Feature Control (Android Enterprise Work Profile)

Use this dialog box to configure individual device features when:

Device Functionality

Features

Allow Camera When enabled, device user can use the camera.
Note: If disabled, SOTI MobiControl prevents all apps in the Work profile from launching the camera.

Android OS compatibility: 6.0 or later.

Allow Screen Capture When enabled, device users can save images or recordings of the device's display.
Allow Smart Lock When enabled, device users can use Smart Lock on Android which enables devices to unlock without a password when they are within 'safe' places that the device user sets.

If you enable Allow All Keyguard Features feature control option, Allow Smart Lock is automatically enabled too.

Android OS compatibility: 6.0 or later.

Allow Printing When enabled, device users can use the device's printing capabilities.

Requires Android 9.0 or later.

Settings

Allow Location Sharing for Work Profile When enabled, you can Location Sharing for all Managed Profile apps. Apps running in the Work profile are unable to use device location information.
Allow Skip App First Use Hints When enabled, when a supported app launches for the first time, it skips any introductory hints or tutorials.
Note: Not available on Android 11 COPE devices.

Security

Security

Allow All Keyguard Features When enabled, device users can use keyguard features on the lockscreen. Keyguard features include fingerprint authentication, viewing of notifications, smart lock access and camera access. Enabling Allow All Keyguard Features automatically enables the other keyguard feature control options.
Allow Fingerprint Authentication When enabled, device users can use Google's fingerprint authentication framework to secure their devices.

If you enable the Allow All Keyguard Features feature control option, Allow Fingerprint Authentication automatically enables too.

Android OS compatibility: 6.0 or later.

Allow Account Creation Specify whether device users can add new accounts to the device. Choose an option from the list:
  • All: enables the creation of any type of account, Google accounts included. Selected by default.
  • All Accounts except Google Account: enables the creation of non-Google accounts
  • No Accounts: prevents device users from creating any new accounts on the device

This does not remove any existing accounts from the device.

Allow Doze Mode When enabled, the device can restrict the SOTI MobiControl Android Device Agent for battery optimization.
Note: Disabling this option negates any battery optimizations provided by doze mode and uses extra battery power to stay connected.
Always On VPN Direct all network traffic on the device through a specified VPN.

Enter the package name of the VPN app.

Allow Verify Apps Enforcement When enabled, the device user can change the Scan device for security threats option within the Play Protect settings of the Google Play Store.
Perform SafetyNet Check on Device Check-in When enabled, the device performs the SafetyNet check at every device check in, in addition to once daily.

Data Protection

Allow Copy/Paste between Work and Personal When enabled, device users can copy text or images between the Work and Personal profiles.
Allow Sensitive Notifications When enabled, notifications from Android Enterprise Apps display all their details when they appear on secure lock screens.

If you enable Allow All Keyguard Features feature control option, Allow Sensitive Notifications automatically enables too.

Android OS compatibility: 6.0 or later.

Allow Uninstallation of Managed Applications When enabled, device users can uninstall any managed applications.
Allow Third Party Input Methods When enabled, device users can enable third-party input methods such as keyboards on their devices.
Allow Caller ID Information for Work Profile Contacts When enabled, device user can see Caller ID information for calls from contacts saved within the Work profile.
Allow Installation from Unknown Sources When enabled, device users can install apps that are not from the Google Play store.
Allow Installation from Unknown Sources on Personal When enabled, device users can install apps that are not from the Google Play store on the personal profile of the device.

Supported on Android 10.0 or later.

Allow Sharing from Work Profile to Personal When enabled, device users can use an app's Share function to share between apps on the Work profile to apps on the Personal profile.

Android OS compatibility: 5.1.1 or later.

Allow Outgoing NFC When enabled, devices users can use NFC to send data (only applies to apps in the Work Profile).
Allow Bluetooth Contact Sharing When enabled, device users can use Bluetooth to share contact information.

Android OS compatibility: 6.0 or later.

Allow Backup Service When enabled, device users can turn control whether the backup service (which managers both backup and restore services) is turned on or off.

Policy Messaging

Restriction Policy

Enter the message that should appear to device users when they try to perform an action blocked by feature control.

Note: If you leave this field empty, the following default message appears to device users: This action is disabled by SOTI MobiControl. Contact your organization's administrator to learn more.

Android OS compatibility: 7.0 or later.

Device Admin Description

Enter the description that should appear if the user presses the more prompt on the restriction policy.

Android OS compatibility: 7.0 or later.

Work Profile Wipe Message

Enter the message that should appear to device users when the Android Work Profile is wiped of its data and removed from the device.

Android OS compatibility: 9.0 or later.