Citrix Endpoint Management

App permissions device policy

For Android Enterprise apps that are within work profiles: You can configure how requests to those apps handle what Google calls “dangerous” permissions. You control whether the user is prompted to grant or deny the permission request from the app. This feature applies to devices running Android 7.0 and later.

Google defines dangerous permissions as permissions that:

  • Give the app access to data or resources that involve the user’s private information.
  • Or, can potentially affect the user’s stored data or the operation of other apps. For example, the ability to read user contacts is a dangerous permission.

You can configure a global status to control the behavior of all dangerous permission requests. The scope of this configuration is Android Enterprise apps that are within work profiles. You can also control the behavior of a dangerous permission request for individual permission groups, as defined by Google, for each app. These individual settings override the global status.

For information on how Google defines permission groups, see the Android developers guide.

By default, users are prompted to grant of deny dangerous permission requests.

To add or configure this policy, go to Configure > Device Policies. For more information, see Device policies.

Android Enterprise settings

Device Policies configuration screen

  • Global State: Controls the behavior of all dangerous permission requests. In the list, click Prompt, Grant, or Deny.
    • Prompt: Users are prompted to grant or deny dangerous permission requests.
    • Grant: All dangerous permission requests are granted. The user isn’t prompted.
    • Deny: All dangerous permission requests are denied. The user isn’t prompted.

    Default is Prompt.

  • Set an individual behavior for each permission group, for each app. To configure the behavior for a permission group: Click Add. Then under App, choose an app from the list. If you configure Android Enterprise system apps, click Add new and enter the application package name you enabled in the Restrictions device policy. Under Grant Status, choose Prompt, Grant, or Deny. This grant status overrides the global status.
    • Prompt: Users are prompted to grant or deny dangerous permission requests from this permission group for this app.
    • Grant: Dangerous permission requests from this permission group for this app are granted. The user isn’t prompted.

      Note:

      For the devices enrolled in the Profile Owner mode, Grant permission isn’t applicable for Camera, Location, Microphone, and Sensor if the device is running on Android 12 or later.

    • Deny: Dangerous permission requests from this permission group for this app are denied. The user isn’t prompted.

    Default is Prompt.

  • Click Save next to the app and grant status.
  • To add more apps for the permission group, click Add again and repeat these steps.
  • When you have finished setting the Grant Status for permission groups, click Next.
App permissions device policy