Limit the apps that can run on a device

You can limit the use of a device to a single app or a set of apps using an app lock mode profile. For example, you can use an app lock mode profile to limit devices to run only one app for training purposes or for point-of-sales demonstrations. On iOS devices, the home button is disabled and the app automatically opens when the user reboots the device or wakes it.

If the user does not install the app on a device, when you assign the profile to a user or user group the device is not restricted to the app.

You need the app package ID of the app, or if you plan to use the app list to select an app, make sure that the app is available in the app list.
  1. In the management console, on the menu bar, click Policies and profiles > Policy > App lock mode.
  2. Click The Add icon.
  3. Type a name and description for the profile.
  4. Specify the device types the profile applies to.
  5. Perform one of the following tasks:

    Task

    Steps

    Specify the app to run on supervised iOS devices.

    In the Specify the app to run on the device section, perform one of the following actions:
    • Click Select an app from the app list, click Add an app, and click an app in the list.
    • Click Specify the app package ID of an app and type the app package ID (for example, <com.company.appname>). Valid characters are uppercase and lowercase letters, 0 to 9, hyphen (-), and period (.).
    • Click Select a built-in iOS app and select an app from the drop-down list.

    Specify the apps to run on Android devices (Android Enterprise and devices managed using Samsung Knox MDM).

    Click The Add icon and do the following to specify the apps that you want to limit the device to:

    • Click Specify the app package ID of an app and type the app package ID (for example, <com.company.appname>) and the name of the app. Valid characters are uppercase and lowercase letters, 0 to 9, hyphen (-), and period (.). Click Add.
    • Click Select an app from the app list, and click an app in the list. Click Add.

    For Android Enterprise devices, if you want to limit the device to a specific app, click Limit device to a single app and select the app. The app that you specify in this setting automatically opens when the device starts and the user always returns to it. The app can access the other apps that you specify in the profile when it is required.

    Specify the app to run on Windows devices.

    • In the Account field, type a user account name that includes the domain name and user name. For a local user, use the device name in place of the domain name.
    • In the Application User Model ID field, type the AUMID of the app (for example, the AUMID for the Calculator app is Microsoft.WindowsCalculator_8wekyb3d8bbwe!App.
  6. For iOS and Android devices, in the Administrator-enabled settings, select the options that you want to enable for the user when using the app.
  7. For iOS devices, in the User-enabled settings, select the options that the user can enable.
  8. Click Add.
If necessary, rank the profiles.