click on the plus sign
4. Specify your app name in the **Title** field, and upload your **APK** file
5. Click on the button **Create**

![](/files/c6sOgeNeJOD29E4f7Zoa)

The first time you publishes an app in the iframe, the iframe silently creates a Play Console account on behalf of the enterprise. If you want to make advanced edits, you're prompted to sign in with a Google Account—this can be any Google Account (e.g. Gmail, Cloud Identity). This Google Account is added as an admin of the enterprise's Play Console account. Afterwards, you can use your Google Account to sign into the Play Console directly, where you can:

* Add and manage admin accounts.
* Add advanced app details, including a descriptions, screenshots, and more.
* Un-publish apps.

{% hint style="info" %}
For more details on how to add/approve public applications head over to [**Private Apps**](https://docs.cubilock.com/application-management/private-apps) section.&#x20;
{% endhint %}

### 1.3. Web Applications

You can also add web applications from EMM console. From the **App Management**, head over to **PlayStore Apps** page and choose **Private Apps** from the iframe. The Web apps page lets you publish website shortcuts as private apps to managed Google Play. Web apps are identifiable by their package name (productId) and typically take 10 minutes to publish. After publishing, they’re automatically approved for your enterprise and can be distributed to users just like any other approved app. Web apps are compatible with other managed Play iframe features: they’re searchable in the Play Search page and can be added to collections.

The web app creation form requires a **title**, HTTPS or HTTP **URL**, and **icon** image (512 x 512 JPG or 32-bit PNG). Additionally, you can choose from the three display options:

* **Full screen:** The app opens in full screen mode, hiding the device's status bar and navigation bar.
* **Standalone (default):** The app shows the device's status bar and navigation bar.
* **Minimal UI:** The app shows the device's status bar and navigation bar, the app's URL, and a refresh option. For HTTP URLs, this is the only available option.

### Publish Web Apps From Google PlayStore:

From your CubiLock dashboard:

1. From the **App Management**, head over to **PlayStore Apps** page and choose **Web Apps**
2. On the bottom right corner, click on the plus button
3. Specify your web app **Title**, **URL**, Display and **Icon**
4. Click on the button **Create**
5. Your web app appears in the **Enterprise Apps** tab

![](/files/c6d73zHXKcjq8DsSJqyT)

You can see all your managed applications - public, private and web applications in the **Enterprise Apps** menu.

{% hint style="info" %}
For more details on how to add/approve public applications head over to [**Web Apps**](https://docs.cubilock.com/application-management/web-apps) section.&#x20;
{% endhint %}

## Step 2: Create a Profile

Profiles (sometimes also called *policies*) are the central element in Android Enterprise‑based EMM solutions. A profile is a named set of device and app management settings that you apply to a group of devices. Each profile can contain a unique policy configuration and target a specific use case.

A device can only have **one profile applied at a time**. Devices that do not have a profile applied will be restricted and unable to function until the profile is assigned. Under the Android Management API behavior, if a policy (profile) is not applied within a short period during enrollment, the device enrolment may fail or the device may factory reset.

### 2.1. Create a Profile

#### **Navigate to the Device Profiles Page**

1. Go to **Device Management > Device Profiles** in the CubiLock console.
2. Click **Create New Profile** (top right of the page).

#### **Enter a Profile Name**

* In the **Profile** field, enter a unique name for the profile.
* The name should clearly identify the purpose or target use case (e.g., *Sales Devices*, *Kiosk Check‑In*, *Warehouse Scanners*, etc.)

| **Profile Type**           | **Short Description (UI)**                                                                                  | **What It Is (Android Enterprise)**                                                                                                                                    | **Typical Use Cases**                                                                                                |
| -------------------------- | ----------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- |
| **Work Profile Mode**      | I am using my own device and want to keep work and personal data separate.                                  | A work profile creates a separate container for work apps and data on a device; personal apps/data remain private and uncontrolled by IT.                              | *BYOD scenarios; Personal device used for work while keeping personal data private*.                                 |
| **Dedicated App Mode**     | I have a brand new company device that serves a specific purpose and I want the company to manage entirely. | Also called *Dedicated Device Mode* (or kiosk), devices are fully managed and locked to one app or specific set of apps in a controlled environment.                   | *Kiosks, digital signage, single‑purpose terminals such as check‑in stations*.                                       |
| **Fully Managed App Mode** | I have a brand new company device which I want the company to manage entirely.                              | Fully managed (device owner) gives IT full control over device and policies, managing all apps, settings, restrictions, and security features across the whole device. | *Company‑owned phones/tablets where full governance is required; enterprise devices not used for personal purposes*. |

![](/files/eNgdWRqSLQCoj58d3CZz)

#### **Finish and Create**

3. After choosing the mode, click **Create**.
4. The new profile will be added to the list of Device Profiles.
5. Once created, you can **configure policies, assign apps, and set restrictions** for that profile.

### 2.2. Configure Profile

After you create a device profile in CubiLock, you need to configure the policies and settings that control how devices behave once the profile is applied.

When you create a profile it will appear in the **Device Profiles** list. From here you can update, duplicate, or configure the profile further.

#### **Editing an Existing Profile**

To configure a profile you’ve already created:

1. Go to **Device Management > Device Profiles**.
2. Find the profile you want to edit.
3. Click the **three‑dot menu** at the right of the profile row.
4. Select **Update Profile**.

This will open the **Edit Device Profile** page, where you can view and adjust all available settings for that profile.

![](/files/WF5dEJMxt2XQG78EAcSz)

#### **Edit Device Profile Page**

On the **Edit Device Profile** screen you will see multiple tabs including:

* **Applications** – Configure which apps are installed and how they are managed.
* **Policies** – Apply behavior controls and restrictions (Global Restrictions, User Restrictions, Cross Profile Policies).
* **Kiosk Settings** – Configure kiosk mode behavior (if applicable).
* **Update Settings** – Control system update behavior.
* **Network Settings** – Configure Wi‑Fi, VPN, and network policies.
* **Privacy Settings** – Set privacy related controls such as camera and sharing.
* **Integrations** – Configure third party integrations.
* **Contact Settings** – Set options like contact visibility and sharing.

![](/files/evDdXHl40KNmv85OX6EC)

### 2.3. Push and Configure Applications

The **Applications** tab of your Device Profile allows you to define exactly how applications are distributed and managed on devices assigned to this profile.

Once on the **Edit Device Profile** page, switch to the **Applications** tab to begin adding, updating, and managing apps for that profile.

![](/files/wspjf3HR1S2ywDdwwyKD)

**2.3.1: Application List Overview**

In the Applications section you will see a list of all apps configured for this profile. For each app you can control:

| **Column**             | **Purpose**                                                |
| ---------------------- | ---------------------------------------------------------- |
| **Application**        | Name and package identifier of the app.                    |
| **Install Type**       | How the app is installed and behaves on the device.        |
| **Auto Update Mode**   | The update priority for the app (e.g., **High Priority**). |
| **Default Permission** | Default runtime permission policy for the app.             |
| **Disabled**           | Whether the app is disabled on the device.                 |
| **Visible**            | Whether the app is visible to end users.                   |
| **Pin To Dock**        | Whether the app is pinned to the device launcher dock.     |
| **Actions**            | Additional actions available for the app.                  |

![](/files/-MB-NrPm1lXV4AE6AVk-)

**2.3.2: Configure Individual App Settings**

**Install Type**

The **Install Type** dropdown determines how the application is installed on managed devices. The options available in the current UI are:

* Unspecified
* Force Installed
* Pre Installed
* Blocked
* Available
* Required For Setup

![](/files/2wNmlUxuanUZseckLr1L)

Here’s what each means:

| **Install Type**       | **Meaning / Behavior**                                                                                                                |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified**        | No specific install behavior is applied. The app may be controlled by other policies (like PlayStore settings) or not managed at all. |
| **Force Installed**    | The app is automatically installed and cannot be removed by the user.                                                                 |
| **Pre Installed**      | The app is automatically installed but *can be removed* by the user.                                                                  |
| **Blocked**            | The app cannot be installed. If it is already on the device from a prior policy, it will be *uninstalled*.                            |
| **Available**          | The app appears in *Managed Google Play* on the device, and the user may install/uninstall it at will.                                |
| **Required For Setup** | The app must be installed before device setup can finish. The app is automatically installed and cannot be removed by the user.       |

#### **2.3.3 Auto Update Mode**

For each app, you can select an **Auto Update Mode**, such as:

* **High Priority** – Updates are pushed quickly and with priority.
* **Unspecified** – Default behavior; no explicit update priority set.

This controls how and when app updates are applied to managed devices.

#### **2.3.4 Default Permissions**

From the **Default Permission** dropdown, you can define a default runtime permission policy for the app (e.g., allow all, deny all, or prompt). This simplifies mass permission handling for managed apps.

#### **2.3.5 Additional App Actions**

In the **Actions** column (three‑dot menu), you’ll find additional controls:

| **Action**              | **Purpose**                                                 |
| ----------------------- | ----------------------------------------------------------- |
| **App Track**           | Assign which release track to use (e.g., production, beta). |
| **Permissions**         | Configure detailed app permission settings.                 |
| **Set Min Version**     | Specify the minimum required version of the app.            |
| **Delegated Scope**     | Define delegated scopes if applicable.                      |
| **Credential Provider** | Enable credential provider behavior (for Android 14+ apps). |

#### **2.3.6 How to Add / Remove Apps**

* **Add an App:** Click **+ Choose application** to pick applications from your Managed Google Play catalog or private apps you’ve uploaded.
* **Remove an App:** Select one or more apps using the checkboxes and click **Remove application** to remove them from this profile.

#### **2.3.7 Key Points**

* **Only one kiosk install type per profile** can be set (if your profile is in kiosk mode).
* The policies and install types you configure here apply to all devices that use this profile.
* If an app is marked **Blocked**, it will be removed from devices if already installed under a previous configuration.

## Step 3: Enrol the Device

Once you have created and configured a Device Profile, the next step is to **enroll Android devices** with that profile so they become manageable under CubiLock.

CubiLock supports multiple Android Enterprise enrollment methods that let you provision devices with minimal user interaction. These include:

* **QR Code Enrollment** (recommended)
* **URL‑based Enrollment** (Sign‑in URL)
* **DPC Identifier Enrollment** (afw#setup)
* **NFC Enrollment** (where hardware permits)
* **Android Zero‑Touch Enrollment** for large fleets

![](/files/L9TeHY1OX0hqDSYk9Hlh)

Once your enrollment settings (SSID, password, language, system apps, etc.) are configured, CubiLock generates a **QR code** tied to that Device Profile.

To enroll a device using the QR code:

1. **Reset the device to factory defaults** (required for most Android Enterprise provisioning methods).
2. Turn on the device — at the first Welcome screen:
   * Tap the screen **six times** in the same spot to launch the built‑in QR scanner.
   * (If that doesn’t work on older devices, use the **DPC identifier** method by entering `afw#setup` when prompted for an email).
3. **Connect to Wi‑Fi** (the device will use the SSID and password encoded in the QR code).
4. Scan the **QR code** displayed on the right side of the Device Enrollment page.
5. The Android Device Policy app is downloaded automatically and begins provisioning.
6. Follow on‑screen instructions to finalize setup — once complete, CubiLock policies, apps, and restrictions are applied automatically.

> 💡 **Tip:** If the QR code expires, click **Refresh QR code** to generate a new one. New QR codes include your updated Wi‑Fi and localization settings.

Check out our video of a Device Owner enrolment below:

{% embed url="<https://www.youtube.com/watch?v=I4D2r2ro89Q>" %}
Fully Managed Device Enrolment Using QR Code
{% endembed %}


# Dashboard

When you log in to the CubiLock EMM Console, the first screen you see is the **Dashboard**. It gives you a **high‑level overview** of your entire device fleet and management status at a glance — *without navigating through multiple pages*.

The CubiLock dashboard provides key metrics and visual summaries that help you quickly understand how your enterprise devices are configured and performing. These insights help IT administrators assess their environment, spot issues, and verify compliance with policies efficiently

![](/files/gIm30i3L9E5YA7ZCEboz)

Summary Panel

| **Metric**        | **What It Shows**                               |
| ----------------- | ----------------------------------------------- |
| **Profiles**      | Total number of device profiles created.        |
| **Users**         | Number of admin users in your CubiLock account. |
| **Total Devices** | Total number of devices currently enrolled.     |

#### Profile Types Panel

This displays counts of devices segmented by profile types:

| **Profile Type** | **Meaning**                                     |
| ---------------- | ----------------------------------------------- |
| Fully Managed    | Devices fully controlled by the enterprise.     |
| Work             | Work profiles for BYOD scenarios.               |
| Dedicated        | Devices configured in kiosk/dedicated use mode. |

#### Profile Assignments Chart

Shows the distribution of devices across different device profiles. Each slice represents how many devices are assigned to a specific profile.

#### Devices Make & Models

Visual breakdown of devices by manufacturer and model helps you identify the most common hardware in your fleet.

The dashboard helps you assess device deployment, configuration states, and fleet diversity all in one place — saving time and aiding operational decisions.:contentReference\[oaicite:7]{index=7}


# Useful Videos


# Profile Management


# How to setup actions in CubiLock

{% embed url="<https://youtu.be/JASFjGHsAPM>" %}
setup actions
{% endembed %}


# How to set auto update mode in CubiLock

{% embed url="<https://youtu.be/2kyVrMG_flM>" %}
auto update mode
{% endembed %}


# How to set min version of an app in CubiLock

{% embed url="<https://youtu.be/AJhHqFWsXIo>" %}
set min version
{% endembed %}


# How to set an app track in CubiLock

{% embed url="<https://youtu.be/OFa_Whu623s>" %}
set an app track
{% endembed %}


# Device Management


# CubiLock Enrolment

{% embed url="<https://www.youtube.com/watch?v=I4D2r2ro89Q>" %}
Fully Managed Device Enrolment Using QR Code
{% endembed %}


# How to clear profile data in CubiLock

{% embed url="<https://www.youtube.com/watch?v=LQOzfAspoUM>" %}
clear profile data
{% endembed %}


# How to force sync changes in CubiLock

{% embed url="<https://youtu.be/FwLPX833heE>" %}
force sync
{% endembed %}


# How to launch an app from CubiLock

{% embed url="<https://youtu.be/sEimLXp1i24>" %}
launch an app
{% endembed %}


# How to re-enroll a device in CubiLock

{% embed url="<https://youtu.be/OjC8rZdXvws>" %}
re-enroll device
{% endembed %}


# How to clear app data in CubiLock

{% embed url="<https://youtu.be/amB69NfgdQA>" %}
clear app data
{% endembed %}


# File Management


# How to push an APK from CubiLock

{% embed url="<https://youtu.be/ICacetJ-6xA>" %}
push an APK
{% endembed %}


# How to upload a file in CubiLock

{% embed url="<https://youtu.be/-yQSS0xffmM>" %}
file upload
{% endembed %}


# Public Apps

How to Approve Public Apps?


# Approve Public Apps

How to Approve Public Apps?

Once you logged in to the **CubiLock** console, one of the first steps is to define which applications you want to manage for your enterprise. In the **App Management** section you can manage all the applications authorized for installation on your Android Devices. If you want to add a public application, head over to the **PlayStore Apps** page. Select the app you want to approve, click on it to add in your **Enterprise Apps**.

### Approve Public Apps From the Google PlayStore:

From your CubiLock console:

1. Head over to the **PlayStore Apps** page, under **Application Management**
2. Search for the **Slack** application, and select it for management

![](/files/oT8Tm5zciQpHuf4GyMpl)

3\. Approve the app from its listing by clicking on **Select** button.

![](/files/yiZQEttHgdOXnwIH8tsl)

4\. Add the app into **Enterprise Apps** by clicking on **Add** button.

![](/files/CYOGHKX0h5NYi4uzUPsE)

5\. You can also add this app directly into the Profile by specifying the **Install Type** and selecting **Profiles** you want to add this application to and hit **Apply**.

![](/files/7eV9FNq0K4rL46kncQTf)

> There are 6 install types available for your applications:
>
> 1. **Force installed**: The app is automatically installed and can't be removed by the user.
> 2. **Available**: To list the app in the Managed Google Play accessible from the device. The user can install and uninstall the app anytime.
> 3. **Preinstalled:** The app is automatically installed and can be removed by the user.
> 4. **Blocked:** The app is blocked and can't be installed. If the app was installed under a previous policy, it will be uninstalled.
> 5. **KIOSK:** The app is automatically installed in kiosk mode: it's set as the preferred home intent and whitelisted for lock task mode. Device setup won't complete until the app is installed. After installation, users won't be able to remove the app. You can only set this `installType` for one app per policy. When this is present in the policy, status bar will be automatically disabled.
> 6. **Required for setup**: The app is automatically installed and can't be removed by the user and will prevent setup from completion until installation is complete.

6\. Slack will now appear in your **Enterprise Applications** page

![](/files/tngfzB3Ra1DOc4Mny8IE)


# Support Managed Configurations

How to Whitelist/Blacklist URLs With the Chrome App?

Some apps designed for enterprises include built-in settings called **Managed Configurations** that IT admins can configure remotely. For example, an app may have the option to only sync data when a device is connected to Wi-Fi. Providing IT admins the ability to specify managed configurations and apply them to devices is a requirement for all [solution sets](https://developers.google.com/android/work/requirements).&#x20;

This article explains how to block or allow some specific URLs with the Chrome app, using its Managed Configuration.&#x20;

### To access the Chrome Managed Configuration:

![](/files/-MBD6d2UVHO_E65dPy18)

From your CubiLock dashboard:

1. Head over to the **PlayStore Apps** page, under **Application Management**
2. Select **Public Apps** from iframe&#x20;
3. Search for the **Chrome** application, and select it for management
4. Approve the app from its listing by clicking on **Select** button
5. Add the app into **Enterprise Apps** by clicking on **Add** button
6. You can also add this app directly into the Profile by specifying the **Install Type** and selecting **Profiles** you want to add this application to and hit **Apply**
7. Head over to the **Device Profile** page
8. From the context menu choose **Update Profile**, you will be navigated to **Edit Device Profile** page.
9. In the **Applications** tab of your Profile, click on **Configurations** next to the **Chrome** app

![](/files/-MBD7M_xgq3rfLejeN2v)

### To Block URLs

To block an URL or a list of URLs, locate the **Block access to a list of URLs** entry, using the search engine. Enter the list of URLs following this pattern:`["blacklist1.com","blacklist2.org","anothersite.net"]`

![](/files/-MBDOG_fQZnmIUpgr-S5)

{% hint style="info" %}
Note: if you want to block all URLs, enter this:`["*"]` &#x20;
{% endhint %}

### To Authorize URLs&#x20;

If you want to only authorize URLs, locate the **Allow access to a list of URLs**, using the search engine. Enter the list of URLs following the same pattern as above:`["wikipedia.org","google.com"]`

Do not use wildcards `*` in the URL (except to blacklist everything), else it won’t work. For example, blocking all Facebook sites by specifying `["*.facebook.com"]` won’t work. Simple use `["facebook.com"]` instead.&#x20;

![](/files/-MBDNcl1pplkTIHne3Wn)


# Private Apps


# Upload & Distribute Private Apps

A private app is an app that’s only available to an enterprise’s users. Private apps are fully compatible with managed Google Play. An enterprise can publish private apps to its managed Google Play store and install private apps remotely to users’ devices.&#x20;

The Private apps page allows you to publish and manage private apps directly from your EMM console. Specify your app name in the **Title** field, and upload your **APK** file. To streamline private app publishing for you, the page:

* Silently creates a Play Console account on behalf of the enterprise and grants admin access to IT admins.
* Waives the $25 USD Play Console registration fee previously required to publish apps.
* Requires only an app’s APK and title.
* Publishes apps in as little as 10 minutes (compared to 2 hours in the Play Console).

**Note:** Apps published from the Private apps page can never be made public.

### Upload Private Apps to Your Managed PlayStore:

Uploading a private app from CubiLock console is quite simple and easy. From your CubiLock dashboard:

1. Head over to the **PlayStore Apps** page, under **Application Management**
2. Select **Private Apps** from iframe
3. On the bottom right corner, click on the plus sign
4. Specify your app name in the **Title** field, and upload your APK file
5. Click on the button **Create**

![](/files/c6sOgeNeJOD29E4f7Zoa)

Specify your app name in the **Title** field, and upload your APK file.

![](/files/-MBEBk0TRk9Jh_C3lbmY)

Once your application has been uploaded to your managed Google Play store, you still need to select it for management. To do so, simply click on your application, then click on the **Select** button. Once your private application is selected, it will appear in your **Enterprise Apps** page.

![](/files/EpMBxHGfPr7qIjhCLI1t)

**Notes:**

* Uploading your private app in your managed Play Store has the huge advantage of benefiting from the Google Play Protect automatic security scanning.&#x20;
* You can also **host your private applications on your own servers**, and distribute them through the Google Play store. [Check this article ](https://docs.cubilock.com/application-management/private-apps/externally-host-private-apps)and contact us for more information.
* Private applications can be distributed to other organizations' managed Google Play store. A private app can be distributed to up to 100 organizations.&#x20;


# Update Private Apps

An app can receive updates if it's installed on a user’s device and is available according to the device's policy. If an app is removed from the device's policy, this device will no longer receive updates for that app.

### On-device Update Settings

You can enforce the update preference by setting **Auto Update Policy** in the device's policy.

If you set **Auto Update Policy** to `choiceToTheUser` or leave it unset, then the device user can set update preferences for their apps from the managed Google Play app. The recommendation is for users to leave auto updates enabled for all their apps.

{% hint style="info" %}
Note that devices check for auto updates daily. Because auto updates are optimized for battery life, data usage, and user experience, it can take up to a few days for a device to receive an update automatically.
{% endhint %}

### How to Push Updates to Your Managed PlayStore:

Updating a private app from CubiLock console is quite simple and easy. From your CubiLock dashboard:

1. Head over to the **PlayStore Apps** page, under **Application Management**
2. Select **Private Apps** from iframe
3. Choose the private app that you wish you update by clicking on its icon
4. Click on **Edit** button, this will take you app details where you can change the name or upload an updated version
5. Click on **Edit** button, this will ask you to choose the **APK** file
6. Once the **APK** is uploaded, click on the button **Save** button

{% hint style="info" %}
Note: It will take 10 mins for the changes to approve from Google
{% endhint %}

![Choose the private app that you wish you update by clicking on its icon](/files/-MBDHvAiENK4Oh1B_qbA)

![Click on Edit button, this will take you app details where you can change the name or upload an updated version](/files/-MBDI-oOFA4nIIfkdIXs)

![Click on Edit button, this will ask you to choose the APK file](/files/-MBDI3sj3UOc4TB0nr_b)


# Externally Host Private Apps

{% hint style="info" %}
**Warning:** Because externally hosted Android Packages (APKs) aren't scanned, the safety of their content can't be guaranteed. Users are informed of this when they access an externally hosted app.
{% endhint %}

Enterprise customers also have the option of hosting their private apps themselves and only using the managed Google Play infrastructure to manage app installation. Self-hosted private apps can be installed on devices running the **Profile Owner** mode of operation, but they aren’t compatible with legacy devices and can only be push installed to devices running the **Device Owner** mode of operation.

To successfully publish a self-hosted private app, an enterprise customer must first build an APK definition file that contains metadata captured from the app's manifest in JSON format. This definition file replaces the APK within Google Play and needs to be uploaded during the publishing process. The detailed guidance on how to generate an APK definition file is as follows:

### Generate JSON Metadata File

To publish a self-hosted private app, a customer must first build an externally-hosted APK definition file (plain-text JSON file). This definition file replaces the APK within Google Play so the app may be hosted externally, containing only a minimal set of information rather than the entire APK itself.

[Google provides a Python script](https://github.com/google/play-work/tree/master/externally-hosted-apks) you can use to generate the file yourself. To use the script, the following must be installed on your machine and available on your system's PATH:

* OpenSSL
* JDK
* Python 2.x
* [Android Asset Packaging Tool](https://developer.android.com/studio/command-line/aapt2)

The JSON file format of this definition file looks like this:

```
{
  "package_name" : "com.example.package.name",
  "version_name" : "0.8",
  "version_code" : 12,
  "minimum_sdk" : 1,
  “maximum_sdk” : 19,
  "application_label" : "My Package Name",
  "file_sha1_base64" : "7qiBi1Z\m8wFmghQUp3H5FwiGRg0=",
  "file_sha256_base64" : "qIiv0CDHW6esQtsAN4fZzc822szPCXsg6bwgx0ZIhP0=",
  "icon_base64" : "base64encodedicon",
  "file_size" : 14638, //bytes
  "certificate_base64" : ["BASE64ENCODEDCERTIFICATE"],
  "externally_hosted_url" : "https://www.example.com/filename.apk",
}
```

Please note that all fields save for `maximum_sdk` are mandatory, and will be evaluated on-device against the APK that is installed to ensure the correct APK has been provided. The JSON object may also include the following additional fields:

```
{
  "package_name" : "com.example.package.name",
  ...
  "externally_hosted_url" : "https://www.example.com/filename.apk",
  “uses-permission” : [{“name”: “android.permission.WRITE_CONTACTS”},
      {“name”:”android.permission.WRITE_EXTERNAL_STORAGE”,
       “maxSdkVersion”:18} ],
  “uses-feature” : [“android.hardware.bluetooth", "android.hardware.camera”],
}
```

Please ensure that the permissions required by the app are present in the JSON file and correct, to avoid your app being unable to access the correct features when installed on the device.

### Android for Work Self-Hosting Tool

This is a Google-developed tool for generating definition files from APKs. You will need aapt installed on your machine, and available on your system’s **PATH**. Execute using the following command, replacing where appropriate:

```
python externallyhosted.py --apk=<path/to/apk.apk> \
  --externallyHostedUrl="<https://www.example.com/test.apk>”
```

This will print the required contents of the definition file to your console.

### Authenticating the download on the Enterprise Server

When the Google Play client makes a request to download the self-hosted APK from an enterprise server, the request will include a cookie which contains a JSON Web Token.

We strongly recommend that you use a standard library (which are available in many languages) to decode the JWT, in order to ensure all verification is correctly performed before accepting the authentication token (this includes ensuring the token has not expired).

The public key needed to verify the JWT is unique to the application, and available in the Google Play Developer Console in the application’s **“Services and API”** section, listed under **“your license key for this application.”** The private key is owned by Google, so the signature confirms the authenticity of the request.

Once verified and decoded, the JWT will provide the following information about the download request:

```
{
  “aud” : “https://www.example.com/test.apk”,
  “uri-query” : “url_param_1=5&url_param_2=test”, // URL query parameters
  “iss” : “https://play.google.com”,
  “exp” : “<expiry-timestamp>”
  “cid” : “user_id_token”
}
```

Optionally, the user ID token can be matched with a user via the [EMM API](https://developers.google.com/play/enterprise/v1/users/get).


# Delete a Private Application

To delete an application, you must submit a ticket on the Google Play Console support center, by [clicking on this link](https://support.google.com/googleplay/android-developer/contact/publishing).

You will need to submit details of your managed Google Play account, such as:&#x20;

* Developer name
* Developer account ID
* App name
* App package name

You can access these settings on your [Play Console settings page](https://play.google.com/apps/publish/#ProfilePlace). To access this settings page, click on the "**Make Advanced Edits**" link on your private app page, which will bring you to your Google Play console.

![](/files/-MBEOl9NAg1GdhhUfkJW)

On the ticket, you must select the radio button "I want to request for app deletion".

![](/files/-MBEP0-Q4yomzAyopqto)

You must make sure that your application has first been unpublished for 24 hours.&#x20;

To un-publish your app:

1. Go to your [Play Console](https://play.google.com/apps/publish/).
2. Select an app.
3. Select **Store presence** > **Pricing & distribution**.
4. In the "App Availability" section, select **Un-publish**.

Once the ticket submitted, an agent from the Google Play Console support team will get back to you.


# Web Apps

How to Publish Web Apps?

You can also add web applications from EMM console. In order to do that head over to the **App Management** page, go to the **PlayStore Apps** and choose **Web Apps** from the iframe. The Web apps page lets you publish website shortcuts as private apps to managed Google Play.&#x20;

Web apps are identifiable by their **package name** (productId) and typically take 10 minutes to publish. After publishing, they’re automatically approved for your enterprise and can be distributed to users just like any other approved app. Web apps are compatible with other managed Play iframe features: they’re searchable in the Play Search page and can be added to collections.

The web app creation form requires a **Title**, HTTPS or HTTP **URL**, and **icon** image (512 x 512 JPG or 32-bit PNG). Additionally, you can choose from the three display options:

* **Full screen:** The app opens in full screen mode, hiding the device's status bar and navigation bar.
* **Standalone (default):** The app shows the device's status bar and navigation bar.
* **Minimal UI:** The app shows the device's status bar and navigation bar, the app's URL, and a refresh option. For HTTP URLs, this is the only available option.

### Publish Web Apps From Google PlayStore:

From your CubiLock dashboard:

1. From the **App Management**, head over to the **PlayStore Apps** and choose **Web Apps**
2. On the bottom right corner, click on the plus button
3. Specify your web app **Title**, **URL**, Display and **Icon**
4. Click on the **Create** button and wait for Google to approve the web app
5. Once approved, you will be able to add it into your enterprise

![To create a web app, click the plus button.](/files/-MBEPKDEC2DRb9Prh-ek)

Then you need to specify:

* **Title**: that will be shown on Managed PlayStore and the launcher
* **URL**: the web URL that you want to navigate to
* **Display mode**: that defines how the web app will be displayed on the device.

{% hint style="info" %}
You can also set an **icon** for the web app to help users identify it. Icons are optional, but recommended.
{% endhint %}

![Click on the Create button and wait for Google to approve the web app](/files/c6d73zHXKcjq8DsSJqyT)

Once approved, you can add it into your enterprise for your users to use

![Click select to add this web app into your enterprise](/files/ndw62MOdoWwwIQWq9cSl)


# System Apps

How to Whitelist System Apps?

A system application is a native application which comes built-in with shipped devices. Using the CubiLock console, you can approve which system apps you want to whitelist for use in your profiles.

The approval of system apps is done after first enrolment of a device model. Once you have enrolled a device, your CubiLock console will keep in memory the system apps of the enrolled model, even if you un-enrol all of your devices.

### To Approve System Apps for Enterprise:

From your CubiLock dashboard:

1. Head over to the **System Apps** page, under **Application Management**
2. Search for the **device model** (of which you want to manage the system apps) from the dropdown menu. If your device model does not appear, please enrol your device with any profile.
3. The systems apps of the selected device model will appear
4. Select one or more **System Apps**
5. Click **Add**
6. The selected system applications are now approved for use in your profiles
7. You can now add them into your profile from **Edit Device Profile** page

![](/files/-MBEPeg5UWVaNtJoPZlQ)

Once approved, the **System Apps** will appear in your **Enterprise Apps** page.


# Organize Apps

Managed Google Play's Organize apps feature lets you group work apps into collections. Collections are displayed on the front page of the managed Play Store app, giving your users quick and easy access to the apps they need for work. You can use collections to organize apps into different categories. For example, you can create an **Essentials** collection for frequently used apps, and an **Expenses** collection for apps related to tracking costs, logging travel, etc.

In the managed Play Store app, each collection is displayed as a row of apps on the homepage. Users can identify collections by their title (Essentials or Expenses, for example), and can scroll horizontally to view all the apps in a collection.

### Before You Begin

Only approved apps can be added to a collection. Before you can create a collection, you need to approve apps for your organization. The managed Play Store app automatically displays a collection if it contains at least one app that's been made available to the user. Any app in a collection that hasn't been made available to a user will be automatically hidden in the user's managed Play store app.

### 1. Create a Collection

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. Click **Create a collection.**\
   **Note:** You can create up to 30 collections.
3. Name the collection and click **Next**.
4. Select up to 100 apps to add to the collection and click **Add apps**. You can use the search bar to find specific apps.
5. At the bottom, click **Save**.

![](/files/W9SYxrnYPFKd0iYNLX7W)

### 2. Edit a Collection

Before you save your changes you can cancel any edits you make by clicking **Cancel** at the bottom of the window. To save your changes, click **Save** at the bottom of the window. Once you save your changes, they can't be undone.

#### 2.1 Add Apps to Collection

{% hint style="info" %}
**Note:** A collection can include a maximum of 100 apps.
{% endhint %}

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. On the left of the collection you want to edit, click Add ![Add](http://storage.googleapis.com/support-kms-prod/jGbiJw2tGliUWOsg332Sj8KxyEiv3nsqQSfm) .
3. Select the apps that you want to add and click **Add apps**. You can use the search bar to find specific apps.
4. At the bottom, click **Save**.

#### 2.2 Reorder Apps in a Collection

1. On the left, click Organize apps![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. Open the collection you want to edit and next to each apps, use the Left arrow ![Left arrow](http://lh3.googleusercontent.com/yABlhnwB_tAJp1QBgiBp06Elq8Ney_qpSRqEUSXnymORQmd7mo1R8WEy7belNAK_UXE=w18) and Right arrow ![Right arrow](http://lh3.googleusercontent.com/ULcgMFTsKraViiF8Q1PGHgkGq8-T1ykA2jrRE2hRTbUydqvVkf_l5QHSJD3HQS5nRZs=w18) to arrange the apps in your preferred order.
3. At the bottom, click **Save**.

#### 2.3 Remove Apps From Collection

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. Open the collection you want to edit and at the top of each app that you want to remove, click Remove ![Remove](http://lh3.googleusercontent.com/S-8mOhgs0iX3vjE8OKn4nVFuSrE2iXyqhJSLHcU9fho61YmlPMMFyoL36Ur0VhypPIs=w18-h18).
3. At the bottom, click **Save**.

#### 2.4 Rename a Collection

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. In the collection you want to rename, click Edit ![Edit](http://lh3.ggpht.com/-xujKpwhmzZcDSmXNewBe_6-oam__hvkMLO72Ej0PFQUghHxGj7xOtpy4AtLIvjnh3Kn=w18-h18).
3. Enter a new name for the collection and click **OK**.
4. At the bottom, click **Save**.

#### 2.5 Reorder Collections

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. On the right of each collection you want to reorder, use the Up arrow ![Up arrow](http://lh3.googleusercontent.com/GRdr0nu0fp--9vYehIgPrA1cU4uWNcyIRUN8YaTUQzJUdIW3liUd4vzG9RYtipHWe14=h18) and Down arrow ![Down Arrow](http://lh3.googleusercontent.com/dW0yyTPf131NnuLju8o-VuiHWYkxcb6MLAfu8hKNjYOoA3euoyQEGc9YiruwUjhzJ9U8=w18-h18) to arrange them in your preferred order.
3. At the bottom, click **Save**.

### 3. Copy a Collection

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. Click copy ![Copy](http://storage.googleapis.com/support-kms-prod/7Y5QPa6WvjPBPnHjimEnhCvC6oR57ze5rzn5).
3. Click **Create**.
4. (Optional) To edit the collection, follow the steps in Edit a collection.
5. At the bottom, click **Save**.

### 4. Delete a Collection

1. On the left, click Organize apps ![organize-apps](http://lh3.googleusercontent.com/6px01zZ8GU1mhdeh8-xU0ueoGwW4t8OrIE2lQsV0DddUxvtN0l3t3NHyliqBhbAoMWM=w18).
2. In the collection that you want to delete, click delete ![Delete](http://storage.googleapis.com/support-kms-prod/7JYaaGp429Vxyjl0VUfXF8YpXXeZi9QXQsLY).
3. Click **Delete**.
4. At the bottom, click **Save**.


# Getting Started

What are Profiles?

Policies (also called a policy) are the core resource of the Android Management API. You use them to create and save groups of device and app management settings for your customers to apply to devices. Usually companies create a specific profile per business use case.&#x20;

A policy can be applied to one or more devices. However, a device can only have a single policy at any given time. Devices enrolled without a policy are blocked from all functions until a policy is applied. If a policy isn't applied within five minutes, then enrolment will fail and the device will be factory reset.

In order to create a new profile, head over to **Device Profiles** and click on **+ New Profile** button. Specify a unique **Profile Name**, **Pass Code** (to exit profile) and toggle on the **Kiosk Mode** switch. A new profile will be created an added into your profile list, which then you can configure and add apps into.

![](/files/-MB-1QB6tVN1WXMZaTw2)

### 2. Configure Policies

You can configure the device policies by heading over to **Device Profiles** page and choose **Update Profile** from context men&#x75;**.** You will be navigated to **Edit Device Profile** page where you can configure all the available settings.

![](/files/-MB-2-JLIJ8kBzgZ2-3d)

**Edit device profile** section includes a list of 80+ policies you can configure on the devices using this profile. You can use CubiLock's default policies settings or select policies restrictions according to your needs. Move the slider to the right to enforce a policy.&#x20;

There are six main sections that allow you to set profile policies, they are as follows:

1. Applications
2. Policies
3. Kiosk Settings
4. Update Settings
5. Network Settings
6. Privacy Settings

![](/files/-MBEQlEIfbN5w0uIU5-6)


# How to Exit From Kiosk

Exit code allows selective users to exit kiosk mode and use the device in a slightly less restricted environment.

{% hint style="info" %}
Feature only supported when using [CubiLock Kiosk Application](/mobile-apps/cubilock-kiosk-application)
{% endhint %}

![](/files/Hk3xYQPEHiUI5whyx7on)

<figure><img src="/files/zl3X78VEhZcT18MfKZhU" alt=""><figcaption></figcaption></figure>


# Permission Management

Determine the default permission policy for runtime permission requests. Every Android app runs in a limited-access sandbox. If an app needs to use resources or information outside of its own sandbox, the app has to request the appropriate permission. (e.g. Facebook requesting to access your camera).

In the **Configuration** tab of your profile, the following policies are available:&#x20;

* **Unspecified**: If no policy is specified for a permission at any level, then the PROMPT behaviour is used by default.
* **Prompt**: Prompt the user for the request.
* **Deny**: Automatically deny a permission.
* **Grant**: Automatically grant a permission.

![](/files/siPVq3xSXRJIKLUvQERG)


# PlayStore Settings

CubiLock has two choices for the availability of applications on the device:

1. The **Whitelisted PlayStore** means that the public PlayStore is not accessible. Only the applications selected in the Profile will be available.
2. The **Blacklisted PlayStore** means that the public PlayStore is fully accessible. Applications can then be blacklisted in the Profile.

![](/files/-MBERqFA2edSmOLACdHo)


# Applications


# Add Application

### To Add Application to Profile:

From your CubiLock console:

1. Head over to **Device Profiles** page and Click on the three dot menu of the policy you want to add application in.
2. Click on **Update Profile** to open profile in edit mode.
3. Click on **Choose Application** and a list of [approved apps](/application-management/public-apps/approve-public-apps) will be shown.
4. Select the apps you want to add to profile by clicking on the checkbox next to it and Click on **Submit**.
5. Click on **Save** and **Confirm** to apply changes to your profile.

!["Choose Application" available in profile opened in edit mode](/files/kB84eqEmuEKLJ9Ib3dhJ)

![Select the application you want to add to profile and click "Submit"](/files/TirYAq6PkZl1mUDErU0j)

![Click on "Save" to apply changes to profile](/files/4dkLT8QLK2n98qhvsU0T)


# Remove Application

### To Remove Application From Profile:

From your CubiLock console:

1. Head over to **Device Profiles** page and Click on the three dot menu of the policy you want to remove application from.
2. Click on **Update Profile** to open profile in edit mode.
3. Select the app you want to remove from profile by checking the checkbox next to it.
4. Click on **Remove Application** and confirm by pressing **Delete**
5. Click on **Save** and **Confirm** to apply changes to your profile.

![Select the application(s) you want to remove and click "Remove Application"](/files/Jgw79YW5kmXwFB0pPV3a)

![Click on "Delete" to confirm](/files/RP7H7BZe0pNE1M1gsVll)

!["Save" to apply changes to profile](/files/PoMqAOUNFhyXJXIJvIpp)


# Set Install Type

CubiLock supports multiple install types for applications. Install types ensures the availability of the application on your devices. The following install types are available:

* **FORCE INSTALLED:** The app will be installed forcefully and user will not be able to uninstall it.&#x20;
* **PREINSTALLED:** The app will be installed or comes pre-installed but the user will be able to uninstall it.&#x20;
* **BLOCKED:** The app will be removed and user will not be able to install it manually too.
* **AVAILABLE:** The app is available to download and install for user but does not automatically install.
* **REQUIRED FOR SETUP:** The app will be installed during the setup phase and user will not be able to uninstall it.
* **KIOSK:** The app will be installed during the setup phase. It will be default app your user sees when they press home button and will replace any pre-installed launcher. The user will not be able to uninstall it.&#x20;

{% hint style="warning" %}
There can be only one app with install type of **KIOSK**
{% endhint %}

### To set / change install type of an Application:

From your CubiLock console:

1. Head over to **Device Profiles** page
2. Click on the three dot menu next to the profile and click **Update Profile** to open profile in edit mode.
3. Select the install type from the drop down menu and hit **Save** and **Confirm** to apply changes to profile.

![Select the install type you want from the drop down menu](/files/YoDpUI1ljjgPOKMyLr1H)


# Set Default Permissions

CubiLock allows setting default permissions for app so that you have full control over app's permissions. Following permissions are supported:

* **Unspecified:** Permission not specified by profile. If no permission is specified at any level, then the "Prompt" behavior is used by default.
* **Prompt:** Prompts every permission to user and leaves it on user to grant or deny.
* **Grant:** Force grants all permissions disallowing user to change them.
* **Deny:** Force deny all permissions disallowing user to change them.

### To Set Default Permissions:

From your CubiLock console:

1. Head over to **Device Profiles** page.
2. Click on the three dot menu next to profile you want to edit and click **Update Profile** to open it in edit mode.
3. From the **Default Permission** drop down menu, select the default permission you want to specify to the application.
4. Click **Save** and **Confirm** to apply changes.

![Default permission drop down with permission options](/files/XF2nbKIJcaSNDIFf994Z)


# Set Managed Configurations

### To Set Managed Configurations:

From your CubiLock console:

1. Once you login to cubilock console, head over to **Device Profiles** page.
2. Click the context menu to open profile in edit mode.
3. Click on **Choose Application** button and select Gmail (or **any app that has configurations** such as Chrome) to add it to your profile.
4. Click on **Configurations** action and specify the configurations.
5. Hit **Save** and **Confirm** to apply changes to profile.

![Configurations action available next to apps which have managed configurations](/files/-MGrfMVUtB4y5BPsGCzb)

![Configurations screen for Gmail app](/files/-MGrfvOFDlL2ivFsmiFW)


# Show/Hide Apps

### To Show/Hide Apps:

From your CubiLock console:

1. Head over to the **Device Profiles** page.
2. Click on the three dot menu of the profile you want to edit and click **Update Profile** to open profile in edit mode.
3. Enabling the **Visible** toggle shows the application and disabling the **Visible** toggle will hide the application from your devices.
4. Click on **Save** and **Confirm** to apply changes to your profile.

![To hide apps, disable the toggle](/files/ZpyC5RNevkPPH0MJyAeh)


# Set an App Track

### How to set App Tracks:

{% embed url="<https://www.youtube.com/watch?v=OFa_Whu623s&list=PLRRljmxgMuYzY0bDEvQmt3qCXhQPrUfBC&index=4>" %}

From your CubiLock console:

1. Head over to the **Device Profiles** page.
2. Click on the context menu and choose **Update Profile** to open the profile in edit mode.
3. Click on the context menu and choose **App Track** to open a dialog containing list of tracks available for this app.
4. Choose the desired app track and hit **Add**.
5. Click on **Save** and **Confirm** to apply changes to your profile.


# Set an Auto Update Mode

### How to set Auto Update Mode:

{% embed url="<https://www.youtube.com/watch?v=2kyVrMG_flM&list=PLRRljmxgMuYzY0bDEvQmt3qCXhQPrUfBC&index=1>" %}

In the **Applications** tab of the **Edit Device Profile**, you can control **how managed apps receive updates** by selecting an **Auto Update Mode** for each app using the dropdown shown below. This determines *when and how app updates are applied* to devices in that profile.

&#x20;**Navigation:**\
Go to **Device Management > Device Profiles > Update Profile > Applications tab**, then use the **Auto Update Mode** dropdown for each app.

The app auto-update policy, which controls when automatic app updates can be applied.

| **Mode**          | **When It Applies**                                | **Update Behavior**                                                                                                                                                                                                                                                  |
| ----------------- | -------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified**   | Default state when no specific mode is selected    | The system uses Managed Google Play’s default update behavior (apps update automatically based on constraints)                                                                                                                                                       |
| **Default**       | Standard auto‑update setting                       | Apps update automatically when certain conditions are met: device is connected to Wi‑Fi, charging, idle, and app isn’t running in the foreground. Updates may take up to \~24 hours to appear and install.                                                           |
| **High Priority** | When you want the latest version installed quickly | Apps update *as soon as a new release is published and approved* by Google Play. If the device is offline when the update is published, it will update once the device reconnects. Constraints such as idle/charging may be ignored.                                 |
| **Postponed**     | When you want to delay updates                     | Apps will *not* update automatically for an initial **90‑day period** after a new version is published. After this period, the latest version installs automatically under default behavior. This can be useful to avoid immediate updates during sensitive periods. |

<figure><img src="/files/VVuLSORthbxT0C2hZ2du" alt=""><figcaption></figcaption></figure>


# Setup Actions

### How to Setup Actions:

{% embed url="<https://www.youtube.com/watch?v=JASFjGHsAPM&list=PLRRljmxgMuYzY0bDEvQmt3qCXhQPrUfBC&index=2>" %}

From your CubiLock console:‌

1. Head over to the **Device Profiles** page.
2. Click on the context menu and choose **Update Profile** to open the profile in edit mode.
3. Set the install type of your desired application to **Required For Setup**.
4. Head over to **Kiosk Settings** and choose **Setup Actions** tab.
5. Click on **New Setup Action** button, fill in the necessary details and hit **Add**.
6. Click on **Save** and **Confirm** to apply changes to your profile.

| Enums                  | Description                                                     |
| ---------------------- | --------------------------------------------------------------- |
| `RUN_ON_EVERY_INSTALL` | This will launch actions only once when the app gets installed  |
| `RUN_ON_EVERY_UPDATE`  | This will launch actions every time app will receive new update |


# Set Min Version

### How to set Min Version:

{% embed url="<https://www.youtube.com/watch?v=AJhHqFWsXIo&list=PLRRljmxgMuYzY0bDEvQmt3qCXhQPrUfBC&index=3>" %}

1. Head over to the **Device Profiles** page.
2. Click on the context menu and choose **Update Profile** to open the profile in edit mode.
3. Click on the context menu and choose **Set Min Version**.
4. Choose the desired min version and hit **Add**.
5. Click on **Save** and **Confirm** to apply changes to your profile.


# Work Profile Widget

The **Work Profile Widget** feature in Cubilock  allows administrators to manage and control whether applications within the **work profile** are permitted to add widgets to the device's home screen. This policy is specifically applicable to devices that have a **work profile** set up.

#### **Key Features**

* **Work Profile Widget Policy**: This policy controls if a work profile application is allowed to add widgets to the home screen. It ensures that only applications within the managed work profile can add widgets, maintaining control over the user experience.
* **Applicability**: The **Work Profile Widget** setting is **only applicable to work profiles** on Android devices. It does not apply to fully managed profiles or devices without a work profile.

<figure><img src="/files/REUV2S48LBhOkBIHgC8Y" alt=""><figcaption></figcaption></figure>

#### **Setting Up Work Profile Widget**

1. **Navigate to the Applications Tab**:
   * Go to the **Applications** tab within your **Cubilock  dashboard**.
2. **Choose the Application**:
   * From the list of installed applications, select an app that is part of the **work profile** (e.g., **Google Chrome** or any other app configured for the work profile).
3. **Access Work Profile Widget Settings**:
   * Click on the **three dots** in the **Actions** column for the selected app.
   * From the dropdown menu, choose **Work Profile Widget**.
4. **Configure the Widget Permissions**:
   * A window will appear where you can configure the widget permissions for the selected app. You will have three options:
     * **Allowed**: The application is allowed to add widgets to the home screen.
     * **Disallowed**: The application is not allowed to add widgets.
     * **Unspecified**: No specific preference is set, leaving the decision to the default behavior or system settings.
5. **Save Configuration**:
   * After setting the desired permission, click **Save** to apply the changes.

<figure><img src="/files/ZtVgpjSouIgYmpycFixH" alt=""><figcaption></figcaption></figure>

#### **Work Profile Widget Policy Details**

* **OS Support**: The **Work Profile Widget** policy is supported on devices running **Android 5.0** (Lollipop) and above, with full functionality available on more recent versions of Android.
* **Permission Settings**:
  * **Allowed**: Grants permission for the application to add widgets to the home screen within the work profile.
  * **Disallowed**: Prevents the application from adding widgets, restricting users from seeing widgets on the home screen.
  * **Unspecified**: Leaves the decision to the default behavior, which may vary depending on device and system configuration.

#### **Additional Notes**

* The **Work Profile Widget** setting is crucial for organizations that need to ensure strict control over the work profile and user experience. Only allow widgets for apps that are trusted and essential for productivity.
* Regular updates to both the system and apps within the work profile should be conducted to maintain compliance with the policy.


# Credential Manager

#### **Overview**

The **Credential Manager** feature in Cubilock allows administrators to manage and configure password management and authentication systems. This feature provides seamless integration with Android devices, enabling users to authenticate and securely manage their credentials across enterprise systems.

#### **Key Features**

* **Credential Provider Policy**: The **Credential Manager** feature allows apps, such as password managers, to act as credential providers on devices running Android 14 or higher. This enables users to securely store and auto-fill login credentials for supported apps and services.
* **Application Integration**: Applications like **1Password** and other password managers can be integrated into the system to provide enhanced security and streamlined authentication.
* **Device Support**: The **Credential Provider Policy** ensures that only apps compatible with Android 14+ are authorized to function as credential providers, providing a high level of security and user control.

<figure><img src="/files/d4ccIIF8XR8UrsgcTr8U" alt=""><figcaption></figcaption></figure>

#### **Setting Up Credential Manager**

1. **Navigate to the Applications Tab**:
   * From the **Cubilock EMM dashboard**, go to the **Applications** tab to view and manage installed applications on the devices.
2. **Select the Application**:
   * Choose the **password manager app** (e.g., 1Password) from the list of available applications.
   * Click on the **three dots** in the **Actions** column and select **Credential Provider**.
3. **Enable the Credential Provider Policy**:
   * In the pop-up window, toggle the **Credential Provider Policy** to **ON**. This setting allows the selected application to act as a credential provider for devices running Android 14 and above.
4. **Save the Configuration**:
   * Once the configuration is set, click **Save** to apply the changes.
5. **Testing the Integration**:
   * Enroll a device and ensure that the selected password manager is functioning as the credential provider. Test by logging into a supported app and verifying that the credentials are autofilled correctly.

<figure><img src="/files/D76Hh6Hyp4FOUAsfPrNQ" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/mx93bG6CRCvxip1xBX9g" alt=""><figcaption></figcaption></figure>

#### **Credential Provider Policy Details**

* **OS Version Support**: The **Credential Provider Policy** is supported on devices running **Android 14 and above**. Make sure that the devices in your enterprise meet the system requirements for full functionality.
* **Permission Settings**: The **Credential Provider** policy can be set for specific applications that meet the criteria. This policy ensures that only the selected apps are granted permission to manage credentials on the device.

#### **Additional Notes**

* The **Credential Provider Policy** is only applicable to **Android 14+** devices. For older versions of Android, this functionality may not be supported.
* Regular updates should be applied to ensure that the password manager apps remain compliant with the latest security protocols.


# Profile Policies

How to set Profile Policies?


# Global Restrictions

Policies tab includes a list of 50+ policies allow you to configure Bluetooth, Status Bar, Settings, Camera etc.

You can configure the device policies by heading over to **Device Profiles** and choose **Update Profile** from context men&#x75;**.** You will be navigated to **Edit Device Profile** page where you can configure all the available settings.

![](/files/49pcUBr2CfjxlIF2mDTK)

### Global Restrictions

Below is the detail list of global restrictions that you can apply on any device:

| **Policy Name**                        | **Policy Details**                                                                        | **Options Available**                                          | **What This Policy Does (Android Enterprise)**                                         | **UI Navigation**                                                                                          |
| -------------------------------------- | ----------------------------------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- |
| **Disable Camera**                     | Whether all cameras on the device are disabled.                                           | Enabled / Disabled                                             | Blocks camera hardware access system‑wide, preventing any app from opening the camera. | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disable Camera**.                     |
| **Disable Screen Capture**             | Whether screen capture is disabled.                                                       | Enabled / Disabled                                             | Prevents screenshots and screen captures on managed devices.                           | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disable Screen Capture**.             |
| **Disable Keyguard**                   | Whether the keyguard is disabled.                                                         | Enabled / Disabled                                             | Disables the lock screen (keyguard). The device will not enforce a lock screen.        | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disable Keyguard**.                   |
| **Set Auto Time Required**             | Whether auto time is required, preventing manual date/time changes.                       | Enabled / Disabled                                             | Forces automatic network‑provided date/time; user can’t manually adjust.               | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Set Auto Time Required**.             |
| **Set Bluetooth Off**                  | Whether Bluetooth is disabled.                                                            | Enabled / Disabled                                             | Turns Bluetooth off and prevents users from enabling it.                               | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Set Bluetooth Off**.                  |
| **Disallow Data Roaming**              | Whether data roaming configurations are disabled.                                         | Enabled / Disabled                                             | Prevents users from enabling data roaming.                                             | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disallow Data Roaming**.              |
| **Enable USB Mass Storage**            | Whether USB storage is enabled.                                                           | Enabled / Disabled                                             | Controls USB file transfer (disallow prevents data transfer over USB).                 | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Enable USB Mass Storage**.            |
| **Disabled Uninstallation of Apps**    | Whether user uninstallation of applications is disabled.                                  | Enabled / Disabled                                             | Prevents apps from being uninstalled by users.                                         | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Uninstallation of Apps**.    |
| **Disabled Changing Wallpaper**        | Whether changing the wallpaper is disabled.                                               | Enabled / Disabled                                             | Blocks the ability to change home and lock screen wallpapers.                          | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Changing the Wallpaper**.    |
| **Disabled Bluetooth Contact Sharing** | Whether Bluetooth contact sharing is disabled.                                            | Enabled / Disabled                                             | Prevents contacts being shared via Bluetooth.                                          | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Bluetooth Contact Sharing**. |
| **Disabled Share Location**            | Whether location sharing is disabled.                                                     | Enabled / Disabled                                             | Disables location sharing services.                                                    | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Share Location**.            |
| **Disabled SMS**                       | Whether sending/receiving SMS is disabled.                                                | Enabled / Disabled                                             | Prevents SMS messages from being sent or received.                                     | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled SMS**.                       |
| **Disabled Unmute Microphone**         | Whether microphone audio and volume adjustment is disabled.                               | Enabled / Disabled                                             | Mutes microphone system‑wide and blocks audio adjustments.                             | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Unmute Microphone**.         |
| **Enabled Network Escape Hatch**       | Whether the network escape hatch is enabled.                                              | Enabled / Disabled                                             | Permits bypassing some network restrictions for troubleshooting. (Vendor/MAM feature)  | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Enabled Network Escape Hatch**.       |
| **Enabled Skip First Use Hints**       | Skip system hints/tutorials on first app start.                                           | Enabled / Disabled                                             | Skips built‑in app/setup tutorial hints after enrollment.                              | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Enabled Skip First Use Hints**.       |
| **Enabled Private Key Selection**      | Shows UI for user to choose a private key alias if no rule matches.                       | Enabled / Disabled                                             | Enables the private key alias selection UI when needed.                                | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Enabled Private Key Selection**.      |
| **Disabled Credentials Config**        | Whether configuring user credentials is disabled.                                         | Enabled / Disabled                                             | Blocks credential (certificate/keystore) configuration by users.                       | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Disabled Credentials Config**.        |
| **Printing Policy**                    | Controls whether printing is allowed.                                                     | Unspecified , Allowed , Disallowed                             | Determines if Android printing services are usable.                                    | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Printing Policy**.                    |
| **Assist Content Policy**              | Controls whether AssistContent (assistant data) can be sent to privileged assistant apps. | Unspecified , Allowed , Disallowed                             | Restricts sending contextual content to assistant apps.                                | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Assist Content Policy**.              |
| **Auto Date and Time Zone**            | Whether auto date/time/timezone is enabled.                                               | Unspecified , User Choice , Enforced                           | Forces use of network‑provided date/time & timezone settings.                          | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Auto Date and Time Zone**.            |
| **Credential Provider Policy Default** | Controls which apps are allowed to act as credential providers on Android 14+.            | <p>Unspecified,</p><p>Disallowed ,Disallowed except system</p> | Determines default credential provider apps on OS ≥14.                                 | Go to **Edit Profile > Policies > Global Restrictions** and toggle **Credential Provider Policy Default**. |


# User Restrictions

Policies tab includes a list of 50+ policies allow you to configure Bluetooth, Status Bar, Settings, Camera etc.

You can configure the device policies by heading over to **Device Profiles** and choose **Update Profile** from context men&#x75;**.** You will be navigated to **Edit Device Profile** page where you can configure all the available settings.

<figure><img src="/files/xkRWHHXh3DxKpTJRpRUu" alt=""><figcaption></figcaption></figure>

User Restrictions

Below is the detail list of user restrictions that you can apply on any device:

| **Policy Name**                     | **Policy Details**                                                                                 | **Options Available**                                      | **What This Policy Does (Android Enterprise)**                              | **UI Navigation**                                                                                     |
| ----------------------------------- | -------------------------------------------------------------------------------------------------- | ---------------------------------------------------------- | --------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------- |
| **Tethering Settings**              | Controls access to personal hotspot and internet sharing capabilities on the device.               | Unspecified / Allow All Tethering / Disallow All Tethering | Enables or restricts tethering/hotspot functionality on the device.         | Go to **Edit Profile > Policies > User Restrictions** and select **Tethering Settings**.              |
| **Disallow Add Account**            | Whether adding new users and profiles is disabled.                                                 | Enabled / Disabled                                         | Prevents users from adding additional accounts on the device                | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Add Account**.            |
| **Disallow Adjust Volume**          | Whether adjusting the master volume is disabled.                                                   | Enabled / Disabled                                         | Disables user ability to change device volume.                              | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Adjust Volume**.          |
| **Disallow Config Bluetooth**       | Whether configuring Bluetooth is disabled.                                                         | Enabled / Disabled                                         | Blocks Bluetooth configuration through settings.                            | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Config Bluetooth**.       |
| **Disallow Config Cell Broadcasts** | Whether configuring cell broadcast settings is disabled.                                           | Enabled / Disabled                                         | Blocks modification of cell broadcast settings                              | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Config Cell Broadcasts**. |
| **Disallow Config Mobile Networks** | Whether configuring mobile network settings is disabled.                                           | Enabled / Disabled                                         | Disables modification of mobile network settings such as APNs.              | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Config Mobile Networks**. |
| **Disallow Config Wi‑Fi**           | Whether configuring Wi‑Fi networks is disabled.                                                    | Enabled / Disabled                                         | Blocks user from adding/removing or editing Wi‑Fi networks.                 | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Config Wi‑Fi**.           |
| **Disallow Create Windows**         | Whether creating windows besides app windows is disabled.                                          | Enabled / Disabled                                         | Prevents certain system UI windows from being created outside app contexts. | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Create Windows**.         |
| **Disallow Factory Reset**          | Whether factory resetting from settings is disabled.                                               | Enabled / Disabled                                         | Prevents the user from resetting the device via system Settings.            | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Factory Reset**.          |
| **Disallow Fun**                    | Whether the user is allowed to have fun; controls whether Easter egg/game in Settings is disabled. | Enabled / Disabled                                         | Disables UI Easter Eggs / fun items; specific OEM features                  | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Fun**.                    |
| **Disallow Install Applications**   | Whether apps other than configured are blocked from being installed.                               | Enabled / Disabled                                         | Prevents user from installing arbitrary apps via Play Store or APKs.        | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Install Applications**.   |
| **Disallow Modify Accounts**        | Whether adding or removing accounts is disabled.                                                   | Enabled / Disabled                                         | Prevents modifying accounts on the device.                                  | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Modify Accounts**.        |
| **Disallow Mount Physical Media**   | Whether the user mounting physical external media is disabled.                                     | Enabled / Disabled                                         | Prevents the user from mounting external storage media.                     | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Mount Physical Media**.   |
| **Disallow Network Reset**          | Whether resetting network settings is disabled.                                                    | Enabled / Disabled                                         | Blocks user from resetting network settings.                                | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Network Reset**.          |
| **Disallow Outgoing Beam**          | Whether NFC Beam (sharing via NFC) is disabled.                                                    | Enabled / Disabled                                         | Disables NFC data beaming.                                                  | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Outgoing Beam**.          |
| **Disallow Outgoing Calls**         | Whether outgoing calls are disabled.                                                               | Enabled / Disabled                                         | Prevents placing outgoing phone calls.                                      | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Outgoing Calls**.         |
| **Disallow Remove Account**         | Whether adding or removing accounts is disabled.                                                   | Enabled / Disabled                                         | Prevents users removing accounts.                                           | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Remove Account**.         |
| **Disallow Set User Icon**          | Whether changing the user icon is disabled.                                                        | Enabled / Disabled                                         | Blocks user from changing profile icon                                      | Go to **Edit Profile > Policies > User Restrictions** and toggle **Disallow Set User Icon**.          |


# Cross Profile Policies

Define weather cross-profile data sharing is allowed or not .

<figure><img src="/files/ME4iDyV9ou5joki15OLJ" alt=""><figcaption></figcaption></figure>

### Cross Profile Policies&#x20;

| **Policy Name**                            | **Policy Details**                                                                                                        | **Options Available**                                                                       | **What This Policy Does (Android Enterprise)**                                                                                                                           | **UI Navigation**                                                                                                 |
| ------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ----------------------------------------------------------------------------------------------------------------- |
| **Show Work Contacts In Personal Profile** | Whether contacts stored in the work profile can be shown in personal profile contact searches and incoming calls.         | Allowed / Disallowed / Unspecified                                                          | Controls whether personal profile apps (e.g., dialer/contacts) can see and use work profile contacts. If disallowed, work contacts remain hidden in the personal profile | Go to **Edit Profile > Policies > Cross Profile Policies** and select **Show Work Contacts In Personal Profile**. |
| **Cross Profile Copy Paste**               | Whether text copied from one profile (personal or work) can be pasted in the other profile.                               | Allowed / Disallowed / Unspecified                                                          | Determines clipboard sharing across profiles. If **Allowed**, text copied in either profile can be pasted across; if **Disallowed**, cross‑profile pasting is blocked.   | Go to **Edit Profile > Policies > Cross Profile Policies** and select **Cross Profile Copy Paste**.               |
| **Cross Profile Data Sharing**             | Whether data from one profile (personal or work) can be shared with apps in the other profile (beyond clipboard actions). | Data Sharing Allowed / Work to Personal Disallowed / Data Sharing  Disallowed / Unspecified | Controls general data sharing across profiles via intents (e.g., share actions, file sharing). Different options restrict sharing in one or both directions.             | Go to **Edit Profile > Policies > Cross Profile Policies** and select **Cross Profile Data Sharing**.             |


# Kiosk Settings


# Kiosk Customizations

When you enable **Kiosk Mode** on a device profile in CubiLock, you can finely control how the device behaves in a locked‑down environment. The **Kiosk Settings** tab on the **Edit Device Profile** page lets you customize several kiosk behavior options, including how navigation works, what users can see, what actions are allowed, and how the screen behaves.

![](/files/Y1Gr71O0MQIJDY559LkT)

| **Setting**                 | **Description**                                                                                                         | **Example / Behavior**                                                                                                     |
| --------------------------- | ----------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
| **Apps per row**            | Defines how many app icons are displayed per row on the kiosk launcher screen.                                          | Enter a number (e.g., 3) to control layout density on the home grid.                                                       |
| **Kiosk Wallpaper**         | Upload a custom wallpaper that will be used as the home screen background in kiosk mode.                                | You can directly upload an image to set as wallpaper                                                                       |
| **Power Button Actions**    | Defines what happens if a user long‑presses the Power button while in kiosk mode.                                       | Can control whether Power triggers shutdown, options menu, or is disabled entirely.                                        |
| **System Error Warnings**   | Controls whether system dialogs (e.g., crash/recovery dialogs) are shown in kiosk mode.                                 | When blocked, the system force‑stops the app instead of showing an error dialog, maintaining a consistent kiosk experience |
| **System Navigation**       | Specifies which navigation features are enabled (e.g., Home, Overview buttons) in kiosk mode.                           | You can hide navigation buttons to prevent users from escaping the kiosk interface.                                        |
| **Status Bar**              | Determines whether system info and notifications are displayed in kiosk mode.                                           | You can disable the status bar to prevent access to quick settings and notifications                                       |
| **Device Settings**         | Controls whether the Settings app is allowed in kiosk mode.                                                             | Allowing settings gives users access; disallowing keeps the environment fully locked down.                                 |
| **Maximum Time to Lock**    | The timeout (in milliseconds) before the device automatically locks. If unspecified, no timeout restriction is applied. | A value of 0 typically means *no restriction*.                                                                             |
| **Auto Rotate Screen**      | Enables or disables the device’s auto‑rotate behavior in kiosk mode.                                                    | Turn on to allow the screen to rotate with device orientation; disable to lock orientation.                                |
| **Screen Orientation**      | Pre‑sets the screen orientation (e.g., Portrait or Landscape).                                                          | Choose the orientation users will see; useful when a kiosk app requires a specific orientation                             |
| **Auto Brightness**         | Controls whether auto‑brightness is enabled when the device is in kiosk mode.                                           | Use this to conserve battery or keep consistent brightness.                                                                |
| **Adjust Brightness Level** | Slider to define a fixed brightness level when auto‑brightness is off.                                                  | Set a comfortable level depending on your environment.                                                                     |
| **Adjust Player Volume**    | Slider that determines the device volume level while in kiosk mode.                                                     | Useful for public or retail devices to avoid audio that is too loud or muted entirely.                                     |


# Location Settings

In the **Kiosk Settings** tab of the **Edit Device Profile** page, you can control how the device’s **location services behave** when a profile is applied. This influences whether devices report their location and whether system location services are enabled or disabled.

&#x20;**Navigation:**\
Go to **Device Management > Device Profiles > Edit Profile > Kiosk Settings > Location Settings**.

| **Option**      | **Description**                                                                                                                                                                                                   |
| --------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified** | No specific location policy is set by CubiLock. The device retains its default Android behavior for location services.                                                                                            |
| **Enforced**    | The profile *requires location services to be turned on* during provisioning and while the device is managed. If location services are off, the device will show a compliance issue until the user turns them on. |
| **Disabled**    | The profile *requires location services to be turned off*. If location is on, the device will show a compliance issue until the user turns it off.                                                                |

### **How to Use This Setting**

Use **Location Mode** to control how device location services are treated as part of your security or compliance strategy:

* **Unspecified:**\
  Leave location control to the device’s normal settings or other policies.
* **Enforced:**\
  If your use case requires accurate location reporting (e.g., field force tracking, asset management), enforce location so the device must have location services enabled when provisioning and during operation.
* **Disabled:**\
  For privacy‑focused use cases — for example, customer‑facing kiosks where location doesn’t matter — you can require location services be turned off.

| **Scenario**                                                                                | **Recommended Setting** |
| ------------------------------------------------------------------------------------------- | ----------------------- |
| Fleet tracking, asset tracking, or geofencing requirements                                  | **Enforced**            |
| Devices used in private spaces with no location requirement                                 | **Disabled**            |
| Devices with no specific location requirement, or leave control up to the user’s OS default | **Unspecified**         |


# User Facing Messages

When devices are locked down in **Kiosk Mode**, users may attempt actions that are restricted by the profile (e.g., trying to access a blocked feature, settings, or navigation). **User Facing Messages** let you communicate *why* a particular feature is unavailable or provide helpful support details directly on the device.

In the updated CubiLock console, you can configure multiple types of user‑facing messages under **Kiosk Settings → User Facing Messages**.

### Types of Messages You Can Configure

| **Message Type**                  | **Where It Appears**                                                   | **Purpose**                                                                                                              |
| --------------------------------- | ---------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------ |
| **Short Support Message**         | Displayed to the user in contextual UI where functionality is blocked. | A brief explanation shown when a user interacts with a disabled feature. Use short, clear text (under \~200 characters). |
| **Long Support Message**          | Shown on the device in the administrator settings screen.              | A more detailed explanation or instructions users can read when they want more context about a restriction.              |
| **Device Owner Lock Screen Info** | Displayed on the device lock screen.                                   | Helpful information shown when the device is locked — e.g., support contact, help text, or allowed actions.              |

#### **How to Set User Facing Messages**

You can configure user facing messages from the CubiLock Console:

1. Go to **Device Management > Device Profiles** and click **Edit** on a profile.
2. Navigate to **Kiosk Settings**.
3. Select **User Facing Messages**.
4. Enter your custom messages in the appropriate text fields:
   * **Short Support Message** — shown when a restricted action is attempted.
   * **Long Support Message** — shown when the user selects *Learn more* or views details.
   * **Device Owner Lock Screen Info** — shown prominently on the device lock screen.
5. Click **Save** to apply your changes.

Because these messages appear *directly on the device*, use concise and clear language that helps users understand what is restricted and, if appropriate, how they can get help.

![Support message accessible from User Facing Messages under Configurations tab](/files/ePL54oVAR7xzzYU5LT3c)

![Short User Facing Message](/files/-MBmKyAHAjmzUHoNTrQa)

![Long User Facing Message](/files/-MBmL0Ax6RgJVYyOhwsJ)


# Key-guard Features Settings

In the **Kiosk Settings** tab of the **Edit Device Profile** page, the **Keyguard Disabled Features** section allows IT admins to *control specific lock‑screen (keyguard) behaviors* on fully managed or kiosk devices.

These settings determine which features are **disabled on the secure keyguard screen** (i.e., the screen shown before device unlock). By disabling specific features, you can tighten security, reduce distraction, or enforce stricter kiosk environments.

**Navigation:**\
`Device Management > Device Profiles > Edit Profile > Kiosk Settings > Keyguard Disabled Features`

Below is a description of each toggle shown

| **Feature**                  | **Description**                                                                                                                                                    |
| ---------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Camera**                   | Prevents access to the camera from the **lock screen** (secure keyguard). Users cannot launch the camera without first unlocking the device                        |
| **Notifications**            | Hides **all notifications** on the lock screen, preventing users from seeing notification banners or content before unlock                                         |
| **Unredacted Notifications** | Allows notifications to appear but hides sensitive content (only redacted notification headlines are shown)                                                        |
| **Trust Agents**             | Disables *trust‑agent logic* (like Smart Lock) that can keep a device unlocked under certain conditions (e.g., trusted Bluetooth device).                          |
| **Disable Fingerprints**     | Disables **fingerprint authentication** on the lock screen. Users must unlock with PIN/Password/Pattern                                                            |
| **Disable Remote Input**     | On **Android 6 and below**, this prevents input into notification text expansion on lock screen notifications. (No effect on Android 7+.)                          |
| **Face**                     | Disables **face recognition** for unlocking the device at the lock screen                                                                                          |
| **Iris**                     | Disables **iris scanning** authentication at the lock screen (where supported)                                                                                     |
| **Biometrics**               | Disables **all biometric authentication** — fingerprint, face, and iris — at the lock screen. This overrides individual biometric toggles.                         |
| **All Features**             | Turns *off all the above* keyguard customizations at once. This is useful in kiosk environments where you want to remove all interactive lock‑screen functionality |

![](/files/Y3wyso1G2LwpGAVtB5b5)

#### **How This Affects Devices**

These settings let you **tighten lock‑screen behavior** in managed environments:

**Enhanced Security:** Prevent access to notifications, camera, or biometrics before an authorized user unlocks the device.\
**Consistent Kiosk Experience:** Disable features that could let users interact with system UI or exit kiosk apps.\
**Compliance Enforcement:** Enforce standard behaviors across a fleet of devices, especially in regulated industries.


# Stay On Plugged Modes

In the **Kiosk Settings** tab of the **Edit Device Profile** screen, the **Stay On Plugged Modes** section lets you define which **power source types** should keep the device *awake* and prevent it from going into sleep or power‑saving mode.

This is useful in kiosk, signage, point‑of‑sale, or dedicated‑use devices where the screen and system *must remain active* while the device is connected to power.

**Navigation:**\
`Device Management > Device Profiles > Edit Profile > Kiosk Settings > Stay On Plugged Modes`

<figure><img src="/files/p8a3EXDXizPary8HHh2o" alt=""><figcaption></figcaption></figure>

### **What Stay On Plugged Modes Controls**

When a device is plugged into power, Android normally decides whether to keep the screen on or allow it to go to sleep based on system settings. With **Stay On Plugged Modes**, you can *override this default behavior* for specific power sources:

| **Option**      | **What It Means**                                                                                                                                                                                                  |
| --------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Unspecified** | No specific behavior is enforced. The system defaults are used, and Android may allow the device to sleep normally when idle.                                                                                      |
| **AC**          | If checked, the device will **stay awake (prevent sleep)** while connected to an **AC mains charger**. The screen and CPU remain active, which is useful for permanent displays or kiosks powered by wall outlets. |
| **USB**         | If checked, the device will stay awake **when connected to a USB power source** (e.g., USB wall adapter, PC USB port). Useful for devices powered via USB cables (e.g., docking stations).                         |
| **Wireless**    | If checked, the device will stay awake **when charging wirelessly** (Qi or other wireless charging). This prevents the device from sleeping while on a wireless charging pad.                                      |

These settings help ensure that devices *do not automatically sleep or turn off the display* while plugged into a chosen power source — which is important for use‑cases where the device should always remain visible and responsive (e.g., retail signage, kiosks, attendance terminals)

### **Device Behavior Example**

* **AC only checked** → Device stays awake only when connected to a wall charger; it may sleep when on battery or other power sources.
* **AC + USB checked** → Device stays awake on both mains and USB power connections.
* **All unchecked (Unspecified)** → Let Android’s default power‑saving behavior control the device sleep/idle state.


# Permitted Accessibility Services

In the **Kiosk Settings** tab of the **Edit Device Profile** screen in CubiLock, the **Permitted Accessibility Services** setting allows you to *specify which accessibility service apps are allowed to run on managed Android devices*. This controls the set of accessibility services that can operate under a device or work‑profile policy.<br>

### Navigation

Device Management → Device Profiles → Edit Profile → Kiosk Settings → Permitted Accessibility Services

#### **Overview**

Accessibility services are specialized Android services that can assist users with disabilities or provide alternate UI interaction capabilities (such as screen readers, switch access, voice‑linked navigation, or other assistive tools). All accessibility services require specific Android permissions and are closely controlled for security reasons.

In enterprise device management, uncontrolled accessibility services can be a security risk because they have broad access to UI content and input. To mitigate this, the **Permitted Accessibility Services** policy lets you *explicitly list which services are permitted*.

#### What This Setting Controls

| **Term**                    | **Meaning**                                                                                                                                                  |
| --------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Unspecified**             | No explicit list is defined. *All accessibility services supported by the system may be used* (including third‑party accessibility apps).                    |
| **Permitted Services List** | Only the listed accessibility services *and system built‑in accessibility services* are allowed to run. All other accessibility services are blocked.        |
| **Empty List**              | When set to an empty list, **only system built‑in accessibility services** (e.g., TalkBack) are permitted; no third‑party accessibility services can be used |
|                             |                                                                                                                                                              |

#### Examples of Use Cases

| **Scenario**                                                                     | **Recommended Setting**                                                                                            |
| -------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------ |
| Devices used by employees with special accessibility needs                       | List specific accessibility services (e.g., screen readers or switch access).                                      |
| Devices in kiosk/retail environments where accessibility features are not needed | Use an *empty list* so only built‑in services are allowed, preventing external accessibility tools from operating. |
| General corporate devices where accessibility support is optional                | Leave as *Unspecified* to allow all services when needed.                                                          |

#### **How to Configure**

1. Open **Device Profiles** and choose the profile to edit.
2. Go to **Kiosk Settings**.
3. Select **Permitted Accessibility Services**.
4. Use the toggles to *allow the packages* that represent the accessibility services you want permitted.
5. Save the profile.

When applied, only the selected accessibility services (plus built‑in Android services) will be permitted to function on enrolled devices.


# Setup Actions

In the **Kiosk Settings** tab of the **Edit Device Profile** screen, the **Setup Actions** section lets you *define a one‑time automated action* that will execute when a device is being provisioned (during or immediately after enrollment). This is especially useful for kicking off companion apps, onboarding workflows, or configuration assistants that must run before the user can fully use the device.

#### Navigation

Device Management → Device Profiles → Edit Profile → Kiosk Settings → Setup Actions

### **What Setup Actions Are**

**Setup Actions** are one‑off procedures that run **during the initial setup of a device**. These actions are executed as part of the Android Enterprise provisioning process and occur *before the user reaches the home screen or main UI*. In most cases, they launch a designated app that helps complete device configuration or onboarding.

In Android Enterprise (via the Android Management API), the underlying policy field that governs this behavior is called `setupActions`, which determines which actions (such as launching an app) are executed during setup. Only one Setup Action is allowed per profile.

<figure><img src="/files/VuOTqbgZatqGZdie9eJN" alt=""><figcaption></figcaption></figure>

#### Setup Action Fields Explained

| **Field**             | **Description**                                                                                                                                                        |
| --------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Launch App**        | The application that will be automatically started during setup. To use this, the app must be included in the profile’s app list and marked as **Required for Setup**. |
| **Title**             | A short label or name for the action that may be shown during provisioning.                                                                                            |
| **Description**       | Optional text explaining the action — this can help users understand what the action does during setup.                                                                |
| **Launch Mode**       | Determines *when* the action will run:                                                                                                                                 |
| **During Enrollment** | Runs during the enrollment flow before the user finishes setting up the device.                                                                                        |
| **After Enrollment**  | Runs just after enrollment completes, once the policy is applied.                                                                                                      |
| **Both**              | Runs once during enrollment *and* again immediately after.                                                                                                             |

### **How It Works in Practice**

To successfully run a Setup Action:

1. **Add the App to the Profile:**\
   Include the app in the device profile’s *Applications* list.
2. **Mark as Required for Setup:**\
   From the Install Type dropdown for the app, choose **Required for Setup**. This tells Android that this app must be installed and launched during device provisioning.
3. **Create a Setup Action:**\
   In **Setup Actions**, click **New Setup Actions** → select the app → enter a Title & Description → choose a Launch Mode → click **Add**.
4. **Save the Profile:**\
   Save and apply the profile so that when new devices enroll, the Setup Action runs as configured.

<figure><img src="/files/Q8VFbADJQBpYdUyYQ2Zc" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/XqKa0ObidN5CecWKT87s" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/NZ3VkyUySHpFzU2hF2sI" alt=""><figcaption></figcaption></figure>


# Managed Play Store Mode

The **Managed Play Store Mode** setting in the **Kiosk Settings** tab lets administrators control *how the managed Google Play store behaves* on fully managed devices. It determines which apps end‑users can see and install from the Play Store and how apps not defined in the device policy are handled.

#### Navigation

Device Management → Device Profiles → Edit Profile → Kiosk Settings → Managed PlayStore Mode

### **What Managed Play Store Mode Controls**

Android Enterprise provides a policy called `playStoreMode` that governs the visibility and installation behaviour of Play Store apps. In CubiLock’s UI, you can choose between the following options:

<figure><img src="/files/vQT9Py7B0zgBukscniG6" alt=""><figcaption></figcaption></figure>

| **Mode**            | **Description**                                                                                                                                                                                                                                                                                             |
| ------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified**     | No explicit Play Store mode is set. By default, the Android Management API treats this as **whitelist mode** — meaning only the apps listed in the device policy are available. Apps not in the policy will be automatically uninstalled.                                                                   |
| **Restricted Mode** | Only the apps that are **defined in the device profile** (in the Applications list) are available to install or use. Any app *not included* in that list will be automatically removed from the device. This tightly restricts the Play Store to *only approved apps*.                                      |
| **Normal Mode**     | Users can browse and install apps through the managed Google Play Store *more freely*, subject to any other policy restrictions. This mode gives a standard managed Play Store experience, where approved apps are visible but users may see additional content depending on your enterprise configuration. |

### **Impact of Each Mode**

#### **Restricted Mode**

* End‑users can **only see or install apps that the administrator has explicitly added to the device profile**.
* Any app *not in the policy list* is removed from the device and hidden in the Play Store.
* This mode is ideal for kiosk, signage, or controlled enterprise devices where only *defined applications* should be allowed.

#### **Normal Mode**

* Devices have access to the managed Play Store with a broader set of installable apps.
* Users can view and install *all approved managed apps* through the Play Store interface.
* Other EMM restrictions may still apply (e.g., blocked apps or app permissions).

#### **Unspecified**

* This lets Android Management API apply the default behaviour, which usually enforces a whitelist of policy‑defined apps and uninstalls others.
* It behaves similarly to Restricted Mode if no other Play Store configuration is specified.

#### When to Use Each Setting

| **Use Case**                                 | **Recommended Mode**                                             |
| -------------------------------------------- | ---------------------------------------------------------------- |
| **Locked‑down device (kiosk or dedicated)**  | **Restricted Mode** — ensures only corporate apps are available. |
| **Corporate device with standard app needs** | **Normal Mode** — gives users access to a managed app catalog.   |
| **Default policy behavior**                  | **Unspecified** — lets the system use its default handling.      |

### **How It Works in Practice**

When your policy’s Play Store Mode is set:

* **Restricted Mode** → Only applications present in the profile’s *Applications list* can be installed or accessed. Others are removed.
* **Normal Mode** → Devices connect to **Managed Google Play**, where approved apps are shown. Users can install and update these apps subject to admin control.
* **Unspecified** → Default system behaviour applies, defaulting to whitelist behavior similar to restricted mode unless overridden by other settings.


# Update Settings


# System Updates

The system update policy controls how OS updates are applied. If the update type is "Windowed", the update window will automatically apply to Play app updates as well.

In the **Configuration** tab of your profile, the following update policies are available:

* **Unspecified**: Follow the default update behaviour for the device, which typically requires the user to accept system updates.
* **Automatic**: Install automatically as soon as an update is available.
* **Postponed**: Postpone automatic install up to a maximum of 30 days.
* **Windowed**: Install automatically within a daily maintenance window. This also configures Play Store apps to be updated within the window. This is strongly recommended for kiosk devices because this is the only way apps persistently pinned to the foreground can be updated by the Play Store.


# Auto Update Settings

The app auto update policy, which controls when automatic app updates can be applied.

1. **Always:** Install automatically as soon as an update is available.
2. **User Choice:** The user decides when to update.
3. **Never:** Apps are never auto-updated.
4. **Wifi Only:** Apps are auto-updated over Wi-Fi only.

![](/files/RPnQs6cyeNlkh1kCIyaC)


# Network Settings


# Basic Network Settings

The **Basic Network Settings** section in the **Network Settings** tab lets you control fundamental network behavior on managed Android devices — such as whether users can configure Wi‑Fi and how the device uses preferential network services.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Network Settings → Basic Network Settings

### **What Basic Network Settings Controls**

#### **1. Configure Wi‑Fi**

This setting determines whether users can manually configure Wi‑Fi on the device.

| **Option**                                            | **Meaning**                                                                                                                                                                                                                                                 |
| ----------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified**                                       | No explicit restriction is set. Devices follow the default provisioned behavior, and users may be able to add or edit Wi‑Fi networks unless other policies deny it.                                                                                         |
| **Allowed**                                           | Users are allowed to manually configure Wi‑Fi networks on the device. They can add, modify, or remove Wi‑Fi connections from the device’s network settings.                                                                                                 |
| **Disallowed** / **Disallow Adding Wi‑Fi** *(OS 13+)* | Users are prevented from manually adding or modifying Wi‑Fi configurations. This ensures that only administrator‑pushed Wi‑Fi networks are available. This matches enterprise‑level behavior where network connectivity is centrally controlled via policy. |

On fully managed devices, restricting Wi‑Fi configuration means the **openNetworkConfiguration** policy (if defined) is used to push all Wi‑Fi networks, and users **cannot** override those settings manually.

<figure><img src="/files/VBs0CGGplCtnzMRXXItX" alt=""><figcaption></figcaption></figure>

#### **2. Preferential Network Service**

This setting controls whether Android’s **Preferential Network Service** is enabled on the device.

| **Option**      | **Meaning**                                                                                                                                                                                               |
| --------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Unspecified** | The system default applies; no explicit policy enforces the preferential network behavior.                                                                                                                |
| **Enabled**     | The device uses the preferred network service when available. Preferential network services can help maintain the best possible network connection or switch intelligently between available connections. |
| **Disabled**    | The device does not use preferential network service; network selection is handled by the OS default logic without enterprise priority.                                                                   |

#### 3. Prevent Mobile Network Settings (OS 5.0+)

This toggle controls whether users can access and modify mobile network settings on the device (e.g., switching carriers, APN configuration).

<figure><img src="/files/7IT3QNMiBYtVetyidlgx" alt=""><figcaption></figcaption></figure>

| State         | Meaning                                                                                                 |
| ------------- | ------------------------------------------------------------------------------------------------------- |
| Off (default) | Users can access and modify mobile network settings.                                                    |
| On            | Mobile network settings are locked. Users cannot change carrier or network preferences from the device. |

Use this to ensure devices remain on the correct mobile network configuration set by your organization.


# WiFi Networks

Wi-Fi networks can be pre-configured in the CubiLock console and referenced in a profile so that they apply automatically to all devices enrolled into that profile.

**To Configure Wi-Fi Networks in Your CubiLock Console:**

1. **Navigate to the Wi-Fi Networks Section**:
   * Go to the **Device Profiles** section.
   * Click **Choose Wi-Fi Network**.
2. **Create a New Wi-Fi Network**:
   * In the configuration tab, select the **Wi-Fi Networks** section.
   * Click on the **Add Wi-Fi Network** button.
   * Provide the network **Name**, **SSID**, and **Security Protocol**.
   * Choose the **Auto-connect** option to automatically connect devices to this Wi-Fi network after enrollment.

**Supported Security Protocols:**

* **None**: For open networks (no password required).
* **WEP-PSK**: A common but insecure protocol.
* **WPA-PSK**: Common protocol with better encryption.
* **WPA-EAP**: Advanced security protocol for enterprise networks.

***

**To Select a Configured Wi-Fi Network For Use in a Profile:**

1. **Access Profile Settings**:
   * From the **Device Profiles** section, select the desired profile.
2. **Add Wi-Fi Network**:
   * In the profile's configuration section, navigate to **Wi-Fi Networks**.
   * Select the pre-configured Wi-Fi network from the list and **add it to the profile**.

<figure><img src="/files/UAP2d5cHZeWcpJ78b7S5" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
Note: You can modify at all times the Wi-Fi configurations, and changes will be automatically reflected on your enrolled devices.
{% endhint %}

<figure><img src="/files/iNADS3mwZtQrpERuoWcn" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/FiUkO1Q6dRPG5r4IRRQu" alt=""><figcaption></figcaption></figure>


# VPN Settings

The **VPN Configuration** section within **Network Settings** lets administrators control how VPN (Virtual Private Network) connectivity is managed on enrolled Android devices. You can disable the user’s ability to configure VPNs, enforce VPN lockdown, and specify which VPN app should be used for secure connectivity.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Network Settings → VPN Configuration

![VPN Configuration tab available in Configurations](/files/PQqx69xe3CIw0A7sWZwt)

### **What Each Setting Does**

#### **Disallow Config VPN**

When enabled, users are **prevented from accessing VPN configuration settings** on the device. This means VPN profiles *cannot be created or modified manually* by the user, ensuring only admin‑pushed VPN configurations apply.

* **Disabled (default):** User can manually open and edit VPN settings.
* **Enabled:** Users cannot open or change VPN settings.

#### **Enabled Lockdown**

This option enforces a **network lockdown around the VPN connection**. When enabled:

* The device **will not allow network access unless the VPN is connected**.
* All network traffic is blocked if the VPN is not actively connected – preventing unprotected communications.

This is especially useful for high‑security environments where **all traffic must go through the corporate VPN** and no unencrypted network access should be allowed.

#### **Manage VPN App**

This dropdown lets you *select the application* that will be used as the primary **VPN client app** on the device. Only apps that are already added to the profile’s application list will appear here.

* Choose a VPN client app (such as a third‑party VPN app you have included in the profile).
* The selected app will be used as the configured VPN service provider for the device.

> This setting is helpful when the built‑in Android VPN is not sufficient or when using a managed VPN app that supports always‑on or advanced tunneling.

<figure><img src="/files/CAOEunS2sHJuAmvn5jWd" alt=""><figcaption></figcaption></figure>

#### How These Settings Work Together

| **Setting**             | **Effect**                                                                                           |
| ----------------------- | ---------------------------------------------------------------------------------------------------- |
| **Disallow Config VPN** | Prevents users from editing or adding VPN connections manually.                                      |
| **Enabled Lockdown**    | Locks all network traffic if the VPN is not connected. Device has no network access outside the VPN. |
| **Manage VPN App**      | Specifies the VPN client to use for device connectivity.                                             |

### **Why This Matters for Admins**

* **Security Enforcement:** Ensures all network traffic is routed through a trusted VPN endpoint before allowing connectivity.
* **Prevent User Interference:** Stops users from disabling VPN or creating insecure connections.
* **Consistent Deployment:** Guarantees that only selected VPN apps with corporate configurations are used on enrolled devices.

This approach helps maintain secure network access for corporate data and compliance with IT policies across all managed endpoints.


# eSIM Settings

**Navigation:** Device Management → Device Profiles → Edit Profile → Network Settings → eSIM Settings

The eSIM Settings section lets you control whether users can self-provision eSIM profiles on managed devices.

***

### 1. eSIM User Initiated Provisioning *(Android 15+)*

Controls whether end users can independently add new eSIM profiles to their device without administrator intervention.

| Option      | Meaning                                                                                 |
| ----------- | --------------------------------------------------------------------------------------- |
| Unspecified | No explicit restriction. Device follows its default behavior.                           |
| Allowed     | Users can add eSIM profiles on their own from the device settings.                      |
| Disallowed  | Users cannot add eSIM profiles. All eSIM provisioning must be done by an administrator. |

{% hint style="info" %}
This policy requires Android 15 or later. On older Android versions, this setting has no effect.
{% endhint %}

<figure><img src="/files/hh3wx69zjMfUrvWP4IgI" alt=""><figcaption></figcaption></figure>


# Privacy Settings


# Password Constraints

CubiLock allows you to define the password constraints required for device security. The password policy helps ensure users set secure passwords for their managed devices. These constraints can be set from the **Privacy Settings** under **Password Constraints** in your **Device Profile** configuration.

**To Add a Password Constraint:**

1. **Go to Privacy Settings**:\
   Navigate to the **Privacy Settings** section of the device profile, where you can see **Password Constraints**.

<figure><img src="/files/KEAfoAPCLJPwbUpHOKn2" alt=""><figcaption></figcaption></figure>

* **Click on "Add Constraint"**:\
  You'll see an **"Add Constraint"** button at the top-right of the Password Constraints section. Click on this to create a new password policy.
* **Define Password Policy Settings**:\
  The following fields are available for configuring your password constraints:
  * **Password Policy Scope**:
    * **Unspecified**: No specific requirement for the password scope.
    * **Scope Device**: The password requirement applies to the device.
    * **Scope Profile**: The password requirement applies to the user profile.

<figure><img src="/files/31moIEUBeCSU3E4ZyhGH" alt=""><figcaption></figcaption></figure>

**Password Quality**:\
Set the required quality of the password. The available options include:

* **Unspecified**
* **Biometric Weak**: A password based on a low-security biometric method.
* **Something**: No specific requirements, just a password.
* **Numeric**: Requires numeric-only passwords.
* **Numeric Complex**: Numeric passwords must be complex (no repeated numbers or ordered sequences).
* **Alphabetic**: Requires alphabetic characters.
* **Alphanumeric**: A combination of both numeric and alphabetic characters.
* **Complex**: A stronger password that meets several minimum security requirements.

<figure><img src="/files/74dBmNyqVOIgKaAd8028" alt=""><figcaption></figcaption></figure>

**Additional Settings**:

* **Password Expiration Time Out**: The number of days before the password must be reset.
* **Maximum Failed Passwords For Wipe**: Defines the number of incorrect password attempts before the device is wiped.
* **Require Password For Unlock**: Specifies if a password is required to unlock the device after a specific duration. The options include:
  * **Unspecified**
  * **Scope Device**
  * **Require Every Day**

<figure><img src="/files/XQ29FSbfTO7Oi8ayODbA" alt=""><figcaption></figcaption></figure>

1. **Save**:\
   After configuring the settings, click **Add** to apply the password policy.

**Example Configuration:**

You might configure a policy with **Password Quality** set to **Numeric**, **Password Policy Scope** set to **Scope Device**, and a **Maximum Failed Passwords For Wipe** value of **8**.

<figure><img src="/files/aCNKFWMQL6hwFOU2tb44" alt=""><figcaption></figcaption></figure>


# Encryption Policy Settings

The encryption strategy that allow devices to boot straight to the lock screen with or without entering password.

1. **Un-Specified:** This value is ignored, i.e. no encryption required.
2. **Without Password:** Encryption required but no password required to boot.
3. **With Password:** Encryption required with password required to boot.

![](/files/c0s7KNj2HzuJsK865GBA)


# Policy Enforcement Settings

**Policy Enforcement Rules** let administrators define *custom compliance actions* when a managed device or work profile falls out of compliance with specific policy settings. Instead of relying on Android’s default compliance handling, you can create rules that determine how many days a device can remain non‑compliant before it is **blocked** and then **wiped**.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Privacy Settings → Policy Enforcement Rules

#### **What Policy Enforcement Rules Do**

Android automatically enforces compliance for core policies (such as password requirements, encryption, keyguard settings, permitted accessibility services, etc.). If a device is non‑compliant, Android Device Policy *will block usage immediately by default*, and if non‑compliance persists for 10 days, it will *factory‑reset the device or delete the work profile*.

Policy Enforcement Rules allow you to override this behavior and define your own timelines and actions.

#### **Rule Components**

Each enforcement rule consists of:

* **Setting Name**\
  Select the policy setting to enforce (e.g., Password Policies, Encryption Policy, Keyguard Disabled, etc.). This corresponds to the top‑level policy key that determines compliance.
* **Block After (Days)**\
  The number of days a device can remain non‑compliant before it is **blocked** (restricted from normal use). Setting this to **0** blocks the device immediately when non‑compliance is detected.
* **Wipe After (Days)**\
  The number of days the device can remain non‑compliant *after* the block before it is **wiped** (factory reset or work profile removed). This value must always be **greater** than the Block After days.
* **Block Scope**\
  Choose whether the block applies to the **entire device** or just the **work profile** (for corporate‑owned profiles).
* **Factory Reset Protection (FRP)** toggle\
  Enable this to **preserve FRP** when the device is wiped due to non‑compliance. With FRP preserved, the device may require the original account credentials to be activated after reset.

#### When to Use Policy Enforcement Rules

| **Scenario**                    | **Use Case**                                                                  |
| ------------------------------- | ----------------------------------------------------------------------------- |
| Sensitive security environments | Block and wipe quickly when password or encryption policies are violated.     |
| Staged escalation               | Allow users time to remediate non‑compliance before restricting or wiping.    |
| Custom compliance behavior      | Deviate from default 10‑day enforcement to match organizational requirements. |

#### **How to Add a Policy Enforcement Rule**

1. Click **Add Rule** in the Policy Enforcement Rules section.
2. In the **New Compliance Rule** modal:
   * Select the **Setting Name** from the dropdown.
   * Enter the **Block After (Days)** value.
   * Enter the **Wipe After (Days)** value (must be greater than block days).
   * Choose the **Block Scope** (Device or Work Profile).
   * Optionally enable **Factory Reset Protection** to preserve FRP upon wipe.
3. Click **Add** to save the rule.

<figure><img src="/files/FF5ygSi1YBzna926nQu8" alt=""><figcaption></figcaption></figure>

#### **Sample Rule Logic**

A typical enforcement rule for password policy violation might be:

| **Setting Name**  | **Block After** | **Wipe After** | **Block Scope** | **FRP** |
| ----------------- | --------------- | -------------- | --------------- | ------- |
| Password Policies | 6 Days          | 7 Days         | Device          | Enabled |

This means if a device fails to meet password requirements, it will be blocked after **6 days** of non‑compliance, and if still non‑compliant after **7 days**, it will be wiped.


# Untrusted Apps Policy

Untrusted apps policy defines the scale in which user is allowed to install apps. Following are allowed scopes:

* **Unspecified:** Unspecified. Defaults to "Disallow install"
* **Disallow install:** Prevent users from installing apps on their own.
* **Allow install in personal profile only:** Allows users to install apps on their personal profile only, this is useful for BYOD mode as user is free to install apps in their environment while keeping your enterprise environment safe.
* **Allow install device wide:** Allows users to install apps globally on their device.

### To Set Untrusted Apps Policy:

From your CubiLock console:

1. Once you have logged in, head over to **Device Profiles** page.
2. Click on the context menu next to the profile you want to edit and click **Update Profile** to open profile in edit mode.
3. Navigate to **Privacy Settings**.
4. From **Untrusted Apps Policy** set configuration to your preference.
5. Hit **Save** and **Confirm** to save changes.

![](/files/P630F6RAt663ONtqfBKy)


# Factory Reset Protection

**Factory Reset Protection (FRP)** is a security feature designed to protect Android devices from unauthorized use after a factory reset. When this protection is enabled, only authorized Google accounts — entered here in the CubiLock console — will be allowed to provision or activate a device after it has been reset.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Privacy Settings → Factory Reset Protection

#### **What Factory Reset Protection Does**

Android’s built‑in **Factory Reset Protection** stops a device from being reused without proper authentication if it has been wiped outside normal device settings (e.g., via recovery mode or hardware keys). If a reset is attempted, the system will require a Google account that **was previously authorized** to complete setup.

In an enterprise environment, FRP helps:

* **Protect corporate devices** from unauthorized reuse if lost or stolen.
* **Ensure only IT‑approved accounts** can reactivate a factory reset device.
* Avoid lockouts when assigning devices to new users after decommissioning or repurposing.

#### **How to Add an FRP Email**

1. Click **Add Email** in the Factory Reset Protection section of the Privacy Settings tab.<br>

<figure><img src="/files/yGbEUcSdFpEq3Ur3u8c0" alt=""><figcaption></figcaption></figure>

2. in the **Add New Factory Reset Protection Email** dialog that appears:
   * Enter the Google account email that you want authorized to unlock and activate a device after a factory reset.
   * Click **Add** to save the email.

<figure><img src="/files/P8iYGCcf8NxghOtis9kc" alt=""><figcaption></figcaption></figure>

2. After adding the desired email(s), click **Save** at the top right of the profile to apply the policy.<br>

<figure><img src="/files/YgfHy2rnFbjVgY6H9JuU" alt=""><figcaption></figcaption></figure>


# Chose Private Key Rules

**Choose Private Key Rules** let you define how managed apps on Android devices gain access to private keys stored in the system keystore. Private keys are used for things like secure TLS client authentication or signing operations. These rules determine **which private key alias** should be granted to an app when it requests access.

**Navigation:**

Device Management → Device Profiles → Edit Profile → Privacy Settings → Choose Private Key Rules

Many enterprise apps require a private key to authenticate securely to internal servers or APIs. Android’s Device Policy Controller (DPC) allows apps to request appropriate private key aliases via standard APIs (for example, `KeyChain.choosePrivateKeyAlias`). The **Choose Private Key Rules** section lets you pre‑configure policies that control:

* **Which apps are allowed to access private keys**
* **For which URL patterns this applies**
* **Which private key alias should be used for a given request**

This ensures that managed apps have predictable, secure access to cryptographic keys on managed devices without exposing them to unauthorized applications.

#### **UI Walkthrough**

1. **Rule List Interface**\
   When no rules are present, the list will be empty.

<figure><img src="/files/ZKIFv4gVFTC2QiAejARh" alt=""><figcaption></figcaption></figure>

2. **Create a New Rule**\
   Click **New Rule** to begin defining an access rule for private keys. This opens a modal where you can specify patterns, apps, and key aliases.

<figure><img src="/files/fpFLritiIcDlwLHrDGoG" alt=""><figcaption></figcaption></figure>

3. **Rule Form Fields Explained**

* **URL Pattern** – A regular expression pattern that matches the URL of outgoing requests. This is used to restrict private key selection only for specific URLs. For example, `https://*.corp.internal/*`.\
  If left unspecified, it matches all URLs.
* **Select Apps** – The package names of one or more managed apps that this rule applies to. If no packages are specified, the rule applies to *all managed apps*.
* **Private Key Alias** – The alias (identifier) of the private key to grant when the app makes a request.

Click **Add** to save the rule once fields are complete.

<figure><img src="/files/U3NZhO8QHoEN0o5VQWP9" alt=""><figcaption></figcaption></figure>

4. **Save Your Profile**\
   After you’ve added rules, be sure to click **Save** in the main profile UI to apply these changes to all devices attached to this profile.

<figure><img src="/files/psVAlJMyyGwTVHSDoNSC" alt=""><figcaption></figcaption></figure>


# Developer Settings

The **Developer Settings** profile option allows administrators to control access to Android’s developer settings — including **Developer Options** and **Safe Boot** — on managed devices. These settings are normally used for debugging, testing, and advanced OS configuration. In an enterprise environment, restricting access can help improve device security by preventing users from enabling features like USB Debugging or other system‑level tools.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Privacy Settings → Developer Settings

#### **What This Setting Controls**

Android devices include a hidden **Developer Options** menu that grants access to advanced settings like USB debugging, animation control, hardware acceleration options, and more. In a corporate‑managed environment, allowing end users to access these options can pose security risks or undermine policy enforcement.

The **Developer Settings** dropdown in CubiLock allows you to control this behavior:

* **Unspecified** – No explicit override is applied; the default Android management behavior remains in effect.
* **Disabled** – All developer settings are **blocked**. The device user will not see or be able to enable Developer Options or Safe Boot via the system settings.
* **Allowed** – Developer settings are **permitted**. Users may see and enable Developer Options if they can access them through the Android system UI (e.g., tapping the build number).

These options map to the `developerSettings` enumeration used in the Android Management API, where:

* `DEVELOPER_SETTINGS_DISABLED` **prevents users from accessing developer settings**, and
* `DEVELOPER_SETTINGS_ALLOWED` **permits access**.

#### **Why Use Developer Settings Restrictions**

Controlling developer settings can help:

* **Prevent misuse of debugging features** such as USB debugging or secure‑boot disabling.
* **Stop unauthorized bypasses** of security controls or device lockdown measures.
* **Ensure consistency of managed policy enforcement** across all devices in an enterprise deployment.

💡 On some device types or enrollment configurations (especially personally‑owned devices), restrictions on developer settings may function differently or be limited in scope.

<figure><img src="/files/D4ekXBSPHcfcKjeeXzFD" alt=""><figcaption></figcaption></figure>


# Google Play Protect verify Apps

The **Google Play Protect Verify Apps** setting controls whether **Google Play Protect’s app verification** feature is enforced on managed Android devices.

**Google Play Protect** is a built‑in Android security service that continuously scans installed apps — including those installed from unknown sources — for malware and potentially harmful behavior. It helps prevent threats by warning users or blocking the installation of suspicious apps.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Privacy Settings → Google Play Protect Verify Apps

#### **What This Setting Does**

This policy setting corresponds to the `googlePlayProtectVerifyApps` field in the underlying Android Management API. It determines how Play Protect’s *Verify Apps* feature is applied on managed devices.

**Options available in your CubiLock UI:**

* **Unspecified** – No explicit override. Default behavior is applied, which typically means *Play Protect verification is enabled by default*.
* **Enforced** – *Google Play Protect verification is forced ON* for all managed devices. This ensures that app scanning and verification remains active at all times.
* **User Choice** – The end user is allowed to decide whether Play Protect should be enabled or disabled. This gives flexibility but may reduce security enforcement.

<figure><img src="/files/GHsqfkHwny85v1PY3Y00" alt=""><figcaption></figcaption></figure>

#### **How to Use It**

1. Navigate to the **Privacy Settings** tab in the profile editor.
2. Select **Google Play Protect Verify Apps**.
3. Choose one of the three options:
   * **Enforced** to mandate verification on all devices,
   * **User Choice** to allow users to decide, or
   * **Unspecified** to leave default Android behavior in place.
4. After selecting the desired option, click **Save** at the top right to apply the changes.


# Personal Apps Work Notification

**Personal Apps Work Notification** lets administrators control which **personal apps** are allowed to **read work profile notifications** using Android’s `NotificationListenerService`. By default, apps in the personal profile cannot receive or read notifications generated by work profile apps unless explicitly allowed. This policy setting lets you selectively permit trusted personal apps to read those work notifications.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Privacy Settings → Personal Apps Work Notification

#### **What This Setting Controls**

Android separates work profiles from personal profiles on the same device to protect corporate data and user privacy. Work profile notifications (such as messages from a corporate email app or reminders from a work calendar) are delivered separately from personal app notifications.

By default:

* **No personal apps** (aside from Android system apps) can listen for notifications generated by work profile apps.
* Work notifications are isolated from the personal profile by design for security and privacy reasons.

The `Personal Apps Work Notification` section allows you to add specific personal apps that are permitted to read work notifications using a `NotificationListenerService`. This can be useful for scenarios such as:

* Allowing a personal productivity app to consolidate notifications from work apps.
* Supporting wearable or companion apps that must display or act on work notifications.
* Enabling third‑party notification managers that require access to work profile notifications.

#### **How to Configure Personal Apps Work Notification**

1. **Open the Personal Apps Work Notification section** in the Privacy Settings tab.\
   You will see an empty list if no apps are added yet.

<figure><img src="/files/GxOpHkwBLMP71OlT57SP" alt=""><figcaption></figcaption></figure>

2. Click **Add Application** to open a searchable list of installed apps (both system and user‑installed).

<figure><img src="/files/gr3YdAIdmkBRpVprsycK" alt=""><figcaption></figcaption></figure>

3. In the **Add Application** dialog:

* Search for and select the personal app(s) that you want to allow to read work profile notifications.
* Check the box next to the app name.
* Click **Add** to include it in the list.

4. After adding the desired apps, click **Save** in the profile editor to apply these changes to the devices.

<figure><img src="/files/c4oh5qjfsKB88LeP16ED" alt=""><figcaption></figcaption></figure>

Once saved, the selected personal app(s) will be allowed to use Android’s `NotificationListenerService` to monitor and read notifications coming from work profile apps, while still respecting Android’s notification access permissions.

#### **On‑Device Behavior**

* Only the personal apps you explicitly add here will receive callbacks for work profile notifications via a notification listener.
* Other personal apps will not have access to work profile notifications, preserving separation between personal and corporate data streams.
* Devices enforce this at the OS level; developers cannot bypass this restriction without this configured allowlist.

#### **Best Practices & Considerations**

* **Minimize the number of personal apps allowed** to read work profile notifications — only add trusted apps.
* Ask app developers to use professional NotificationListenerService best practices to avoid privacy leakage and unnecessary access.
* Ensure users understand that enabling a personal app to read work notifications means that sensitive work notification content might be available to that app.


# Integrations

## Linking Work Account with Google

Overview

After migrating your enterprise to a Google-managed domain, it's essential to link the user devices to the Google Work account for better security and access control. This process ensures that only authenticated Google Workspace accounts can be used to sign in to devices. Below is a guide to configuring the necessary settings in the **Cubilock**

#### **Steps to Link Work Account with Google**

1. **Authentication Setup**:
   * In the **Google Work Account Setup Config** section, you will have two options for **Authentication Type**:
     * **Google Authenticated**: Select this option to enforce that only Google-managed accounts (Google Workspace) can be used to sign in to the device. This ensures that only users from your enterprise's Google Workspace domain can access the device.
     * **Unspecified**: If you choose this option, no specific authentication type will be enforced.
2. **Required Account Email (Optional)**:
   * If you select **Google Authenticated**, specify the **Required Account Email** field with the email address of a Google-managed enterprise account.
   * This email will be the only account allowed to sign in on the device, providing an added layer of control over who can access your company's devices.
3. **Saving and Enforcing the Configuration**:
   * Once the **Required Account Email** is set under the **Google Authenticated** option, it should only be modified once. Changing this field after the initial setup will have no effect, as the email is directly linked to the device for authentication.

<figure><img src="/files/N4UonLmMcQop35vHX5lO" alt=""><figcaption></figcaption></figure>

#### **Additional Notes**

* This configuration is only relevant for enterprises that have been migrated to use **Google Managed Domains**. For non-managed Google accounts, this feature will not be applicable.
* Make sure that the necessary admin permissions are granted to handle these configurations on the platform.


# Contact Setting

The **Contact Settings** section allows administrators to **push a curated list of contacts** directly into managed Android devices so that they appear in the device’s native phonebook automatically. This is useful for provisioning corporate directories, emergency numbers, support teams, or other key contacts that should be available to device users without manually entering them.

#### Navigation:

Device Management → Device Profiles → Edit Profile → Contact Settings

#### **What This Setting Does**

In a mobile fleet, administrators may want to ensure employees have access to important phone numbers such as help‑desk support, field team staff, emergency numbers, or shared company contacts. The **Contact Settings** UI lets you define and manage these contacts centrally so that they are **automatically added** to the device’s contacts list once the policy is applied.

Unlike sync from personal or corporate accounts, this is a **direct MDM‑driven push** of contact records to devices — the contacts get provisioned in the device address book without requiring user action.

#### **UI Overview and Steps**

**Empty Contact List**

When no contacts have been configured, the section will appear empty:

<figure><img src="/files/m68EovuudhIk9xgRMRK0" alt=""><figcaption></figcaption></figure>

#### **Add a Contact**

1. Click **Choose Contacts** to open the list of available contacts from your organization’s contact repository or directory.
2. In the selection dialog, check the desired contacts you want to push to devices.
3. Click **Add** to include them in the contact settings for this profile.

<figure><img src="/files/mBDYkvFqaRxgz9oeTn6y" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/NGrNizGNfnjVjUsSTVir" alt=""><figcaption></figcaption></figure>

#### **View and Manage Added Contacts**

Once contacts are added:

* The contact will appear in the list with columns for **Name**, **Primary Number**, **Primary Email**, and two optional flags:
  * **Set As Emergency** – Mark this contact as an emergency contact on the device.
  * **Pin to Dock** – Pin the contact for quick access on supported launchers.

<figure><img src="/files/B5b1XOQ4KSGDKTVjTgDX" alt=""><figcaption></figcaption></figure>

#### **Save Your Changes**

After adding all required contacts, click the **Save** button in the top right of the screen to commit the contact list to the device profile. This ensures that devices assigned to this profile will receive the defined contacts.

<figure><img src="/files/xTdzcj4roLrMaqNo4XY3" alt=""><figcaption></figcaption></figure>

#### **Remove Contacts**

If you need to remove a contact from the list:

1. Check the box next to the contact(s) you want to delete.
2. Click **Delete** above the list.
3. Confirm the removal in the dialog.

<div><figure><img src="/files/B0pkGyRHw2kHnXn2oSuR" alt=""><figcaption></figcaption></figure> <figure><img src="/files/rAvHnnqM2GtWtsoSOaMZ" alt=""><figcaption></figcaption></figure></div>

#### **How It Works on Device**

When the updated profile is pushed to an Android device:

* The contacts you selected will be automatically added to the **native Contacts app** and the **phonebook**, even if the user has not configured any contact sync.
* Contacts provisioned via this method appear as normal entries in the device’s address book and can be used in dialers, messaging apps, and caller ID.


# Device Enrolment


# Device Enrolment - QR Code

How to Enrol Fully Managed Devices?

{% hint style="info" %}
The QR Code Enrolment works on any Android 7+ devices.
{% endhint %}

Selecting the best enrolment method depends on your use case. There are 3 steps to enrol an Android device in a fully-managed mode with CubiLock:

1. Factory reset device
2. Get the QR code
3. Enrol the device

{% embed url="<https://www.youtube.com/watch?v=I4D2r2ro89Q>" %}

### Step 1: Factory Rest Device&#x20;

Follow the steps below to factory reset your Android device:

1. Make sure the device is plugged in or has enough battery to go through the reset process.
2. Open the **Settings** app.
3. Select **System**.
4. Expand the menu by hitting **Advanced**.
5. Go into **Reset options**.
6. Hit **Erase all data (factory reset)**.
7. Tap on **Erase all data**.
8. Enter your PIN (if prompted).
9. Select **Erase all data** and let the phone do its thing.

### Step 2: Get the QR code

For a quick enrolment method follow the steps below:

1. From the **Device Management** section, go to **Device Profile** page&#x20;
2. Click on the profile name you want to enrol your device with
3. Use the **QR Code** provided on the **Device Profile** screen&#x20;

![](/files/wEwAgwU9t6A48DMqoNiA)

{% hint style="info" %}
The QR has a validity of 30 days. To create a new one, simply click on **Refresh QR Code** button.
{% endhint %}

### Step 3: Enrol the Device

The final step is to scan the **QR Code** and start the enrolment process. The process is straightforward and does not require any technical expertise.

1. Make sure the device is factory reset
2. Tap 6 times on the **Welcome** screen
3. Select your **WiFi** and enter the password to connect
4. Click on **Accept & Continue** and wait for Android to finish setup

<div align="center"><img src="/files/-MB37t8NebGy-Lr5R9aI" alt="Tap 6 times on Welcome Screen"></div>

![Select your WiFi and enter password to connect](/files/-MB3ADuTGQs2d1dYvnlQ)

![Click on Accept & Continue to initiate enrolment process](/files/-MB3AOS1T2rIBvvzyyYx)

![The Google PlayStore will be downloaded and installed on a device](/files/-MB3Ac89Zd0DnWWANVTL)

![At this step your organization's policies will be applied on to the device](/files/-MB3AtjeT64R_B-5LZ0c)

![At this step, the device is downloading all the necessary apps to function properly](/files/-MB3BMzp9QpN4dHtoqVn)

![Grant all the permissions requested bu the KIOSK app, as all these permissions are necessary for the KIOSK app to function](/files/-MB3B_9h4Bnd-NzwJDxX)

**Congratulations!** you have successfully enrolled an Android device with CubiLock.

{% hint style="info" %}
On the Android factory-reset home screen, tap 6 times anytime on the screen. If that does not work, set up your device as a new device, and when prompted to input your email address, input this code: **afw#setup**. This will launch the Android Enterprise setup.
{% endhint %}


# Device Enrolment - NFC

{% hint style="info" %}
The enrolments by NFC for fully managed devices works on any Android OS 6.0 or above.
{% endhint %}

You can use NFC provisioning method to set up a device in a device owner mode. In the NFC provisioning method, or NFC bump, you create an NFC programmer app that contains the initial policies, Wi-Fi configuration, settings, and provisioning details required to configure the device owner mode of operation. When you or your customer installs the NFC programmer app on an Android device, that device becomes the programmer device.

To provision a device, the IT admin takes a new device out of the box and bumps it against the programmer device. The bump transfers configurations to the device, so it connects to the Internet and downloads the appropriate policies and settings.

After a device is provisioned, for a short time Google Play displays unmanaged consumer content instead of the approved apps and collections that should display. This delay can last from a few minutes up to an hour.

### Provision a Customer Device

1. Download the **CubiLock NFC** app from PlayStore.
2. Install the **CubiLock NFC** on the device that will be a programmer device.
3. From your CubiLock console, scan the **QR code** of the profile you wish your devices to enrol with. This will fetch all the details of that profile including WiFi SSID, WiFi security, WiFi password and Enrolment token.
4. Bump the programmer device with a new device or the one that has been factory reset.
5. Verify that the device remains on the initial **Welcome** screen that’s displayed when it starts. The text is specified in `Tap to beam:{...}` in the programmer app.
6. Wait while the Android Device Policy Controller:
   1. Encrypts the device.
   2. If it’s a Code-Division Multiple Access (CDMA) device: Activates the phone while a telephony user interface is shown (no interaction required).
   3. Sets up the Wi-Fi connection.
   4. Apply your specified policies.
   5. Installs required applications for setup to complete
7. After the setup completes, you will be navigated to the **CubiLock Kiosk** app where you will be able to see all the apps whitelisted for the profile you enrolled with.

![On first launch you will be taken to on-boarding screen to guide you through the NFC enrolment process. You can either skip or continue watching the tutorial](/files/-MBh7RN0g_okN4-CMaqf)

![Once you are done with on-boarding, you will be navigated to configurations screen where you can add configurations by scanning the QR code present on Device Enrolment screen on your CubiLock console](/files/-MBh7RN3yG-3fmGsaOWx)

![Scan the QR code provided on Device Enrolment screen of your profile to fetch configurations. You can also enter all the details manually by simply taping on Enter Manually button at the bottom of the screen. This will take you to configuration details screen where you will be able to add all the details manually](/files/-MBh7RN49MSaKM3c2ta3)

![Once scanned, all the configuration details will be presented to you. Verify or fill in the missing details and press Start Enrolment button to continue enrolling your devices ](/files/-MBh7RN5s5krlt2aJe4C)

![At this stage your programmer device is ready. To provision a device, takes a new device out of the box and bump it against this device](/files/-MBh7RN6zC7ZnI2nay_m)

![Once you bump both device, it will ask for Tap to beam, tap on the screen once to transfer all the configurations to a new device](/files/-MBh7RN7vvQqYBP_OFls)

![The configurations will be save for you to use in future. You can simply tap on the store configuration to start NFC enrolment](/files/-MBh7RN88oJ3VSg2-jxO)

![You can also Edit or Delete the stored configuration](/files/-MBh7RN9RQ8IKkJYLEup)

![Upon clicking on Edit icon, you will be taken to configuration details screen where you can edit its details and start enrolment if you want](/files/-MBh7RN5s5krlt2aJe4C)

![You can also delete the stored configurations by simply clicking on Delete icon. It will ask you for your confirmation and once confirmed, the configuration will be deleted permanently](/files/-MBh7RNAzt32wAhJLLEo)

### **Additional Resources**

[Advanced NFC](http://developer.android.com/guide/topics/connectivity/nfc/advanced-nfc.html) describes advanced NFC topics, such as working with various tag technologies, writing to NFC tags, and foreground dispatching.


# Device Enrolment - DPC identifier method

If Android Device Policy can't be added via QR code or NFC a user or IT admin can follow these steps to provision a fully managed or dedicated device:

1. Follow the setup wizard on a new or factory-reset device.
2. Enter Wi-Fi login details to connect the device to the internet.
3. When prompted to sign in, enter **afw#setup**, which downloads Android Device Policy.
4. Scan a [QR code](https://developers.google.com/android/management/provision-device#using_qr_codes) or manually enter an enrolment token to provision the device.


# Device Enrolment - Sign-in URL

In order to enrol using Sign in URL

From your CubiLock console:

1. Head over to **Global enrolment**.
2. From your **Factory resetted** device, tap on the screen 7 times to open QR reader.
3. **Scan** the Global enrolment QR code.
4. Enter Wi-Fi details and wait for the setup to finish.
5. On the Sign in page, enter the Sign in credentials provided to you by your IT Admin.

![](/files/-MHAck7bjasil_u9N8qg)


# Bulk Registration - CSV

You can register devices into CubiLock before enrolling them, if you wish. This allows you to keep track of which devices you still need to enrol.

From your CubiLock console:&#x20;

1. Go to the **Device List** page, under **Device Management**
2. Click on the button **Import Devices** at the top right corner
3. **Download** the CSV template, and fill it in with your device **Serial Numbers** and the associated CubiLock profile
4. **Upload** your CSV into your console

All of the devices you have registered will appear in your **Device List**, having the state `Registered`.

Once a device has been enrolled and wiped, it still appears as `Registered` in the console. You can unregister a device by selecting it and clicking on the **Delete** button (found in the context menu).

![](/files/-MB3CzZzdncozQmoQCNA)


# Send a Broadcast Message

Users of the CubiLock console can send messages with push notifications to enrolled devices.

### How to Send a Broadcast Message to Specific Group:

From your CubiLock console:

* From the menu, go to the **Broadcast Message** page
* Click on the **Broadcast** button at the top right corner of the screen
* Specify the title and content of your message
* Go to **Groups** tab to select a particular group
* Click **Broadcast,** a notification will be sent to all the devices in a  selected group

### How to Send a Broadcast Message to Specific Profile:

From your CubiLock console:

* From the menu, go to the **Broadcast Message** page
* Click on the **Broadcast** button at the top right corner of the screen
* Specify the title and content of your message
* Go to **Profile** tab to select a particular profile
* Click **Broadcast,** a notification will be sent to all the devices in a selected profile

### How to Send a Broadcast Message to Specific Device:

From your CubiLock console:

* From the menu, go to the **Broadcast Message** page
* Click on the **Broadcast** button at the top right corner of the screen
* Specify the title and content of your message
* Go to **Device** tab to select a particular device
* Click **Broadcast,** a notification will be sent to a selected device

<figure><img src="/files/dLKzkfcOook8T3kSjYi2" alt=""><figcaption></figcaption></figure>


# Remotely Lock Screen

A device which has been **Screen Off**-ed goes to its lock screen - meaning the user of the device will need to enter a password to access the device (if a password has been defined).&#x20;

### How to Remotely Turn off the Device Screen:

From your CubiLock dashboard:

1. Go to the **Device list** tab, under **Device Management**
2. Click on a device **Serial Number** to open device details
3. On the top-right of the page, click on **Lock** under the **Actions** drop-down menu

<figure><img src="/files/auU7Awz6ms653rW7t0qj" alt=""><figcaption></figcaption></figure>

&#x20;

<figure><img src="/files/ER1HuoI9iQ30tPZW86Qk" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1dQagrEARG5JTQuADshr" alt=""><figcaption></figcaption></figure>


# Reset Device Password

If an employee forgets his device lock screen password, the CubiLock admin can remotely reset the password from the console.

### To Reset a Device Password:

From your CubiLock dashboard:

1. Go to the **Device List** page, under **Device Management**
2. Click on a device **Serial Number** to open device details
3. On the top-right of the page, click on **Reset Password** under the **Actions** drop-down menu
4. Click on **Save** to initiate **Reset Password** command

<figure><img src="/files/oja4QHDFnLnUaHdhGbd5" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/xTRObsqQU7VO7FG3i8JY" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Od66xMI2cWh9HPjxBoDm" alt=""><figcaption></figcaption></figure>


# Remotely Reboot a Device

### To Reboot a Device Remotely:

From your CubiLock dashboard:

1. Go to the **Device List** page, under **Device Management**
2. Click on a device **Serial Number** to open device details
3. On the top-right of the page, click on **Reboot** under the **Actions** drop-down menu
4. Click on **Save** to initiate **Reboot** command

<figure><img src="/files/ytrq6CxCCu9s5WhHWyo1" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/1rugRMiJo9NY5rku6Kxn" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/aWfZALfVgSZi6UU1bWOm" alt=""><figcaption></figcaption></figure>


# Remotely Block/Unblock a Device

### To Block/Unblock a Device Remotely:

From your CubiLock console:

1. Go to the **Device List** page, under **Device Management**
2. Click on a device **Serial Number** to open device details
3. On the top-right of the page, click on **Block** under the **Actions** drop-down menu
4. Click on **Save** and **Confirm** to block a device.
5. On the top-right of the page, click on **Unblock** under the **Actions** drop-down menu
6. Click on **Save** and **Confirm** to unblock a device.

<figure><img src="/files/5hOOdk8Hbk5cNamZlpEY" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/jll9RL0bPA3aBDrgpCnD" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/9XKstuazkv0Q6ClKjh1d" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Gaem6to63vUy67A0wKrr" alt=""><figcaption></figcaption></figure>


# Remotely Factory Reset

**Wiping** a device means deleting all of its data, and doing a factory reset. This is a good solution when a device is reported as stolen, or is at its end of life.

### To Remotely Wipe a Device:

From your CubiLock dashboard:

1. Go to the **Device List** page, under **Device Management**
2. Click on a device **Serial Number** to open device details
3. On the top-right of the page, click on **Factory Reset** under the **Action** dropdown menu
   1. (Optional) Wipe eSIM Data      \
      After selecting Factory Reset, a Wipe eSIM data checkbox will appear. If enabled, all eSIM profiles stored on the device's embedded SIM will also be erased during the factory reset.
4. The device will go the factory reset

{% hint style="info" %}
Warning: Once initiated, this action cannot be reversed. All data on the managed device will be deleted.
{% endhint %}

<figure><img src="/files/yIWsTAJ987uoTcKgtYh9" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/mYqzzmaskQe47geLOzco" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/Q0FOzyT5zA3SEcZC3SbN" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/H0GGbbmnZFXQDRoFJI6a" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/sMwpo2hqbB5Voicrwy55" alt=""><figcaption></figcaption></figure>


# Remove Device (Factory Reset)

CubiLock allows you to delete devices from your enterprise in few simple steps.

### To Delete Device:

From your CubiLock dashboard:

1. Navigate to **Devices** from side menu.
2. Here you can see all devices added to your enterprise. Click on the three dot **menu** next to the device you wish to delete.
3. Click on **Delete** and confirm to remove the device.

Or

1. Navigate to **Devices** from side menu.
2. Here you can see all devices added to your enterprise. Click on the **Device Serial** of the device you wish to delete.
3. Click on **Delete** and confirm to remove the device.

<figure><img src="/files/oZRJoW6HfaEGQ0sxRd1v" alt=""><figcaption></figcaption></figure>

<figure><img src="/files/AToH4nc4nYtLndBwNU5w" alt=""><figcaption></figcaption></figure>

&#x20;

<figure><img src="/files/InWy69umrE76UJJvWSZF" alt=""><figcaption></figcaption></figure>


# How to Create a Group

CubiLock provides easy access to handle multiple devices by adding them in a **Group**. A Group is a virtual collection of multiple devices and a profile. This helps in defining better roles for your enterprise for example creating an **Admin** group and adding all devices in that group to automatically use the profile defined against **Admin** group, later if the profile is desired to be changed instead of changing on all devices - a simple change in Group will update all devices.

### To Create Group:

From your CubiLock console:

1. Navigate to **Device Groups** from side menu.
2. Click on **Add Group** and enter a **name** for the group. Here you should also **select the profile** you want to apply for all the devices in the group.
3. Click on **Submit** and your group will be created.

![Device Groups accessible from side menu](/files/SKgABwl7vvBPRkTQi83W)

![Click on + Create Group button to create a new group](/files/3IqrTTV1yEBCxbP8ZDxO)

![Add Group by giving it name and assigning it a profile](/files/39l356bYiXo2ifjCXHPy)


# Managing Devices in Group


# Add Device

### To Add Device(s):

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name to open group details or the three dot **Menu** and **Edit** to modify the group.
3. Here you will be able to see all devices added in the current group. To add new device click on **Add Devices**.
4. **Select** the device(s) from the list of enrolled devices and press **Submit**.
5. Your selected device(s) will be added to the group and you will be able to view it.

![Edit option available in three dot menu](/files/JiUVDOo9PPEuddEzlxEY)

![Add Devices available in group](/files/aCtmhgP1GYO370QAQ3Hz)

![Select device(s) to add to group](/files/gmZU73WhORhluY7wAMuC)

![Device will be visible in the group list](/files/K1oz2CwvAOZhhI1Wkx0H)


# Find Device

### To Find Device in Group:

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name or the three dot **Menu** and **Edit** to open group details.
3. Under the Devices tab, use the search text bar to enter Device Name.
4. Press enter or click the search icon next to search text bar to filter out devices matching entered device name.

![Edit option available in three dot menu](/files/5U9fdx1RGLNnB8jbqT11)

![Click on the search icon after entering a keyword](/files/KdL1LkYMLPbnXBgOISM7)


# Remove Device

### To Remove Device(s):

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name to open group details or the three dot **Menu** and **Edit** to modify the group.
3. Here you will be able to see all devices added in the current group. To remove a device click on the three-dot **menu** in front of it and click **Remove Device**.
4. **Confirm** that you want to remove it from the group.
5. Your selected device(s) will be removed from the group.

{% hint style="info" %}
Removing a device from group does not remove it from the enterprise
{% endhint %}

![Edit option available in three dot menu](/files/EwJkxGNpR3S5mPXr0u35)

![Select remove device from menu](/files/v1XOaw7mBgeazunjBHsz)

![Confirm for device removal from group](/files/-MFUF5TRsuaIjsMK5gl6)


# Changing Profile for Group

Groups make it easier to manage multiple devices without much hassle. This allows for more control over devices like changing profiles for the entire group in a few simple steps.

## To Change Profile:

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name to open group details or the three dot **Menu** and **Edit** to add modify the group.
3. Select the **drop-down** to reveal a list of all profiles available in your enterprise.
4. Select the **Profile** you wish to apply to the group.
5. Click **Save** and **Confirm** changes for them to be applied.

![Edit option available in three dot menu](/files/EwJkxGNpR3S5mPXr0u35)

![Click on drop down to reveal all profiles and hit save](/files/A1ZaL1EgzGV0AraCQFI1)

![Confirm changes to reflect](/files/1WxGf09nMBLZHF4gop22)

&#x20;


# Subgroups

CubiLock further improves on Groups by providing **Sub Groups** within a Group or other Sub Groups. This allows enterprises to keep a logical hierarchy for example, for an **Admin** group some devices should be promoted to **Super Admin** devices with fewer restrictions meanwhile others should be **Regular Admin** devices. This is possible using Sub Groups without any hassle.

### Create Sub Groups:

From your CubiLock console:

1. Navigate to **Device Groups** using the side menu.
2. Click the group name to open group detail or the three-dot **Menu** and **Edit** to modify the group.
3. From here click on **Sub Groups** tab and click on **Add Subgroup**.
4. Enter the subgroup name and select a profile to associate with the subgroup.
5. Click **Submit** to create a subgroup.

### Add Device in Sub Group:

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name to open group details or the three dot **Menu** and **Edit** to modify group.
3. In the **Sub Groups** tab, click on the sub group name to open sub group details or click the three dot **Menu** and **Edit** to modify sub group.
4. From sub group detail click on **Add Devices**.
5. Select device(s) from the list of available devices and click **Submit**.
6. Your selected device(s) will be added to the sub group and you will be able to view it.

### Finding Device from Sub Group:

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name or the three dot **Menu** and **Edit** to open group details.
3. In the **Sub Groups** tab, click on the sub group name or click the three dot **Menu** and **Edit** to open sub group details.
4. Under the Devices tab, use the search text bar to enter Device Name.
5. Press enter or click the search icon next to search text bar to filter out devices matching entered device name.

### Remove Device from Sub Group:

From your CubiLock console:

1. Navigate to **Device Groups** using side menu.
2. Click the group name to open group details or the three dot **Menu** and **Edit** to modify group.
3. In the **Sub Groups** tab, click on the sub group name to open sub group details or click the three dot **Menu** and **Edit** to modify sub group.
4. Here you will be able to see all devices added in the current sub group. To remove a device click on the three dot **Menu** in front of it and click **Remove Device**.
5. **Confirm** that you want to remove it from the sub group.
6. Your selected device(s) will be removed from the sub group.

{% hint style="info" %}
Deleting **Sub Group** does not remove devices from the enterprise. The devices retain the last applied Device Profile.
{% endhint %}




---

[Next Page](/llms-full.txt/1)

